base注入测试数据

命令

sqlmap.py -u "http://www.samilsys.com/project_detail.php?id=12" -v3 --dbs

测试结果

[09:23:36] [CRITICAL] heuristics detected that the target is protected by some kind of WAF/IPS/IDS

do you want sqlmap to try to detect backend WAF/IPS/IDS? [y/N] y

[09:23:52] [WARNING] dropping timeout to 10 seconds (i.e. '--timeout=10')

[09:23:52] [DEBUG] loading WAF script '360'

[09:23:52] [DEBUG] loading WAF script 'airlock'

[09:23:52] [DEBUG] loading WAF script 'anquanbao'

[09:23:52] [DEBUG] loading WAF script 'armor'

[09:23:52] [DEBUG] loading WAF script 'aws'

[09:23:52] [DEBUG] loading WAF script 'baidu'

[09:23:52] [DEBUG] loading WAF script 'barracuda'

[09:23:52] [DEBUG] loading WAF script 'bigip'

[09:23:52] [DEBUG] loading WAF script 'binarysec'

[09:23:52] [DEBUG] loading WAF script 'blockdos'

[09:23:52] [DEBUG] loading WAF script 'ciscoacexml'

[09:23:52] [DEBUG] loading WAF script 'cloudflare'

[09:23:52] [DEBUG] loading WAF script 'cloudfront'

[09:23:52] [DEBUG] loading WAF script 'comodo'

[09:23:52] [DEBUG] loading WAF script 'datapower'

[09:23:52] [DEBUG] loading WAF script 'denyall'

[09:23:52] [DEBUG] loading WAF script 'dotdefender'

[09:23:52] [DEBUG] loading WAF script 'edgecast'

[09:23:52] [DEBUG] loading WAF script 'expressionengine'

[09:23:52] [DEBUG] loading WAF script 'fortiweb'

[09:23:52] [DEBUG] loading WAF script 'generic'

[09:23:52] [DEBUG] loading WAF script 'hyperguard'

[09:23:52] [DEBUG] loading WAF script 'incapsula'

[09:23:52] [DEBUG] loading WAF script 'isaserver'

[09:23:52] [DEBUG] loading WAF script 'jiasule'

[09:23:52] [DEBUG] loading WAF script 'knownsec'

[09:23:52] [DEBUG] loading WAF script 'kona'

[09:23:52] [DEBUG] loading WAF script 'modsecurity'

[09:23:52] [DEBUG] loading WAF script 'netcontinuum'

[09:23:52] [DEBUG] loading WAF script 'netscaler'

[09:23:52] [DEBUG] loading WAF script 'newdefend'

[09:23:52] [DEBUG] loading WAF script 'nsfocus'

[09:23:52] [DEBUG] loading WAF script 'paloalto'

[09:23:52] [DEBUG] loading WAF script 'profense'

[09:23:52] [DEBUG] loading WAF script 'proventia'

[09:23:52] [DEBUG] loading WAF script 'radware'

[09:23:52] [DEBUG] loading WAF script 'requestvalidationmode'

[09:23:52] [DEBUG] loading WAF script 'safe3'

[09:23:52] [DEBUG] loading WAF script 'safedog'

[09:23:52] [DEBUG] loading WAF script 'secureiis'

[09:23:52] [DEBUG] loading WAF script 'senginx'

[09:23:52] [DEBUG] loading WAF script 'sitelock'

[09:23:52] [DEBUG] loading WAF script 'sonicwall'

[09:23:52] [DEBUG] loading WAF script 'sophos'

[09:23:52] [DEBUG] loading WAF script 'stingray'

[09:23:52] [DEBUG] loading WAF script 'sucuri'

[09:23:52] [DEBUG] loading WAF script 'tencent'

[09:23:52] [DEBUG] loading WAF script 'teros'

[09:23:52] [DEBUG] loading WAF script 'trafficshield'

[09:23:52] [DEBUG] loading WAF script 'urlscan'

