Hacking Websites 1: SQL Injection
Hello, this is a short Tutorial, how to hack a Website with SQLi.
1. Search vuln site ->
Photo of Bangkok. Photos from Bangkok, Thailand.'
2. 1. Try to find Columcount ->
No Photo
2. 2. Go down with the Number, until no Error is displayed on the site ->
No Photo
3. Put the Number in an Union Select ->
8
4. Replace the Number with guessed Columnnames in a concat (concat(1,0x3a,2)), and guess the Tablename. ->
8
5. Crack the Hash ( i used Havij ) -> 1c9059170910835368500990479a5cf828444d34 = arsenal
6. Admin data:
tony@ris*****.uk
arsenal
Login
7. We just hacked a Website, lolz
tell me where to buy the base mail? for game hacks