Jump to content

Recommended Posts

Posted

Credits Olympus&Me.

 

 

 

 

 

This is an simple guide of how to hack an website with SQL.

 

First of all we need to find an website.

To do this us a google dork.

Enter inurl:id=5 in the searchbox and press enter.

 

If you found the site that you want let's see if it's vulnerable.

Just add the ( ' ) to the end of the url.

 

An window is gonna 'bump' and is gonna say 'Error Executing Database Query.'

"You have an error in your SQL...etc...."  (if something like this or a black is gonna show you an black the page is vulnerable).

 

 

The way to check how many columns there are is this one:

Just order by 1/* to the end of the url and keep increasing it until you get an error.(p.x www.test.com order by 1/*,www.test.com order by 2/*...etc...)

When you will get an error p.x at the 100 it means that they are 99 columns.

 

Now that we found how many columns there are we use the union command.

Just make the id negative and add union all select (columns)/* to the end of the url.

 

So in my 'case:

union all select 1,2,3....99/*  (because of the 99 columns).;)

 

 

If 'your' site is version 5 then you can see all the tables+columns.

wHEN THE VERSION IS LOWER THAT 5 THEN YOU HAVE TO GUESS THE TABLES AND COLUMNS (COMMON ARE:USERS,USER,USR,USRS,ADMIN,ADMINS,memmber,members.....etc...)

Common columns are:user_name,username,user,passowrd....

 

Now at the version 5 to view the tables you will have to replace the digit shown on your screen(I have 99) with table_nameand at the end of the url of the url you will add from information_schema.tables/*

Now to check your version it might show you 2 or other digits.Let's say that my version is 78.

So in my case I am gonna replace 78 with versions() or @@version(when is gonna show you 2 at your screen you will have to replace 2 with the version() or the @@version.).

p.x www.test.com union all select 1,2,3,version@@,5,6,7,...etc..99/*    This is gonna show you the system like Microsoft,Debian..etc....

 

 

Now it shows you all the tables.After that use ctrl+F to search for something that you like.(p.x:users)

Note:if is gonna show you only one table then we should use limit.( add limit 0,1/* to the end of the url and keep increasing the 0 until you are gonna find something that you like.).

 

 

 

 

I said that an interesting thing was the users.

If you want to find passwords&usernames then replace the table_name with:

column_name and replace from informations_schema.tables with from informations_schema.columns.

Now you should search something like username&password.

 

 

 

Now if you have found everything let's display it on our screen.

To do this I am gonna replace 99 with concat.(username,test,passowrd)and at the end of the url I am will add from users/*    .  (they may have an different and not users.Search it.).

*conact will put the username and password in this form:"username:password" without the quotes of course.).

So when you will find the table with the users..etc...the usernames are stored in the column user and the password are stored in the column user and passwords are stored in the column pwd you use concat.(user,test,pwd) and at the end of the url you will add users/*  .

 

That's it.I hope to have fun with this little and simple guide.

Posted

Simple guide of how to hack and site with SQL.

 

First change the tittle to : How to hack a website with Sql Injection.

 

Second  Sql is not a hacking tool is just a type of database so "This is an simple guide of how to hack an website with SQL." this don't make sense.

 

We live in 2012 you need something better. :) Give me a pm if you want I can help you a bit .

 

 

Posted

Simple guide of how to hack and site with SQL.

 

First change the tittle to : How to hack a website with Sql Injection.

 

Second  Sql is not a hacking tool is just a type of database so "This is an simple guide of how to hack an website with SQL." this don't make sense.

 

We live in 2012 you need something better. :) Give me a pm if you want I can help you a bit .

 

 

Not for the time being+thanks.

p.s what grade you have?(white,red...etc....)

As you see I am an amateur 'hacker'.

