Showing posts with label Website hacking. Show all posts
Showing posts with label Website hacking. Show all posts

Monday, November 14, 2011

Epicgames.com database hacked and leacked by contra


Epicgames.com database hacked and leacked by contra






Epicgames is a big name in gaming industry
Website epicgames.com has been hacked by Contra and the database is leaked on internet.
Hacker posted the complete database detail on the link
http://pastebin.com/X455ZARH


The website is now showing the message that "website is down for maintenance and will be back soon"

Epicgames.com database hacked and leacked by contra


Epicgames.com database hacked and leacked by contra






Epicgames is a big name in gaming industry
Website epicgames.com has been hacked by Contra and the database is leaked on internet.
Hacker posted the complete database detail on the link
http://pastebin.com/X455ZARH


The website is now showing the message that "website is down for maintenance and will be back soon"

Lulzsec hacked Sony Computer Entertainment Developer Network and leaked source code


Lulzsec hacked Sony Computer Entertainment Developer Network  and leaked  source code


hats off to the Lulz security. They again hit sony network and relesed the source code of Sony Computer Entertainment Developer Network "scedev.net" Via there Twitter account. They share this data using a mediashare link


Download Here
http://www.mediafire.com/?ev1zo010c020764

Lulzsec hacked Sony Computer Entertainment Developer Network and leaked source code


Lulzsec hacked Sony Computer Entertainment Developer Network  and leaked  source code


hats off to the Lulz security. They again hit sony network and relesed the source code of Sony Computer Entertainment Developer Network "scedev.net" Via there Twitter account. They share this data using a mediashare link


Download Here
http://www.mediafire.com/?ev1zo010c020764

Sony music brazil (sonymusic.com.br) hacked and defaced


Sony music brazil (sonymusic.com.br) hacked and defaced


This time again a sony website is hacked by hackers. I do not know what's happening with sony but it's now daily news. sony hacked again and again and again.................
This time a group of hackers "The UnderTakers" were able to deface the website of sonyMusic brazil. I think it's too much for the company. They should take some protective action and try to secure it's network and all websites.
Now website is recovered and running.

Sony music brazil (sonymusic.com.br) hacked and defaced


Sony music brazil (sonymusic.com.br) hacked and defaced


This time again a sony website is hacked by hackers. I do not know what's happening with sony but it's now daily news. sony hacked again and again and again.................
This time a group of hackers "The UnderTakers" were able to deface the website of sonyMusic brazil. I think it's too much for the company. They should take some protective action and try to secure it's network and all websites.
Now website is recovered and running.

Sony pictures website hacked and millions accounts exposed


Sony pictures website hacked and millions accounts exposed

Lulzsec, a group hacker claimed to have compromised sonypictures.com and gained access to it's database of millions of user accounts. This group was also responsible for attacks against sony, some days ago. Lulzsec claimed to hack website database by simple SQL injection attack which a common attack against websites. 


They have owned the entire database of the website.  Database contains personal information of over 1 million people who had accounts on the website, 75,000 music codes and 3.5 million music coupons. Sony stored all passwords in form of plain texts which is really unsecure. Now it's recommended by all security experts for web developers to store passwords in encrypted forms. Group only decided to extract sample data for proof and leaked via pirate bay.

see this
http://lulzsecurity.com/releases/sownage_PRETENTIOUS%20PRESS%20STATEMENT.txt

Sony pictures website hacked and millions accounts exposed


Sony pictures website hacked and millions accounts exposed

Lulzsec, a group hacker claimed to have compromised sonypictures.com and gained access to it's database of millions of user accounts. This group was also responsible for attacks against sony, some days ago. Lulzsec claimed to hack website database by simple SQL injection attack which a common attack against websites. 


They have owned the entire database of the website.  Database contains personal information of over 1 million people who had accounts on the website, 75,000 music codes and 3.5 million music coupons. Sony stored all passwords in form of plain texts which is really unsecure. Now it's recommended by all security experts for web developers to store passwords in encrypted forms. Group only decided to extract sample data for proof and leaked via pirate bay.

see this
http://lulzsecurity.com/releases/sownage_PRETENTIOUS%20PRESS%20STATEMENT.txt

download Burp Suite Free Edition v1.4 – Web Application Security Testing Tool

Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application’s attack surface, through to finding and exploiting security vulnerabilities.


Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.


New Features

  1. The ability to compare site maps
  2. Functions to help with testing access controls using your browser
  3. Support for preset request macros
  4. Session handling rules to help you work with difficult situations
  5. In-browser rendering of responses from all Burp tools
  6. Auto recognition and rendering of character sets
  7. Support for upstream SOCKS proxies
  8. Headless mode for unattended scripted usage
  9. Support for more types of redirection
  10. Support for NTLMv2 and IPv6
  11. Numerous enhancements to Burp’s extensibility
  12. Greater stability on OSX



Download Here:
http://portswigger.net/burp/burpsuite_v1.4.zip

download Burp Suite Free Edition v1.4 – Web Application Security Testing Tool

Burp Suite is an integrated platform for performing security testing of web applications. Its various tools work seamlessly together to support the entire testing process, from initial mapping and analysis of an application’s attack surface, through to finding and exploiting security vulnerabilities.


Burp gives you full control, letting you combine advanced manual techniques with state-of-the-art automation, to make your work faster, more effective, and more fun.


New Features

  1. The ability to compare site maps
  2. Functions to help with testing access controls using your browser
  3. Support for preset request macros
  4. Session handling rules to help you work with difficult situations
  5. In-browser rendering of responses from all Burp tools
  6. Auto recognition and rendering of character sets
  7. Support for upstream SOCKS proxies
  8. Headless mode for unattended scripted usage
  9. Support for more types of redirection
  10. Support for NTLMv2 and IPv6
  11. Numerous enhancements to Burp’s extensibility
  12. Greater stability on OSX



Download Here:
http://portswigger.net/burp/burpsuite_v1.4.zip

Codemasters website hacked and customer data leaked


Codemasters website hacked and customer data leaked


Hackers attacked one more gaming company website. This time british video game development company CodeMaster has been hacked and it's customer data has been stolen. According to reports this intrusion was done on 3rd june but company took 3 weeks to detect this. This is again a hit on cyber world by hackers.


company informed it's customer about this attack via email. But 1 thing is really good for the company that it uses external payment gateway and stored no information about payment in it's server.


Now the website is offline and will be offline till it's rebuild. The new version is expected to be launched sometime later this year.The company is advising customers to change their passwords on all Codemasters properties, as well as other online websites where they might have used them.


"Please note that Codemasters will never ask you for any payment data such as credit card numbers or bank account details, nor will Codemasters ask you for passwords or other personal identifying data. Be aware too of fraudulent emails that may outwardly appear to be from Codemasters with links inviting you to visit websites," the company stresses.

Codemasters website hacked and customer data leaked


Codemasters website hacked and customer data leaked


Hackers attacked one more gaming company website. This time british video game development company CodeMaster has been hacked and it's customer data has been stolen. According to reports this intrusion was done on 3rd june but company took 3 weeks to detect this. This is again a hit on cyber world by hackers.


company informed it's customer about this attack via email. But 1 thing is really good for the company that it uses external payment gateway and stored no information about payment in it's server.


Now the website is offline and will be offline till it's rebuild. The new version is expected to be launched sometime later this year.The company is advising customers to change their passwords on all Codemasters properties, as well as other online websites where they might have used them.


"Please note that Codemasters will never ask you for any payment data such as credit card numbers or bank account details, nor will Codemasters ask you for passwords or other personal identifying data. Be aware too of fraudulent emails that may outwardly appear to be from Codemasters with links inviting you to visit websites," the company stresses.

Anonymous India attacked on NIC server again



This is again the Anonymous india group who hacked the secret credentials of NIC servers and posted it to a wesite. Hackers claiming this step as a part of fight against corruption. It's really shamefull to NIC team that they are hacked again. They are not focused on their work while they have very important government websites hosted on their server

/etc/passwd file : http://pastebin.com/NV5QwLuw
List of websites Hosted on NIC server: http://pastebin.com/kHvawbtH

Message By Anonymous India :

We are Anonymous Again.
To the People of India and Government.
You Have Underestimated the Power of people.
You thought First NIC Hack by Anonymous was Playful act, "THINK AGAIN".
We are not here to Play with anyone.
We are here to send a Message to all the people who support the Anti-corruption bill.
We took Down Indian Army Officail Site and NIC knows more what we did.
We do not support anyone, We Support Only The Anti-Corruption Bill.
No one can speak for Anonymous, Nothing is Official.
We are Not the "FLAME", We are just a "SPARK".
Stop Your Brutal Voilence and Blame games.
Anonymous are the people. 
We do not forget.
We do not forgive.
We are legion.
Expect us

They also claimed to have the whole data of the server and they can leak it in future.

