Имена таблиц

Discussion in 'Уязвимости' started by Dr.Z3r0, 1 Aug 2007.

  1. Dr.Z3r0

    Dr.Z3r0 Leaders of the World

    Joined:
    6 Jul 2007
    Messages:
    284
    Likes Received:
    595
    Reputations:
    567
    Вообщем меня интересует такой вопрос. Существует ли в нете такой словарик с наиболее вероятными именами таблиц юзверей и именами столбцов с пассами и логинами? Если нет то предлагаю его составить, думаю будет полезно всем...
     
  2. aka PSIH

    aka PSIH Elder - Старейшина

    Joined:
    7 Feb 2006
    Messages:
    582
    Likes Received:
    284
    Reputations:
    51
    вот:
     
    1 person likes this.
  3. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    aka PSIH забыл mysql.user
     
    3 people like this.
  4. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138

    user
    uname
    users
    login
    username
    auth_user
    pass
    passw
    passwd
    password
    pwd
    user_password
    user_pass
     
    #4 Ksander, 1 Aug 2007
    Last edited by a moderator: 31 May 2011
  5. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    Tables:
    Code:
    4images_users
    account
    accounts
    admin
    admin
    administer
    administrable
    administrate
    administrator
    administrators
    administratrix
    admins
    client
    clients
    contact
    contacts
    content
    cpg_bridge
    cpg_config
    dbadmins
    dealer
    dealers
    fusion_new_users
    fusion_user_groups
    fusion_users
    group
    groups
    ibf_admin_sessions
    ibf_conf_settings
    ibf_member_extra
    ibf_members
    ibf_members_converge
    icq
    jos_blastchatc_users
    jos_comprofiler_members
    jos_joomblog_users
    jos_messages_cfg
    jos_moschat_users
    jos_users
    kpro_adminlogs
    kpro_user
    login
    logins
    mb_users
    member
    members
    minibbtable_users
    mybb_forums
    mybb_users
    news
    nuke_authors
    nuke_bbconfig
    nuke_config
    nuke_popsettings
    nuke_users
    obb_profiles
    partner
    partners
    passes
    password
    passwords
    phorum_users
    phpads_affiliates
    phpads_clients
    phpads_config
    phpbb_users
    products
    punbb_users
    pwd
    pwds
    reguser
    regusers
    sites
    smf_members
    sn_admins
    system
    usebb_members
    usebb_name
    user
    user_list
    user_logins
    user_names
    useralbums
    userlist
    userlogins
    usernames
    users
    xar_roles
    xoops_bannerclient
    xoops_users
    Fields:
    Code:
    account
    adid
    admin
    admin_email
    admin_id
    admin_pw
    admin_pwd
    adminemail
    adminmail
    aid
    aim
    aim_name
    alb_password
    album_id
    albumname
    blogmail_account
    blogmail_password
    board_email
    cansendemail
    ci_accountname
    ci_email
    cid
    client
    clientid
    clientname
    clientpassword
    clientusername
    converge_email
    converge_id
    converge_pass_hash
    converge_pass_salt
    data
    db_database_name
    db_hostname
    db_password
    db_username
    displaygroupid
    email
    e-mail
    email_full
    email_pm
    emailaddress
    emailnotification
    emailonpm
    emailstamp
    fid
    forumname
    gid
    group
    group_id
    group_id_misc
    group_name
    hash
    hashsalt
    homepage
    i_xar_roles_email
    i_xar_roles_name
    icq
    icq_number
    id
    id_group
    id_member
    ip
    ip_addr
    ip_address
    ipaddress
    key
    languageid
    last_ip
    last_login
    lastname
    legacy_password
    license_number
    login
    login_anonymous
    loginkey
    mail
    mapid
    member
    member_login_key
    membergroupids
    memberid
    memberip
    membername
    msnname
    name
    org_perm_id
    page_id
    parentemail
    partner
    pass
    passtemp
    passwd
    password
    passworddate
    passwordsalt
    phone
    pid
    pntomail
    pwd
    pwd
    realname
    referenceid
    referrerid
    regip
    registration_ip
    reputationlevelid
    salt
    salt
    secretanswer
    secretquestion
    sendemail
    session_id
    session_ip_address
    session_member_id
    session_member_login_key
    session_member_name
    short_name
    showemail
    sid
    smtp_host
    smtp_password
    smtp_username
    status
    styleid
    szemailaddress
    table_prefix
    text
    uid
    uname
    usebb_bans
    user
    user_aim
    user_email
    user_hide_email
    user_icq
    user_id
    user_ip
    user_name
    user_newpasswd
    user_newpwdkey
    user_password
    user_table
    user_viewemail
    user_website
    usergroupid
    userid
    userlogin
    username
    userpass
    userpassword
    usr
    ustid
    version
    website
    xar_email
    xar_name
    xar_pass
    xar_uid
    xar_uname
    zip
     
    2 people like this.
  6. [Raz0r]

    [Raz0r] Elder - Старейшина

    Joined:
    25 Feb 2007
    Messages:
    425
    Likes Received:
    484
    Reputations:
    295
    Стандартные таблицы:
    Code:
    tbl
    users
    news
    admins
    user
    admin
    regusers
    reg_users
    reguser
    reg_user
    account
    accounts
    member
    members
    settings
    lostpass
    lost_pass
    lostpasswords
    lost_passwords
    logs
    password
    passwords
    statistics
    test
    config
    session
    sessions
    orders
    customers
    articles
    links
    main
    clients
    client
    info
    login
    logins
    group
    groups
    partner
    partners
    content
    contact
    contacts
    icq
    dealer
    dealers
    administration
    
    Таблицы публичных движков, форумов и пр.
    Code:
    phpbb_users
    ibf_members
    e107_user
    ibf_sessions
    phpmyadmin.pma_table_info
    pma_table_info
    SS_orders
    cpg132_users
    poll_user
    phorum_session
    vbulletin_session
    vb_user
    phorum_user
    vbulletin_user
    customers_basket
    _wfspro_admin
    news_lostpass
    knews_lostpass
    yabb_settings
    yabbse_settings
    Dragon_users
    chat_users
    chat_messages
    shop.cards
    shop.orders
    smallnuke_members
    voodoo_members
    joomla_users
    ipb_sessions
    phpBB2.phpbb_users
    phpBB2.forum_users
    ipb.ibf_members
    forum.ibf_members
    e107.e107_user
    chat_config
    mambo_session
    mambo_users
    
    Поля
    Code:
    id
    uid
    username
    login
    userlogin
    name
    userpass
    userpassword
    pwd
    pass
    password
    passwd
    nick
    icq
    email
    e-mail
    mail
    personal_key
    temppass
    temp_pass
    temppasword
    temp_password
    user_pass
    user_password
    user_id
    admin
    last_login
    user_ip
    userip
    ip_address
    member_login_key
    member_name
    member_id
    user_level
    cc_type
    cc_owner
    cc_number
    cc_expires
    sesskey
    text
    data
    group
    usr
    status
    phone
    member
    account
    hash
    md5hash
    salt
    hashsalt
    login_name
    login_pw
    login_pwd
    pw
    userpw
    user_pw
    
     
  7. groundhog

    groundhog Elder - Старейшина

    Joined:
    12 May 2007
    Messages:
    1,159
    Likes Received:
    425
    Reputations:
    180
    [Raz0r], у меня был случай когда пассы хранились в таблице parol. Что-то я среди перечисленных не нашёл. Кстати, думаю, что такое имя может быть использовано и в качестве столбца при определённом кривоумии кодописателя...
     
    #7 groundhog, 27 Aug 2007
    Last edited: 27 Aug 2007
  8. Dr.Frank

    Dr.Frank Elder - Старейшина

    Joined:
    31 Jul 2002
    Messages:
    301
    Likes Received:
    72
    Reputations:
    12
    + к этому у движка koobi не только kpro_user,но и
    Code:
    kpro6_user
    kpro5_user
    koobi4_user
    
     
  9. Dr.Z3r0

    Dr.Z3r0 Leaders of the World

    Joined:
    6 Jul 2007
    Messages:
    284
    Likes Received:
    595
    Reputations:
    567
    Вот кому надо объеденно и дополненно
    Кстати кому надо седня выложил скрипт для перебора таблиц и столбцов в свою статью вот http://forum.antichat.ru/showthread.php?p=407222 в конце. Конечно самому тоже не сложно впринципе написать но все же...
    Code:
    adm
    admin
    admins
    administrator
    administrators
    adminlogin
    login
    logins
    usr
    user
    users
    nick
    nicks
    name
    names
    client
    clients
    member
    members
    account
    accounts
    pw
    userpw
    user_pw
    login_name
    login_pw
    login_pwd
    login_pass
    login_password
    last_login
    usrlogin
    usr_login
    userlogin
    user_login
    usr_name
    usename
    use_name
    username
    user_name
    nickname
    nick_name
    user_nick
    nickuser
    nick_user
    nickusers
    nick_users
    member
    membername
    member_name
    mem_name
    member_login_key
    member_login
    memberlogin
    memberid
    firstname
    first_name
    pwd
    personal_key
    temppass
    temp_pass
    temppasword
    temp_password
    pas
    pass
    password
    passwords
    pasword
    paswords
    usrpas
    usrpass
    usrpassword
    usrpasswords
    usr_pas
    usr_pass
    usr_password
    usr_passwords
    userpas
    userpass
    userpassword
    userpasswords
    user_pas
    user_pass
    user_password
    user_passwords
    secretword
    secretsword
    secretswords
    secret_word
    secrets_word
    secrets_words
    passw
    paswd
    passwd
    pwd
    hash
    key
    keys
    email
    e-mail
    mail
    usrmail
    usermail
    usr_mail
    user_mail
    usremail
    useremail
    usr_email
    user_email
    id
    usd
    usrid
    userid
    usr_id
    user_id
     
  10. Zitt

    Zitt Elder - Старейшина

    Joined:
    7 May 2006
    Messages:
    736
    Likes Received:
    268
    Reputations:
    59
    Вбелетин)) Покрайней мере на ачате так =\\
     
  11. bulbazaur

    bulbazaur Banned

    Joined:
    10 Sep 2006
    Messages:
    125
    Likes Received:
    40
    Reputations:
    10
    слышал есть ачатовский брутер таблиц, не дадите линк?
     
  12. [Raz0r]

    [Raz0r] Elder - Старейшина

    Joined:
    25 Feb 2007
    Messages:
    425
    Likes Received:
    484
    Reputations:
    295
    SQLBruter

    http://www.inattack.ru/article/542.html
    Мой SQLBruter)
     
    1 person likes this.
  13. Dr.Z3r0

    Dr.Z3r0 Leaders of the World

    Joined:
    6 Jul 2007
    Messages:
    284
    Likes Received:
    595
    Reputations:
    567
    кхм... Как читал?
     
    #13 Dr.Z3r0, 30 Aug 2007
    Last edited: 31 May 2011
  14. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    Может кто-нибудь выложить объединенный словарь ТОЛЬКО таблиц а не полей?Их и так угадать нетрудно))
     
    #14 Велемир, 18 Jul 2008
    Last edited: 18 Jul 2008
  15. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    http://dok.net78.net/TblWordList.dic