
22.11.2009, 17:22
|
|
Участник форума
Регистрация: 17.09.2006
Сообщений: 248
Провел на форуме: 556476
Репутация:
66
|
|
привожу листинг глюк при работе со стандартным Mysql4 inj чтоб ты понял где исправит:
C:\Perl64\toolza1.0>toolza.pl
-----------------------------------------
-----------------------------------------
Toolza 1.0 by Pashkela [ BugTrack Team ] (c) 2009
----------------------------------------------------------
Choose mode:
----------------------------------------------------------
[1] Mysql injection
[2] MSSQL injection
[3] PostgreSQL injection
[4] Sybase SQL injection
[5] Access & Jet SQL injection
================================================== =====
[6] LFI/Reader/Load_file() bruter
[7] Scan site for folders & files
[8] FTP checker
[9] FTP bruter
[10] Proxy checker
[11] Proxy grabber
================================================== =====
[12] Exit
----------------------------------------------------------
1
Your choice: 1
----------------------------------------------------------
Choose mode:
----------------------------------------------------------
[1] Mysql inj system information
[2] Mysql inj get tables from information_schema
[3] Mysql inj get column_name from table
[4] Mysql inj get data from columns
[5] Mysql inj brute tables & columns
[6] Mysql inj column number bruter
[7] Mysql inj Blind
[8] Mysql inj NAME_CONST
----------------------------------------------------------
[9] Main menu
----------------------------------------------------------
3
Your choice: 3
-----------------------------------------
Enter the table_name: companies
Table: companies
----------
Database for companies: localhost.com (но при system information дб другой, не само название сайта)
Number of columns in localhost.com.companies: localhost.com
----------
Request method - GET
Threads - 10
Proxy - no
----------------------
----------
Saved in z_localhost.com.txt
----------------------------------------------------------
Choose mode:
----------------------------------------------------------
[1] Mysql inj system information
[2] Mysql inj get tables from information_schema
[3] Mysql inj get column_name from table
[4] Mysql inj get data from columns
[5] Mysql inj brute tables & columns
[6] Mysql inj column number bruter
[7] Mysql inj Blind
[8] Mysql inj NAME_CONST
----------------------------------------------------------
[9] Main menu
----------------------------------------------------------
На старых версиях норм брутил колонки, и теперь появился после добавления MSACCESS & JET
|
|
|