Jump to content

How to hack your own website passes using Auto SQL I Helper V.2.7


Recommended Posts

Posted

Hello maxcheaters.com! I'm beginner on your forum. I don't know  some cool exploits in L2 , WOW etc.But what i know  much about web site cracking_) This is no my artikle , but if you have questions ,  write in this topic, i will answer ..

COPYPASTED( DON't remember the author )

I have been asked lately to write a tutorial on how to use

"SQL I Helper V.2.7" tool.

At the beggining "SQLIHelperV.2.7" is a tool that will hack vulnarable websites using SQL injection. You don't have to spend hours and hours trying to find your way in a website and trying hundreds of combinations and codes to hack a website.

This tool will do it all by itself. You only have to tell her what do and where to look.

You can download it from here:

http://rapid^share.com/files/270668589/SQL_Helper_by_Zuzun.rar.html   ( delete ^)

ps : this program is for penetrating and hacking webseites sql and may be seen by your anti virus as a hacking tool.But it is totally 100% harmless

Lets start.

first you need to find the potential website that you think it might be possible to hack it. Remember that some websites are simply unhackable.

After you find your website ( better to end with "article.php?id=[number]" ) example: "http://encycl.anthropology.ru/article.php?id=1"

 

I will explain my tut on how to hack this website.

 

Check if your website can be hacked by trying to go this address :

http://encycl.anthropology.ru/article.php?id='1 <------ notice the ' before the number 1.

 

you should get this message:

Code:

 

Query failedYou have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '\'1 ORDER BY lastname' at line 1 SELECT * FROM person_old WHERE id=\'1 ORDER BY lastname

 

 

This mean that this website can be hacked because you get an error.

 

Now open your SQL I Helper V.2.7

and write the link :

http://encycl.anthropology.ru/article.php?id='1 <---- without the '

here

 

and press the inject button.

 

Now you should wait until the tool finish searching for columns . Time may vary depending on your connection speed , your pc speed , and the number of columns in the website.

So now you should have this:

 

 

then select "Get database" and you get this:

 

 

Now select any element from the "database name" box and press the "Get tables" button , I will select "anthropo_encycl":

 

 

 

then select any element from the "table name" box and press the "Get columns" button , I will select "user":

 

 

then select any elements you want from the "columns name" box and press "Dump Now" , i will select "usr_login" and "usr_pass"

 

 

After clicking "Dump Now" , you should see this new window

 

 

Now copy the hash on a peace of paper and go to this website:

md5Crack.com | online md5 cracker

 

enter the hash and press the button "Crack that hash baby!" and you should get the source of the hash.

hash:21232f297a57a5a743894a0e4a801fc3

username: admin

 

hash:202cb962ac59075b964b07152d234b70

pass: 123

 

 

COPYPASTED END.

 

P.S. I want to say that this  is  only a program  and without understendin what are SQL injections it will give you nothing...

 

One more link if smb have problems with rapid.... http://hotfi^le.com/dl/10737822/2540192/SQL_Helper_by_Zuzun.rar.html (delete ^)

  • 4 months later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...