Advertisement
Guest User

Pakistani electric suplay got leaked by IES

a guest
Feb 25th, 2020
793
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 23.85 KB | None | 0 0
  1.  
  2. Target: http://www.pesco.gov.pk/
  3. Vulnerability: SQL Injection
  4. Author: Gh05t666include
  5.  
  6.  
  7. .-------.
  8. .' `.
  9. .' `.
  10. | NO SKIDS |
  11. | ALLOWED |
  12. | BEYOND |
  13. ' THIS '
  14. `. POINT .'
  15. `._______.' __ __
  16. | | .----/ \ / \---.
  17. | | | | | | |____
  18. | | | |`--''`--'| / | \_
  19. ,----.| \~O~| ~O~ _ | | | \
  20. | ---'| '._/ \_.| `| | | |
  21. \.---'| | | `- ,| |
  22. `---'| | : |
  23. | | | | '._.-- ;
  24. | | | . .: ` /
  25. '-' | '....' `.______/
  26. | |
  27. | |
  28. `----------------'
  29. || ||
  30. || ||
  31. _.---'' '-, ,-' ''---._
  32. / __..' '..__ \
  33. '---''` `''---'
  34.  
  35. Greets to all members of Indonesian error system
  36.  
  37.  
  38. List Member IES Leaked
  39.  
  40.  
  41.  
  42. MR.W4HYU - Mr.Fotolio/Tn.Fotolia - Gh05t666include/Ahor4 - Queen Tata - ./JuN07#/TN.JuN07# - Tn.Sky/sky.id - Y4d!Gh05t / Server 78 - 0janGh05t - Curut**part1kel-Xen4Sec-Kexz - ExAmHacker's- azhargh05t -S4!S|A - X|D
  43.  
  44.  
  45. available databases
  46. [37]:
  47. [*] CP
  48. [*] cp_mepco
  49. [*] cp_pesco
  50. [*] fesco
  51. [*] fescobill
  52. [*] gepco
  53. [*] gepco123
  54. [*] gepcoInnovation
  55. [*] gepcoitax
  56. [*] GepcoLeave
  57. [*] gepcomis
  58. [*] GI
  59. [*] gpayroll
  60. [*] Hardware
  61. [*] hesco
  62. [*] hesco-mis
  63. [*] hesco-wh
  64. [*] hesco_hrm
  65. [*] hescoNAP
  66. [*] hr
  67. [*] IESCOMIS
  68. [*] IncomeTax
  69. [*] master
  70. [*] mepco_com_pk
  71. [*] mepcomis
  72. [*] mepcomis1
  73. [*] misgepco
  74. [*] model
  75. [*] msdb
  76. [*] PEPCO-INVENTORY
  77. [*] pesco
  78. [*] pescomis
  79. [*] qesc
  80. [*] SEPCO-MIS
  81. [*] SRS
  82. [*] tempdb
  83. [*] testqesco
  84.  
  85. Database: msdb
  86. [9 tables]
  87. +-----------------------+
  88. | dbo.backupfile |
  89. | dbo.backupmediafamily |
  90. | dbo.backupmediaset |
  91. | dbo.backupset |
  92. | dbo.logmarkhistory |
  93. | dbo.restorefile |
  94. | dbo.restorefilegroup |
  95. | dbo.restorehistory |
  96. | dbo.suspect_pages |
  97. +-----------------------+
  98.  
  99. Database: master
  100. [291 tables]
  101. +---------------------------------------------------+
  102. | INFORMATION_SCHEMA.CHECK_CONSTRAINTS |
  103. | INFORMATION_SCHEMA.COLUMNS |
  104. | INFORMATION_SCHEMA.COLUMN_DOMAIN_USAGE |
  105. | INFORMATION_SCHEMA.COLUMN_PRIVILEGES |
  106. | INFORMATION_SCHEMA.CONSTRAINT_COLUMN_USAGE |
  107. | INFORMATION_SCHEMA.CONSTRAINT_TABLE_USAGE |
  108. | INFORMATION_SCHEMA.DOMAINS |
  109. | INFORMATION_SCHEMA.DOMAIN_CONSTRAINTS |
  110. | INFORMATION_SCHEMA.KEY_COLUMN_USAGE |
  111. | INFORMATION_SCHEMA.PARAMETERS |
  112. | INFORMATION_SCHEMA.REFERENTIAL_CONSTRAINTS |
  113. | INFORMATION_SCHEMA.ROUTINES |
  114. | INFORMATION_SCHEMA.ROUTINE_COLUMNS |
  115. | INFORMATION_SCHEMA.SCHEMATA |
  116. | INFORMATION_SCHEMA.TABLES |
  117. | INFORMATION_SCHEMA.TABLE_CONSTRAINTS |
  118. | INFORMATION_SCHEMA.TABLE_PRIVILEGES |
  119. | INFORMATION_SCHEMA.VIEWS |
  120. | INFORMATION_SCHEMA.VIEW_COLUMN_USAGE |
  121. | INFORMATION_SCHEMA.VIEW_TABLE_USAGE |
  122. | dbo.spt_fallback_db |
  123. | dbo.spt_fallback_dev |
  124. | dbo.spt_fallback_usg |
  125. | dbo.spt_monitor |
  126. | dbo.spt_values |
  127. | sys.all_columns |
  128. | sys.all_objects |
  129. | sys.all_parameters |
  130. | sys.all_sql_modules |
  131. | sys.all_views |
  132. | sys.allocation_units |
  133. | sys.assemblies |
  134. | sys.assembly_files |
  135. | sys.assembly_modules |
  136. | sys.assembly_references |
  137. | sys.assembly_types |
  138. | sys.asymmetric_keys |
  139. | sys.backup_devices |
  140. | sys.certificates |
  141. | sys.check_constraints |
  142. | sys.column_type_usages |
  143. | sys.column_xml_schema_collection_usages |
  144. | sys.columns |
  145. | sys.computed_columns |
  146. | sys.configurations |
  147. | sys.conversation_endpoints |
  148. | sys.conversation_groups |
  149. | sys.credentials |
  150. | sys.crypt_properties |
  151. | sys.data_spaces |
  152. | sys.database_files |
  153. | sys.database_mirroring |
  154. | sys.database_mirroring_endpoints |
  155. | sys.database_mirroring_witnesses |
  156. | sys.database_permissions |
  157. | sys.database_principal_aliases |
  158. | sys.database_principals |
  159. | sys.database_recovery_status |
  160. | sys.database_role_members |
  161. | sys.databases |
  162. | sys.default_constraints |
  163. | sys.destination_data_spaces |
  164. | sys.dm_broker_activated_tasks |
  165. | sys.dm_broker_connections |
  166. | sys.dm_broker_forwarded_messages |
  167. | sys.dm_broker_queue_monitors |
  168. | sys.dm_clr_appdomains |
  169. | sys.dm_clr_loaded_assemblies |
  170. | sys.dm_clr_properties |
  171. | sys.dm_clr_tasks |
  172. | sys.dm_db_file_space_usage |
  173. | sys.dm_db_index_usage_stats |
  174. | sys.dm_db_mirroring_connections |
  175. | sys.dm_db_missing_index_details |
  176. | sys.dm_db_missing_index_group_stats |
  177. | sys.dm_db_missing_index_groups |
  178. | sys.dm_db_partition_stats |
  179. | sys.dm_db_session_space_usage |
  180. | sys.dm_db_task_space_usage |
  181. | sys.dm_exec_background_job_queue |
  182. | sys.dm_exec_background_job_queue_stats |
  183. | sys.dm_exec_cached_plans |
  184. | sys.dm_exec_connections |
  185. | sys.dm_exec_query_memory_grants |
  186. | sys.dm_exec_query_optimizer_info |
  187. | sys.dm_exec_query_resource_semaphores |
  188. | sys.dm_exec_query_stats |
  189. | sys.dm_exec_query_transformation_stats |
  190. | sys.dm_exec_requests |
  191. | sys.dm_exec_sessions |
  192. | sys.dm_fts_active_catalogs |
  193. | sys.dm_fts_index_population |
  194. | sys.dm_fts_memory_buffers |
  195. | sys.dm_fts_memory_pools |
  196. | sys.dm_fts_population_ranges |
  197. | sys.dm_io_backup_tapes |
  198. | sys.dm_io_cluster_shared_drives |
  199. | sys.dm_io_pending_io_requests |
  200. | sys.dm_os_buffer_descriptors |
  201. | sys.dm_os_child_instances |
  202. | sys.dm_os_cluster_nodes |
  203. | sys.dm_os_hosts |
  204. | sys.dm_os_latch_stats |
  205. | sys.dm_os_loaded_modules |
  206. | sys.dm_os_memory_allocations |
  207. | sys.dm_os_memory_cache_clock_hands |
  208. | sys.dm_os_memory_cache_counters |
  209. | sys.dm_os_memory_cache_entries |
  210. | sys.dm_os_memory_cache_hash_tables |
  211. | sys.dm_os_memory_clerks |
  212. | sys.dm_os_memory_objects |
  213. | sys.dm_os_memory_pools |
  214. | sys.dm_os_performance_counters |
  215. | sys.dm_os_ring_buffers |
  216. | sys.dm_os_schedulers |
  217. | sys.dm_os_stacks |
  218. | sys.dm_os_sublatches |
  219. | sys.dm_os_sys_info |
  220. | sys.dm_os_tasks |
  221. | sys.dm_os_threads |
  222. | sys.dm_os_virtual_address_dump |
  223. | sys.dm_os_wait_stats |
  224. | sys.dm_os_waiting_tasks |
  225. | sys.dm_os_worker_local_storage |
  226. | sys.dm_os_workers |
  227. | sys.dm_qn_subscriptions |
  228. | sys.dm_repl_articles |
  229. | sys.dm_repl_schemas |
  230. | sys.dm_repl_tranhash |
  231. | sys.dm_repl_traninfo |
  232. | sys.dm_tran_active_snapshot_database_transactions |
  233. | sys.dm_tran_active_transactions |
  234. | sys.dm_tran_current_snapshot |
  235. | sys.dm_tran_current_transaction |
  236. | sys.dm_tran_database_transactions |
  237. | sys.dm_tran_locks |
  238. | sys.dm_tran_session_transactions |
  239. | sys.dm_tran_top_version_generators |
  240. | sys.dm_tran_transactions_snapshot |
  241. | sys.dm_tran_version_store |
  242. | sys.endpoint_webmethods |
  243. | sys.endpoints |
  244. | sys.event_notification_event_types |
  245. | sys.event_notifications |
  246. | sys.events |
  247. | sys.extended_procedures |
  248. | sys.extended_properties |
  249. | sys.filegroups |
  250. | sys.foreign_key_columns |
  251. | sys.foreign_keys |
  252. | sys.fulltext_catalogs |
  253. | sys.fulltext_document_types |
  254. | sys.fulltext_index_catalog_usages |
  255. | sys.fulltext_index_columns |
  256. | sys.fulltext_indexes |
  257. | sys.fulltext_languages |
  258. | sys.http_endpoints |
  259. | sys.identity_columns |
  260. | sys.index_columns |
  261. | sys.indexes |
  262. | sys.internal_tables |
  263. | sys.key_constraints |
  264. | sys.key_encryptions |
  265. | sys.linked_logins |
  266. | sys.login_token |
  267. | sys.master_files |
  268. | sys.master_key_passwords |
  269. | sys.message_type_xml_schema_collection_usages |
  270. | sys.messages |
  271. | sys.module_assembly_usages |
  272. | sys.numbered_procedure_parameters |
  273. | sys.numbered_procedures |
  274. | sys.objects |
  275. | sys.openkeys |
  276. | sys.parameter_type_usages |
  277. | sys.parameter_xml_schema_collection_usages |
  278. | sys.parameters |
  279. | sys.partition_functions |
  280. | sys.partition_parameters |
  281. | sys.partition_range_values |
  282. | sys.partition_schemes |
  283. | sys.partitions |
  284. | sys.plan_guides |
  285. | sys.procedures |
  286. | sys.remote_logins |
  287. | sys.remote_service_bindings |
  288. | sys.routes |
  289. | sys.schemas |
  290. | sys.securable_classes |
  291. | sys.server_assembly_modules |
  292. | sys.server_event_notifications |
  293. | sys.server_events |
  294. | sys.server_permissions |
  295. | sys.server_principals |
  296. | sys.server_role_members |
  297. | sys.server_sql_modules |
  298. | sys.server_trigger_events |
  299. | sys.server_triggers |
  300. | sys.servers |
  301. | sys.service_broker_endpoints |
  302. | sys.service_contract_message_usages |
  303. | sys.service_contract_usages |
  304. | sys.service_contracts |
  305. | sys.service_message_types |
  306. | sys.service_queue_usages |
  307. | sys.service_queues |
  308. | sys.services |
  309. | sys.soap_endpoints |
  310. | sys.sql_dependencies |
  311. | sys.sql_logins |
  312. | sys.sql_modules |
  313. | sys.stats |
  314. | sys.stats_columns |
  315. | sys.symmetric_keys |
  316. | sys.synonyms |
  317. | sys.sysaltfiles |
  318. | sys.syscacheobjects |
  319. | sys.syscharsets |
  320. | sys.syscolumns |
  321. | sys.syscomments |
  322. | sys.sysconfigures |
  323. | sys.sysconstraints |
  324. | sys.syscurconfigs |
  325. | sys.syscursorcolumns |
  326. | sys.syscursorrefs |
  327. | sys.syscursors |
  328. | sys.syscursortables |
  329. | sys.sysdatabases |
  330. | sys.sysdepends |
  331. | sys.sysdevices |
  332. | sys.sysfilegroups |
  333. | sys.sysfiles |
  334. | sys.sysforeignkeys |
  335. | sys.sysfulltextcatalogs |
  336. | sys.sysindexes |
  337. | sys.sysindexkeys |
  338. | sys.syslanguages |
  339. | sys.syslockinfo |
  340. | sys.syslogins |
  341. | sys.sysmembers |
  342. | sys.sysmessages |
  343. | sys.sysobjects |
  344. | sys.sysoledbusers |
  345. | sys.sysopentapes |
  346. | sys.sysperfinfo |
  347. | sys.syspermissions |
  348. | sys.sysprocesses |
  349. | sys.sysprotects |
  350. | sys.sysreferences |
  351. | sys.sysremotelogins |
  352. | sys.syssegments |
  353. | sys.sysservers |
  354. | sys.system_columns |
  355. | sys.system_components_surface_area_configuration |
  356. | sys.system_internals_allocation_units |
  357. | sys.system_internals_partition_columns |
  358. | sys.system_internals_partitions |
  359. | sys.system_objects |
  360. | sys.system_parameters |
  361. | sys.system_sql_modules |
  362. | sys.system_views |
  363. | sys.systypes |
  364. | sys.sysusers |
  365. | sys.tables |
  366. | sys.tcp_endpoints |
  367. | sys.trace_categories |
  368. | sys.trace_columns |
  369. | sys.trace_event_bindings |
  370. | sys.trace_events |
  371. | sys.trace_subclass_values |
  372. | sys.traces |
  373. | sys.transmission_queue |
  374. | sys.trigger_events |
  375. | sys.triggers |
  376. | sys.type_assembly_usages |
  377. | sys.types |
  378. | sys.user_token |
  379. | sys.via_endpoints |
  380. | sys.views |
  381. | sys.xml_indexes |
  382. | sys.xml_schema_attributes |
  383. | sys.xml_schema_collections |
  384. | sys.xml_schema_component_placements |
  385. | sys.xml_schema_components |
  386. | sys.xml_schema_elements |
  387. | sys.xml_schema_facets |
  388. | sys.xml_schema_model_groups |
  389. | sys.xml_schema_namespaces |
  390. | sys.xml_schema_types |
  391. | sys.xml_schema_wildcard_namespaces |
  392. | sys.xml_schema_wildcards |
  393. +---------------------------------------------------+
  394.  
  395. Database: master
  396. Table: sys.sysusers
  397. [20 columns]
  398. +-------------+-----------+
  399. | Column | Type |
  400. +-------------+-----------+
  401. | altuid | smallint |
  402. | createdate | datetime |
  403. | environ | varchar |
  404. | gid | smallint |
  405. | hasdbaccess | int |
  406. | isaliased | int |
  407. | isapprole | int |
  408. | islogin | int |
  409. | isntgroup | int |
  410. | isntname | int |
  411. | isntuser | int |
  412. | issqlrole | int |
  413. | issqluser | int |
  414. | name | nvarchar |
  415. | password | varbinary |
  416. | roles | varbinary |
  417. | sid | varbinary |
  418. | status | smallint |
  419. | uid | smallint |
  420. | updatedate | datetime |
  421. +-------------+-----------+
  422.  
