[phpMyAdmin Developers] How do I determine if versions of phpMyAdmin before 4.8.5 is SQL Injectable using sqlmap?

Turritopsis Dohrnii Teo En Ming <[email protected]> Wed, 17 Apr 2019 13:57:19 +0000
Newsgroups gmane.comp.php.phpmyadmin.devel
Message-ID <HK0PR01MB26445ACB131A6CE62416D42087250@HK0PR01MB2644.apcprd01.prod.exchangelabs.com>
--===============9002108147104766984==
Content-Language: en-US
Content-Type: multipart/alternative;
	boundary="_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_"

--_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Subject/Topic: How do I determine if versions of phpMyAdmin before 4.8.5 is=
 SQL Injectable using sqlmap?

Good evening from Singapore,

Our customer (company name is Confidential/not disclosed) reported that the=
ir MySQL database has been found missing or was deleted a few times. They a=
re using Ubuntu 16.04 LTS Linux server with Apache2 Web Server, MySQL and P=
HP (LAMP).

We responded to these security incidents by changing the passwords of the r=
egular user, root user, and MySQL database user root. We have also examined=
 /var/log/auth.log and think that the hacker could not have come in through=
 ssh or sftp over ssh. From /var/log/mysql/error.log, we can ascertain that=
 the MySQL database has been deleted at certain timings. We have also found=
 nothing abnormal after examining /var/log/apache2/access.log.

Even though we have secured the Ubuntu Linux server by changing passwords, =
the hacker was still able to delete our customer's MySQL database again and=
 again. I have already proposed to install ModSecurity Open Source Web Appl=
ication Firewall (WAF) to defend against web application attacks but my bos=
s has told me to put that on hold at the moment. In fact, I have already de=
ployed ModSecurity 2.9.0 on a Ubuntu 16.04 LTS *Testing* server and found t=
hat it actively detects and logs Nessus and sqlmap vulnerability scans in b=
locking mode.

Since we did not find any evidence that the hacker had breached our custome=
r's Ubuntu 16.04 LTS production server through ssh or Teamviewer, we suspec=
t that the hacker could have achieved it by SQL injection. I took the initi=
ative of downloading and installing Nessus Professional 8.3.1 Trial version=
 for Windows 64-bit. The vulnerability scan report generated by Nessus Web =
Application Tests shows that our customer is using a version of phpMyAdmin =
prior to 4.8.5 which could be vulnerable to SQL injection using the designe=
r feature.

Further research shows that I can use sqlmap to determine if phpMyAdmin is =
SQL injectable. I already have a Testing Ubuntu 16.04 LTS Linux server with=
 a Testing MySQL database and a Testing phpMyAdmin 4.8.4. I have purposely =
installed phpMyAdmin 4.8.4 because this version was reported to be vulnerab=
le to SQL injection using the designer feature, and our customer is using a=
 vulnerable version, according to CVE-2019-6798 ( https://nvd.nist.gov/vuln=
/detail/CVE-2019-6798 ). Then I proceeded to download and execute sqlmap on=
 our Ubuntu Linux desktop against our Testing server.

No matter how many commands I try, sqlmap always report that phpMyAdmin 4.8=
.4 is *NOT* SQL injectable. Perhaps I was using the wrong sqlmap commands a=
ll the time? The following is one of the many sqlmap commands I have used.

$ python sqlmap.py -u "https://www.EXAMPLE.com/phymyadmin/index.php?id=3D1"=
 --level=3D1 --dbms=3Dmysql --sql-query=3D"drop database"

Replace database by database name.

May I know what is the correct sqlmap command that I should use to determin=
e that my Testing phpMyAdmin 4.8.4 is SQL injectable? I would like to know =
if I can successfully drop/delete the Testing database on our Testing serve=
r. If I can successfully drop/delete the Testing MySQL database using sqlma=
p, I would be able to conclude that the hacker must have carried out SQL in=
jection to drop/delete the customer's database. I have already turned off t=
he Testing ModSecurity Web Application Firewall on our Testing server to al=
low sqlmap to go through.

Please point me to any good tutorial on SQL injection using sqlmap. Maybe I=
 do not understand SQL injection well enough. Our customer is also using a =
customised in-house inventory management system that relies on PHP applicat=
ion and MySQL database.

Would open source Snort Intrusion Detection System (IDS) and Intrusion Prev=
ention System (IPS) be able to detect and block SQL injection as well?

Please advise.

Thank you very much.

-----BEGIN EMAIL SIGNATURE-----

The Gospel for all Targeted Individuals (TIs):

[The New York Times] Microwave Weapons Are Prime Suspect in Ills of
U.S. Embassy Workers

Link: https://www.nytimes.com/2018/09/01/science/sonic-attack-cuba-microwav=
e.html

***************************************************************************=
*****************

Singaporean Mr. Turritopsis Dohrnii Teo En Ming's Academic
Qualifications as at 14 Feb 2019

[1] https://tdtemcerts.wordpress.com/

[2] https://tdtemcerts.blogspot.sg/

[3] https://www.scribd.com/user/270125049/Teo-En-Ming

-----END EMAIL SIGNATURE-----


--_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 15 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:DengXian;
	panose-1:2 1 6 0 3 1 1 1 1 1;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:"\@DengXian";
	panose-1:2 1 6 0 3 1 1 1 1 1;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0cm;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri",sans-serif;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:#0563C1;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:#954F72;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal-compose;
	font-family:"Calibri",sans-serif;
	color:windowtext;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-family:"Calibri",sans-serif;}
@page WordSection1
	{size:612.0pt 792.0pt;
	margin:72.0pt 72.0pt 72.0pt 72.0pt;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-SG" link=3D"#0563C1" vlink=3D"#954F72">
<div class=3D"WordSection1">
<p class=3D"MsoNormal">Subject/Topic: How do I determine if versions of php=
MyAdmin before 4.8.5 is SQL Injectable using sqlmap?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Good evening from Singapore,<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Our customer (company name is Confidential/not discl=
osed) reported that their MySQL database has been found missing or was dele=
ted a few times. They are using Ubuntu 16.04 LTS Linux server with Apache2 =
Web Server, MySQL and PHP (LAMP).<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">We responded to these security incidents by changing=
 the passwords of the regular user, root user, and MySQL database user root=
. We have also examined /var/log/auth.log and think that the hacker could n=
ot have come in through ssh or sftp
 over ssh. From /var/log/mysql/error.log, we can ascertain that the MySQL d=
atabase has been deleted at certain timings. We have also found nothing abn=
ormal after examining /var/log/apache2/access.log.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Even though we have secured the Ubuntu Linux server =
by changing passwords, the hacker was still able to delete our customer's M=
ySQL database again and again. I have already proposed to install ModSecuri=
ty Open Source Web Application Firewall
 (WAF) to defend against web application attacks but my boss has told me to=
 put that on hold at the moment. In fact, I have already deployed ModSecuri=
ty 2.9.0 on a Ubuntu 16.04 LTS *Testing* server and found that it actively =
detects and logs Nessus and sqlmap
 vulnerability scans in blocking mode.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Since we did not find any evidence that the hacker h=
ad breached our customer's Ubuntu 16.04 LTS production server through ssh o=
r Teamviewer, we suspect that the hacker could have achieved it by SQL inje=
ction. I took the initiative of downloading
 and installing Nessus Professional 8.3.1 Trial version for Windows 64-bit.=
 The vulnerability scan report generated by Nessus Web Application Tests sh=
ows that our customer is using a version of phpMyAdmin prior to 4.8.5 which=
 could be vulnerable to SQL injection
 using the designer feature.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Further research shows that I can use sqlmap to dete=
rmine if phpMyAdmin is SQL injectable. I already have a Testing Ubuntu 16.0=
4 LTS Linux server with a Testing MySQL database and a Testing phpMyAdmin 4=
.8.4. I have purposely installed phpMyAdmin
 4.8.4 because this version was reported to be vulnerable to SQL injection =
