Re: How do I determine if versions of phpMyAdmin before 4.8.5 is SQL Injectable using sqlmap?
Christian Varas <[email protected]>
| Newsgroups | gmane.comp.apache.mod-security.user |
|---|---|
| Message-ID | <[email protected]> |
Hi, there is a tons of post about how to use sqlmap in google and youtube. This list is to disccuss things about modsecurity. Cheers. El 17-04-19 a las 10:24, Turritopsis Dohrnii Teo En Ming escribió: > Subject/Topic: How do I determine if versions of phpMyAdmin before 4.8.5 is SQL Injectable using sqlmap? > > Good evening from Singapore, > > Our customer (company name is Confidential/not disclosed) reported that their MySQL database has been found missing or was deleted a few times. They are using Ubuntu 16.04 LTS Linux server with Apache2 Web Server, MySQL and PHP (LAMP). > > We responded to these security incidents by changing the passwords of the regular user, root user, and MySQL database user root. We have also examined /var/log/auth.log and think that the hacker could not have come in through ssh or sftp over ssh. From /var/log/mysql/error.log, we can ascertain that the MySQL database has been deleted at certain timings. We have also found nothing abnormal after examining /var/log/apache2/access.log. > > Even though we have secured the Ubuntu Linux server by changing passwords, the hacker was still able to delete our customer's MySQL database again and again. I have already proposed to install ModSecurity Open Source Web Application Firewall (WAF) to defend against web application attacks but my boss has told me to put that on hold at the moment. In fact, I have already deployed ModSecurity 2.9.0 on a Ubuntu 16.04 LTS *Testing* server and found that it actively detects and logs Nessus and sqlmap vulnerability scans in blocking mode. > > Since we did not find any evidence that the hacker had breached our customer's Ubuntu 16.04 LTS production server through ssh or Teamviewer, we suspect that the hacker could have achieved it by SQL injection. I took the initiative of downloading and installing Nessus Professional 8.3.1 Trial version for Windows 64-bit. The vulnerability scan report generated by Nessus Web Application Tests shows that our customer is using a version of phpMyAdmin prior to 4.8.5 which could be vulnerable to SQL injection using the designer feature. > > Further research shows that I can use sqlmap to determine if phpMyAdmin is SQL injectable. I already have a Testing Ubuntu 16.04 LTS Linux server with a Testing MySQL database and a Testing phpMyAdmin 4.8.4. I have purposely installed phpMyAdmin 4.8.4 because this version was reported to be vulnerable to SQL injection using the designer feature, and our customer is using a vulnerable version, according to CVE-2019-6798 ( https://nvd.nist.gov/vuln/detail/CVE-2019-6798 ). Then I proceeded to download and execute sqlmap on our Ubuntu Linux desktop against our Testing server. > > No matter how many commands I try, sqlmap always report that phpMyAdmin 4.8.4 is *NOT* SQL injectable. Perhaps I was using the wrong sqlmap commands all the time? The following is one of the many sqlmap commands I have used. > > $ python sqlmap.py -u "https://www.EXAMPLE.com/phymyadmin/index.php?id=1" --level=1 --dbms=mysql --sql-query="drop database" > > Replace database by database name. > > May I know what is the correct sqlmap command that I should use to determine that my Testing phpMyAdmin 4.8.4 is SQL injectable? I would like to know if I can successfully drop/delete the Testing database on our Testing server. If I can successfully drop/delete the Testing MySQL database using sqlmap, I would be able to conclude that the hacker must have carried out SQL injection to drop/delete the customer's database. I have already turned off the Testing ModSecurity Web Application Firewall on our Testing server to allow sqlmap to go through. > > Please point me to any good tutorial on SQL injection using sqlmap. Maybe I do not understand SQL injection well enough. Our customer is also using a customised in-house inventory management system that relies on PHP application and MySQL database. > > Would open source Snort Intrusion Detection System (IDS) and Intrusion Prevention System (IPS) be able to detect and block SQL injection as well? > > Please advise. > > Thank you very much. > > -----BEGIN EMAIL SIGNATURE----- > > The Gospel for all Targeted Individuals (TIs): > > [The New York Times] Microwave Weapons Are Prime Suspect in Ills of > U.S. Embassy Workers > > Link: https://www.nytimes.com/2018/09/01/science/sonic-attack-cuba-microwave.html > > ******************************************************************************************** > > Singaporean Mr. Turritopsis Dohrnii Teo En Ming's Academic > Qualifications as at 14 Feb 2019 > > [1] https://tdtemcerts.wordpress.com/ > > [2] https://tdtemcerts.blogspot.sg/ > > [3] https://www.scribd.com/user/270125049/Teo-En-Ming > > -----END EMAIL SIGNATURE----- > > > > _______________________________________________ > mod-security-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mod-security-users > Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: > http://www.modsecurity.org/projects/commercial/rules/ > http://www.modsecurity.org/projects/commercial/support/ _______________________________________________ mod-security-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mod-security-users Commercial ModSecurity Rules and Support from Trustwave's SpiderLabs: http://www.modsecurity.org/projects/commercial/rules/ http://www.modsecurity.org/projects/commercial/support/
pEpkey.asc
(application/pgp-keys, 3.1 KB)
-----BEGIN PGP PUBLIC KEY BLOCK----- mQINBFvbV84BEACzsqs6dSJgB3Q/DaQs99P5GLxjM9gF02gsAIzJeFC4RwJ6wcji wMuWYo+eLzg2asbUOJZ60ed2O64+jtFEBVEsho92KXU5ioLc+9tP5lW+m8mS/FI9 ZPvfMsv+brp68LjunTMeJwwnK34hAiTrQSc0taZq6nFDJwkn04DhCL//cm29uepU hYAorv6cjo8g+ZbBeOY3fk1SsqzsnENyN+o6rwVGOlifEOj1Ys90StvjNNlEoxp6 7tNRnp++I0mx9G/VtWZZcg/XGwf1GBdmtA/uIBJyiZljsaaNzV76zkPzJk5TKO8M ASRReH4a6h90exxKddzXWURfy0DtB9AxU2hQRnRzaf8U0xcE0p6UQNW8WWLiphnJ FQjCrwSkHYDlXAt8MpNwNKVE8PWT8faF7ND5c6ptZZySW2O/RR48dzUgLiqtI8SK gqsftsPh1MOZHJrm1+g+VzfLwkH4f4v7aXRaMRJWdvYN5j2vjGvjlTp+fPN87aa+ FZ4NZLW8nTOQa38ba8x1NfKS/N1ytlLECRxmgXRwg4B+AwBOCvzyi50PzXGfGq79 UABGt3RGDFe3IvNo8F7xBXcBEqhpPHlQx16TBnCbX1/cz6xl3Kgu49qblhcfx6/2 ReL1DeYXig01Sc1OABwIPrd1QvRBgVKvtbjpgHdQTyyIvlR5twy0l/uTuQARAQAB tCFDaHJpc3RpYW4gVmFyYXMgPGN2YXJhc0BpdHNlYy5jbD6JAlQEEwEIAD4WIQRB wAMUnQLquo2R2nGflDtJ11upfAUCW9tXzgIbAwUJDSsLgAULCQgHAgYVCgkICwIE FgIDAQIeAQIXgAAKCRCflDtJ11upfFT/EACeTME2pqYmW50i8BoRJYIfzHVW6KNr tsAgvb/wCPk8wkV6H9dcoO8nrR4lYzgF/tON6t6hYlwVVMtQqvbeHQV/I4bOdM3B fnp5sWWdROgesi72lWUIKkovwvG9hSWxDHtZBXdWPJCO9GpVihby9KBLyoHVmDXV anSppaiVazC9Bt3pqtJQvUr4fP2npWjIeIAUE8Cu10blZ/U0h22tUDITpm5u111b tIr4yXcZsWkzLt7Hv/mxverMpLOpxIugJ+50OQe8D+oBzzJj3k7skgqHrQ/DTJ1o Z5mroV4IBkGEiEi9bXPzbQ6ECYj4kI8gV/aU/nKKTl6SrXk1Vd80KK1rLpYGlG7I eNdwCod0iNdAygWSZg9cUbuLkehWwPn54q4Aowxd1hNQ9wGX9rfquBYj6KdUvFyX NYadJlCGiU4ZPzw7ZXhMdDlVbyNpO+XXmt3jZjB20onyD3lJY7JI35a3htGD3coa Tp6HExipsp3mB7WdxnEmJap9Q0MDBFQ08UQHMqMLMZvYHzdHRb67QG/G2qiAZ7+J WtfEvM+Fo52NnSqipMfIM2wTZZTm3y4ZgteDBrMXRoZ1tVrTi5p9zWCF/dqJNBrR mvkoVy4gfPNvAfM/j8Pvy3dN/l7bx3Z4r0EGOAbW8msetXiGPoM/Pj2YWAaag3FN Y5lJ7xZ8aa2Km7kCDQRb21fOARAAvfscAEN2+S8z2cUYYa1GjZmWPwEFtMNZMDDA aK7W+5Gqdmhtb/pRI8SaJG8amZL4HDXIllCu9rG+LHprEmTaRSpg9/MkBv1tXAtH U1egK4fB9NZ7JiWanMrCLwtF/z2CGPQEzjZ/CDCArgjtOX47cpLArVsVLaz68p7g lTwdLrT7iwIwpevtpWUntkoyAlZpmAfjdGZ1OUZ1eYooD9yg8wxCHUBHI9SoFF5h GMcekxujZuNxmEwnwx+P11d2O8xdXwhYQGibdHeq9ipXtM+EEbPCqeSrRzkHpvHZ qjTg4crC1ImyDN5HXHT8FiHBZ/rapwZNVxHEilpe9tngPXzJ/F8+7QbJs5iHsmg+ k5naT0j8nqFl0TqPTYQye4bvqUaZ9ZCphqC1caELwajFH05jni3n9simYb0GMiyD 5Y7MIb7iHPCksBRgLl62WCOwp8hxlzN35eAhykkV/gNNSzLLlWLz3R2P7t1bd/y2 AqcV4fkgjdOPKzdZN/DFlF/UhZ4G7IguAf+rAYZeyI62tq6ZW7tsY9A0Qq1ZwLpH 5U2TjqkvVBP7dya3UXrBfe8JEoDKpa2+KQ68xtdUwdeTQLkop/UjZeJZMeofRuAD 8Mc/voH6S1I0sRuOaq072RH8+N8y1BwUESJmZxuI4JyayWIlDltlcMZhTc2nV215 KCWgPWsAEQEAAYkCPAQYAQgAJhYhBEHAAxSdAuq6jZHacZ+UO0nXW6l8BQJb21fO AhsMBQkNKwuAAAoJEJ+UO0nXW6l8JdEP/jRKb6xhvUyOW3yt4AHrXFE0KoVwVXDG evSwRmdySi2o7kQgp8+RccXhwG3YAuj3/+sh0gV7KRiQHXMh+VAfBe0qSMSnZzoJ E6F1IJdjruLTksY2aBk2iwaFoUccMa5U1Fl2sK5ZRwqDg2W2mpUxY3aP2adD4g2C L8N6jFtqqUScM4fNp8PYR6vMvtSZcQqzBQFk6sKfUixwyFPgb3kKi2m535ZmRp8a QsLMCXe7ZpSl5UebN4gq5VK+xXNZPXbfYI+BEjutFSWGBTBk4zDkOy8R8DY5CdjG WTgsu6EdoSzJgrN1LiWjep1nRDGyc626+LDNZUeO3jrDSUxM2HS8g4g16X3LcSsZ 4fKKhO361Q0yJ4raFy3r93peL5MKugRINnQVKGfCZIQUkMxmttyzu/JyZ5x31mcO RKZBVuQD3ZIz754JCF+3AR0cIKViAVzUKOQA03vfY7sn+qP+pDVC1euecI3ecJUT tF+0TgD5A4pMt6/4C5u6O81300/yD1xm0z7Zr2ASpaRILkaEaF5heBJvGDgyS0BA 8thHHPKBv+Nj5DRLFZJGtuJNONQe5W3T8R+1IwRSMwgZSSKRMsf1iDQqSEJ1hLXB ueffTQ+94pYest+ui5EdlAe/30URQSFzrQIxoAy7jbxo/IvGAnOLgN/5wz7pyiJ5 GZNokvLk6b5A =ZAfD -----END PGP PUBLIC KEY BLOCK-----