  423. Database: master
  424. Table: sys.sysusers
  425. [14 entries]
  426. +--------------------+--------+----------+
  427. | name | status | password |
  428. +--------------------+--------+----------+
  429. | db_accessadmin | 0 | NULL |
  430. | db_backupoperator | 0 | NULL |
  431. | db_datareader | 0 | NULL |
  432. | db_datawriter | 0 | NULL |
  433. | db_ddladmin | 0 | NULL |
  434. | db_denydatareader | 0 | NULL |
  435. | db_denydatawriter | 0 | NULL |
  436. | db_owner | 0 | NULL |
  437. | db_securityadmin | 0 | NULL |
  438. | dbo | 0 | NULL |
  439. | guest | 0 | NULL |
  440. | INFORMATION_SCHEMA | 0 | NULL |
  441. | public | 0 | NULL |
  442. | sys | 0 | NULL |
  443. +--------------------+--------+----------+
  444.  
  445. Database: pesco
  446. [67 tables]
  447. +-----------------------------------------+
  448. | dbo.Results |
  449. | dbo.bod |
  450. | dbo.breakers_11_kv |
  451. | dbo.breakers_132_66_33_kv |
  452. | dbo.circles |
  453. | dbo.complaint_file |
  454. | dbo.complaint_pop_sdno |
  455. | dbo.complaint_pop_type |
  456. | dbo.conn_given |
  457. | dbo.conn_given_headings |
  458. | dbo.curr_disposal_notice |
  459. | dbo.curr_tender_notice |
  460. | dbo.cust_serv_center |
  461. | dbo.detail_capacitor_bank |
  462. | dbo.detail_capacitor_bank_headings |
  463. | dbo.detect_bill_monthly |
  464. | dbo.detect_bill_progressive |
  465. | dbo.dtproperties |
  466. | dbo.elect_direc |
  467. | dbo.elect_directory_name |
  468. | dbo.electricity_tariff |
  469. | dbo.feedback |
  470. | dbo.feedback_populate |
  471. | dbo.gso_comprises |
  472. | dbo.gso_comprises_additional |
  473. | dbo.instal_powers_disconect_conec |
  474. | dbo.instal_powers_running_conec |
  475. | dbo.item_category_list |
  476. | dbo.item_imp_price_bulletin |
  477. | dbo.job_results |
  478. | dbo.maintenance_schedule |
  479. | dbo.mis_cash_revenue_report |
  480. | dbo.mis_daily_report |
  481. | dbo.mis_dead_defaulter_report |
  482. | dbo.mis_defaulter_report |
  483. | dbo.mis_general_report |
  484. | dbo.mis_line_losses_report |
  485. | dbo.mis_monthly_report |
  486. | dbo.mis_reports_comment |
  487. | dbo.mis_wapda_billing_report |
  488. | dbo.mis_weekly_report |
  489. | dbo.news_detail |
  490. | dbo.news_main_page |
  491. | dbo.offices |
  492. | dbo.overview_pesco |
  493. | dbo.phy_finan_prog_yr1 |
  494. | dbo.phy_finan_prog_yr1_headings |
  495. | dbo.phy_finan_prog_yr2 |
  496. | dbo.phy_finan_prog_yr2_headings |
  497. | dbo.prog_htlt_line_added |
  498. | dbo.prog_htlt_line_added_headings |
  499. | dbo.reg_bill_collect_percen_rec |
  500. | dbo.regis_contractor |
  501. | dbo.regis_suppliers |
  502. | dbo.stat_prog_defective_meters |
  503. | dbo.stat_prog_defective_meters_headings |
  504. | dbo.summary_projec_ann_sav |
  505. | dbo.theft_material_cases |
  506. | dbo.theft_report_reward |
  507. | dbo.transfor_damage_mon |
  508. | dbo.transfor_damage_mon_headings |
  509. | dbo.transfor_instal_as_on_1 |
  510. | dbo.transfor_instal_as_on_1_headings |
  511. | dbo.transfor_instal_as_on_2 |
  512. | dbo.transfor_instal_for_mon |
  513. | dbo.transfor_instal_for_mon_headings |
  514. | dbo.usernames |
  515. +-----------------------------------------+
  516.  
  517. Database: master
  518. Table: sys.login_token
  519. [3 entries]
  520. +----------+-----------+---------------+
  521. | sid | name | usage |
  522. +----------+-----------+---------------+
  523. | \x02 | public | GRANT OR DENY |
  524. | \t | dbcreator | GRANT OR DENY |
  525. | ??????C? | <blank> | <blank> |
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement