##################################### HACKED BY TEAM T!g3R ################################# REGITRAR GENERAL'S DEPARTMENT, GOVT OF SRILANKA MEMBERS : w3bd3f4c3r, n3ll@!s4mur@!, !nd!@nRuBuk, r00t, burn3r. WEBSITE : http://www.rgd.gov.lk/ VULNERABLE : SQLi VULNERABLE LINK HIDDEN ######################################## PROOFS ############################################ PROOF THAT TABLES ACCESSED : http://i56.tinypic.com/2nv8rnp.png PROOF THAT USERS ACCESSED : http://i53.tinypic.com/xmvhxl.png #####################################SERVER DETAILS######################################## Target: http://www.rgd.gov.lk/ Host IP: 220.247.225.200 Web Server: Apache/2.2.3 (Red Hat) Powered-by: PHP/5.2.10 DB Server: MySQL >=5 Resp. Time(avg): 1324 ms Current User: rgd_dbuser@localhost Sql Version: 5.0.77 Current DB: rgdgov_rgdcms System User: rgd_dbuser@localhost Host Name: singhaya2.lk Installation dir: /usr/ DB User: 'rgd_dbuser'@'localhost' ################################## DATABASE NAMES ######################################## Data Bases: information_schema rgdgov_rgdcms rgdgov_search test test_db ############################ TABLES NAMES OF DB rgdgov_rgdcms ########################### snippet_sin snippet_eng sinnews projects_history_sin projects_history newssin news lastupdate faqquestionssin faqquestions faqanswersin faqanswer engnews editdatasin editdataeng downloadsin download currentprojectssin currentprojects authteam ############################# USER DETAILS OF DB rgdgov_rgdcms ########################### Data Found: id=1 Data Found: uName=admin Data Found: pWord=admin123 Data Found: uLevel=1 Data Found: name=Main Administrator Data Found: id=2 Data Found: uName=englishadmin Data Found: pWord=admin123 Data Found: uLevel=2 Data Found: name=English Administrator Data Found: id=3 Data Found: uName=sinhalaadmin Data Found: pWord=admin123 Data Found: uLevel=3 Data Found: name=Sinhala Administrator Data Found: id=4 Data Found: uName=superadmin Data Found: pWord=rgadminsup Data Found: uLevel=1 Data Found: name=Super Administrator ################################# TABLES OF DB rgdgov_search ############################# temp sites site_category query_log pending links link_keyword keywords categories ########################### HACKED BY TEAM T!g3R #####################################