I am learning.;)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now


  • Posts

    • Kroma — Lineage II Interlude on LU4 Client (Latest client)   I'm selling this project. Here's what it actually is and what's been done.   This is a few months of work, most of it on the reverse engineering side. I built it because I wanted to open my own Interlude server on it. That's not happening any more — I've moved on to other projects and don't have the free time left to take it the rest of the way, so I'd rather it went to someone who will.   The idea was to take the modern LU4 client and make it run an Interlude version of the game. Not a reskin of an old client — the actual current client, playing Interlude, against a server I wrote. That's what this is, and it works end to end: the client boots, authenticates, connects, and you play. There are six repositories. Roughly, it splits into three kinds of work: reverse engineering the client, writing the server, and rebuilding the client's own content so it matches Interlude.   Fully reverse engineered   The client's protocol wasn't documented anywhere, so it was derived from scratch off real traffic. I built a sniffer (bypassing anticheat packet encryption) that drops into the client's binaries folder and dumps live traffic to disk, then a separate Java toolchain that decrypts those captures — login and game traffic, both directions. Everything the server knows about the protocol came out of that loop: capture, decrypt, read, implement, test against the real client.   On top of that there's a native x64 hook and injector in C++. It points the client at your own servers and handles its authentication and session layer, plus a few client-side stability fixes that were needed to keep it from falling over once it's talking to something that isn't the official backend. The hooking is pattern-based rather than address-based, so a client patch doesn't automatically break it.   The reverse-engineering notes are in the repos — the patterns, the disassembly, the decompiled functions, what each one does and why it's hooked. That documentation is a real part of what's being sold; it's the difference between inheriting a working system and inheriting a black box.   The server   Interlude ruleset, aCis lineage, but substantially rewritten and extended to speak the LU5 client's protocol with modern features like Party matching, Offline shops or Mailbox. The geodata has been updated according to some layout changes in LU4 cities. There's also a separate login server handling the client's auth flow.   Customized client to adapt to Interlude   This is the part people underestimate. The retail client ships retail content — retail NPCs, retail items, retail zones, retail UI. All of that had to be reshaped. The whole client-side pipeline is scripted: extract the retail PAKs, apply every edit from data files, rebuild, drop the result back into the game folder. 23 purpose-built C# tools, ~6,700 lines, organised into three pipelines that are guaranteed not to write over each other. There's a documented checklist for regenerating everything from scratch when a new patch drops. The important thing is that none of it is hand-editing. Every change is a line in a data file. When the client updates, you re-run the scripts instead of redoing the work from memory.   All NPC / item / drop lists updated according to Interlude   The client's own data tables were rewritten from the real Interlude client data files — `npcname-e`, `itemname-e`, `skillname-e`, `systemmsg-e`, `npcgrp`. That means roughly 6,470 NPC and skill name/title updates and about 4,000 Drops/Spoils rows written directly into the client's `NPCDataTable` and `SkillTable`, so the client shows Interlude names, Interlude item text, Interlude system messages, and Interlude drop and spoil lists. There are also custom NPC rows on top of that, plus 304 game action rewrites.   Opened the catacombs   In the LU4 client the catacombs and necropolises are unusable — flooded, unlit, and with holes in the geometry. All three were fixed: Water removed. Water exclusion volumes were placed over all 12 of them: Rifts, Apostate, Patriots, Devotion, Dark Omens, Heretics, Pilgrims, Saints, Worship, Martyr, Forbidden Path and Witch. This was more involved than it sounds — the volumes' scale is ignored at runtime, so the tool picks the best-fitting native template per hole, and nearby lakes and rivers are separate water bodies that have to be excluded individually or you get leftover water borders. Lights added. About 28,900 light definitions imported into the client's level files. Missing walls fixed. Mesh actors replaced and spawned to close the gaps in the geometry.   Removed the modern "slop" features from the UI   The LU4 client is full of things that have no business in an Interlude server, and most of them are wired into the UI. Those are stripped out: The assistant manager — the auto-hunt / auto-play slot on the XP bar Vitality*and the XP lock button The fatigue system — updated the format to a regular VIP format The in-game browser** and **in-game radio** buttons The "Learn Skill" tab in the player skills window Removals are scripted by path, so they survive a client patch and are trivially reversible if a buyer wants any of them back.   Reworked the UI toward an actual Lineage II feel   The original LU4 UI looks AI-generated. It doesn't feel like Lineage II. A good part of it has been reworked toward the classic look — the menu button row rebuilt as a wrapping layout with a proper background, the self status and target windows cleaned up, and 590 asset field edits covering textures, positions, colours, text and compiled Blueprint literals.   This part is not finished, and I want to be straight about that But the tooling to continue it is all there, and it's the good kind of tooling: you can target any widget property in any UI asset by dotted path, remove widgets by path without knowing their auto-generated slot names, and edit text that's dynamically bound through Blueprint bytecode rather than stored as a plain property. Continuing the UI work means adding lines to a data file, not reverse engineering anything new.   Other client-side work   A custom login scene, built in a real Unreal Engine project that's included Interlude music restored, plus ambient sound work (cities only for now) Custom splash and branding   What's included   All six git repositories, the Unreal Engine project and its custom assets, all the tooling — injector, hook, sniffer, decryptor, asset editor — every data set including geodata, XML, HTML and the SQL schema, the build and repack scripts, and the per-repo technical documentation including the reverse-engineering notes.   Happy to answer questions or show it running.   Gallery
  • Topics

×
×
  • Create New...

Important Information

This community uses essential cookies to function properly. Non-essential cookies and third-party services are used only with your consent. Read our Privacy Policy and We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue..