RE: Hack a website using SQL Injection - step by step guide 02-21-2014, 09:04 PM
#6
Thanks for taking the time it took to write this, but I must admit that this was really disappointing. Spartans is supposed to be a HQ group sharing HQ content, and this does not fit that. There are several things in this post that is both misleading and just plain and simple wrong.
- Shell uploads
- Read files
- DoS
Now, in step 2 you claim the following
This is as far from the truth you can get. Identifying vulnerabilities can be done in so many ways. It all boils down to the code.
A few examples are ....
.... and I could go on forever.
In step 3 you are right but you should also add that you can also combine these into ...
... which will return a message saying something like "Unknown column '6' in 'order clause'" which means that union select should use 5 columns
Step 4 if no values are printed to the screen you can use INTO OUTFILE/INTO DUMPFILE to store the output in a file. Just make sure it's saved to a path accessible from the browser
In addition to what you have in step 5 I would also like to add these
@@datadir - Get the default data directory in the mysql config
@@hostname - Get the server hostname
UUID() - MAC Address Read more details
In step 7 you are not informing about how to use hex encoding to bypass string filtering, which can be useful if CHAR() isn't working. Just make sure that the hex string is prefixed with 0x otherwise MySQL won't interpret it as hex
------
Even what I have added here is still lacking tons of information... I really had expected more from a Spartans tutorial than this
Quote:What a hacker can do with SQL Injection attack?Missing from that list is
- Shell uploads
- Read files
- DoS
Now, in step 2 you claim the following
Quote:To check the vulnerability ,add the single quotes(') at the end of the url and hit enter.
If the page remains in same page or showing that page not found, then it is not vulnerable.
This is as far from the truth you can get. Identifying vulnerabilities can be done in so many ways. It all boils down to the code.
A few examples are ....
Code:
"
\"
\'
\
'%0A)
CASE 1 WHEN 1=1 THEN 1 ELSE 0 END
'/*!OR*/1=1
1%2B1
(1%2B1)
1%2B1)
IF(1=1,1,2)In step 3 you are right but you should also add that you can also combine these into ...
Code:
order by 1,2,3,4,5,6,7,8,9,10,11,12,13Step 4 if no values are printed to the screen you can use INTO OUTFILE/INTO DUMPFILE to store the output in a file. Just make sure it's saved to a path accessible from the browser

In addition to what you have in step 5 I would also like to add these
@@datadir - Get the default data directory in the mysql config
@@hostname - Get the server hostname
UUID() - MAC Address Read more details
In step 7 you are not informing about how to use hex encoding to bypass string filtering, which can be useful if CHAR() isn't working. Just make sure that the hex string is prefixed with 0x otherwise MySQL won't interpret it as hex
------
Even what I have added here is still lacking tons of information... I really had expected more from a Spartans tutorial than this



![[+]](https://sinister.li/images/modern/collapse_collapsed.png)