|
本帖最后由 zglloo 于 2012-7-14 15:20 编辑
黑客称利用union-based SQL注入漏洞获得了XXX.yahoo.com的用户数据。其中包括453492条用户数据记录,超过2700个数据库表和列名,298个MySQL参数。在曝光的数据中有一条HOSTNAME =>> dbb1.ac.bf1.yahoo.com该域名属于Yahoo Voice应用。因此很可能就是Yahoo Voice应用被成功入侵了。
可以到这里查询是否泄露自己的账户- #######################################
- #[ - Owned and Exposed - ] #
- # Brought to you by the D33Ds Company #
- # #
- # Target: <censored>.yahoo.com #
- # Method: Union-based SQL Injection #
- # #
- #######################################
- -------------
- Jump to:
- 1. MySQL Variables
- 2. Database/Table/Column Names
- 3. email:pass dump (450k users)
- 4. Final Notes
- -------------
- 1. MySQL Variables
- ------------------
- MAX_PREPARED_STMT_COUNT =>> 16382
- CHARACTER_SETS_DIR =>> /home/y/share/mysql/charsets/
- HAVE_CRYPT =>> YES
- CONNECT_TIMEOUT =>> 10
- ......
- 2. Database/Table/Column Names
- -------------------------------
- [ * ] schema_name ==> table_name :::: column_name
- information_schema =>> CHARACTER_SETS :::: CHARACTER_SET_NAME
- information_schema =>> CHARACTER_SETS :::: DEFAULT_COLLATE_NAME
- information_schema =>> CHARACTER_SETS :::: DESCRIPTION
- information_schema =>> CHARACTER_SETS :::: MAXLEN
- ......
- 3. email:pass dump (450k users)
- --------------------------------
- count() = 453491
- user_id : user_name : clear_passwd : passwd
- 1:[email protected]:@fl!pm0de@
- 4:[email protected]:pass
- 5:[email protected]:steveol
- 6:[email protected]:chotzi
- ....
- 366641:[email protected]:uplgmotv
复制代码 排名前10的密码
123456 = 1666 (0.38%)
password = 780 (0.18%)
welcome = 436 (0.1%)
ninja = 333 (0.08%)
abc123 = 250 (0.06%)
123456789 = 222 (0.05%)
12345678 = 208 (0.05%)
sunshine = 205 (0.05%)
princess = 202 (0.05%)
qwerty = 172 (0.04%)
top 10 base words
password = 1373 (0.31%)
welcome = 534 (0.12%)
qwerty = 464 (0.1%)
monkey = 430 (0.1%)
jesus = 429 (0.1%)
love = 421 (0.1%)
money = 407 (0.09%)
freedom = 385 (0.09%)
ninja = 380 (0.09%)
writer = 367 (0.08%)
top 10 e-mail:
yahoo.com (31.07%)
gmail.com (24.14%)
hotmail.com (12.45%)
aol.com (5.76%)
comcast.net (1.93%)
msn.com (1.44%)
sbcglobal.net (1.17%)
live.com (0.97%)
verizon.net (0.68%)
bellsouth.net (0.64%) |
|