[phpMyAdmin Developers] How do I determine if versions of phpMyAdmin before 4.8.5 is SQL Injectable using sqlmap?
Turritopsis Dohrnii Teo En Ming <[email protected]> Wed, 17 Apr 2019 13:57:19 +0000
| Newsgroups | gmane.comp.php.phpmyadmin.devel |
|---|---|
| Message-ID | <HK0PR01MB26445ACB131A6CE62416D42087250@HK0PR01MB2644.apcprd01.prod.exchangelabs.com> |
--===============9002108147104766984==
Content-Language: en-US
Content-Type: multipart/alternative;
boundary="_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_"
--_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Subject/Topic: How do I determine if versions of phpMyAdmin before 4.8.5 is=
SQL Injectable using sqlmap?
Good evening from Singapore,
Our customer (company name is Confidential/not disclosed) reported that the=
ir MySQL database has been found missing or was deleted a few times. They a=
re using Ubuntu 16.04 LTS Linux server with Apache2 Web Server, MySQL and P=
HP (LAMP).
We responded to these security incidents by changing the passwords of the r=
egular user, root user, and MySQL database user root. We have also examined=
/var/log/auth.log and think that the hacker could not have come in through=
ssh or sftp over ssh. From /var/log/mysql/error.log, we can ascertain that=
the MySQL database has been deleted at certain timings. We have also found=
nothing abnormal after examining /var/log/apache2/access.log.
Even though we have secured the Ubuntu Linux server by changing passwords, =
the hacker was still able to delete our customer's MySQL database again and=
again. I have already proposed to install ModSecurity Open Source Web Appl=
ication Firewall (WAF) to defend against web application attacks but my bos=
s has told me to put that on hold at the moment. In fact, I have already de=
ployed ModSecurity 2.9.0 on a Ubuntu 16.04 LTS *Testing* server and found t=
hat it actively detects and logs Nessus and sqlmap vulnerability scans in b=
locking mode.
Since we did not find any evidence that the hacker had breached our custome=
r's Ubuntu 16.04 LTS production server through ssh or Teamviewer, we suspec=
t that the hacker could have achieved it by SQL injection. I took the initi=
ative of downloading and installing Nessus Professional 8.3.1 Trial version=
for Windows 64-bit. The vulnerability scan report generated by Nessus Web =
Application Tests shows that our customer is using a version of phpMyAdmin =
prior to 4.8.5 which could be vulnerable to SQL injection using the designe=
r feature.
Further research shows that I can use sqlmap to determine if phpMyAdmin is =
SQL injectable. I already have a Testing Ubuntu 16.04 LTS Linux server with=
a Testing MySQL database and a Testing phpMyAdmin 4.8.4. I have purposely =
installed phpMyAdmin 4.8.4 because this version was reported to be vulnerab=
le to SQL injection using the designer feature, and our customer is using a=
vulnerable version, according to CVE-2019-6798 ( https://nvd.nist.gov/vuln=
/detail/CVE-2019-6798 ). Then I proceeded to download and execute sqlmap on=
our Ubuntu Linux desktop against our Testing server.
No matter how many commands I try, sqlmap always report that phpMyAdmin 4.8=
.4 is *NOT* SQL injectable. Perhaps I was using the wrong sqlmap commands a=
ll the time? The following is one of the many sqlmap commands I have used.
$ python sqlmap.py -u "https://www.EXAMPLE.com/phymyadmin/index.php?id=3D1"=
--level=3D1 --dbms=3Dmysql --sql-query=3D"drop database"
Replace database by database name.
May I know what is the correct sqlmap command that I should use to determin=
e that my Testing phpMyAdmin 4.8.4 is SQL injectable? I would like to know =
if I can successfully drop/delete the Testing database on our Testing serve=
r. If I can successfully drop/delete the Testing MySQL database using sqlma=
p, I would be able to conclude that the hacker must have carried out SQL in=
jection to drop/delete the customer's database. I have already turned off t=
he Testing ModSecurity Web Application Firewall on our Testing server to al=
low sqlmap to go through.
Please point me to any good tutorial on SQL injection using sqlmap. Maybe I=
do not understand SQL injection well enough. Our customer is also using a =
customised in-house inventory management system that relies on PHP applicat=
ion and MySQL database.
Would open source Snort Intrusion Detection System (IDS) and Intrusion Prev=
ention System (IPS) be able to detect and block SQL injection as well?
Please advise.
Thank you very much.
-----BEGIN EMAIL SIGNATURE-----
The Gospel for all Targeted Individuals (TIs):
[The New York Times] Microwave Weapons Are Prime Suspect in Ills of
U.S. Embassy Workers
Link: https://www.nytimes.com/2018/09/01/science/sonic-attack-cuba-microwav=
e.html
***************************************************************************=
*****************
Singaporean Mr. Turritopsis Dohrnii Teo En Ming's Academic
Qualifications as at 14 Feb 2019
[1] https://tdtemcerts.wordpress.com/
[2] https://tdtemcerts.blogspot.sg/
[3] https://www.scribd.com/user/270125049/Teo-En-Ming
-----END EMAIL SIGNATURE-----
--_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:DengXian;
panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:"\@DengXian";
panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0cm;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
span.EmailStyle17
{mso-style-type:personal-compose;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-family:"Calibri",sans-serif;}
@page WordSection1
{size:612.0pt 792.0pt;
margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-SG" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Subject/Topic: How do I determine if versions of php=
MyAdmin before 4.8.5 is SQL Injectable using sqlmap?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Good evening from Singapore,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Our customer (company name is Confidential/not discl=
osed) reported that their MySQL database has been found missing or was dele=
ted a few times. They are using Ubuntu 16.04 LTS Linux server with Apache2 =
Web Server, MySQL and PHP (LAMP).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">We responded to these security incidents by changing=
the passwords of the regular user, root user, and MySQL database user root=
. We have also examined /var/log/auth.log and think that the hacker could n=
ot have come in through ssh or sftp
over ssh. From /var/log/mysql/error.log, we can ascertain that the MySQL d=
atabase has been deleted at certain timings. We have also found nothing abn=
ormal after examining /var/log/apache2/access.log.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Even though we have secured the Ubuntu Linux server =
by changing passwords, the hacker was still able to delete our customer's M=
ySQL database again and again. I have already proposed to install ModSecuri=
ty Open Source Web Application Firewall
(WAF) to defend against web application attacks but my boss has told me to=
put that on hold at the moment. In fact, I have already deployed ModSecuri=
ty 2.9.0 on a Ubuntu 16.04 LTS *Testing* server and found that it actively =
detects and logs Nessus and sqlmap
vulnerability scans in blocking mode.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Since we did not find any evidence that the hacker h=
ad breached our customer's Ubuntu 16.04 LTS production server through ssh o=
r Teamviewer, we suspect that the hacker could have achieved it by SQL inje=
ction. I took the initiative of downloading
and installing Nessus Professional 8.3.1 Trial version for Windows 64-bit.=
The vulnerability scan report generated by Nessus Web Application Tests sh=
ows that our customer is using a version of phpMyAdmin prior to 4.8.5 which=
could be vulnerable to SQL injection
using the designer feature.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Further research shows that I can use sqlmap to dete=
rmine if phpMyAdmin is SQL injectable. I already have a Testing Ubuntu 16.0=
4 LTS Linux server with a Testing MySQL database and a Testing phpMyAdmin 4=
.8.4. I have purposely installed phpMyAdmin
4.8.4 because this version was reported to be vulnerable to SQL injection =
using the designer feature, and our customer is using a vulnerable version,=
according to CVE-2019-6798 ( https://nvd.nist.gov/vuln/detail/CVE-2019-679=
8 ). Then I proceeded to download
and execute sqlmap on our Ubuntu Linux desktop against our Testing server.=
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">No matter how many commands I try, sqlmap always rep=
ort that phpMyAdmin 4.8.4 is *NOT* SQL injectable. Perhaps I was using the =
wrong sqlmap commands all the time? The following is one of the many sqlmap=
commands I have used.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">$ python sqlmap.py -u "https://www.EXAMPLE.com/=
phymyadmin/index.php?id=3D1" --level=3D1 --dbms=3Dmysql --sql-query=3D=
"drop database"<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Replace database by database name.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">May I know what is the correct sqlmap command that I=
should use to determine that my Testing phpMyAdmin 4.8.4 is SQL injectable=
? I would like to know if I can successfully drop/delete the Testing databa=
se on our Testing server. If I can
successfully drop/delete the Testing MySQL database using sqlmap, I would =
be able to conclude that the hacker must have carried out SQL injection to =
drop/delete the customer's database. I have already turned off the Testing =
ModSecurity Web Application Firewall
on our Testing server to allow sqlmap to go through.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Please point me to any good tutorial on SQL injectio=
n using sqlmap. Maybe I do not understand SQL injection well enough. Our cu=
stomer is also using a customised in-house inventory management system that=
relies on PHP application and MySQL
database.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Would open source Snort Intrusion Detection System (=
IDS) and Intrusion Prevention System (IPS) be able to detect and block SQL =
injection as well?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Please advise.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal">Thank you very much.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">-----BEGIN EMAIL SIGNATURE-----<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">The Gospel for all Targeted Individuals (TIs):=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">[The New York Times] Microwave Weapons Are Pri=
me Suspect in Ills of<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">U.S. Embassy Workers<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">Link:
<a href=3D"https://www.nytimes.com/2018/09/01/science/sonic-attack-cuba-mic=
rowave.html">
<span style=3D"color:blue">https://www.nytimes.com/2018/09/01/science/sonic=
-attack-cuba-microwave.html</span></a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">**********************************************=
**********************************************<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">Singaporean Mr. Turritopsis Dohrnii Teo En Min=
g's Academic<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">Qualifications as at 14 Feb 2019<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">[1]
<a href=3D"https://tdtemcerts.wordpress.com/"><span style=3D"color:blue">ht=
tps://tdtemcerts.wordpress.com/</span></a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">[2]
<a href=3D"https://tdtemcerts.blogspot.sg/"><span style=3D"color:blue">http=
s://tdtemcerts.blogspot.sg/</span></a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">[3]
<a href=3D"https://www.scribd.com/user/270125049/Teo-En-Ming"><span style=
=3D"color:blue">https://www.scribd.com/user/270125049/Teo-En-Ming</span></a=
><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black"><o:p> </o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:"Co=
urier New";color:black">-----END EMAIL SIGNATURE-----</span><o:p></o:p=
></p>
<p class=3D"MsoNormal"><o:p> </o:p></p>
</div>
</body>
</html>
--_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_--
--===============9002108147104766984==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline
X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRGV2ZWxvcGVy
cyBtYWlsaW5nIGxpc3QKRGV2ZWxvcGVyc0BwaHBteWFkbWluLm5ldApodHRwczovL2xpc3RzLnBo
cG15YWRtaW4ubmV0L21haWxtYW4vbGlzdGluZm8vZGV2ZWxvcGVycwo=
--===============9002108147104766984==--