Daftar Rekening Paypal klik disini

Sign up for PayPal and start accepting credit card payments instantly.

Monday, May 23, 2011

Tutorial sql injection with sql helper v 2.7

qeqeqe ...
ada tutorial nih ...
lumayan sql injection, disebelah kan ada yg pake scemafuzz ...
klo ini beda lagi pake software *.exe ... Senang
jadi tinggal klak-klik doank kelar ...
efek samping : bikin orang jadi males ... ;))
tapi klo udah tau dasarnya yg pake "order+by+ bla .. bla ..." it's ok lah...
yg penting kita tau jalannya klo disuruh manual ...

tool :
SQL I Helper V.2.7


lanjut kita mulai
1. cari target site yg vuln contoh
Code:
http://encycl.anthropology.ru/article.php?id=1'
trus masukin ke kolom target (jangan pake ') ...
kaya gini ...
[Image: 3446x5g.jpg]

2. trus klik injek ...
hasilnya nanti kluar kayak gini ...
[Image: 10rvekz.jpg]

3.next, klik "get database" hasilnya kayak gini
[Image: t8rmmu.jpg]

4.pilih database yg mau kita cek ada di kotak database name & trus klik "get tables"
[Image: 14e437a.jpg]

5. pilih table yg kira2 kita bisa dapet user & pass contoh: admin, user, staff, moderator dll ...
pada contoh ini kita pilih "user" trus kita klik "get columns"
[Image: w7n536.jpg]

6. pilih column mana aja yg mau kita intip (ctrl+click) misalnya: usr_login & usr_pass
[Image: eakw00.jpg]

trus klik "dump now"

7.kluar deh username ama passwordnya :wb:
[Image: 35hiz9k.jpg]

8. klo passwordnya md5 langsung aja buka http://www.md5decrypter.co.uk/ kali aja ketemu ... :))

9. cari admin pagenya klik "admin finder" mudah2an aja ketemu ... ;))

10. login deh ...

No comments:

Post a Comment

Mungkin Anda mencari

Related Posts Plugin for WordPress, Blogger...

Label

Twitter Delicious Facebook Digg Stumbleupon Favorites More

 
Design by Free WordPress Themes | Bloggerized by Lasantha - Premium Blogger Themes | Best Buy Printable Coupons