Hack a Site With sqli Cancer V2.7 For Newbie's 01-27-2011, 05:09 AM
#1
Hack a Site With sqli Cancer V2.7 For Newbie's
By
M@$T3R MuFl3H
Credits : These Tutorial Made By M@$T3R MuFl3h
In This Tut i Will Help u with hacking a Website
First Off all u Need
1.SQL Helper V2.7 (Google It)
2.Exploit Scanner
3.Havij For Admin Finder And MD5
4.Dorks If u want i can post them here
lets Start xD
Open Exploit Scanner and Put at Dorks Space One Of Those
///////////////////////////////////////
trainers.php?id=
article.php?ID=
play_old.php?id=
declaration_more.php?decl_id=
Pageid=
games.php?id=
newsDetail.php?id=
staff_id=
historialeer.php?num=
product-item.php?id=
news_view.php?id=
humor.php?id=
communique_detail.php?id=
sem.php3?id=
opinions.php?id=
spr.php?id=
pages.php?id=
chappies.php?id=
prod_detail.php?id=
viewphoto.php?id=
view.php?id=
website.php?id=
hosting_info.php?id=
///////////////////////////////////////
Wait 1 Min and Sites Will Come Up After it Say's Finished press at Test
And Wait Another Minute xD
After that it will find a Vuln Sites Like This
![[Image: now1.png]](http://img709.imageshack.us/img709/4778/now1.png)
Test Some Site You Should Get this
Query failedYou have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'1 ORDER BY lastname' at line 1 SELECT * FROM person_old WHERE id=\'1 ORDER BY lastname
After Getting These That Mean The Site is Vuln
Open SQL Helper V2.7
Add The Site just like in the Picture
Add Target Then inject
![[Image: 2n8wtow.jpg]](http://img823.imageshack.us/img823/2599/2n8wtow.jpg)
Leave it one minute Till the Tool searching for columns . (Time may vary depending on your connection speed , your pc speed , and the number of columns in the website.)
![[Image: 15xvl2v.jpg]](http://img339.imageshack.us/img339/4495/15xvl2v.jpg)
Make sure that the website support union otherwise the injection won't work.
If u get this you are okay till now xD
Now We Will press Get DataBase
![[Image: znq9tz.jpg]](http://img28.imageshack.us/img28/2329/znq9tz.jpg)
Now select any element from the "database name" box and press the "Get tables" button , I will select "anthropo_encycl":
![[Image: 668zs6.jpg]](http://img714.imageshack.us/img714/6337/668zs6.jpg)
then select any element from the "table name" box and press the "Get columns" button , I will select "user":
![[Image: 24e3vyo.jpg]](http://img227.imageshack.us/img227/4665/24e3vyo.jpg)
then select any elements you want from the "columns name" box and press "Dump Now" , i will select "usr_login" and "usr_pass"
![[Image: 2vb4ndj.jpg]](http://img80.imageshack.us/img80/2671/2vb4ndj.jpg)
Then A Screen With Number Will POP up Dont Worry its Called MD5 u can see them online
http://www.md5crack.com/
But i prefer Havij cause its guarantee
So Hope u Like My Tut Thanks For Reading Remember say thanks xD
Gifted : to the Wonderfull Fourm Alboraaq.com
if u have any Question am Ready
bekool221@hotmail.com
By
M@$T3R MuFl3H
Credits : These Tutorial Made By M@$T3R MuFl3h
In This Tut i Will Help u with hacking a Website
First Off all u Need
1.SQL Helper V2.7 (Google It)
2.Exploit Scanner
3.Havij For Admin Finder And MD5
4.Dorks If u want i can post them here
lets Start xD
Open Exploit Scanner and Put at Dorks Space One Of Those
///////////////////////////////////////
trainers.php?id=
article.php?ID=
play_old.php?id=
declaration_more.php?decl_id=
Pageid=
games.php?id=
newsDetail.php?id=
staff_id=
historialeer.php?num=
product-item.php?id=
news_view.php?id=
humor.php?id=
communique_detail.php?id=
sem.php3?id=
opinions.php?id=
spr.php?id=
pages.php?id=
chappies.php?id=
prod_detail.php?id=
viewphoto.php?id=
view.php?id=
website.php?id=
hosting_info.php?id=
///////////////////////////////////////
Wait 1 Min and Sites Will Come Up After it Say's Finished press at Test
And Wait Another Minute xD
After that it will find a Vuln Sites Like This
![[Image: now1.png]](http://img709.imageshack.us/img709/4778/now1.png)
Test Some Site You Should Get this
Query failedYou have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'1 ORDER BY lastname' at line 1 SELECT * FROM person_old WHERE id=\'1 ORDER BY lastname
After Getting These That Mean The Site is Vuln
Open SQL Helper V2.7
Add The Site just like in the Picture
Add Target Then inject
![[Image: 2n8wtow.jpg]](http://img823.imageshack.us/img823/2599/2n8wtow.jpg)
Leave it one minute Till the Tool searching for columns . (Time may vary depending on your connection speed , your pc speed , and the number of columns in the website.)
![[Image: 15xvl2v.jpg]](http://img339.imageshack.us/img339/4495/15xvl2v.jpg)
Make sure that the website support union otherwise the injection won't work.
If u get this you are okay till now xD
Now We Will press Get DataBase
![[Image: znq9tz.jpg]](http://img28.imageshack.us/img28/2329/znq9tz.jpg)
Now select any element from the "database name" box and press the "Get tables" button , I will select "anthropo_encycl":
![[Image: 668zs6.jpg]](http://img714.imageshack.us/img714/6337/668zs6.jpg)
then select any element from the "table name" box and press the "Get columns" button , I will select "user":
![[Image: 24e3vyo.jpg]](http://img227.imageshack.us/img227/4665/24e3vyo.jpg)
then select any elements you want from the "columns name" box and press "Dump Now" , i will select "usr_login" and "usr_pass"
![[Image: 2vb4ndj.jpg]](http://img80.imageshack.us/img80/2671/2vb4ndj.jpg)
Then A Screen With Number Will POP up Dont Worry its Called MD5 u can see them online
http://www.md5crack.com/
But i prefer Havij cause its guarantee
So Hope u Like My Tut Thanks For Reading Remember say thanks xD
Gifted : to the Wonderfull Fourm Alboraaq.com
if u have any Question am Ready
bekool221@hotmail.com
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)