using the designer feature, and our customer is using a vulnerable version,=
 according to CVE-2019-6798 ( https://nvd.nist.gov/vuln/detail/CVE-2019-679=
8 ). Then I proceeded to download
 and execute sqlmap on our Ubuntu Linux desktop against our Testing server.=
<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">No matter how many commands I try, sqlmap always rep=
ort that phpMyAdmin 4.8.4 is *NOT* SQL injectable. Perhaps I was using the =
wrong sqlmap commands all the time? The following is one of the many sqlmap=
 commands I have used.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">$ python sqlmap.py -u &quot;https://www.EXAMPLE.com/=
phymyadmin/index.php?id=3D1&quot; --level=3D1 --dbms=3Dmysql --sql-query=3D=
&quot;drop database&quot;<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Replace database by database name.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">May I know what is the correct sqlmap command that I=
 should use to determine that my Testing phpMyAdmin 4.8.4 is SQL injectable=
? I would like to know if I can successfully drop/delete the Testing databa=
se on our Testing server. If I can
 successfully drop/delete the Testing MySQL database using sqlmap, I would =
be able to conclude that the hacker must have carried out SQL injection to =
drop/delete the customer's database. I have already turned off the Testing =
ModSecurity Web Application Firewall
 on our Testing server to allow sqlmap to go through.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Please point me to any good tutorial on SQL injectio=
n using sqlmap. Maybe I do not understand SQL injection well enough. Our cu=
stomer is also using a customised in-house inventory management system that=
 relies on PHP application and MySQL
 database.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Would open source Snort Intrusion Detection System (=
IDS) and Intrusion Prevention System (IPS) be able to detect and block SQL =
injection as well?<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Please advise.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal">Thank you very much.<o:p></o:p></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">-----BEGIN EMAIL SIGNATURE-----<o:p></o:p></sp=
an></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">The Gospel for all Targeted Individuals (TIs):=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">[The New York Times] Microwave Weapons Are Pri=
me Suspect in Ills of<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">U.S. Embassy Workers<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">Link:
<a href=3D"https://www.nytimes.com/2018/09/01/science/sonic-attack-cuba-mic=
rowave.html">
<span style=3D"color:blue">https://www.nytimes.com/2018/09/01/science/sonic=
-attack-cuba-microwave.html</span></a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">**********************************************=
**********************************************<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">Singaporean Mr. Turritopsis Dohrnii Teo En Min=
g's Academic<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">Qualifications as at 14 Feb 2019<o:p></o:p></s=
pan></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">[1]
<a href=3D"https://tdtemcerts.wordpress.com/"><span style=3D"color:blue">ht=
tps://tdtemcerts.wordpress.com/</span></a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">[2]
<a href=3D"https://tdtemcerts.blogspot.sg/"><span style=3D"color:blue">http=
s://tdtemcerts.blogspot.sg/</span></a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">[3]
<a href=3D"https://www.scribd.com/user/270125049/Teo-En-Ming"><span style=
=3D"color:blue">https://www.scribd.com/user/270125049/Teo-En-Ming</span></a=
><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black"><o:p>&nbsp;</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:10.0pt;font-family:&quot;Co=
urier New&quot;;color:black">-----END EMAIL SIGNATURE-----</span><o:p></o:p=
></p>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
</div>
</body>
</html>

--_000_HK0PR01MB26445ACB131A6CE62416D42087250HK0PR01MB2644apcp_--


--===============9002108147104766984==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: base64
Content-Disposition: inline

X19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX19fX18KRGV2ZWxvcGVy
cyBtYWlsaW5nIGxpc3QKRGV2ZWxvcGVyc0BwaHBteWFkbWluLm5ldApodHRwczovL2xpc3RzLnBo
cG15YWRtaW4ubmV0L21haWxtYW4vbGlzdGluZm8vZGV2ZWxvcGVycwo=

--===============9002108147104766984==--