[Hack a site EASY]SQL Inject with Havij v1.16 (NOOB FRIENDLY TUT WITH PICS) 12-16-2012, 10:46 PM
#2
This is a simple tutorial on how to hack sites with Havij v1.16 
In this tutorial I assume that you already know how to find a vulnerable site, and I wont go through that part.
This is also my first tutorial ever made so please be nice ^^
Knowledge is free, but the one who are reading this are responsible for how they use this knowledge.
Please note that this is Illegal in most countries.
Step 1 - Analyze target and find Database
1. First find a vulnerable site, and then copy the URL of it.
2. In Havij, paste the vulnerable link in the 'Target' section as shown below:
![[Image: azaxop.jpg]](http://i46.tinypic.com/azaxop.jpg)
3. Press 'Analyze'
![[Image: aacdaf.jpg]](http://i48.tinypic.com/aacdaf.jpg)
Now you will get information about the site such as Host IP, Web Server etc.
Here the Database is called 'Vize' as shown in the picture under 'Current Database'.
![[Image: qoczt1.jpg]](http://i46.tinypic.com/qoczt1.jpg)
Step 2 - Get Tables and Columns
1. Head over to the 'Tables' section and press 'Get Tables'.
![[Image: 2mqqm38.jpg]](http://i47.tinypic.com/2mqqm38.jpg)
![[Image: ftfscz.jpg]](http://i49.tinypic.com/ftfscz.jpg)
So here is our victims Tables:
![[Image: 1gnbwh.jpg]](http://i50.tinypic.com/1gnbwh.jpg)
2. Now select 'users' or any other relative Table and click 'Get Columns'.
![[Image: a5ckjn.jpg]](http://i48.tinypic.com/a5ckjn.jpg)
![[Image: 34phyts.jpg]](http://i49.tinypic.com/34phyts.jpg)
3. Now you should have some columns called things like 'ID', 'Usernames', 'Passwords' or something similar.
![[Image: 2vskz86.jpg]](http://i48.tinypic.com/2vskz86.jpg)
In this case we had 'login' and 'passwd' and it seemed to be relevant.
Step 3 - Get Admins login details
1. Select all relative columns and press 'Get Data'
![[Image: 2houu8o.jpg]](http://i48.tinypic.com/2houu8o.jpg)
Success! We now have our Admin username and password!
![[Image: x3sf38.jpg]](http://i48.tinypic.com/x3sf38.jpg)
Step 3 - Find Admins Page
1. Go to the 'Find Admin' section and press 'Start'.
![[Image: 16thjr.jpg]](http://i49.tinypic.com/16thjr.jpg)
![[Image: 2iho3nl.jpg]](http://i50.tinypic.com/2iho3nl.jpg)
It'll now start scanning
![[Image: 27yvjg3.jpg]](http://i47.tinypic.com/27yvjg3.jpg)
Success! Here is our admin page!
![[Image: 2coiv07.jpg]](http://i45.tinypic.com/2coiv07.jpg)
2. Go to the URL and Log In with the admin credentials we found in Step 3, have fun!
I am sorry if this was a little bit fuzzy and hard to understand, but I did my best! Give me some feedback!

In this tutorial I assume that you already know how to find a vulnerable site, and I wont go through that part.
This is also my first tutorial ever made so please be nice ^^
Knowledge is free, but the one who are reading this are responsible for how they use this knowledge.
Please note that this is Illegal in most countries.
Step 1 - Analyze target and find Database
1. First find a vulnerable site, and then copy the URL of it.
2. In Havij, paste the vulnerable link in the 'Target' section as shown below:
Spoiler: Picture
![[Image: azaxop.jpg]](http://i46.tinypic.com/azaxop.jpg)
3. Press 'Analyze'
Spoiler: Picture
![[Image: aacdaf.jpg]](http://i48.tinypic.com/aacdaf.jpg)
Now you will get information about the site such as Host IP, Web Server etc.
Here the Database is called 'Vize' as shown in the picture under 'Current Database'.
Spoiler: Picture
![[Image: qoczt1.jpg]](http://i46.tinypic.com/qoczt1.jpg)
Step 2 - Get Tables and Columns
1. Head over to the 'Tables' section and press 'Get Tables'.
Spoiler: Picture 1
![[Image: 2mqqm38.jpg]](http://i47.tinypic.com/2mqqm38.jpg)
Spoiler: Picture 2
![[Image: ftfscz.jpg]](http://i49.tinypic.com/ftfscz.jpg)
So here is our victims Tables:
Spoiler: Picture
![[Image: 1gnbwh.jpg]](http://i50.tinypic.com/1gnbwh.jpg)
2. Now select 'users' or any other relative Table and click 'Get Columns'.
Spoiler: Picture 1
![[Image: a5ckjn.jpg]](http://i48.tinypic.com/a5ckjn.jpg)
Spoiler: Picture 2
![[Image: 34phyts.jpg]](http://i49.tinypic.com/34phyts.jpg)
3. Now you should have some columns called things like 'ID', 'Usernames', 'Passwords' or something similar.
Spoiler: Picture
![[Image: 2vskz86.jpg]](http://i48.tinypic.com/2vskz86.jpg)
In this case we had 'login' and 'passwd' and it seemed to be relevant.
Step 3 - Get Admins login details
1. Select all relative columns and press 'Get Data'
Spoiler: Picture 2
![[Image: 2houu8o.jpg]](http://i48.tinypic.com/2houu8o.jpg)
Success! We now have our Admin username and password!

Spoiler: Picture
![[Image: x3sf38.jpg]](http://i48.tinypic.com/x3sf38.jpg)
Step 3 - Find Admins Page
1. Go to the 'Find Admin' section and press 'Start'.
Spoiler: Picture 1
![[Image: 16thjr.jpg]](http://i49.tinypic.com/16thjr.jpg)
Spoiler: Picture 2
![[Image: 2iho3nl.jpg]](http://i50.tinypic.com/2iho3nl.jpg)
It'll now start scanning
Spoiler: Picture
![[Image: 27yvjg3.jpg]](http://i47.tinypic.com/27yvjg3.jpg)
Success! Here is our admin page!
Spoiler: Picture
![[Image: 2coiv07.jpg]](http://i45.tinypic.com/2coiv07.jpg)
2. Go to the URL and Log In with the admin credentials we found in Step 3, have fun!

I am sorry if this was a little bit fuzzy and hard to understand, but I did my best! Give me some feedback!
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)