sqlmap web gui + kali - не работает

Discussion in 'Песочница' started by Vald, 4 Aug 2015.

  1. Vald

    Vald Member

    Joined:
    6 Aug 2009
    Messages:
    25
    Likes Received:
    16
    Reputations:
    0
    Такая проблема, пытаюсь поставить гуй (который от Hood3dRob1n).
    json установил, конфиг поправил

    Но запущенный sqlmapapi выдает такое:
    Code:
    root@kali:~# python /usr/share/sqlmap/sqlmapapi.py -s
    [18:32:33] [INFO] Running REST-JSON API server at '127.0.0.1:8775'..
    [18:32:33] [INFO] Admin ID: 1c952759513cd1a4fae7e023208807b9
    [18:32:33] [DEBUG] IPC database: /tmp/sqlmapipc-Y4WwsM
    [18:32:33] [DEBUG] REST-JSON API server connected to IPC database
    [18:33:18] [DEBUG] Created new task: '4618cc754b7ae6a8'
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Requested to set options
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Retrieved value for option url
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Started scan
    [18:33:18] [DEBUG] [4618cc754b7ae6a8] Retrieved scan status
    python: can't open file 'sqlmap.py': [Errno 2] No such file or directory
    [18:33:19] [DEBUG] [4618cc754b7ae6a8] Retrieved scan status
    [18:33:19] [DEBUG] [4618cc754b7ae6a8] Retrieved scan data and error messages
    [18:33:19] [DEBUG] [4618cc754b7ae6a8] Retrieved scan log messages
    [18:33:19] [DEBUG] [4618cc754b7ae6a8] Deleted task
    В чем может быть проблема и как поправить? Сам sqlmap.py лежит в папке с апи.
     
  2. Эрос

    Эрос New Member

    Joined:
    5 Dec 2011
    Messages:
    17
    Likes Received:
    1
    Reputations:
    -3
    А на хрена тебе GUI? чем тебе терминал не нравится?
     
  3. rct

    rct Active Member

    Joined:
    13 Jun 2015
    Messages:
    359
    Likes Received:
    107
    Reputations:
    7
    this
    >python: can't open file 'sqlmap.py': [Errno 2] No such file or directory
    Читай внимательно мануал
    >Edit the sqlmap/inc/config.php file so the paths all point to the right locations on your system

    Code:
    <?php
      // App Version Tracker
      define('GUI_VERSION', '0.01b');
      // API URL to Connect to, default: http://127.0.0.1:8775/
      define('API_URL', 'http://127.0.0.1:8775/');
      // Path to where the core SQLMAP python files can be found
      //    i.e. sqlmap.py, sqlmapapi.py, extra/, tamper/, etc
      define('SQLMAP_BIN_PATH', '/home/username/tools/sqlmap/'); //здесь поправить на каталог с sqlmap
      // Path to SQLMAP's Default Output Directory
      define('SQLMAP_OUTPUT_PATH', '/home/username/.sqlmap/output/'); //здесь тоже поправить
      // Define where to write our local scan file archives to
      define('TMP_PATH', '/tmp/sqlmap/');
      // Path to the local Metasploit directory
      // May be used to generate shellcode for advanced exploit functionalities
      // May also use for building of reverse shell payloads for file writer, tbd...
      define('MSF_PATH', '/home/username/tools/msf/'); //и здесь, коли метасполит нужен
      // Admin Username & Password
      // *For future admin panel to flush and kill scan tasks....
      define('ADMIN_USER', 'admin');
      define('ADMIN_PASS', 'admin');
    ?>
     
    #3 rct, 24 Sep 2015
    Last edited: 24 Sep 2015
  4. ubepkr

    ubepkr Member

    Joined:
    17 Aug 2015
    Messages:
    96
    Likes Received:
    20
    Reputations:
    1
    Добрый день!
    У меня при любых раскладах GUI моментально выдает что-то типа "SQLMAP Scan Summary for ScanID: 16c9182ce1cfa1bd" и все (Kali2).
    config.php в норме, sqlmapapi.py -s запущен, apache2, разумеется, тоже. Сам GUI внешне в порядке, а вот отрабатывать не хочет.
    Кто знает, где собака порылась?))

    Upd. Разобрался. Все невнимательность.... в конфиге указал /usr/share/sqlmap/, а сервер (sqlmapapi) запускал из другой директории((
     
    #4 ubepkr, 9 Nov 2015
    Last edited: 9 Nov 2015
  5. nikbim96

    nikbim96 Member

    Joined:
    16 Jan 2014
    Messages:
    112
    Likes Received:
    22
    Reputations:
    1
    Чувак ты попробуй в burp suite sqlmap есть если тебе мышкой работать удобней )
     
Loading...