Sinisterly
SQLi Dumper Tutorial { Pics Included } - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: SQLi Dumper Tutorial { Pics Included } (/Thread-SQLi-Dumper-Tutorial-Pics-Included)

Pages: 1 2


RE: SQLi Dumper Tutorial { Pics Included } - cupopigi - 07-03-2019

(01-07-2019, 01:46 PM)Trilly Reign Wrote: ~ By The End Of This, You'll Be Pumping Combo Lists No Issue ~

1. Downloading and Installing SQLI Dumper

This tutorial will be using SQLI Dumper v.9.0.
Your version might be different, but it will still work the same.
I have uploaded a copy { 9.2 } in Hacking Tools.

2. Proxies
Proxies can be found publicly via google or forums. If you want to get more advance look for a Proxy Scraper.

3. Dorks
Here is some information about Dorks and how to make them.

https://whatis.techtarget.com/definition/Google-dork-query
https://en.wikipedia.org/wiki/Google_hacking
Dorks can also are found on Google and Forums alike.

4. Online Scanner

Getting vulnerable URLs using SQLI Dumper and Dorks.

Paste dorks:

https://i.imgur.com/6PBrGDt.png

Select what sites you want to grab URLs:

https://i.imgur.com/BwdoOvc.png

Then click "Start Scanner":

https://i.imgur.com/dbfohdP.png

URLs should start showing:

https://i.imgur.com/d6btqDD.png

5. Exploitables
Now that you have URLs in URLs Queue.
Goto Exploitables and click "Start exploiter".

6.Injectables.
Once you have a few URLs exploited.
Goto injectables and click "Start Analyzer"

You will start to see URLs select all of them and at the bottom it says
"Search Columns\Tables Names (MySQL and MS SQL) "
Enter what you want to search like so and click start:

https://i.imgur.com/HBVsCo0.png

A window should appear like so:
https://i.imgur.com/LzdWN1R.png

Now depending on the search mine was Email, Pass you will see

Search: Email
Rows: Number
[Number]Database.Column

In that column, If you searched Email it will look for a table with said name.
The number is how many rows(Lines) the table in the column has.
The password should have the same amount of Rows and match Database.Column .

Click and highlight the row you want to dump. Click the "Go To Dumper" drop-down button at the top then "New Dumper Instance":

https://i.imgur.com/oRcYCys.png

7. Dumping
Once Dumper is open tick threads check box:

https://i.imgur.com/3KLSMxT.png

Then click and highlight the column and click "Get Columns"

https://i.imgur.com/qxyxGmM.png

Now look for the Table name you searched for and tick/check-mark them accordingly.
Then move Threads slider to 50 this will speed up dumping but will use more resources:

https://i.imgur.com/m4XEiZ1.png

Once it's done click "Dump Data":

https://i.imgur.com/Z7ss9zW.png

Once dumping is finished click "Export Data":

https://i.imgur.com/lbOiE7U.png

Keep "Plaintext". Change "Delimiter" to "Custom :"
Then click Start and save to a location.

That's it you dumped a combo congratulations!!!!!


~ Some things can be done better in this tutorial ~

1. Getting URLs via "SQLI Dumper" is slow. You can get URLs through programs such as "Dork Searcher EZ"LINK "SQL MAP"LINK.

2. Using "SQLI Dumper" to dump rows is also slow you could speed this up using "SQL Map" LINK.

3. Learning how dorks can be private and public can make getting URLs easier. Resulting in higher quality combos.

4. You might run into some hashed passwords.
Most common way to crack hashed passwords is using "Hashcat"
Hash identify. Don't know what the hash is? Lookup using. https://hashc.co.uk/hashid
https://hashcat.net/hashcat/
https://en.wikipedia.org/wiki/Cryptographic_hash_function

5. Running multiple instances.
Yes, you can dump more than one database at a time. Simply open another Dumper Instance.
The limit is your internet speed.

6. Make sure Email or Username is above password table. You can move them with the arrow buttons near "Dump Data". Failing this saving will be PASS:EMAIL and not EMAIL: PASS

7. If you get !~!1 it means the row is empty/null

thanks for great tutorial!
BTW,
do I have to use proxies for Sqli dumper?


RE: SQLi Dumper Tutorial { Pics Included } - fsociety - 07-03-2019

i am just a begginer in making dork and combo.


RE: SQLi Dumper Tutorial { Pics Included } - cupopigi - 07-04-2019

need some help here.

after several running, I got a few websites after Scanning.
and got no websites for Exploitable.

where am I wrong?
I should change the dorks?


RE: SQLi Dumper Tutorial { Pics Included } - cupopigi - 07-04-2019

anybody please help me?
I can not move on and getting no result.

is this sqli dumper still working?


