RE: Effective means of hacking websites 02-26-2020, 05:18 PM
#7
(02-26-2020, 03:07 AM)mothered Wrote:good to hear it's full privileges 😎(02-25-2020, 05:18 PM)xdlwilliamz Wrote:(02-25-2020, 02:28 PM)mothered Wrote: Correct.wow that's cool, i see the dedication :)
There must be a flaw, some sort of weakness/vulnerability to allow exploitation and access the back-end thereafter. It's just a matter of Identifying their security loopholes. I've spent as long as two weeks on one site, and finally gained access.
So aside from scanners like nmap and the rest, what other means can one detect vulnerabilities in a site ?
and what level of access could one get with SQL injection ?
Depending on the site Itself, I use a number of SQL Injection attack vectors.
Content-Based/Boolean-Based, In-Band SQLi (Union & Error-Based being the most common) and Time-Based/Blind SQLi. The level of access Is full elevated (admin) privileges. You can edit, update, modify and delete data, and manipulate the database to obtain the Table & Column names, thereby grab sensitive details thereafter.
Most tools i have for these attacks are in Linux,
what os do you use, Linux or Windows ? am following your guide now ...




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)