Hack Websites Using Havij [SQL Injection Tutorial]

Prince

[ Verified Seller ]
Staff member
Trusted Seller
Joined
11 yrs. 6 mth. 27 days
Messages
5,381
Reaction score
18,380
Age
45
Wallet
11,590$
According to a survey the most common technique of hacking a website is SQL Injection. SQL Injection is a technique in which hacker insert SQL codes into web Forum to get Sensitive Information like (User Name , Passwords) to access the site and Deface it. The traditional SQL injection method is quite difficult, but now a days there are many tools available online through which any script kiddie can use SQL Injection to deface a webite, because of these tools websites have became more vulnerable to these types of attacks.

One of the popular tools is Havij, Havij is an advanced SQL injection tool which makes SQL Injection very easy for you, Along with SQL injection it has a built in admin page finder which makes it very effective.

Supported Databases With Havij

- MsSQL 2000/2005 with error.

- MsSQL 2000/2005 no error union based

- MySQL union based

- MySQL Blind

- MySQL error based

- MySQL time based

- Oracle union based

- MsAccess union based

- Sybase (ASE)

Demonstration

Now i will Show you step by step the process of SQL injection.

Step1: Find SQL injection Vulnerability in tour site and insert the string (like
Please, Log in or Register to view URLs content!
) of it in Havij as show below.

havij1.JPG

Step2: Now click on the Analyse button as shown below.

havij2.JPG

Now if the your Server is Vulnerable the information about the target will appear and the columns will appear like shown in picture below:

havij4.JPG

Step3: Now click on the Tables button and then click Get Tables button from below column as shown below:

havij5.JPG

Step4: Now select the Tables with sensitive information and click Get Columns button.After that select the Username and Password Column to get the Username and Password and click on the Get Table button.

Countermeasures:


1. Renaming the admin page will make it difficult for a hacker to locate it
2. Use a Intrusion detection system and compose the signatures for popular SQL injection strings
3. One of the best method to protect your website against SQL Injection attacks is to disallow special characters in the admin form, though this will make your passwords more vulnerable to bruteforce attacks but you can implement a capcha to prevent these types of attack.

Please, Log in or Register to view URLs content!


This tutorial is only for beginners SQLi
 
Paid adv. expire in 2 months
CLICK to buy Advertisement !
westernunion carding Verified & Trusted WesternUnion | MoneyGram | Bank - Transferring [299$ BTC for 2000$ WU]
electronics carding Verified & Trusted Electronics Carding, Carding iPhone, Samsung Carding, MacBook Carding, Laptops Carding

expo

Well-known member
Member
Joined
11 yrs. 7 mth.
Messages
1,552
Reaction score
5,695
Wallet
0$
Does it work with any site at all., i have tried one but does not give me any table, not even status as yours...do i make mistake anywhere, thanks for sharing.
 

frontend

Well-known member
Member
Joined
11 yrs. 6 mth. 2 days
Messages
2,464
Reaction score
1,297
Wallet
0$
Thanks for d share
@expo the site must be vulnerable to sql if not it wont work u need a google dork to find a vulnerable site in google.com
 

Biortosh

V.I.P
V.I.P
Joined
11 yrs. 7 mth.
Messages
2,571
Reaction score
8,720
Wallet
0$
yes nice one
 
Top Bottom