RE: SQLi Dumper Tutorial { Pics Included } - refa - 07-13-2019

(01-07-2019, 01:46 PM)Trilly Reign Wrote: ~ By The End Of This, You'll Be Pumping Combo Lists No Issue ~

1. Downloading and Installing SQLI Dumper

This tutorial will be using SQLI Dumper v.9.0.
Your version might be different, but it will still work the same.
I have uploaded a copy { 9.2 } in Hacking Tools.

2. Proxies
Proxies can be found publicly via google or forums. If you want to get more advance look for a Proxy Scraper.

3. Dorks
Here is some information about Dorks and how to make them.

https://whatis.techtarget.com/definition/Google-dork-query
https://en.wikipedia.org/wiki/Google_hacking
Dorks can also are found on Google and Forums alike.

4. Online Scanner

Getting vulnerable URLs using SQLI Dumper and Dorks.

Paste dorks:

https://i.imgur.com/6PBrGDt.png

Select what sites you want to grab URLs:

https://i.imgur.com/BwdoOvc.png

Then click "Start Scanner":

https://i.imgur.com/dbfohdP.png

URLs should start showing:

https://i.imgur.com/d6btqDD.png

5. Exploitables
Now that you have URLs in URLs Queue.
Goto Exploitables and click "Start exploiter".

6.Injectables.
Once you have a few URLs exploited.
Goto injectables and click "Start Analyzer"

You will start to see URLs select all of them and at the bottom it says
"Search Columns\Tables Names (MySQL and MS SQL) "
Enter what you want to search like so and click start:

https://i.imgur.com/HBVsCo0.png

A window should appear like so:
https://i.imgur.com/LzdWN1R.png

Now depending on the search mine was Email, Pass you will see

Search: Email
Rows: Number
[Number]Database.Column

In that column, If you searched Email it will look for a table with said name.
The number is how many rows(Lines) the table in the column has.
The password should have the same amount of Rows and match Database.Column .

Click and highlight the row you want to dump. Click the "Go To Dumper" drop-down button at the top then "New Dumper Instance":

https://i.imgur.com/oRcYCys.png

7. Dumping
Once Dumper is open tick threads check box:

https://i.imgur.com/3KLSMxT.png

Then click and highlight the column and click "Get Columns"

https://i.imgur.com/qxyxGmM.png

Now look for the Table name you searched for and tick/check-mark them accordingly.
Then move Threads slider to 50 this will speed up dumping but will use more resources:

https://i.imgur.com/m4XEiZ1.png

Once it's done click "Dump Data":

https://i.imgur.com/Z7ss9zW.png

Once dumping is finished click "Export Data":

https://i.imgur.com/lbOiE7U.png

Keep "Plaintext". Change "Delimiter" to "Custom :"
Then click Start and save to a location.

That's it you dumped a combo congratulations!!!!!


~ Some things can be done better in this tutorial ~

1. Getting URLs via "SQLI Dumper" is slow. You can get URLs through programs such as "Dork Searcher EZ"LINK "SQL MAP"LINK.

2. Using "SQLI Dumper" to dump rows is also slow you could speed this up using "SQL Map" LINK.

3. Learning how dorks can be private and public can make getting URLs easier. Resulting in higher quality combos.

4. You might run into some hashed passwords.
Most common way to crack hashed passwords is using "Hashcat"
Hash identify. Don't know what the hash is? Lookup using. https://hashc.co.uk/hashid
https://hashcat.net/hashcat/
https://en.wikipedia.org/wiki/Cryptographic_hash_function

5. Running multiple instances.
Yes, you can dump more than one database at a time. Simply open another Dumper Instance.
The limit is your internet speed.

6. Make sure Email or Username is above password table. You can move them with the arrow buttons near "Dump Data". Failing this saving will be PASS:EMAIL and not EMAIL: PASS

7. If you get !~!1 it means the row is empty/null

Thanks nice tut!!!!


RE: SQLi Dumper Tutorial { Pics Included } - Pinkz0rd - 07-13-2019

amazing job! Keep posting stuff like this Smile


RE: SQLi Dumper Tutorial { Pics Included } - amberligtt22 - 07-15-2019

thnk you for shar hope workSmile


RE: SQLi Dumper Tutorial { Pics Included } - amberligtt22 - 07-15-2019

thnk you for shar hope workSmile


RE: SQLi Dumper Tutorial { Pics Included } - diksimo - 10-02-2019

gooddddddddddddddddddddddddddddddddddddddddddd


RE: SQLi Dumper Tutorial { Pics Included } - cyberwild - 10-18-2019

nice tutorial but SQLI dumper its not working anymore in google and bing, btw how can we dorking with specific country in sqldumper?