{"id":70,"date":"2023-08-04T23:39:24","date_gmt":"2023-08-04T15:39:24","guid":{"rendered":"https:\/\/meiyitou.top\/?p=70"},"modified":"2023-08-04T23:39:25","modified_gmt":"2023-08-04T15:39:25","slug":"sqlmap%e7%9a%84%e5%ae%89%e8%a3%85%e4%b8%8e%e5%b8%b8%e8%a7%81%e7%9a%84%e5%91%bd%e4%bb%a4","status":"publish","type":"post","link":"https:\/\/meiyitou.top\/index.php\/2023\/08\/04\/sqlmap%e7%9a%84%e5%ae%89%e8%a3%85%e4%b8%8e%e5%b8%b8%e8%a7%81%e7%9a%84%e5%91%bd%e4%bb%a4\/","title":{"rendered":"sqlmap\u7684\u5b89\u88c5\u4e0e\u5e38\u89c1\u7684\u547d\u4ee4"},"content":{"rendered":"\n<p>sqlmap \u7b80\u4ecb<br>sqlmap \u662f\u4e00\u4e2a\u81ea\u52a8\u5316\u7684 SQL \u6ce8\u5165\u5de5\u5177\uff0c\u4e3b\u8981\u529f\u80fd\u662f\u626b\u63cf\u3001\u53d1\u73b0\u5e76\u5229\u7528\u7ed9\u5b9a url \u7684 sql \u6ce8\u5165\u6f0f\u6d1e\uff0c\u5185\u7f6e\u4e86\u5f88\u591a\u7ed5\u8fc7\u63d2\u4ef6\uff0c\u652f\u6301\u7684\u6570\u636e\u5e93\u662f MySQL\u3001Oracle\u3001PostgreSQL\u3001Microsoft SQL server\u3001Microsoft Access\u3001IBM DB2\u3001SQLite\u3001Firebird\u3001Sybase \u548c SAP MaxDB\u3002<br>sqlmap \u91c7\u7528\u7684 sql \u6ce8\u5165\u6280\u672f\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li>-\u57fa\u4e8e\u5e03\u5c14\u7c7b\u578b\u7684\u76f2\u6ce8\u3002\u53ef\u4ee5\u5de5\u5177\u8fd4\u56de\u9875\u9762\u5224\u65ad\u6761\u4ef6\u771f\u5047\u7684\u6ce8\u5165\u3002<\/li>\n\n\n\n<li>-\u57fa\u4e8e\u65f6\u95f4\u7684\u76f2\u6ce8\u3002\u4e0d\u80fd\u5de5\u5177\u9875\u9762\u8fd4\u56de\u5185\u5bb9\u5224\u65ad\u4efb\u4f55\u4fe1\u606f\uff0c\u8981\u7528\u6761\u4ef6\u8bed\u53e5\u67e5\u770b\u65f6\u95f4\u5ef6\u8fdf\u8bed\u53e5\u662f\u5426\u88ab\u6267\u884c\u6765\u5224\u65ad\u3002<\/li>\n\n\n\n<li>\u57fa\u4e8e\u62a5\u9519\u6ce8\u5165\u3002\u9875\u9762\u4f1a\u8fd4\u56de\u9519\u8bef\u4fe1\u606f\uff0c\u6216\u8005\u628a\u6ce8\u5165\u7684\u8bed\u53e5\u7ed3\u679c\u76f4\u63a5\u8fd4\u56de\u5230\u9875\u9762\u4e2d\u3002<\/li>\n\n\n\n<li>\u8054\u5408\u67e5\u8be2\u6ce8\u5165\u3002\u53ef\u4ee5\u4f7f\u7528 union \u7684\u60c5\u51b5\u4e0b\u7684\u6ce8\u5165\u3002<\/li>\n\n\n\n<li>\u5806\u67e5\u8be2\u6ce8\u5165\u3002\u53ef\u4ee5\u6267\u884c\u591a\u6761\u8bed\u53e5\u65f6\u7684\u6ce8\u5165\u3002<\/li>\n<\/ol>\n\n\n\n<p>sqlmap \u7684\u5b89\u88c5<br>sqlmap \u7684\u5b89\u88c5\u9700\u8981 python \u7684\u73af\u5883\uff0c\u5e76\u4e14\u4e0d\u652f\u6301 python3 \uff0cpython2 \u53ef\u76f4\u63a5\u5230\u641c\u7d22\u4e0b\u8f7d\u5b89\u88c5\u3002<br>\u5982\u679c\u5df2\u7ecf\u88c5\u4e86 python3 \u4e0d\u60f3\u5378\u8f7d\uff0c\u53ef\u4ee5\u6709\u4e24\u8005\u517c\u5bb9\u7684\u65b9\u6cd5\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong><\/strong><strong><\/strong><code>https:\/\/blog.csdn.net\/Goodric\/article\/details\/115646211?spm=1001.2014.3001.5501\n<\/code><\/pre>\n\n\n\n<p>sqlmap\u5b98\u7f51\u4e0b\u8f7d \uff1a<a rel=\"noreferrer noopener\" href=\"http:\/\/sqlmap.org\/\" target=\"_blank\">http:\/\/sqlmap.org\/<\/a><br>\u70b9\u51fb\u4e0b\u8f7d\u538b\u7f29\u5305\u3002<br><img decoding=\"async\" src=\"https:\/\/lmboke.com\/upload\/2023\/07\/%E5%9B%BE%E7%89%87-1690649477660.png\" alt=\"\u56fe\u7247-1690649477660\"><br>\u5c06\u6587\u4ef6\u89e3\u538b\u5728 python \u7684\u5b89\u88c5\u8def\u5f84\u4e0b\u3002<br>\u5982\u6211\u7684\u662f\u5728 E \u76d8\u7684 Python27 \u6587\u4ef6\u5939\u4e0b\u3002<br><img decoding=\"async\" src=\"https:\/\/lmboke.com\/upload\/2023\/07\/%E5%9B%BE%E7%89%87-1690650586861.png\" alt=\"\u56fe\u7247-1690650586861\"><br>\u7136\u540e\u8fdb\u5165sqlmap\u76ee\u5f55\u4e0b\uff0c\u6267\u884ccmd\u547d\u4ee4<br>\u4e3a\u4e86\u65b9\u4fbf\uff0c\u6211\u4eec\u53ef\u4ee5\u5728\u684c\u9762\u53f3\u952e\u521b\u5efa\u4e00\u4e2a\u5feb\u6377\u65b9\u5f0f\u3002<br>\u5bf9\u8c61\u4f4d\u7f6e\u586b\u5199 cmd \u3002<br><img decoding=\"async\" src=\"https:\/\/lmboke.com\/upload\/2023\/07\/%E5%9B%BE%E7%89%87-1690649716158.png\" alt=\"\u56fe\u7247-1690649716158\"><br><img decoding=\"async\" src=\"https:\/\/lmboke.com\/upload\/2023\/07\/%E5%9B%BE%E7%89%87-1690649750056.png\" alt=\"\u56fe\u7247-1690649750056\"><br><img decoding=\"async\" src=\"https:\/\/lmboke.com\/upload\/2023\/07\/%E5%9B%BE%E7%89%87-1690649765430.png\" alt=\"\u56fe\u7247-1690649765430\"><br>\u8fd9\u6837\u70b9\u51fb\u5feb\u6377\u65b9\u5f0f\u5c31\u5df2\u7ecf\u5728\u8def\u5f84\u4e0b\u4e86\uff0c\u4e0d\u7528\u6bcf\u6b21 cd \u8fdb\u5165\u6587\u4ef6\u8def\u5f84\u3002<br>\u7136\u540e\u8f93\u5165\u547d\u4ee4\uff1a<a rel=\"noreferrer noopener\" href=\"http:\/\/sqlmap.py\/\" target=\"_blank\">sqlmap.py<\/a><br>\u53ef\u4ee5\u770b\u5230 sqlmap \u6210\u529f\u8fd0\u884c\u4e86\u3002<br>\u6211\u8fd9\u91cc\u56e0\u4e3a\u540c\u65f6\u88c5\u4e86 python2 \u548cpython3 \uff0c\u6240\u4ee5\u9700\u8981\u5728\u8bed\u53e5\u524d\u52a0\u4e0a python2 \uff0c\u4e0d\u7136\u7cfb\u7edf\u65e0\u6cd5\u81ea\u5df1\u8bc6\u522b\u3002<br>\u6240\u4ee5\u540e\u9762\u7684\u547d\u4ee4\u6d4b\u8bd5\u90fd\u5728\u524d\u9762\u52a0\u4e86 python2 \uff1b\u5982\u679c\u53ea\u88c5\u4e86\u4e00\u4e2a python2 \u800c\u6ca1\u6709\u88c5 python3 \uff0c\u5c31\u53ef\u4ee5\u4e0d\u7528\u52a0\uff0c\u76f4\u63a5\u00a0<a rel=\"noreferrer