Showing posts with label SQL Injection. Show all posts
Showing posts with label SQL Injection. Show all posts

Sunday, March 27, 2016

What is SQL Injection (SQLi)? & How to secure website from it?

SQL Injection (SQLi)

SQL injection (SQLi) refers to an injection attack wherein an attacker can execute malicious SQL statements (also commonly referred to as a malicious payload) that control a web application’s database server (also commonly referred to as a Relational Database Management System – RDBMS). Since an SQL injection vulnerability could possibly affect any website or web application that makes use of an SQL-based database, the vulnerability is one of the oldest, most prevalent and most dangerous of web application vulnerabilities.
By leveraging an SQL injection vulnerability, given the right circumstances, an attacker can use it to bypass a web application’s authentication and authorization mechanisms and retrieve the contents of an entire database. SQL injection can also be used to add, modify and delete records in a database, affecting data integrity.
To such an extent, SQL injection can provide an attacker with unauthorized access to sensitive data including, customer data, personally identifiable information (PII), trade secrets, intellectual property and other sensitive information.

How SQL Injection works

Automated Blind SQL Injection Attacking Tools~bsqlbf Brute forcer

What is Blind SQL Injection:
Some Websites are vulnerable to SQL Injection but the results of injection are not visible to the attacker.  In this situation, Blind SQL Injection is used. The page with the vulnerability may not be one that displays data but will display differently depending on the results of a logical statement injected into the legitimate SQL statement called for that page. This type of attack can become time-intensive because a new statement must be crafted for each bit recovered.
There are plenty of automated Blind Sql Injection tool available. Here i am introducing one of Tool named as bsqlbf(expanded as Blind Sql Injection Brute Forcer).
This tool is written in Perl and allows extraction of data from Blind SQL Injections. It accepts custom SQL queries as a command line parameter and it works for both integer and string based injections
Supported Database:
  • MS-SQL
  • MySQL
  • PostgreSQL
  • Oracle

Saturday, March 26, 2016

Hacking website using SQL Injection -step by step guide



Before we see what  SQL Injection is. We should know what SQL and Database are.


Database:
Database is collection of data. In website point of view, database is used for storing user ids,passwords,web page details and more.

Some List of Database are:
* DB servers,
* MySQL(Open source),
* MSSQL,
* MS-ACCESS,
* Oracle,
* Postgre SQL(open source),
* SQLite,
SQL:
Structured Query Language is Known as SQL. In order to communicate with the Database ,we are using SQL query. We are querying the database so it is called as Query language.
Definition from Complete reference:

SQL is a tool for organizing, managing, and retrieving data stored by a computer
database. The name “SQL” is an abbreviation for Structured Query Language. For
historical reasons, SQL is usually pronounced “sequel,” but the alternate pronunciation
“S.Q.L.” is also used. As the name implies, SQL is a computer language that you use to
interact with a database. In fact, SQL works with one specific type of database, called a
relational database.
Simple Basic Queries for SQL:
Select * from table_name :
this statement is used for showing the content of tables including column name.
For eg:
select * from users;
Insert into table_name(column_names,…) values(corresponding values for columns):
For inserting data to table.
For eg:
insert into users(username,userid) values(“BreakTheSec”,”break”);
I will give more detail and query in my next thread about the SQL QUERY.
What is SQL Injection?

Latest Full Google Dorks For Hacking 2016

Latest Full Google Dorks For Hacking :) 2016 We call them ;google dorks Inept or foolish people as revealed by Google. Whatever you call these fools, you've found the center of the Google Hacking. I need to see if a site I am testing is vulnerable to any of the multiple Google dorks that are available at sites like this and this.  2016








/* Google Dork List*/

/* Provided by Hackerlaxu */

Sunday, March 20, 2016

How to Upload Shell From SQL injection !



Guyz , This is a laxu here ! So For Starting the Progress , first of all find a website which is vulnerable to sql injection. You can find websites by dorks or manually Depends On your Capability !

But You need 2 main things Here:
  1. Root Path of the website 
  2. A Writable Directory 
Most of the time, you will see root path in SQL error of that site.Like the following one : Example

” Warning: mysql_fetch_assoc() expects parameter 1 to be resource, boolean given in/home/hruday/public_html/functions.php on the line 1327 “

But , If the vulnerable website doesn’t show the root path then don’t worry i will show you how to know the root path. And Also Writable Directory. :

SQL Injection with Hackbar

Hello guys how are you…
iam fine …
So today you learn basic of sql injection
I hope you all are fine
So today we learn how to inject a vulnerable website..