Anonymous India attacked on NIC server again



This is again the Anonymous india group who hacked the secret credentials of NIC servers and posted it to a wesite. Hackers claiming this step as a part of fight against corruption. It's really shamefull to NIC team that they are hacked again. They are not focused on their work while they have very important government websites hosted on their server

/etc/passwd file : http://pastebin.com/NV5QwLuw
List of websites Hosted on NIC server: http://pastebin.com/kHvawbtH

Message By Anonymous India :

We are Anonymous Again.
To the People of India and Government.
You Have Underestimated the Power of people.
You thought First NIC Hack by Anonymous was Playful act, "THINK AGAIN".
We are not here to Play with anyone.
We are here to send a Message to all the people who support the Anti-corruption bill.
We took Down Indian Army Officail Site and NIC knows more what we did.
We do not support anyone, We Support Only The Anti-Corruption Bill.
No one can speak for Anonymous, Nothing is Official.
We are Not the "FLAME", We are just a "SPARK".
Stop Your Brutal Voilence and Blame games.
Anonymous are the people. 
We do not forget.
We do not forgive.
We are legion.
Expect us

They also claimed to have the whole data of the server and they can leak it in future.

citibank confirms data breach at Citi bank Account Online

%3Cdiv+dir%3D%22ltr%22+style%3D%22text-align%3A+left%3B%22+trbidi%3D%22on%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22background-color%3A+%23f9f9f9%3B+color%3A+%23595c5f%3B+font-family%3A+Georgia%2C+%27Times+New+Roman+Times%27%2C+serif%3B+font-size%3A+12px%3B+line-height%3A+20px%3B%22%3E%3C%2Fspan%3E%0D%0A%3Cdiv+class%3D%22separator%22+style%3D%22clear%3A+both%3B+text-align%3A+center%3B%22%3E%0D%0A%3Cb%3E%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3Ecitibank+confirms+data+breach+at+Citi+bank+Account+Online%3C%2Fspan%3E%3C%2Fb%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+class%3D%22separator%22+style%3D%22clear%3A+both%3B+text-align%3A+center%3B%22%3E%0D%0A%3Cb%3E%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3E%0D%0A%3C%2Fspan%3E%3C%2Fb%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+class%3D%22separator%22+style%3D%22clear%3A+both%3B+text-align%3A+center%3B%22%3E%0D%0A%3Ca+href%3D%22http%3A%2F%2F4.bp.blogspot.com%2F-VYxlpNK5oAU%2FTfBRbjCeHqI%2FAAAAAAAAAx0%2FHuFVv5bVK_A%2Fs1600%2Fr2297636246.jpg%22+imageanchor%3D%221%22+style%3D%22color%3A+%231c6fb1%3B+margin-left%3A+1em%3B+margin-right%3A+1em%3B+outline-color%3A+initial%3B+outline-style%3A+none%3B+outline-width%3A+initial%3B+text-decoration%3A+underline%3B%22%3E%3Cimg+border%3D%220%22+src%3D%22http%3A%2F%2F4.bp.blogspot.com%2F-VYxlpNK5oAU%2FTfBRbjCeHqI%2FAAAAAAAAAx0%2FHuFVv5bVK_A%2Fs1600%2Fr2297636246.jpg%22+style%3D%22background-attachment%3A+initial%3B+background-clip%3A+initial%3B+background-color%3A+transparent%3B+background-image%3A+initial%3B+background-origin%3A+initial%3B+background-position%3A+initial+initial%3B+background-repeat%3A+initial+initial%3B+border-bottom-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-bottom-style%3A+none%3B+border-bottom-width%3A+1px%3B+border-color%3A+initial%3B+border-left-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-left-style%3A+none%3B+border-left-width%3A+1px%3B+border-right-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-right-style%3A+none%3B+border-right-width%3A+1px%3B+border-top-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-top-style%3A+none%3B+border-top-width%3A+1px%3B+border-width%3A+initial%3B+margin-bottom%3A+4px%3B+margin-left%3A+0px%3B+margin-right%3A+4px%3B+margin-top%3A+0px%3B+padding-bottom%3A+0px%3B+padding-left%3A+0px%3B+padding-right%3A+0px%3B+padding-top%3A+0px%3B%22+%2F%3E%3C%2Fa%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%0D%0A%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3EBangalore-+Citigroup+Inc.+confirmed+a+computer+breach+at+Citi+bank+accounts+online.+Millions+of+bank+account+detail+was+stolen+by+hackers.+This+was+discovered+through+routing+monitoring+of+bank+networks.%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3E%0D%0A%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3Bin-top%3A+ p|g3B%"t%3E-1D%0 3Cstef+of+its+card+customers+were+affected+by+the+breach.The+name+of+the+customers%2C+account+numbers+and+contact+information+including+email+addresses+of+the+affected+accounts+were+viewed%2C+Citi+said.%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3E%0D%0A%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3Ethe+spokesperson+said%2C+%22We+are+contacting+customers+whose+information+was+impacted.+Citi+has+implemented+enhanced+procedures+to+prevent+a+recurrence+of+this+type+of+event%22%26nbsp%3B%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3C%2Fdiv%3E%0D%0A