noopener\" href=\"http:\/\/sqlmap.py\/\" target=\"_blank\">sqlmap.py<\/a>\u00a0\u540e\u9762\u63a5\u547d\u4ee4\u3002<br><\/p>\n\n\n\n<p><img decoding=\"async\" src=\"https:\/\/lmboke.com\/upload\/2023\/07\/%E5%9B%BE%E7%89%87-1690650430976.png\" alt=\"\u56fe\u7247-1690650430976\"><\/p>\n\n\n\n<p>sqlmap\u5e38\u89c1\u6307\u4ee4<br>1\u3001\u6ce8\u5165\u516d\u8fde\uff1a<\/p>\n\n\n\n<ol class=\"wp-block-list\">\n<li><a href=\"http:\/\/sqlmap.py\/\" target=\"_blank\" rel=\"noreferrer noopener\">sqlmap.py<\/a>&nbsp;-u \u201c<a href=\"http:\/\/www.xx.com\/?id=x\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/www.xx.com?id=x<\/a>\u201d \u3010\u67e5\u8be2\u662f\u5426\u5b58\u5728\u6ce8\u5165\u70b9<\/li>\n\n\n\n<li><strong><\/strong><strong><\/strong><code>--dbs \u3010\u68c0\u6d4b\u7ad9\u70b9\u5305\u542b\u54ea\u4e9b\u6570\u636e\u5e93 <\/code><strong><\/strong><\/li>\n\n\n\n<li><strong><\/strong><strong><\/strong><code>--current-db \u3010\u83b7\u53d6\u5f53\u524d\u7684\u6570\u636e\u5e93\u540d <\/code><strong><\/strong><\/li>\n\n\n\n<li><strong><\/strong><strong><\/strong><code>--tables -D \"db_name\" \u3010\u83b7\u53d6\u6307\u5b9a\u6570\u636e\u5e93\u4e2d\u7684\u8868\u540d -D\u540e\u63a5\u6307\u5b9a\u7684\u6570\u636e\u5e93\u540d\u79f0 <\/code><strong><\/strong><\/li>\n\n\n\n<li><strong><\/strong><strong><\/strong><code>--columns -T \"table_name\" -D \"db_name\" \u3010\u83b7\u53d6\u6570\u636e\u5e93\u8868\u4e2d\u7684\u5b57\u6bb5 <\/code><strong><\/strong><\/li>\n\n\n\n<li><strong><\/strong><strong><\/strong><code>--dump -C \"columns_name\" -T \"table_name\" -D \"db_name\" \u3010\u83b7\u53d6\u5b57\u6bb5\u7684\u6570\u636e\u5185\u5bb9 <\/code><strong><\/strong><\/li>\n<\/ol>\n\n\n\n<p>2#\u3001COOKIE\u6ce8\u5165\uff1a<br><a href=\"http:\/\/sqlmap.py\/\" target=\"_blank\" rel=\"noreferrer noopener\">sqlmap.py<\/a>&nbsp;-u \u201c<a href=\"http:\/\/www.xx.com\/?id=x\" target=\"_blank\" rel=\"noreferrer noopener\">http:\/\/www.xx.com?id=x<\/a>\u201d &#8211;cookie \u201ccookie\u201d &#8211;level 2 \u3010cookie\u6ce8\u5165 \u540e\u63a5cookie\u503c\uff0c<br>\u2013level=LEVEL \u6267\u884c\u7684\u6d4b\u8bd5\u7ea7\u522b(1-5, \u9ed8\u8ba4 1)<br>\u2013risk=RISK \u6267\u884c\u6d4b\u8bd5\u7684\u98ce\u9669 (1-3, \u9ed8\u8ba4 1)<\/p>\n\n\n\n<p>3#\u3001POST\u6ce8\u5165\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong><\/strong><strong><\/strong><code>\uff081\uff09\u76ee\u6807\u5730\u5740http:<em>\/\/ www.xxx.com \/login.asp<\/em>\n\uff082\uff09\u6253\u5f00brup\u4ee3\u7406\u3002\n\uff083\uff09\u70b9\u51fb\u8868\u5355\u63d0\u4ea4\n\uff084\uff09burp\u83b7\u53d6\u62e6\u622a\u4fe1\u606f\uff08post\uff09\n\uff085\uff09\u53f3\u952e\u4fdd\u5b58\u6587\u4ef6\uff08.txt\uff09\u5230\u6307\u5b9a\u76ee\u5f55\u4e0b\n\uff086\uff09\u8fd0\u884csqlmap\u5e76\u6267\u884c\u5982\u4e0b\u547d\u4ee4\uff1a\n\u7528\u4f8b\uff1asqlmap.py -r okay.txt  -p  username\n<\/code><\/pre>\n\n\n\n<p>\/\/ -r\u8868\u793a\u52a0\u8f7d\u6587\u4ef6(\u53ca\u6b65\u9aa4\uff085\uff09\u4fdd\u5b58\u7684\u8def\u5f84)\uff0c-p\u6307\u5b9a\u53c2\u6570\uff08\u5373\u62e6\u622a\u7684post\u8bf7\u6c42\u4e2d\u8868\u5355\u63d0\u4ea4\u7684\u7528\u6237\u540d\u6216\u5bc6\u7801\u7b49name\u53c2\u6570\uff09<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><code>\uff087\uff09\u81ea\u52a8\u83b7\u53d6\u8868\u5355\uff1a<em>--forms\u81ea\u52a8\u83b7\u53d6\u8868\u5355<\/em>\n\n\u4f8b\u5982\uff1asqlmap.py -u www.xx.com\/login.asp <em>--forms<\/em>\n\n\uff088\uff09\u6307\u5b9a\u53c2\u6570\u641c\u7d22\uff1a<em>--data<\/em>\n\n\u4f8b\u5982:sqlmap.py -u www.xx.com\/login.asp <em>--data \"username=1\"<\/em><\/code>\n<\/pre>\n\n\n\n<p>4#\u3001\u5e38\u7528\u6307\u4ee4\uff1a<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"><strong><\/strong><strong><\/strong><code>1.    --purge      \u3010\u91cd\u65b0\u626b\u63cf\uff08--purge \u5220\u9664\u539f\u5148\u5bf9\u8be5\u76ee\u6807\u626b\u63cf\u7684\u8bb0\u5f55\uff09\n\n2.    --tables      \u3010\u83b7\u53d6\u8868\u540d\n\n3.     --dbs         \u3010\u68c0\u6d4b\u7ad9\u70b9\u5305\u542b\u54ea\u4e9b\u6570\u636e\u5e93\n\n4.     --current-db    \u3010\u83b7\u53d6\u5f53\u524d\u7684\u6570\u636e\u5e93\u540d\n\n5.     --current-user  \u3010\u68c0\u6d4b\u5f53\u524d\u7528\u6237\n\n6.    --is-dba   \u3010\u5224\u65ad\u7ad9\u70b9\u7684\u5f53\u524d\u7528\u6237\u662f\u5426\u4e3a\u6570\u636e\u5e93\u7ba1\u7406\u5458\n\n7.    --batch      \u3010\u9ed8\u8ba4\u786e\u8ba4\uff0c\u4e0d\u8be2\u95ee\u4f60\u662f\u5426\u8f93\u5165\n\n8.    --search  \u3010\u540e\u9762\u8ddf\u53c2\u6570 -D -T -C \u641c\u7d22\u5217\uff08C\uff09\uff0c\u8868\uff08T\uff09\u548c\u6216\u6570\u636e\u5e93\u540d\u79f0\uff08D\uff09\n\n9.    --threads 10  \u3010\u7ebf\u7a0b\uff0csqlmap\u7ebf\u7a0b\u6700\u9ad8\u8bbe\u7f6e\u4e3a10\n\n10.  --level 3        \u3010sqlmap\u9ed8\u8ba4\u6d4b\u8bd5\u6240\u6709\u7684GET\u548cPOST\u53c2\u6570\uff0c\u5f53--level\u7684\u503c\u5927\u4e8e\u7b49\u4e8e2\u7684\u65f6\u5019\u4e5f\u4f1a\u6d4b\u8bd5HTTP Cookie\u5934\n                            \u7684\u503c\uff0c\u5f53\u5927\u4e8e\u7b49\u4e8e3\u7684\u65f6\u5019\u4e5f\u4f1a\u6d4b\u8bd5User-Agent\u548cHTTP Referer\u5934\u7684\u503c\u3002\u6700\u9ad8\u4e3a5\n11.  --risk 3           \u3010\u6267\u884c\u6d4b\u8bd5\u7684\u98ce\u9669\uff080-3\uff0c\u9ed8\u8ba4\u4e3a1\uff09risk\u8d8a\u9ad8\uff0c\u8d8a\u6162\u4f46\u662f\u8d8a\u5b89\u5168\n\n12.     -v   \u3010\u8be6\u7ec6\u7684\u7b49\u7ea7(0-6)\n     \t 0\uff1a\u53ea\u663e\u793aPython\u7684\u56de\u6eaf\uff0c\u9519\u8bef\u548c\u5173\u952e\u6d88\u606f\u3002\n    \t 1\uff1a\u663e\u793a\u4fe1\u606f\u548c\u8b66\u544a\u6d88\u606f\u3002\n    \t 2\uff1a\u663e\u793a\u8c03\u8bd5\u6d88\u606f\u3002\n     \t 3\uff1a\u6709\u6548\u8f7d\u8377\u6ce8\u5165\u3002\n     \t 4\uff1a\u663e\u793aHTTP\u8bf7\u6c42\u3002\n     \t 5\uff1a\u663e\u793aHTTP\u54cd\u5e94\u5934\u3002\n    \t 6\uff1a\u663e\u793aHTTP\u54cd\u5e94\u9875\u9762\u7684\u5185\u5bb9\n\n13.    --privileges  \u3010\u67e5\u770b\u6743\u9650\n\n14.   --tamper xx.py,cc.py   \u3010\u9632\u706b\u5899\u7ed5\u8fc7\uff0c\u540e\u63a5tamper\u5e93\u4e2d\u7684py\u6587\u4ef6\n\n15.  --method \"POST\" --data \"page=1&amp;id=2\"   \u3010POST\u65b9\u5f0f\u63d0\u4ea4\u6570\u636e\n\n16.  --threads number\u3000\u3000\u3010\u91c7\u7528\u591a\u7ebf\u7a0b \u540e\u63a5\u7ebf\u7a0b\u6570\n\n17.  --referer  \"\"  \u3010\u4f7f\u7528referer\u6b3a\u9a97\n\n18.  --user-agent \"\"     \u3010\u81ea\u5b9a\u4e49user-agent\n\n19.  --proxy \u201c\u76ee\u6807\u5730\u5740\u2033   \u3010\u4f7f\u7528\u4ee3\u7406\u6ce8\u5165\n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>sqlmap \u7b80\u4ecbsqlmap \u662f\u4e00\u4e2a\u81ea\u52a8\u5316\u7684 SQL \u6ce8\u5165\u5de5\u5177\uff0c\u4e3b\u8981\u529f\u80fd\u662f\u626b\u63cf\u3001\u53d1\u73b0\u5e76\u5229\u7528\u7ed9\u5b9a url \u7684  [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":72,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-70","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-4"],"_links":{"self":[{"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/posts\/70","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/comments?post=70"}],"version-history":[{"count":1,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/posts\/70\/revisions"}],"predecessor-version":[{"id":73,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/posts\/70\/revisions\/73"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/media\/72"}],"wp:attachment":[{"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/media?parent=70"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/categories?post=70"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/meiyitou.top\/index.php\/wp-json\/wp\/v2\/tags?post=70"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}