Do you know about Sql?
if you donot know What is sql .. so i will describe now ..
Sql stand for structured query language and it is a database.
So now talk about sql injection what is it ?
So lets start :

Q1:) What is SQL ?
Ans:) SQL Stand for (Structured Query Language) and it was first introduced as a commercial database systemin 1979 by Oracle Corporation.

Q1:) What is SQL Injection ?
Ans:) An SQL injection is a kind of injection vulnerability in which the attacker tries to inject arbitrary pieces of malicious data into the input fields of an application.

So Today we will a Inject a site .

Basic’s Sql injection from finding column’s to dumping database by Laxu


Hello guy’s welcome back…..

So as you all know my name is Laxu.
Finally we are starting our Pen testing course with basic’s of SQL injection…
This tutorial is for learners or newbies not for Pro..
In this tutorial i will just teach some basics on SQL injection

1)How to find total number of column’s
2)How to find vulnerable column’s
3)Check the version and database of the website
&& in this tutorial i also tell how to extract tables, columns and then how to dump database …..
but these last process will not understand to those who are new so tomorrow i will explain how all these …
======================================================================
So Let’s start

Saturday, March 19, 2016

SQLI Hunter v1.2


An automation tool to scan for an Sql Injection vulnerability.



Description


SQLI Hunter is an automation tool to scan for an Sql Injection vulnerability in a website.
It automates the search of sqli vulnerable links from Google using google dorks!

SQLI Hunter can also find admin page of any website by using some predefined admin page lists.

Fast and Easy to use !
================

Thursday, March 17, 2016

Hacking a website using SQL injection with Havij (Latest version) :Full method with Pics

Today i am gonna show you how to hack a website using sql injection.To find SQL vulnerable sites refer to this post.

Now Lets start---->

Things you will need -->

1. Havij SQL injection Tool, download it from here(Run as Administrator)
2. A sql vunerable site, I am taking this site http://examplesite.com/catalogo_nuevos_detalle.php?id=2 as an example.
3. A very important thing i.e mind.

Checking for sql vulnerability --->

Here i am taking http://examplesite.com/catalogo_nuevos_detalle.php?id=2 as an example. 
Now to check is this site vulnerable to sql, I will simply add ' after the site url
like this http://examplesite.com/catalogo_nuevos_detalle.php?id=2'
and i get this error on the site
You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'' at line 1
It means that site is vulnerable to sql injection.

Advanced SQL Injection Tutorial - Complete website rooting




Hi All,

In this tutorial we will be rooting a vulnerable web server using Mantra Security Toolkit.

What all you need

1. Mantra Security Toolkit - Download

2. A vulnerable website. I'm using a modified version of LAMPSecurity CTF6

3. Any PHP Shell you are comfortable with
- Google for "c99 shell"

Now the process


Step 1:

I'm on the home page of the website now

How To: Trace Web Admin Panel | Kali Linux | BackTrack | ubuntu

                        How to : Trace Web Admin Panel :


                      1 ) Download The Script : Spider-webFinder.pl

                      2 ) How to Install Perl on Linux :

                       # For Ubuntu Linux / Anonymous Linux /                       BackTrack / Kali Linux




sudo apt-get update
sudo apt-get install perl

# For  Redhat / Centos /

yum install perl

3 ) Now Execute the Perl Program :

netwrkspider@netwrkspider:~$ perl spider_adminFinder.pl
sh: -c: line 0: syntax error near unexpected token `('
sh: -c: line 0: `spider Web Admin Finder (Hacker Edition)'

Tuesday, March 15, 2016

Blind SQL Injection



What we know so far

If you've read the above three tutorials, you know the basic theory of what SQL Injection is, you know how to carry it out using you web browser on a vulnerable website, and you know how to use SQLMap to automate some of the process.
Now, for revision's sake, what we did in the Manual SQL injection tutorial was-
  1. Found a potentially vulnerable website (http://testphp.vulnweb.com)
  2. Used the asterisk  ( ' ) to verify vulnerability.
  3. Found out the number of rows and columns by making some small changes to the URL (which eventually changes the query that is executed on the server)
  4. We then obtained names of tables, their columns, and finally extracted data.
However, it is worth noting that the website was intentionally left vulnerable, and most often the flaws in security aren't this obvious. In our case, the website was willingly responding to our queries with errors. This may not always be the case. As long as we can see the errors, we know we're going in the right direction. Errors tend to give us clues. However, some websites may choose to suppress the error messages. This make SQLi harder. This is known as Blind SQL Injection.



What I didn't tell you

I explained in subtle details what each and every step did. However, I did not explain the motive behind each step. (I gave a rough idea in the Sql injection basics post)
The purpose of the asterisk ( ' ) was to find out how the server handles bad inputs. If it has some mechanisms for sanitizing or escaping these dangerous characters, then we would not see any error in output.

SQL Injection : How It Works

 

Introduction

Lets get started at an apparently unrelated point. Lets assume we create a table in SQL. Now there are three main parts of a database management system, like SQL. They are -
  • Creating structure of table
  • Entering data
  • Making queries (and getting meaningful results from data)
Now, when SQL is used to display data on a web page, it is common to let web users input their own queries. For example, if you go to a shopping website to buy a smartphone, you might want to specify what kind of smartphone you want. The site would probably be storing data about phones in table with columns like Name, Price, Company, Screen Size, OS, etc.
Now they allow you to create a query using some sort of user friendly drop down based form which lets you select your budget, preferred company, etc. So basically, you, the user, can create queries and request data from their SQL servers. 
Now this automated method of creating queries for you is relatively safe, there is another method of creating queries which can be exploited by us. A url ending in .php is a direct indication that the website/blog uses sql to deliver a lot of it's data, and that you can execute queries directly by changing the url. Now basically the data in the SQL tables is protected. However, when we send some rogue commands to the SQL server, it doesn't understand what to do, and returns an error. This is a clear indication that with proper coding, we can send queries that will make the database 'go berserk' and malfunction, and give us all the otherwise private data of its tables. This attack can be used to obtain confidential data like a list of username and passwords of all users on a website.

Steps

Hacking Website with Sqlmap in Kali Linux

A screenshot from the SQLmap official website
In the previous tutorial, we hacked a website using nothing but a simple browser on a Windows machine. It was a pretty clumsy method to say the least. However, knowing the basics is necessary before we move on to the advanced tools. In this tutorial, we'll be using Kali Linux (see the top navigation bar to find how to install it if you haven't already) and SqlMap (which comes preinstalled in Kali) to automate what we manually did in the Manual SQL Injection tutorial to hack websites.




Now it is recommended that you go through the above tutorial once so that you can get an idea about how to find vulnerable sites. In this tutorial we'll skip the first few steps in which we find out whether a website is vulnerable or not, as we already know from the previous tutorial that this website is vulnerable.

Kali Linux

First off, you need to have Kali linux (or backtrack) up and running on your machine. Any other Linux distro might work, but you'll need to install Sqlmap on your own. Now if you don't have Kali Linux installed, you might want to go to this page, which will get you started on Beginner Hacking Using Kali Linux

Sqlmap

Basically its just a tool to make Sql Injection easier. Their official website  introduces the tool as -"sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections."
A lot of features can be found on the SqlMap website, the most important being - "Full support for MySQL, Oracle, PostgreSQL, Microsoft SQL Server, Microsoft Access, IBM DB2, SQLite, Firebird, Sybase and SAP MaxDB database management systems." That's basically all the database management systems. Most of the time you'll never come across anything other than MySql. 

Hacking Websites Using Sqlmap in Kali linux

Monday, March 14, 2016

ALL IMPORTANT! GOOGLE DORKS! IN ONE PLACE! #MASTER #TREASURE #FOR #HACKERS

 
Google is not only a searching site but also an important tool for hackers. Yeah, I'm talking about the Google Dorks!

What are Google Dorks ?

It is basically an advanced google search to find vulnerable websites.
 

I have included 6 types of google dorks in this collection: 
  1. Google dorks for SQL injection, 
  2. Google dorks for Local File Inclusion, 
  3. Google dorks For open CCTV cams, 
  4. Google dorks for sensitive information, 
  5. Google Dorks for Uploading Shell in Wordpress Sites, 
  6. Google Dorks To Find Unsecure Web Admin Panels
  7. Carding Dorks
Copy and paste the below google dorks on the search engine and have fun!