citibank confirms data breach at Citi bank Account Online

%3Cdiv+dir%3D%22ltr%22+style%3D%22text-align%3A+left%3B%22+trbidi%3D%22on%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22background-color%3A+%23f9f9f9%3B+color%3A+%23595c5f%3B+font-family%3A+Georgia%2C+%27Times+New+Roman+Times%27%2C+serif%3B+font-size%3A+12px%3B+line-height%3A+20px%3B%22%3E%3C%2Fspan%3E%0D%0A%3Cdiv+class%3D%22separator%22+style%3D%22clear%3A+both%3B+text-align%3A+center%3B%22%3E%0D%0A%3Cb%3E%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3Ecitibank+confirms+data+breach+at+Citi+bank+Account+Online%3C%2Fspan%3E%3C%2Fb%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+class%3D%22separator%22+style%3D%22clear%3A+both%3B+text-align%3A+center%3B%22%3E%0D%0A%3Cb%3E%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3E%0D%0A%3C%2Fspan%3E%3C%2Fb%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+class%3D%22separator%22+style%3D%22clear%3A+both%3B+text-align%3A+center%3B%22%3E%0D%0A%3Ca+href%3D%22http%3A%2F%2F4.bp.blogspot.com%2F-VYxlpNK5oAU%2FTfBRbjCeHqI%2FAAAAAAAAAx0%2FHuFVv5bVK_A%2Fs1600%2Fr2297636246.jpg%22+imageanchor%3D%221%22+style%3D%22color%3A+%231c6fb1%3B+margin-left%3A+1em%3B+margin-right%3A+1em%3B+outline-color%3A+initial%3B+outline-style%3A+none%3B+outline-width%3A+initial%3B+text-decoration%3A+underline%3B%22%3E%3Cimg+border%3D%220%22+src%3D%22http%3A%2F%2F4.bp.blogspot.com%2F-VYxlpNK5oAU%2FTfBRbjCeHqI%2FAAAAAAAAAx0%2FHuFVv5bVK_A%2Fs1600%2Fr2297636246.jpg%22+style%3D%22background-attachment%3A+initial%3B+background-clip%3A+initial%3B+background-color%3A+transparent%3B+background-image%3A+initial%3B+background-origin%3A+initial%3B+background-position%3A+initial+initial%3B+background-repeat%3A+initial+initial%3B+border-bottom-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-bottom-style%3A+none%3B+border-bottom-width%3A+1px%3B+border-color%3A+initial%3B+border-left-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-left-style%3A+none%3B+border-left-width%3A+1px%3B+border-right-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-right-style%3A+none%3B+border-right-width%3A+1px%3B+border-top-color%3A+rgb%28227%2C+227%2C+227%29%3B+border-top-style%3A+none%3B+border-top-width%3A+1px%3B+border-width%3A+initial%3B+margin-bottom%3A+4px%3B+margin-left%3A+0px%3B+margin-right%3A+4px%3B+margin-top%3A+0px%3B+padding-bottom%3A+0px%3B+padding-left%3A+0px%3B+padding-right%3A+0px%3B+padding-top%3A+0px%3B%22+%2F%3E%3C%2Fa%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%0D%0A%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3EBangalore-+Citigroup+Inc.+confirmed+a+computer+breach+at+Citi+bank+accounts+online.+Millions+of+bank+account+detail+was+stolen+by+hackers.+This+was+discovered+through+routing+monitoring+of+bank+networks.%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3E%0D%0A%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3Bin-top%3A+ p|g3B%"t%3E-1D%0 3Cstef+of+its+card+customers+were+affected+by+the+breach.The+name+of+the+customers%2C+account+numbers+and+contact+information+including+email+addresses+of+the+affected+accounts+were+viewed%2C+Citi+said.%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3E%0D%0A%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3Cdiv+style%3D%22margin-bottom%3A+0px%3B+margin-left%3A+0px%3B+margin-right%3A+0px%3B+margin-top%3A+0px%3B%22%3E%0D%0A%3Cspan+class%3D%22Apple-style-span%22+style%3D%22font-family%3A+Arial%2C+Helvetica%2C+sans-serif%3B%22%3Ethe+spokesperson+said%2C+%22We+are+contacting+customers+whose+information+was+impacted.+Citi+has+implemented+enhanced+procedures+to+prevent+a+recurrence+of+this+type+of+event%22%26nbsp%3B%3C%2Fspan%3E%3C%2Fdiv%3E%0D%0A%3C%2Fdiv%3E%0D%0A

SonyPictures France website hacked


SonyPictures France website hacked




Two hackers claimed to hack the database of SonyPictures france website on www.sonypictures.fr 
They posted some screenshots and partial database on a website with their claim. They wrote, "We will not publish all the database and we didn't upload a shell. We are not black hats"

They claimed to have 177,172 accounts detail. A list of system accounts together with hashed passwords was also extracted because the load_file MySQL function wasn't disabled on the system.

this is the link of detail

SonyPictures France website hacked


SonyPictures France website hacked




Two hackers claimed to hack the database of SonyPictures france website on www.sonypictures.fr 
They posted some screenshots and partial database on a website with their claim. They wrote, "We will not publish all the database and we didn't upload a shell. We are not black hats"

They claimed to have 177,172 accounts detail. A list of system accounts together with hashed passwords was also extracted because the load_file MySQL function wasn't disabled on the system.

this is the link of detail

Skipfish - web application security scanner


Skipfish - web application security scanner


Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.


Key features:


High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.
Ease of use: heuristics to support a variety of quirky web frameworks and mixed-technology sites, with automatic learning capabilities, on-the-fly wordlist creation, and form autocompletion.
Cutting-edge security logic: high quality, low false positive, differential security checks, capable of spotting a range of subtle flaws, including blind injection vectors.
The tool is believed to support Linux, FreeBSD, MacOS X, and Windows (Cygwin) environments.


Dowload Here
http://code.google.com/p/skipfish/downloads/list

Skipfish - web application security scanner


Skipfish - web application security scanner


Skipfish is an active web application security reconnaissance tool. It prepares an interactive sitemap for the targeted site by carrying out a recursive crawl and dictionary-based probes. The resulting map is then annotated with the output from a number of active (but hopefully non-disruptive) security checks. The final report generated by the tool is meant to serve as a foundation for professional web application security assessments.


Key features:


High speed: pure C code, highly optimized HTTP handling, minimal CPU footprint - easily achieving 2000 requests per second with responsive targets.
Ease of use: heuristics to support a variety of quirky web frameworks and mixed-technology sites, with automatic learning capabilities, on-the-fly wordlist creation, and form autocompletion.
Cutting-edge security logic: high quality, low false positive, differential security checks, capable of spotting a range of subtle flaws, including blind injection vectors.
The tool is believed to support Linux, FreeBSD, MacOS X, and Windows (Cygwin) environments.


Dowload Here
http://code.google.com/p/skipfish/downloads/list