Login Register






There was a very particular style of DDOS attack just now, it was mitigated.
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 1 Vote(s) - 1 Average


MySQL Injection with SQLHelper. (For noobs) filter_list
Author
Message
MySQL Injection with SQLHelper. (For noobs) #1
If you use this tool you will probably get called a skid, faggot, or other mean things.


First download SQLHelper.
Download

Unpack the zip and run the exe.


Now once you have a vulnerable site copy and paste the link into SQLHelper, then click inject.
Spoiler:
[Image: b99c65a65c.png]

Now click get database.
Spoiler:
[Image: 66796ffa59.png]

Now you should see the databases, choose one and click get tables.
Spoiler:
[Image: c0d1884bf4.png]

Once that is done pick a table and get the columns.
Spoiler:
[Image: 885fa06885.png]

Choose one and click dump now.
Spoiler:
[Image: d22c30d596.png]

Once you have the info you need we will find the admin panel.

Go here and enter the website name.
It should find the admin page.
Spoiler:
[Image: 0c8ecde054.png]

Once logged in we can deface or shell the server.
Spoiler:
[Image: f271b0d91f.png]


I was warned not to make this because I would be insulted for it, I'm making it anyway because there are a lot of members here that don't post because they feel like they can't contribute.
If I am able to teach them things why wouldn't I?

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #2
Awesome tutorial, thanks Biggrin

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #3
Thanks. I'm glad you posted this. Yeah, I could do it manually...but why do it when this is faster? Anyway, I'll be trying to get some DoSing shells up.

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #4
Nice tutorial for the newbies, however I recommend anyone new to SQLi to do it manually and learn how to do it that way. After you know how to do it, and can do it efficiently manually you can use a automated software. By doing it manually first you will have the knowledge to fix any hiccups the software encounters, and if it can't get through, you can always go back and do it manually to figure out the issue. Smile
kawaii~desu

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #5
(05-21-2013, 06:49 AM)Silica Wrote: Nice tutorial for the newbies, however I recommend anyone new to SQLi to do it manually and learn how to do it that way. After you know how to do it, and can do it efficiently manually you can use a automated software. By doing it manually first you will have the knowledge to fix any hiccups the software encounters, and if it can't get through, you can always go back and do it manually to figure out the issue. Smile

Agreed. You probably stated it in the most respectful way possible.
[Image: fSEZXPs.png]

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #6
(05-21-2013, 06:49 AM)Silica Wrote: Nice tutorial for the newbies, however I recommend anyone new to SQLi to do it manually and learn how to do it that way. After you know how to do it, and can do it efficiently manually you can use a automated software. By doing it manually first you will have the knowledge to fix any hiccups the software encounters, and if it can't get through, you can always go back and do it manually to figure out the issue. Smile

I agree with this, when I first started I used a tool, so I had trouble learning it manually.
After taking the time to try again it was well worth it.
Manual is better.

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #7
I use SQL Map (if not doing manual) because you can spawn shell rather quickly using it.

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #8
(05-21-2013, 08:26 AM)Unmasked Wrote: I use SQL Map (if not doing manual) because you can spawn shell rather quickly using it.

I don't think sqlmap is for windows is it though? I just use backtrack in a vm if I need linux for something like this.

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #9
(05-21-2013, 06:39 PM)Sinisterkid Wrote: I don't think sqlmap is for windows is it though? I just use backtrack in a vm if I need linux for something like this.

Theres a way to use it on windows

[Image: zaEk.png] Wink
[Image: GiXvY27.png]

Reply

RE: MySQL Injection with SQLHelper. (For noobs) #10
(05-21-2013, 06:39 PM)Sinisterkid Wrote: I don't think sqlmap is for windows is it though? I just use backtrack in a vm if I need linux for something like this.

You can use it on windows it's just a python script.

Reply







Users browsing this thread:






This forum uses Lukasz Tkacz MyBB addons.