Sabado, Hulyo 27, 2013

[TUTORIAL] Sql Injection / Hack Website Using Havij Pro Edition

[TUTORIAL] Sql Injection / Hack Website Using Havij



Things needed

*Havij Pro - http://fileice.net/download.php?file=3c0q6
*Dorks - http://fileice.net/download.php?file=3e5vl
*Brain if you have :)

What is SQL injection?


It's one of the most common vulnerability in web applications today. It allows attacker to execute database query in url and gain access to some confidential information etc...(in shortly).

1.SQL Injection (classic or error based or whatever you call it) 
2.Blind SQL Injection (the harder part)

TIP you must have vulnerable site.

What is vulnerable? Exposed to the possibility of being attacked or harmed, either physically or emotionally: "we were in a vulnerable position




Start Hacking 


Download the attached file.

1st we need to find vulnerability site to do that we need dork, download it above


here is one i pick out of dork ( index.php? ), so what you have to do is to go to google.com and put this dork there ( index.php?id= )



You will see Vulnerable Site Pick one site.
Open the HAVIJ and insert the website that you want to hack and follow the screenshots.


After that the sofware will look for database of you website. the database i got here is " slighter_website " 

We need to get the number of tables that the database have to do this we click on table as i do in this pic below:

Then the number of tables will show, like below pics:


We need to find the number of column, at this point it depends on the intention you want, either you want to hack admin or you want to hack credit card but here I will use this to get admin password and ID. now click the admin and click get colunm as below pics.

Then you will see another sub columns which is name and password for this database, it depends on the site you want to get their database and hack

click on the sub coloum name and password, then go and click on get data to get the login user name and admin for this database.


At last you will see the admin and pasword 


Thanks :)

Hack to learn and to defend your self :))









2 komento:

  1. I want to shear a life changing story with everyone who cares to read this testimony. Blank atm cards are real and are effective all over the world. my name is Gorge Judy i live in SPAIN . I got this card from [skylink technology] a month ago. this card has really help me pay my debts and now i am free from all financial problems. I no this is hard to believe , but i never knew there was this kind of card until i got one. This card withdraw more than €6000 daily and it is very easy to use. But you have to be very careful in other not to be caught by the police because it is illegal. If you want more information on this card and how to get one just contact the hackers by this address
    skylinktechnes@yahoo.com or whatsapp +1(213)328–0248

    TumugonBurahin
    Mga Tugon
    1. Hello all
      am looking few years that some guys comes into the market
      they called themselves hacker, carder or spammer they rip the
      peoples with different ways and it’s a badly impact to real hacker
      now situation is that peoples doesn’t believe that real hackers and carder scammer exists.
      Anyone want to make deal with me any type am available but first
      I‘ll show the proof that am real then make a deal like

      Available Services

      ..Wire Bank Transfer all over the world

      ..Western Union Transfer all over the world

      ..Credit Cards (USA, UK, AUS, CAN, NZ)

      ..School Grade upgrade / remove Records

      ..Spamming Tool

      ..keyloggers / rats

      ..Social Media recovery

      .. Teaching Hacking / spamming / carding (1/2 hours course)

      discount for re-seller

      Contact: 24/7

      fixitrogers@gmail.com

      Burahin