Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- # TH Köln SQL Injection login form
- ## Info
- Found by: p01ntR
- Date: July 2017
- Affected URL: https://webmail.th-koeln.de/login.php
- Blind SQL Injection in Form-parameter horde_user
- ## Dump snippet
- Passwords seem to be just MD5 hashed in the database. Not sure if salted.
- [...]
- peter.meier@hochschule.tech :: 8445eaf424d41066e817ab195d7a70a4
- michaela.bauer@hochschule.tech :: 6fe0ce7538350ba31c49e07b967b11a6
- julian.franke@hochschule.tech :: c28e4c30aa7d867a8b11757996813c9c
- marcus.schmidt@hochschule.tech :: bea846884e8b766f1b7d7c8132029d10
- paul.baumann@hochschule.tech :: f90b3cc6622e0f0a6d9d2d9147920c22
- florian.bauer@hochschule.tech :: 0c62f7396615ac0e4898ac8740ecf9e5
- ben.sauer@hochschule.tech :: 97c1e2512014521877ab2d837f4a5bdb
- maximilian.koch@hochschule.tech :: cb5a478613c7de838d9f2555631d9d8a
- finn.martin@hochschule.tech :: f95a3a4876fa67fb631715c101d84239
- lea.werner@hochschule.tech :: 8f6156ddae692df2f6bd2d6d3fd3db71
- jonathan.lange@hochschule.tech :: 6d958650ed6d7de5be9223e93878049f
- melina.schubert@hochschule.tech :: f66a3ee2fcc043b404b1a385e96139c8
- marcel.winkler@hochschule.tech :: 87856aa9ad2208aeb5bb216b938bc1a1
- hannah.wolff@hochschule.tech :: 3fe198fe0d5cd497f4d43a2ce72284c1
- tom.scholz@hochschule.tech :: b8f49695ceecc1b5f845984ec4c5aad1
- lina.fischer@hochschule.tech :: 9893a33008e9c5626a349d933a49bb5d
- leonie.meier@hochschule.tech :: 57d7be55e111a68eae95541b200bfbc0
- sarah.lorenz@hochschule.tech :: 902d252b74119e5e15c874c2f0122821
- jonas.horn@hochschule.tech :: 11b05b8e9870d58e7dd4dd9a080a6385
- florian.herrmann@hochschule.tech :: 099f222360225f767e1e9e6177446b88
- julian.vogel@hochschule.tech :: 9ca3aab21a183899e1f03dd2d3612e38
- julian.kuehn@hochschule.tech :: e5111d4e9e78d84f9e6a854dd7466241
- [...]
Add Comment
Please, Sign In to add comment