↑
web application technology: Nginx
back-end DBMS: MySQL >= 5.5
banner: '5.5.44-0+deb7u1'
[20:47:43] [INFO] fetching database names
[20:47:43] [WARNING] the SQL query provided does not return any output
[20:47:43] [INFO] fetching number of databases
[20:47:43] [WARNING] (case) time-based comparison requires larger statistical mo
del, please wait.............................. (done)
[20:47:44] [WARNING] it is very important to not stress the network adapter duri
ng usage of time-based payloads to prevent potential disruptions
[20:47:44] [ERROR] unable to retrieve the number of databases
[20:47:44] [INFO] falling back to current database
[20:47:44] [INFO] fetching current database
[20:47:44] [INFO] resumed: martin
available databases [1]:[*] martin
[20:47:44] [WARNING] HTTP error codes detected during run:
404 (Not Found) - 1 times
Не могу получить таблицы
↑
web application technology: Nginx
back-end DBMS: MySQL >= 5.5
banner: '5.5.44-0+deb7u1'
[20:47:43] [INFO] fetching database names
[20:47:43] [WARNING] the SQL query provided does not return any output
[20:47:43] [INFO] fetching number of databases
[20:47:43] [WARNING] (case) time-based comparison requires larger statistical mo
del, please wait.............................. (done)
[20:47:44] [WARNING] it is very important to not stress the network adapter duri
ng usage of time-based payloads to prevent potential disruptions
[20:47:44] [ERROR] unable to retrieve the number of databases
[20:47:44] [INFO] falling back to current database
[20:47:44] [INFO] fetching current database
[20:47:44] [INFO] resumed: martin
available databases [1]:[*] martin
[20:47:44] [WARNING] HTTP error codes detected during run:
404 (Not Found) - 1 times
Не могу получить таблицы
"available databases" говорит что доступа к information_schema нет, не удивительно что списка баз/таблиц нету)
↑
"available databases" говорит что доступа к information_schema нет, не удивительно что списка баз/таблиц нету)
брутфорс имхо, скульмап вроде это даже умеет
----------------------
хотя не исключаю что может быть какой то waf
-v 3 в помощь