![]() |
|
Quick SQL Question - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Quick SQL Question (/Thread-Quick-SQL-Question) |
Quick SQL Question - peck08 - 11-27-2012 Hey guys, i have a quick question. Is there a way download files by using sql injection.? i know a little about it, well enough to gain access to websites and view their files etc etc but i recently came across a site and found a few documents i wouldnt mind taking a look at so if any one here knows the methods then i would very much appreciate the help or simply point me to a tutorial ( i like reading them lol ) thanks in advance =] RE: Quick SQL Question - Faner - 11-27-2012 Hey, I think function load_file() could help you. I don't know much about it, so here is a part of tutorial from ah forum: Quote:There is a function called load_file() in mysql, which u can use directly after you found a number of columns. For eg. If you know that website you are playing with is using Joomla, then you also know that file that saves username, passwords of admin/database and even salt to taste is in configurations.php. using load_file, all you have to do is, give a pathname /home/blah blah (that is upto you to figure out) and load configurations.php. Any php file loaded without a request HTTP or HTTPS header, will show the file in its TEXT form and not embedded Once you see the file using load_file(path to config file),3,4.. etc.. There is nothing much left to say. Check google for some tutorials about it. RE: Quick SQL Question - RA1N - 11-27-2012 To download actual files off a server you are going to need to get root access. If you can do that you have all the files possible. I do not believe you can obtain files via SQLi because that just gets information from databases files. RE: Quick SQL Question - peck08 - 11-30-2012 thanks to both of you for your replys, just found a pdf tutorial which shows how to use the load_file function so ill give it a go and see what i can do thanks once again guys, much appreciated.
|