Facebook Sql İnjection
-
dbler tabloları
[Database]: fluff1
[Table: Columns]
[0]app_friends: user,friend,time
[1]art_lol_raffle: voter,vote_count,tix,tix_vote,tix_bonus,win
[2]art_love_raffle: voter,vote_count,tix,no_win,win
[3]art_public_lol: artist,art_time,submit_time,num_votes,vote_score,warn_time,num_warn,removed
[4]art_public_love: artist,art_time,submit_time,num_votes,vote_score,early_votes,early_score,warn_time,num_warn,removed
[5]blocked_table: user,blocked,time
[6]checksum: db,tbl,chunk,boundaries,this_crc,this_cnt,master_crc,master_cnt,ts
[7]contest_pts: user,hab_gift_pts,hide_name,mini_gift_pts,dec_gift_pts
[8]elections_2008: voter,votee,time,source
[9]elections_gift_2008: voter,time
[10]elections_prizes_2008: user,rank,claim_time,uncle_wobbly_claim_time,presidential_extra_claim_time
[11]elections_totals_2008: user,votes
[12]ffriend: user,friend_id,friend_name,bubble,friend_version,friend_time,removed,hide_petted,has_bubble,munny,habitat,survey,session_key
,friend_pos,act_time,hide_fluff,caption,bubble_x,bubble_y,wall_version
[13]food_counts: inventory_id,day,amount
[14]fulfilled_wishes: wisher,fulfiller,inventory_id,amount,time
[15]gifts: user,gifter,inventory_id,time,friend_version,feed_num
[16]inven_tmp: user,inventory_id,amount,time,amt_gifted
[17]inventory: user,inventory_id,amount,time,amt_gifted
[18]limited_history: user,buyer,inventory_id,munny_paid,gold_paid,time,start_time
[19]limited_inventory: user,inventory_id,munny_price,gold_price,time,was_gifted
[20]lol_promo: user,promo_reason
[21]lol_promo_final: user,promo_reason,session_key
[22]mini_pts_tmp: gifter,new_gift_pts
[23]pet_counts: user,day,friend_version,num_pets
[24]pet_counts_old_ver: user,day,friend_version,num_pets
[25]petters: user,petter,time
[26]raceEventTurkleTrot2008: user,racerId,racerDefeatedCount,prizeGiven,updateTime,createTime
[27]race_points: user,points,time
[28]race_table: user,race_hour,num_in_hour,first,second,third,fourth,fifth,sixth,total,my_total,last_gift_num,my_earnings
[29]race_with_new: user,other,user_wins,other_wins,day,time
[30]race_with_new2: user,other,user_wins,other_wins,day,time
[31]real_gifts: recipient,gifter,inventory_id,time,privacy,sent_email,message,is_free,got_pts,mini_pts,dec_pts,is_orig,quantity
[32]remind: user,owner,time,is_friend
[33]spring_deco: gifter,recipient,basket,status,points,time,act_time,notif
[34]spring_redeco_results: gifter,gifts,raffle
[35]spring_redeco_swag: user,basket
[36]storage: user,inventory_id,amount,time,amt_gifted
[37]transfer: recipient,gifter,inventory_id,time,privacy,sent_email,message,is_free,got_pts,mini_pts,dec_pts,is_orig,quantity
[38]treasure_hunt_bonus: user,claimed,time
[39]treasure_hunt_bonus_deco: user,claimed,time
[40]treasure_hunt_found: user,profile,day,got_gem_id,time
[41]treasure_hunt_points: user,points,points_found,points_gold,time
[42]trickortreat_bonus: user,claimed,time
[43]trickortreat_found: user,profile,day,got_treat_id,time
[44]trickortreat_points: user,points,points_found,points_gold,time
[45]unlock_id: user,inventory_id,time
[46]wishlist: user,wishlist_id,inventory_id,amount,time,note
[47]wishlist_bonus: user,claimed,time
[Database]: fluff2
[Table: Columns]
[0]ad_clicks: id,cnt
[1]add_times: user,time
[2]announce_email_sent: user,last_sent_id,status
[3]announce_notif_sent: user,last_sent_id,status
[4]app_banned: user,time
[5]app_promos: user,promo,result,install
[6]art_copy_love: copy_artist,copy_art_time,orig_artist,orig_art_time,reporter
[7]art_equipped: artist,art_time,id,x,y,orient,size
[8]art_ffriend: artist,art_time,friend_id,bubble,habitat,friend_pos,fluff_bits,caption,bubble_x,bubble_y,featured_time,title
[9]art_lol_bonus_notif: user,bonus,time
[10]art_lol_raffle: voter,vote_count,tix,tix_vote,tix_bonus,win
[11]art_love_raffle: voter,vote_count,tix,no_win,win
[12]art_old_fav: artist,art_time,num_favorites
[13]art_promote: time,top_added,fav_added
[14]art_public: artist,art_time,submit_time,num_votes,vote_score,num_favorite,contest_time,warn_time,num_warn,is_top,is_fav
[15]art_public_lol: artist,art_time,submit_time,num_votes,vote_score,warn_time,num_warn,removed
[16]art_public_love: artist,art_time,submit_time,num_votes,vote_score,early_votes,early_score,warn_time,num_warn,removed
[17]art_votes: voter,artist,art_time,vote,vote_time,favorite_time,warn_time
[18]art_votes_lol: voter,artist,art_time,vote,vote_time,submit_time,warn_time,tix,ref
[19]art_votes_love: voter,artist,art_time,vote,vote_time,submit_time,warn_time
[20]attachment: user,day,times
[21]birthday: user,raw
[22]captcha: user,hour,times
[23]captcha_solved: user,hour,times
[24]chat_banned: user,time
[25]cheater_safe: user,time
[26]cheaters: user,time,type,count
[27]checksum: db,tbl,chunk,boundaries,this_crc,this_cnt,master_crc,master_cnt,ts
[28]contest_info: user,had_hab,had_mini,had_dec
[29]domain_notif_hit: user,time
[30]egg_hunt_found: user,profile,day,got_egg_id,time
[31]egg_hunt_points: user,points,points_found,points_gold,time,got_basket,got_bonus
[32]election_notif_hit: user,time
[33]election_prize_notif_hit: user,time
[34]email_times: user,rank_time
[35]equipped: user,id,x,y,orient,size
[36]exchange_hist: user,munny_user,time,end_pos,start_time
[37]fbml_times: user,time
[38]feed_wall: user,friend_id,time
[39]ffriend: user,friend_id,friend_name,bubble,friend_version,friend_time,removed,hide_petted,has_bubble,munny,habitat,survey,session_key
,friend_pos,act_time,hide_fluff,caption,bubble_x,bubble_y,wall_version,moreflags
[40]fluff_domain_suggest: user,profile,domain,time
[41]fluff_domains: user,domain,email,activated,code,time,opt_out
[42]freegifts_promo_hit: user,source,time
[43]from_share_tracking: user,day,hits,page
[44]generated_fluffart: artist,art_time,status
[45]gold_clicked: user,time,payer_email
[46]gold_exchange: user,time
[47]gold_hist: user,time,gold,bonus,txn_id
[48]halloween_freebies_given: user,time
[49]halloween_notif_hit: user,time
[50]hard_rock: user,name,cancel,confirm
[51]info: user,gender,location,looking,activities,interests,foods,places,about,time
[52]invite_bonus_rewards: user,got_15,got_30,got_60,last_bonus
[53]invite_points: user,points,points_invite,points_gold,time
[54]invites: user,invitee,invite_time,paid_time,charged
[55]invites_bak: user,invitee,invite_time,paid_time,charged
[56]invites_test: user,invitee,invite_time,paid_time,charged
[57]lol_hit: user,time,reason
[58]lol_promo: user,promo_reason
[59]lol_quickshare: user,spammed,time
[60]maybe_paid: user,time
[61]munny_table: user,munny,time,gold,storage_munny,storage_gold
[62]newtreats_notif_hit: user,time
[63]nf_hit: user,time
[64]notif_hit: user,time
[65]offer: uid,munny,time_done,time,name,err
[66]offer_gold: uid,gold,bonus,time,error,source
[67]old_survey: uid,amt,oid,status,time
[68]olympic_notif_hit: user,time
[69]outgoing_share_tracking: user,day,hits,page
[70]paypal_ipn: user,txn_id,valid_ipn,payment_status,mc_gross,mc_fee,mc_currency,time,receipt_id,payer_id,payer_email,first_name,last_nam
e,address_name,address_street,address_city,address_state,address_zip,address_country,address_country_code,residence_country,payment_date,payment_fee,p
ayment_gross,quantity,payment_type,payer_status,txn_type,custom,duplicate
[71]pet_boon: user,num_pets
[72]pet_limits: user,day,num_pets
[73]pet_limits_new: user,cur_hour,num_pets,last_pet_time
[74]pirate_booty_given: user,time
[75]pirate_email_hit: user,ab,time
[76]pirate_notif_hit: user,time
[77]profile_notify_times: user,time
[78]promos: user,code,time
[79]quest_progress: user,quest,step
[80]race_with: user,other,winner,time,is_bonus
[81]reengagement_value: user,points,gift_time
[82]reimburse: uid,time,munny
[83]stuffed_vote: user,vote,time
[84]survey: uid,amt,oid,status,time
[85]thank_you_gift: user,time,inventory_id
[86]tot_notif_hit: user,time
[87]tote_notif_hit: user,time
[88]treasure_hunt_notif_hit: user,time
[89]trophy: user,bronze,silver,gold
[90]unlock_id: user,inventory_id,time
[91]vanity_domains: user,domain,email
[92]wall_posts: user,hour,times -
hadi canım sende ... hizmetin boqu çıktı :) Neyse Eline Saglık Hoca
-
Şaşırdım
-
İyi güzel bulmussun da column & table adlarında admin vs türü girisi kabul etti mi ? :)
-
bir nane çıkmaz güzel olayda Facebook hacklemek kolay deil hoca xD
-
O.o
-
tebrikler hacı.
-
Buna facebook sql diyemeiz sanırım zira sadece fluff applicationının databaseine ulaşabiliyor... Facebookla tam olarak alakası yok...
-
renegadealien bunu yazdı:
-----------------------------Buna facebook sql diyemeiz sanırım zira sadece fluff applicationının databaseine ulaşabiliyor... Facebookla tam olarak alakası yok...
-----------------------------Katılıyorum üstad :) zaten ilk urlyi filtrelemisler sanırım,admin tablosuna ulasmadıgın sürece ki facebook gibi büyük bi yapının admin tablosu kullanmayacagı gayet acık xD
App'nin db'si bi işe yaramaz hoca :)
-
app miş...
Ben de bi bok sanıp atladım :D
-
laf edenler gidip bi tanede kendileri yapsında görelim:)
eline sağlık hacı.azimle sıçki duvarı del:D