Sinisterly
SQL injection - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: SQL injection (/Thread-SQL-injection)

Pages: 1 2


SQL injection - changeusername123 - 06-16-2011

First thing you need to do is download the following programs (link included at the end):
Admin Finder
Exploit Scanner
sqlihelper 2.7
Dork Lister

1. Open up dork lister and pick any dork you like im gonna pick "inurlageid="



1.Oopen up "Exploit Scanner" put your dork in
2. Tick "get from all domains"
3. Click scan
4. After it finishes scaning press "Test Sites" (if it doesnt work in first time, click few times
5. Choose a volnurable site and click twice
6. If You get an error like this:


Code:
Error : You have an error in your SQL syntax; check the manual that..

That means you are on a good way of getting to a database



1.Open up Sqlihelper paste the link in the box. Remember to delete this from the link '
example:

Code:
http://www.northernltd.co.uk/newsdetail.php?id='11

after:

Code:
http://www.northernltd.co.uk/newsdetail.php?id=11

2. Press inject and wait. In the box at the bottom it will show logs similar like this:

Code:

Get Server Info
Check if URL is Vulnerable
URL is Vulnerable
Check No. of Columns
No. of columns : 9
Check No. of Columns - finished
Looking for larget text visible column
Col num 2 found
Check if supports union
Check if supports union - finished
Check Current user
Check Current user - finished
Check if database version
Check if database version - finished
Check Current Database
Check current database - finished
Checking LoadFile
Check Load File - finished
Mysql version 5 OK - Please Get Database
Getting Database List
Getting Database List - Finished

3. Press Get database. After select a database that is used
4. Press "Get Tables" (tables load up)
5. Now you have to find in table name something like "users" in my situation it was "sis_users" And click "Get Columns"



6. now you have to mark "user name" and "password" in the columns. How? ctrl + two files.
7. Press "Dump now" with the two clumns selected.
8. You get Admin login and Password. extract it and save it somewere. Like This:

Code:

UserNameTongueassword:

admin:7a02ff5c4d66cdd2ecfc472342dfb6ac:

Password is encrypted in MD5 you can find decryptors online

3. Last step:





1. Now you need to find a login page. Open up "Admin Finder"
2. Paste the link of the website in the box
3. "scan"
4. It will find you a login page that you can log in to after you got the password decrypted


Code:
http://www.mediafire.com/?yqznolm2zjnawnf



I hope u like it Biggrin

Credits not to me.


RE: Sqli injection - Coded32 - 06-16-2011

Good tutorial. I have done so many SQLi in the past.


RE: Sqli injection - changeusername123 - 06-16-2011

Thanks Coded32,
Glad U like it.


RE: SQL injection - RepOseSS3d-KillR - 06-21-2011

Exploit Scanner doesn't locate anything... at all.


RE: SQL injection - changeusername123 - 06-22-2011

Weird it works for me..........


RE: SQL injection - HeR97 - 06-23-2011

or if you don't know "real" sql use havij its better that this one it also has md5 decrypter so you don't have to search net Biggrin


RE: SQL injection - changeusername123 - 06-23-2011

(06-23-2011, 07:47 PM)HeR97 Wrote: or if you don't know "real" sql use havij its better that this one it also has md5 decrypter so you don't have to search net Biggrin

Yeah Exactly......


RE: SQL injection - ZeKiiTo - 06-26-2011

Very good tuto Bro

Keep-it-up Biggrin


RE: SQL injection - changeusername123 - 06-26-2011

(06-26-2011, 05:50 PM)ZeKiiTo Wrote: Very good tuto Bro

Keep-it-up Biggrin

Thanks mate. I will.


RE: SQL injection - Coded32 - 06-26-2011

So @everyone you think that's all?
No.
Tell me if you get MD5+Salt Hash what you would do?