RE: Hacking Website With Sql Injection 03-18-2013, 02:56 PM
#3
(03-18-2013, 01:42 PM)i0xIllusi0n Wrote: Havij is next to the worst automatic SQL injection tool there is.I agree. However you can learn something from Havij if you setup a vulnerable script which logs all get/post requests to see how havij gathers information.
Plus, "decrypt hashes?" Obviously you don't know what a hash is.
A hash is a one-way encryption, there is no decryption. Havij sends requests to websites who then have rainbow tables to check and see if the hash you are attempting to crack has been previously cracked or not. It doesn't crack it for you.
Continuing this post, you're a little skid if all you do is use Havij -- or any automatic injection tool -- without knowing manual injection. And we can all surely tell that's what OPs situation is. Learn manual injection buddy. Then come talk.




![[+]](https://sinister.li/images/modern/collapse_collapsed.png)