Administrator accounts of http://cf.gambooz.com/, but I've no idea where the admin login page is.
These aren't MD5 hashes but MySQL5 hashes
wait, i dont get it. Are they free accounts? or..
@-Ben administrator accounts of CF SEA.
I want to point out that you can't use these db credentials -even if you manage to decrypt the hashed passwords-, you wouldn't be able to log in because it's localhost.
You'd have to be part of their local network to access their database.
For example, it's like you were trying to connect to my router by typing "192.168.1.1" in your url bar, no, it won't connect to mine but yours.
You can use those accounts http://pastebin.com/XJNE7F0H but the (decrypted) passwords seems to be incorrect... I guess they changed them already, or the data you gathered was bullshit honeypot.. it would explains why most of all the passwords are "123456" or "123@#456" crap
Originally Posted by Delta[X]
I want to point out that you can't use these db credentials -even if you manage to decrypt the hashed passwords-, you wouldn't be able to log in because it's localhost.
You'd have to be part of their local network to access their database.
For example, it's like you were trying to connect to my router by typing "192.168.1.1" in your url bar, no, it won't connect to mine but yours.
You can use those accounts http://pastebin.com/XJNE7F0H but the (decrypted) passwords seems to be incorrect... I guess they changed them already, or the data you gathered was bullshit honeypot.. it would explains why most of all the passwords are "123456" or "123@#456" crap
It's actually not localhost, you are acting like someone that doesn't know anything about this sort of things.
edit: oh, guess what I found, a XSS vulnerability. You don't even need to "decrypt" the hashes, just steal the staff cookies and then mess with the website...