Post: [TUT] SQL injection w/ Havij free download
05-11-2011, 01:22 PM #1
MrBelfast
I am Bi-Winning
(adsbygoogle = window.adsbygoogle || []).push({}); Don't hate, I know how to do SQLi the real way as well.
This is by far the easiest way to SQL inject a website!

1. Download Havij You must login or register to view this content. and install
2. Find a vulnerable site with the .php?id=123 sort of ending that gives an error when you add a ' to the url.
3. Hit analyze.
4. Have some tea or whatever while it's working :P
5. If it says Target Vulnerable at the bottom, you're good to go.
6. When you get this,
7. Hit 'Get Tables' and wait till you find users or admin or whatever the DB with the admin info is.
8. Check said table, and hit 'Get Columns' and wait until you find columns, and then check appropriate columns, like so, and hit get data.
9. If you have a hash and/or don't know where the admincp is, use 'Find Admin' / 'MD5'
10.Congrats!

edit: I had pics here but the links are broken now, so if anyone needs help with this, just quote me.
(adsbygoogle = window.adsbygoogle || []).push({});
05-11-2011, 01:33 PM #2
Curt
Former Staff
Dude, you posted this twice?
05-11-2011, 01:40 PM #3
MrBelfast
I am Bi-Winning
Originally posted by Curt View Post
Dude, you posted this twice?


yea i seen that , i dont know how it happened . i will get a mod to delete it
05-11-2011, 04:13 PM #4
Epic?
Awe-Inspiring
Originally posted by BELFAST View Post
Don't hate, I know how to do SQLi the real way as well.
This is by far the easiest way to SQL inject a website!

1. Download Havij You must login or register to view this content. and install
2. Find a vulnerable site with the .php?id=123 sort of ending that gives an error when you add a ' to the url.
3. Hit analyze.
4. Have some tea or whatever while it's working :P
5. If it says Target Vulnerable at the bottom, you're good to go.
6. When you get this,
7. Hit 'Get Tables' and wait till you find users or admin or whatever the DB with the admin info is.
8. Check said table, and hit 'Get Columns' and wait until you find columns, and then check appropriate columns, like so, and hit get data.
9. If you have a hash and/or don't know where the admincp is, use 'Find Admin' / 'MD5'
10.Congrats!

edit: I had pics here but the links are broken now, so if anyone needs help with this, just quote me.


Have some tea or whatever?

You must login or register to view this content.
05-13-2011, 04:07 PM #5
BAMF
Social Engineer
No offense but my tut is better and with pics You must login or register to view this content.

The following user thanked BAMF for this useful post:

PsYcHoSiS

The following user groaned BAMF for this awful post:

MrBelfast
05-14-2011, 01:27 AM #6
at least post the offical havij download page so we know its not infected

Copyright © 2026, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo