Saturday, 31 October 2009

CyberSansar Database Disclosure

Not much important here (is old one) but still thought to share these. You know cybersansar.com is one of the most visited sites from Nepal and still its vulnerable to SQLi and XSS. They need to learn codings. Anyway today I am going to show you some old DB dumps of cybersansar.com (I think most of these are still the same at present, too.)
Lets start:

Cyber Sansar virtual host info:

####cybersansar.com

ServerAdmin webmaster@cybersansar.com
DocumentRoot /web/vhosts/cybernepal.com.np/httpdocs
ServerName cybersansar.com
ServerAlias www.cybersansar.com

##PHP / phpmyadmin
php_value register_globals "on"
Include /etc/apache/modules.d/vhosts_modphp
Include /etc/apache/modules.d/vhosts_phpmyadmin

## htpasswd
Include /etc/apache/extra/cybernepal_include


## ReWrite Module
RewriteEngine on
RewriteCond %{HTTP_HOST} !^202.79.32.62(:80)?$
RewriteCond %{HTTP_HOST} !^www.cybersansar.com(:80)?$
RewriteRule ^/(.*) http://www.cybersansar.com/$1 [L,R]
RewriteOptions inherit
RewriteCond %{REQUEST_METHOD} ^(TRACE|TRACK)
RewriteRule .* - [F]

ErrorLog /web/vhosts/cybernepal.com.np/logs/error.log
CustomLog /web/vhosts/cybernepal.com.np/logs/access.log common



DB Dumps:
INSERT INTO `logonuser` VALUES ('cardb', 'ptcn');
INSERT INTO `logonuser` VALUES ('admin', 'rajendra1');

Emails of artists:
Manoj Shrestha: manoz@manozshrestha.com
Nalina Chitrakar: nalina_chitrakar@hotmail.com
Girish: diseezgirish@hotmail.com
Pramod Upadhyaya: cabbageheart@hotmail.com
Sarisma Amatya: sarishmaamatya@hotmail.com
Deepesh Kishor Bhattarai: deepeshforever@hotmail.com
Prem Lama: lamaprem_7@hotmail.com
Avinash Ghishing: generation_np@hotmail.com
Sabin Rai: mesabin03@yahoo.com
Prashna Shakya: prashnas@gmail.com
Mausami Gurung: mausamigurung4@yahoo.com
Abhaya Subba: bacchus_21@yahoo.com
Sudin Pokhrel: itsda69@hotmail.com
Mingma Sherpa: feelmingma@hotmail.com
Resma Sunuwar: resmires@hotmail.com

I just selected few of them from DB. There were more... Also, the DB dump revealed phone numbers of around 116 singers/artists. Do not contact me to send you the phone numbers of the singers unless you have some genuine reason (hardcore fan, need to give me proof).

Tables in CyberSansar's DB:
adminlogin
artist_info
artist_info2
cs_adminuser
cs_menucategory
cs_model_info
cs_section
cs_wallpaper
discography
doc_ques_ans
doc_sub
logers
logonuser
org_para
phpwebgallery_caddie
phpwebgallery_categories
phpwebgallery_comments
phpwebgallery_config
phpwebgallery_favorites
phpwebgallery_group_access
phpwebgallery_groups
phpwebgallery_history
phpwebgallery_image_category
phpwebgallery_image_tag
phpwebgallery_images
phpwebgallery_rate
phpwebgallery_search
phpwebgallery_sessions
phpwebgallery_sites
phpwebgallery_tags
phpwebgallery_upgrade
phpwebgallery_user_access
phpwebgallery_user_cache
phpwebgallery_user_feed
phpwebgallery_user_group
phpwebgallery_user_infos
phpwebgallery_user_mail_notification
phpwebgallery_users
phpwebgallery_waiting
regis
tbl_movie_artist_profile
tbl_movie_person
tbl_movie_persontype
tbl_movie_profilesetup
test1
test2
vdb_artist_info
vdb_discography
vdb_music_category
vdb_video_info

So that's the end of the show... Feeling sleepy (its 12:23 AM already). Bye guys.
Thanks and Happy Hacking!!! :)

5 comments:

  1. ServerAdmin webmaster@cybersansar.com
    DocumentRoot /web/vhosts/cybernepal.com.np/httpdocs
    ServerName cybersansar.com
    ServerAlias www.cybersansar.com

    What are these??

    Nigesh

    ReplyDelete
  2. nice one..............give us more mailing address.......

    ReplyDelete
  3. wow... amazing when did you get the DB of cybersansar.com. Its fabulous...

    ReplyDelete
  4. its just defacing using tools . Nothing zenious.you are only flickers using others tools

    ReplyDelete
  5. hey Anon guy there,
    lulz but we don't use any tool to deface these sites. How the hell could you say we used the tools to do these? We are the people who believe hacking as an art, not the usage of fucking n00b toolz available on the net.

    ReplyDelete