[09:23:52] [DEBUG] loading WAF script 'uspses'

[09:23:52] [DEBUG] loading WAF script 'varnish'

[09:23:52] [DEBUG] loading WAF script 'wallarm'

[09:23:52] [DEBUG] loading WAF script 'webappsecure'

[09:23:52] [DEBUG] loading WAF script 'webknight'

[09:23:52] [DEBUG] loading WAF script 'yundun'

[09:23:52] [DEBUG] loading WAF script 'yunsuo'

[09:23:52] [INFO] using WAF scripts to detect backend WAF/IPS/IDS protection

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product '360 Web Application Firewall (360)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Airlock (Phion/Ergon)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Anquanbao Web Application Firewall (Anquanbao)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Armor Protection (Armor Defense)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Amazon Web Services Web Application Firewall (Amazon)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Yunjiasu Web Application Firewall (Baidu)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Barracuda Web Application Firewall (Barracuda Networks)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'BIG-IP Application Security Manager (F5 Networks)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'BinarySEC Web Application Firewall (BinarySEC)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'BlockDoS'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Cisco ACE XML Gateway (Cisco Systems)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'CloudFlare Web Application Firewall (CloudFlare)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'CloudFront (Amazon)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Comodo Web Application Firewall (Comodo)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'IBM WebSphere DataPower (IBM)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Deny All Web Application Firewall (DenyAll)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'dotDefender (Applicure Technologies)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'EdgeCast WAF (Verizon)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'ExpressionEngine (EllisLab)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'FortiWeb Web Application Firewall (Fortinet)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Hyperguard Web Application Firewall (art of defence)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Incapsula Web Application Firewall (Incapsula/Imperva)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'ISA Server (Microsoft)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Jiasule Web Application Firewall (Jiasule)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'KS-WAF (Knownsec)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'KONA Security Solutions (Akamai Technologies)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'ModSecurity: Open Source Web Application Firewall (Trustwave)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'NetContinuum Web Application Firewall (NetContinuum/Barracuda Networks)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'NetScaler (Citrix Systems)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Newdefend Web Application Firewall (Newdefend)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'NSFOCUS Web Application Firewall (NSFOCUS)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Palo Alto Firewall (Palo Alto Networks)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Profense Web Application Firewall (Armorlogic)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Proventia Web Application Security (IBM)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'AppWall (Radware)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'ASP.NET RequestValidationMode (Microsoft)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Safe3 Web Application Firewall'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Safedog Web Application Firewall (Safedog)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'SecureIIS Web Server Security (BeyondTrust)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'SEnginx (Neusoft Corporation)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'TrueShield Web Application Firewall (SiteLock)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'SonicWALL (Dell)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'UTM Web Protection (Sophos)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Stingray Application Firewall (Riverbed / Brocade)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'CloudProxy WebSite Firewall (Sucuri)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Tencent Cloud Web Application Firewall (Tencent Cloud Computing)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Teros/Citrix Application Firewall Enterprise (Teros/Citrix Systems)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'TrafficShield (F5 Networks)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'UrlScan (Microsoft)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'USP Secure Entry Server (United Security Providers)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Varnish FireWall (OWASP) '

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Wallarm Web Application Firewall (Wallarm)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'webApp.secure (webScurity)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'WebKnight Application Firewall (AQTRONIX)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Yundun Web Application Firewall (Yundun)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Yunsuo Web Application Firewall (Yunsuo)'

[09:23:52] [DEBUG] checking for WAF/IPS/IDS product 'Generic (Unknown)'

[09:23:52] [CRITICAL] WAF/IPS/IDS identified as 'Generic (Unknown)'

are you sure that you want to continue with further target testing? [y/N] y

[09:23:56] [WARNING] please consider usage of tamper scripts (option '--tamper')

[09:23:56] [ERROR] user quit

最后编辑于
©著作权归作者所有,转载或内容合作请联系作者
  • 序言:七十年代末,一起剥皮案震惊了整个滨河市,随后出现的几起案子,更是在滨河造成了极大的恐慌,老刑警刘岩,带你破解...
    沈念sama阅读 199,519评论 5 468
  • 序言:滨河连续发生了三起死亡事件,死亡现场离奇诡异,居然都是意外死亡,警方通过查阅死者的电脑和手机,发现死者居然都...
    沈念sama阅读 83,842评论 2 376
  • 文/潘晓璐 我一进店门,熙熙楼的掌柜王于贵愁眉苦脸地迎上来,“玉大人,你说我怎么就摊上这事。” “怎么了?”我有些...
    开封第一讲书人阅读 146,544评论 0 330
  • 文/不坏的土叔 我叫张陵,是天一观的道长。 经常有香客问我,道长,这世上最难降的妖魔是什么? 我笑而不...
    开封第一讲书人阅读 53,742评论 1 271
  • 正文 为了忘掉前任,我火速办了婚礼,结果婚礼上,老公的妹妹穿的比我还像新娘。我一直安慰自己,他们只是感情好,可当我...
    茶点故事阅读 62,646评论 5 359
  • 文/花漫 我一把揭开白布。 她就那样静静地躺着,像睡着了一般。 火红的嫁衣衬着肌肤如雪。 梳的纹丝不乱的头发上,一...
    开封第一讲书人阅读 48,027评论 1 275
  • 那天,我揣着相机与录音,去河边找鬼。 笑死,一个胖子当着我的面吹牛,可吹牛的内容都是我干的。 我是一名探鬼主播,决...
    沈念sama阅读 37,513评论 3 390
  • 文/苍兰香墨 我猛地睁开眼,长吁一口气:“原来是场噩梦啊……” “哼!你这毒妇竟也来了?” 一声冷哼从身侧响起,我...
    开封第一讲书人阅读 36,169评论 0 254
  • 序言:老挝万荣一对情侣失踪,失踪者是张志新(化名)和其女友刘颖,没想到半个月后,有当地人在树林里发现了一具尸体,经...
    沈念sama阅读 40,324评论 1 294
  • 正文 独居荒郊野岭守林人离奇死亡,尸身上长有42处带血的脓包…… 初始之章·张勋 以下内容为张勋视角 年9月15日...
    茶点故事阅读 35,268评论 2 317
  • 正文 我和宋清朗相恋三年,在试婚纱的时候发现自己被绿了。 大学时的朋友给我发了我未婚夫和他白月光在一起吃饭的照片。...
    茶点故事阅读 37,299评论 1 329
  • 序言:一个原本活蹦乱跳的男人离奇死亡,死状恐怖,灵堂内的尸体忽然破棺而出,到底是诈尸还是另有隐情,我是刑警宁泽,带...
    沈念sama阅读 32,996评论 3 315
  • 正文 年R本政府宣布,位于F岛的核电站,受9级特大地震影响,放射性物质发生泄漏。R本人自食恶果不足惜,却给世界环境...
    茶点故事阅读 38,591评论 3 303
  • 文/蒙蒙 一、第九天 我趴在偏房一处隐蔽的房顶上张望。 院中可真热闹,春花似锦、人声如沸。这庄子的主人今日做“春日...
    开封第一讲书人阅读 29,667评论 0 19
  • 文/苍兰香墨 我抬头看了看天上的太阳。三九已至,却和暖如春,着一层夹袄步出监牢的瞬间,已是汗流浃背。 一阵脚步声响...
    开封第一讲书人阅读 30,911评论 1 255
  • 我被黑心中介骗来泰国打工, 没想到刚下飞机就差点儿被人妖公主榨干…… 1. 我叫王不留,地道东北人。 一个月前我还...
    沈念sama阅读 42,288评论 2 345
  • 正文 我出身青楼,却偏偏与公主长得像,于是被迫代替她去往敌国和亲。 传闻我的和亲对象是个残疾皇子,可洞房花烛夜当晚...
    茶点故事阅读 41,871评论 2 341

推荐阅读更多精彩内容