listOptions($actionTaskId); // We will actually store it for use in a second... break; case "stop": // Stop a specified running Task ID $sqlmap->stopScan($actionTaskId); break; case "kill": // Forcefully Kill a specified running Task ID $sqlmap->killScan($actionTaskId); break; case "del": // Delete a specified running Task ID $sqlmap->deleteTaskID($actionTaskId); break; default: // Do Nothing if nothing is specified... break; } } } }?> SQLMAP Web GUI - Admin Panel
SQLMAP Web GUI - Admin Panel"; if(isset($_SESSION['myAdminID'])) { $taskList = $sqlmap->adminListTasks(trim($_SESSION['myAdminID'])); if(!$taskList) {?>
[WARNING] '' - Appears to be an Invalid Admin ID!
Admin ID:
Total Number of Known Tasks:
'; echo 'ScanID: ' . htmlentities(trim($_GET['task']), ENT_QUOTES, 'UTF-8') . ', API Scan Configuration'; echo ''; echo "[*] API Scan Configuration:\n"; print_r(htmlentities($sqlmap->listOptions(trim($_GET['task']))['options']), ENT_QUOTES, 'UTF-8'); echo '
'; } else { ?>
TaskID |
Target |
Status |
Options |
checkScanStatus($t); $taskConfig = $sqlmap->listOptions($t); echo "
"; echo "
"; echo htmlentities($t, ENT_QUOTES, 'UTF-8'); echo " | "; if(sizeof($taskConfig) > 0) { $targetHost = parse_url($taskConfig['options']['url'], PHP_URL_HOST); echo "
" . htmlentities($targetHost, ENT_QUOTES, 'UTF-8') . " | "; } else { echo "
- | "; } if(isset($status['status'])) { echo "
" . htmlentities($status['status'], ENT_QUOTES, 'UTF-8') . " | "; } else { echo "
- | "; } echo "
Conf | "; if($status['status'] == 'running') { echo "
Stop | "; echo "
Kill | "; } else { echo "
- | "; echo "
- | "; } echo "
Del | "; echo "
"; } ?>
[WARNING] NO Admin ID Set!
Logout
Want to learn more about SQLMAP, Visit the Project Page!
SQLMAP Web Operator Copyright © 2015, Coded By: HR, All rights reserved.
這是後台登入首頁(index.php)的代碼,帳號密碼在config.php中寫死了,是admin,admin。現在登入後台後,顯示[WARNING] NO Admin ID Set!,然後然我輸入一串密文token,token密文貌似是
$salt = "!SQL!"; // Salt for form token hash generation $token = sha1(mt_rand(1, 1000000) . $salt); // Generate CSRF Token Hash $_SESSION['token'] = $token; // Set CSRF Token for Form SubmitVerification
是1-1000000加SALT的sha1加密,然後我在
[WARNING] NO Admin ID Set!
Admin ID:
Total Number of Known Tasks:
'; echo 'ScanID: ' . htmlentities(trim($_GET['task']), ENT_QUOTES, 'UTF-8') . ', API Scan Configuration'; echo ''; echo "[*] API Scan Configuration:\n"; print_r(htmlentities($sqlmap->listOptions(trim($_GET['task']))['options']), ENT_QUOTES, 'UTF-8'); echo '
'; } else { ?>
TaskID |
Target |
Status |
Options |
checkScanStatus($t); $taskConfig = $sqlmap->listOptions($t); echo "
"; echo "
"; echo htmlentities($t, ENT_QUOTES, 'UTF-8'); echo " | "; if(sizeof($taskConfig) > 0) { $targetHost = parse_url($taskConfig['options']['url'], PHP_URL_HOST); echo "
" . htmlentities($targetHost, ENT_QUOTES, 'UTF-8') . " | "; } else { echo "
- | "; } if(isset($status['status'])) { echo "
" . htmlentities($status['status'], ENT_QUOTES, 'UTF-8') . " | "; } else { echo "
- | "; } echo "
Conf | "; if($status['status'] == 'running') { echo "
Stop | "; echo "
Kill | "; } else { echo "
- | "; echo "
- | "; } echo "
Del | "; echo "
"; } ?>
[WARNING] NO Admin ID Set!
Logout
Want to learn more about SQLMAP, Visit the Project Page!
SQLMAP Web Operator Copyright © 2015, Coded By: HR, All rights reserved.
這是後台登入首頁(index.php)的代碼,帳號密碼在config.php中寫死了,是admin,admin。現在登入後台後,顯示[WARNING] NO Admin ID Set!,然後然我輸入一串密文token,token密文貌似是
$salt = "!SQL!"; // Salt for form token hash generation $token = sha1(mt_rand(1, 1000000) . $salt); // Generate CSRF Token Hash $_SESSION['token'] = $token; // Set CSRF Token for Form SubmitVerification
是1-1000000加SALT的sha1加密,然後我在
[WARNING] NO Admin ID Set!
看到了輸出token的語句,在前台查看原始碼後,把密文輸入,但是還是不行。求解,怎麼才能過去?謝謝!!
你通過POST傳遞 myAdminID,但問題是你自己輸入的myAdminID是應該怎麼產生的?
那個token是防止CSRF的,不是用來產生myAdminID的,至於myAdminID應該怎麼產生,你應該看看這段代碼:
$sqlmap->adminListTasks(trim($_SESSION['myAdminID']));