Post: [TUT] SQL injection w/ Havij
03-05-2011, 02:14 PM #1
(adsbygoogle = window.adsbygoogle || []).push({}); This is by far the easiest way to SQL inject a website!

1. Download Havij- You must login or register to view this content. and install
2. Find a vulnerable site with the .php?id=123 sort of ending that gives an error when you add a ' to the url.
3. You must login or register to view this content. Hit analyze.
4. Have some tea or whatever while it's working :P
5. If it says Target Vulnerable Happy at the bottom, you're good to go.
6. When you get this, You must login or register to view this content.
7. Hit 'Get Tables' and wait till you find users or admin or whatever the DB with the admin info is.
8. Check said table, and hit 'Get Columns' and wait until you find columns, and then check appropriate columns, like so, and hit get data. You must login or register to view this content.
9. If you have a hash and/or don't know where the admincp is, use 'Find Admin' / 'MD5'
10.Congrats!
(adsbygoogle = window.adsbygoogle || []).push({});

The following 3 users say thank you to ysinha123 for this useful post:

FullTilt, Honeybro, Josh
03-06-2011, 06:04 PM #11
St0rM
Treasure hunter
Originally posted by Dr.
That's what it says when I try to scan it for vulnerability Facepalm


-Doublefacepalm- You need Acunetix for scanning sites not havij.
03-06-2011, 06:16 PM #12
Josh
League Champion
Originally posted by St0rM View Post
-Doublefacepalm- You need Acunetix for scanning sites not havij.


Triplefacepalm: it says in the tut you can use havij to scan to see if sites are vulnerable. Also the program (I have it), says you can scan a certain website for vulnerability.
03-06-2011, 06:20 PM #13
St0rM
Treasure hunter
Originally posted by Dr.
Triplefacepalm: it says in the tut you can use havij to scan to see if sites are vulnerable. Also the program (I have it), says you can scan a certain website for vulnerability.


No Someone save this child
03-06-2011, 06:24 PM #14
Josh
League Champion
Originally posted by St0rM View Post
No Someone save this child


You try it/download the program then. Then you come back to me.

And I understand, I'm shit at SQL injecting. Hence why I've come here to LEARN.

And, I'm not a child. The term child is used too often here and people think it's an insult when it only means you are a certain age, whereas you can't actually predict people's ages as they use good grammar, etc. Outsider, for example, I know people who think he's in his 30s... He's only about 22...
03-06-2011, 06:28 PM #15
St0rM
Treasure hunter
Originally posted by Dr.
You try it/download the program then. Then you come back to me.

And I understand, I'm shit at SQL injecting. Hence why I've come here to LEARN.

And, I'm not a child. The term child is used too often here and people think it's an insult when it only means you are a certain age, whereas you can't actually predict people's ages as they use good grammar, etc. Outsider, for example, I know people who think he's in his 30s... He's only about 22...


Your in the wrong place to learn then lol I'm not trying to be a dick or anything I'm just saying when you paste the url into havij the url your suppose to be pasting in the vulnerable link.
03-06-2011, 06:36 PM #16
Josh
League Champion
Originally posted by St0rM View Post
Your in the wrong place to learn then lol I'm not trying to be a dick or anything I'm just saying when you paste the url into havij the url your suppose to be pasting in the vulnerable link.


As it says in the tut... "You put in the URL, then press *a button* to check it's vulnerability, if it says SQL Injection available, then carry on!" (or something along those lines).

Have you even got the program that he's mentioned?
03-06-2011, 06:37 PM #17
Originally posted by Dr.
As it says in the tut... "You put in the URL, then press *a button* to check it's vulnerability, if it says SQL Injection available, then carry on!" (or something along those lines).

Have you even got the program that he's mentioned?


What were you having issues with? Sorry, I just got back.
03-06-2011, 06:50 PM #18
St0rM
Treasure hunter
Originally posted by Dr.
As it says in the tut... "You put in the URL, then press *a button* to check it's vulnerability, if it says SQL Injection available, then carry on!" (or something along those lines).

Have you even got the program that he's mentioned?


I've had it before this was posted.
03-06-2011, 07:23 PM #19
Josh
League Champion
Originally posted by ysinha123 View Post
What were you having issues with? Sorry, I just got back.


Finding a vulnerable site. I had a look at some vids on YouTube by typing in Google: inurl:example.php/id=

Then it comes up with loads, but Havij says that they are NOT vulnerable.

---------- Post added at 07:23 PM ---------- Previous post was at 07:22 PM ----------

Originally posted by St0rM View Post
I've had it before this was posted.


Then you've probably got an outdated version..

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo