Dear Everyone, dont bother trying to hack facebook or msn or any other huge websites with this method, it wont work. BUT, i found this method is very effective with school websites! ^_^
I'm sorry to disapoint you all but.... you wont be able to do anything relevant, you won't hack into anything with 13,14,15,16. Wait until you go to a university.
Notice this, the way this video does it, makes it look easy but WHO IN THE HELL STORES THE PASSWORDS NOT EVEN USING MD5??? A lazy ass.
I have reached to the stage where you fetch the data but when I hit enter I get this Warning: mysql_fetch_row(): supplied argument is not a valid MySQL result resource in /home/mobil0/public_html/cwm/neff/main.php on line 45, any tips?
@josiahmahar Depends what you want to do, if you just want to practice then it doesnt matter what the site is (obviously not like a law firm or big names, and if they're nice non deserving people just help them secure their site) but usually i go onto google (all different countries)...type "inurl:php?id=" and then a space and whatever i hate most so like "psychic" or "crystal healing" because they scam idiots....and quite frankly deserve their sites ruining, plus its funny.
I gained access to a website last night through a VPN, emailed the webmaster about the flaws in his website, helped him fix them..and was given permission to look for any other things that need patching up, nice guy really. much more rewarding than defacing :) unless the site you gain entry to deserves it anyway.
Buyayearbook (DOT) COM /Adminlogin.asp You'll Get Arrested
If You Try It You'll Get This Violaton
Security Warning
An attempted security violation by the following address has been detected.
All information on this attempted security violation has been referred to our Information Security Department for further investigation and prosecutions.
Security Violator: 208.54.87.179 (This IP Address Belongs To T-Mobile DNS Severs) & Is Not Mines & Is Traceable To Diffrent States
@TheGuitarplayer12345 Are you using a proxy server and you wont have a problem of getting caught and try to find free proxy servers on the internet the one you should try is proXPN its a good proxy and I use it when I hack so look for free downloads for that on youtube or google
@adofri Potentially, if said HTML is then parsed by PHP or ASP... Just remember this works because we input data, that is passed to a database... HTML doesn't have that capability.
awwww mannnnnnn... i was using your ASCII converter in ur info for years.. .now its discontinued.. :( i cant find any other can someone help me convert ASCII to text ?
@monseigneur16 I understand this, I mean the website is now gone... most likely thanks to idiots defacing it, but I was young at the time of making the video and never really considered the consequences. As to your programming comment, I am currently working on a few projects, and fuzzing a couple of things ;)
@TheGuitarplayer12345 Don't worry it's an automated message when the website detects SQL. Your best bet is to make your own password and username script and try to hack that. :)
Don't freak out. Thousands of these injections happen every second. To the cops its not even considered a crime. Unless you tampered with the website severely
Ah I love this tutorial keep making more, Ive been hacking scince I was 13(Im 14 now) its fun, anyone who says hackers are evil.... there 50% wrong, most hackers are good.... who the hell do they think creates there AVs and there Friewalls? pah srew them, keep on!!!
@tictuga version 4 doesn't support information_schema.tables so you have to guess the table name. So for instance you have the column numbers and it shows you the string numbers. after the column numbers you put "from users" and if it returns the string numbers still that table exists if it doesn't you have to keep guessing it. Once you have type in group_concat("text in here") where the string number is, so for instance if you type password and loads of passwords come up then you know that
@tictuga exists, you can keep doing this until you get usernames, passwords emails etc. you just have to guess, remember to put 0x3a which is the hex value for : which will split the usernames from the passwords and cause less confusion. I hope this helped.
Thank you for your video , i have one question , i tryed it on this website
they said it was ok ( i know the owner ) but i can't make it work , i did the ' , and it worked iit is sql vulnerable but than when i do order by ... none of them work because it doesn't exist as a url... can you help me
Hey man, do u have mail? I would like to tall with u... I know a lot of inyection of sql and I "hack" a lot of important pages. WEELLL, add me: lprdesigners@hotmail.com
@LudakLudi Police find you and you go to jail with 2700 users. Not to be cranky its a nice find dude just remember that what you are doing IS illegal.
@TH3L44R123 So think about it, there using ASP which is generally locked down to MS-SQL as its database, the above video is aimed toward MySQL injection attacks, go research MS-SQL and ASP injection methods.
unknown column name in information_schema i can't get past the ascii code on any website it always says the same thing i have tried and tried can someone please tell me what has happened?
Go to a website where the end of the URL looks like admin/login.asp , adminlogin.asp or anywhere along those lines, and put the username as admin and the password as 'or''='
Isn't it easier to first use "group_concat(table_name") or (column_name) so you get it in a group, and use "from information_schema.tables/columns where table_schema=database()--" ? :P
@klaboem0 I'm not 100% sure on this one but when I looked it up I think the hex is a ':' (colon) which suggests its just how SQL wants you to split up your selections.
The keyword concat that he used is short for concatenate which means that it will chain everything together in one big lump, there is nothing there to separate the entities. So in this case, without the hex, it would look like this:
Thanks for the tutorial. I have been reading up on it all day but seeing you do it and hearing you explain why helped it click when all those hours of reading didn't. Thanks again, I hope you continue to upload these tutorials
@nsahler Pretty much :D And i'm not being a douche but all the people asking questions I have gave you the basics now go away and read read read..... Its better to learn yourself in my opinion.
Hey dragonlover61...everything went fine until findin the desired columns...but the problem i face comes from displaying the column... i type exactly as u said
union all select 1,user,3,4,5 from user--
when i type enter i get a error....why is that...can you help me ??
Hey dragonlover61...everything went fine until findin the desired columns...but the problem i face comes from displaying the column... i type exactly as u said
union all select 1,user,3,4,5 from user--
when i type enter i get a error....why is that...can you help me ??
I use TOR and armyproxy for my hacking. :)
superanimator1 2 days ago
Dear Everyone, dont bother trying to hack facebook or msn or any other huge websites with this method, it wont work. BUT, i found this method is very effective with school websites! ^_^
baar34 1 week ago
awww what do i do they havent got me yet does that mean in in the clear
smiley32142 1 week ago
I got a warning and forgot to use a proxy Is that bad
smiley32142 2 weeks ago
@smiley32142 dude cops are gonna find you
Zoolaan 2 weeks ago
ahh... i see so many kids here eheh.
I'm sorry to disapoint you all but.... you wont be able to do anything relevant, you won't hack into anything with 13,14,15,16. Wait until you go to a university.
Notice this, the way this video does it, makes it look easy but WHO IN THE HELL STORES THE PASSWORDS NOT EVEN USING MD5??? A lazy ass.
Streetkillerful 3 weeks ago
if ur scary about "OMFG POLICE" get a proxy lawlzzzz zzzzzlwal
ChileanCrafter 3 weeks ago
I recommend using TOR, for anonymous browsing and... editing.
DoctorGrambeat 3 weeks ago
I have reached to the stage where you fetch the data but when I hit enter I get this Warning: mysql_fetch_row(): supplied argument is not a valid MySQL result resource in /home/mobil0/public_html/cwm/neff/main.php on line 45, any tips?
DgangaJ 4 weeks ago
guys use a proxy lol u might get done
SCORPION5O 1 month ago
Bleach FTW! :D
DrPokiaka 1 month ago
what sites are you kids trying to hack and what is your reason??
josiahmahar 1 month ago
@josiahmahar Depends what you want to do, if you just want to practice then it doesnt matter what the site is (obviously not like a law firm or big names, and if they're nice non deserving people just help them secure their site) but usually i go onto google (all different countries)...type "inurl:php?id=" and then a space and whatever i hate most so like "psychic" or "crystal healing" because they scam idiots....and quite frankly deserve their sites ruining, plus its funny.
xthorpyx 1 month ago
@josiahmahar "electricretard",com reason: its fucking sick.
I already have basic-intermediate hacking skills though, just not in SQL
DaneAraux 1 day ago
I gained access to a website last night through a VPN, emailed the webmaster about the flaws in his website, helped him fix them..and was given permission to look for any other things that need patching up, nice guy really. much more rewarding than defacing :) unless the site you gain entry to deserves it anyway.
xthorpyx 1 month ago
If You See A Website
Buyayearbook (DOT) COM /Adminlogin.asp You'll Get Arrested
If You Try It You'll Get This Violaton
Security Warning
An attempted security violation by the following address has been detected.
All information on this attempted security violation has been referred to our Information Security Department for further investigation and prosecutions.
Security Violator: 208.54.87.179 (This IP Address Belongs To T-Mobile DNS Severs) & Is Not Mines & Is Traceable To Diffrent States
MarkIMcclam 1 month ago
@MarkIMcclam i did it to this site before i saw this, am i safe?
FUTEBOLSTUD 1 month ago
@MarkIMcclam ...except mine is my actual ip
FUTEBOLSTUD 1 month ago
Comment removed
MarkIMcclam 1 month ago
Den Benjamin right??
SafwanBestBoyZ 1 month ago
@TheGuitarplayer12345 Are you using a proxy server and you wont have a problem of getting caught and try to find free proxy servers on the internet the one you should try is proXPN its a good proxy and I use it when I hack so look for free downloads for that on youtube or google
Ponchovillla14 1 month ago
intro song?
SROCB 1 month ago
DEff. Fullscreen, 720p
McspoondABeast 1 month ago
WTF? this is how magnets works?
batchchip2 2 months ago
it cant be html
???
adofri 2 months ago
@adofri Potentially, if said HTML is then parsed by PHP or ASP... Just remember this works because we input data, that is passed to a database... HTML doesn't have that capability.
bizcuitzrcool 2 months ago
awwww mannnnnnn... i was using your ASCII converter in ur info for years.. .now its discontinued.. :( i cant find any other can someone help me convert ASCII to text ?
AnnaMicrosoft 2 months ago
@AnnaMicrosoft ASCII to text... *sigh* what you want is ASCII to char codes, google it :)
bizcuitzrcool 2 months ago
i hate this accent! you cannot understand his english if you are a beginner!:(
Descentofremoved 2 months ago
@Descentofremoved Good thing my aim is not to teach english then huh.
bizcuitzrcool 2 months ago
@bizcuitzrcool yours aim who? cause it`s not your video...
Descentofremoved 2 months ago
@Descentofremoved Erm yes it is...
bizcuitzrcool 2 months ago
dude why dont disable comments ? :P
extazy666 2 months ago
@extazy666 What purpose would that server? :D
bizcuitzrcool 2 months ago
r u russian?
xGodsHereticx 3 months ago
@xGodsHereticx hes clearly austrlian lol the .au webpage
vraj11590 3 months ago
@vraj11590 an australian web page doesnt mean u cant be russian or any other race
xGodsHereticx 3 months ago
@xGodsHereticx Exactly, I'm not auzzie, or russian... I'm english.
bizcuitzrcool 2 months ago
@xGodsHereticx I can't tell if your trolling or being serious.
DaneAraux 1 day ago
Brazilian Hacking
HigorVortex1 3 months ago
Tha tag says l33t? LOLOLOLOL. Its 1337 n00b.
SwK4Life 4 months ago
You just earned yourself a subscriber my good man.
GordanMFreeman 4 months ago
@GordanMFreeman Sub too my new channel dude :P H4ckingHQ :)
bizcuitzrcool 4 months ago
@bizcuitzrcool done
GordanMFreeman 4 months ago
so if you do this on someones facebook page you get their passwords just like that? and how can you do this safely? and annonymously
whymeproducz 4 months ago
great video helped alot thank you
moshg 5 months ago
What is the need to explain how easy it is to become a bastard?
this technique in the wrong hands can put people in danger.
prove that you are a talented programmer and do create masterpieces instead of showing how to destroy others work
monseigneur16 5 months ago
@monseigneur16 I understand this, I mean the website is now gone... most likely thanks to idiots defacing it, but I was young at the time of making the video and never really considered the consequences. As to your programming comment, I am currently working on a few projects, and fuzzing a couple of things ;)
H4ckingHQ 4 months ago
holyshit a scot!
Afroxec 5 months ago
@Afroxec He isnt from scotland, Probably Manchester, or Liverpool, More than likely, Manchester.
guyphawkes 5 months ago
@guyphawkes mancunian eh? just like oasis and all uk drug dealers
Afroxec 5 months ago
@guyphawkes Still nope but better.
H4ckingHQ 4 months ago
@Afroxec Nope.
H4ckingHQ 4 months ago
@H4ckingHQ i didnt say "fag" so y did YOU speak up? rofl
Afroxec 4 months ago
@Afroxec Cause you were guessing my accent wrong.
H4ckingHQ 4 months ago
@H4ckingHQ no im right its a scot accent.
Afroxec 4 months ago
i dont know what the fuck coments want me to judge
sbukhari7 5 months ago
I did this, and the website gave me some warning.
I'm only 13. I don't want to go to jail/juvenile...
I'm freaking out.
TheGuitarplayer12345 6 months ago 38
@TheGuitarplayer12345 fail
raditsyz 5 months ago
@TheGuitarplayer12345 you are a fucking clown
18iser 4 months ago
@TheGuitarplayer12345 Use a proxy. I'm twelve and trying this.
TheBubaSqua 4 months ago
@TheBubaSqua
Proxy's don't do shit. You are still EASILY traceable since 99% of proxy's log entrys and exits.
iGeckoGaming 3 months ago
@iGeckoGaming unless if your using thor....
glitchhunter96 3 months ago
@glitchhunter96 Lol noob proxies. Use VPNs... Unlogged ones.
XxENovaxX 2 months ago
@XxENovaxX TOR is suitable as well. VPN is easier though, as long as you have guest access to one.
swingfire 2 months ago 2
@TheGuitarplayer12345 calm down bro.
kurtle005 3 months ago
@TheGuitarplayer12345 how can they notice that you are using exploits?
elitotaku 3 months ago
@elitotaku Erm, Server Logs... IDS... MySQL Logs... there are many ways :D
bizcuitzrcool 2 months ago
@TheGuitarplayer12345 Erm, your not going to jail XD Do you remember if it was a CloudFlare message?
Oh and before anyone spurts shit, yes this is my video and yes this is a different account.... clearly :)
bizcuitzrcool 2 months ago
@TheGuitarplayer12345 hahahaha seriously u r very funny
lovewavesfrompriyank 2 months ago
@TheGuitarplayer12345 Don't worry it's an automated message when the website detects SQL. Your best bet is to make your own password and username script and try to hack that. :)
tommydanielyong 2 months ago
@TheGuitarplayer12345
I getted it to and i'm 11
drakola159753 1 month ago 9
@drakola159753 l0l
sk8sbest 3 weeks ago
@TheGuitarplayer12345 Dont worry It happen to me when i was 10 Automaticly close the page and Dont go there again !
MineshaftProductions 1 month ago
@TheGuitarplayer12345 next time use a vps lmao or vpn
profoundPhishes 1 month ago
@TheGuitarplayer12345 Use a proxy, they think i am from germany :-)
Iggy727 1 month ago
@TheGuitarplayer12345 l0l0l0l
sk8sbest 3 weeks ago
@TheGuitarplayer12345
Don't freak out. Thousands of these injections happen every second. To the cops its not even considered a crime. Unless you tampered with the website severely
iEditEffects 3 weeks ago
@TheGuitarplayer12345 LOL are you fucking joking?
Streetkillerful 3 weeks ago
@TheGuitarplayer12345 Should've used a proxy or SecurityKiss!
Bolero5097 2 weeks ago
Great video! One thing, name of song at the end of video? :P
joejenkins23 6 months ago
thx
bucurate4 6 months ago
Comment removed
AnonymousElder 6 months ago
That was nice :)
onurbabadeluxe 6 months ago
anyone got proxee? i need one and tor dont work for crap
Ksernx 7 months ago
@Ksernx try SuperHideIP
BoredAsFlux 6 months ago
@Ksernx check hide my ass.com its awesome
SirHacker13 6 months ago
But isnt it illegal to hack random sites??? or is it legal to hack russian sites?
HACKER71000 7 months ago
@HACKER71000 It is illegal to perform an attack on a site with malicious intent, try being a whitehat instead >_>
daeheadshot 6 months ago
@daeheadshot Im not blackhat, but if there were no blackhats there wouldnt be any whitehats either.
xxKandels 6 months ago
Ah I love this tutorial keep making more, Ive been hacking scince I was 13(Im 14 now) its fun, anyone who says hackers are evil.... there 50% wrong, most hackers are good.... who the hell do they think creates there AVs and there Friewalls? pah srew them, keep on!!!
HACKER71000 7 months ago
UrBAN haha wow sites these days
BossMadnezz 7 months ago
Thank you ;)
MrOMGWTFxCorp 7 months ago
If any body can teach me how to do it over teamviewer I'll pay 5$ over paypal
xlildeebomb13x 7 months ago
I'm having a REALLY hard time finding vulnerable websites to test... :-( I'm putting
"x' or 1=1--" in the password field (a trick I learned from somewhere else) but its always wrong. :-(
madjimms 7 months ago
can i can type in .php?id=8 order by 9999999999999999999999999999999999999999999999999999999999999999999999999-- and it still shows the website
Jooltville 7 months ago
it just turns out like this when i try this;
.php?id=8'%20order%20by%202--
Why? :(
Jooltville 7 months ago
@Jooltville its your browser %20 stands for space, try firefox
bietenprak 7 months ago
What happens if you get caught? Because i got caught..... ( i was just exploring different ways of breaching a website)
NekoTalk 7 months ago
does this work on mysql 4.1.13 ?
tictuga 8 months ago
@tictuga version 4 doesn't support information_schema.tables so you have to guess the table name. So for instance you have the column numbers and it shows you the string numbers. after the column numbers you put "from users" and if it returns the string numbers still that table exists if it doesn't you have to keep guessing it. Once you have type in group_concat("text in here") where the string number is, so for instance if you type password and loads of passwords come up then you know that
oliverxboxable 7 months ago
@tictuga exists, you can keep doing this until you get usernames, passwords emails etc. you just have to guess, remember to put 0x3a which is the hex value for : which will split the usernames from the passwords and cause less confusion. I hope this helped.
oliverxboxable 7 months ago
Hacking on MAC = fail
Paumonsu 8 months ago
Thank you for your video , i have one question , i tryed it on this website
they said it was ok ( i know the owner ) but i can't make it work , i did the ' , and it worked iit is sql vulnerable but than when i do order by ... none of them work because it doesn't exist as a url... can you help me
jmef-serveur.exano.net
MrKingeminem 8 months ago
Comment removed
MrKingeminem 8 months ago
i think you should have used zoom more in this video, it is hard to see some stuff in this video, but yeah i liked the video anyways :P
Vortex93 8 months ago
one thing you nead to know the names of the tables that jou are attacking and than type query
vbtutpro 8 months ago
>Thinks he's 1337 h4x0r - uses Mac..
JACOBFLARSEN 8 months ago
@JACOBFLARSEN >Thinks he's 1337 h4x0r - watches youtube videos on how to hack..
ZlapEx 8 months ago
@ZlapEx >Thinks I think I am 1337 h4x0r . realizes I never stated I was.
>yfw
JACOBFLARSEN 8 months ago
@JACOBFLARSEN >Claims the video owner thinks that he's 1337 h4x0r, when he never stated he was. Yet defends himself when same logic was used on him.
ZlapEx 8 months ago 6
@ZlapEx >Realizes I don't give a fuck, and have no idea of what we are discussing..
>yfw
JACOBFLARSEN 8 months ago
anyone know what this website is called? :P or atleast a good website to do this to?
TechReviewPlus 8 months ago
For me it just says:
An error ocurred while processing your request.
the error returned was: 404.2
with the following error message attached:
Invalid pagemark: 1 order by 2 --
Additionally, an error occured while logging the error.
TomValedro 8 months ago
This has been flagged as spam show
havij works better :) mediafire . com/?d4d9ackbidf77go
sneakylight 8 months ago
i googled how to protect ur pc from sql injections and i destroyed that site lol :P
unfortunatly i cant find it anymore -_-
mysticpower7 8 months ago
thumbs up for sony got effed
bozniankingx1 9 months ago
@bozniankingx1 Sony got DDosed -.-
F-A-I-L
PirateTHESteam1 8 months ago
@PirateTHESteam1
i guess lulzsec when they leak thousands of accounts and voucher codes off sony pictures says otherwise
cozmo195productions 8 months ago
Does anyone know the name of the song in the beginning of the vid???
ThisIsMyUserName242 9 months ago
Login name : admin
Password : 'or''='
I'm not responsable for people who get in jail (works on alot of websites)
dimucchu18 9 months ago
I did a few SQL Injection videos on my YouTube Channel as for 4.0 servers have not figured them out yet.
PhiberOptics 9 months ago
This has been flagged as spam show
Hey man, do u have mail? I would like to tall with u... I know a lot of inyection of sql and I "hack" a lot of important pages. WEELLL, add me: lprdesigners@hotmail.com
lprdesigners 9 months ago
i find web site with 2700 users
i get user ids, usernames, emails and hashed password :)
LudakLudi 9 months ago
@LudakLudi Police find you and you go to jail with 2700 users. Not to be cranky its a nice find dude just remember that what you are doing IS illegal.
H4ckingHQ 9 months ago
@H4ckingHQ ooo nooo they are at my door , they are coming , what should i do ??? police is here !!!!! xD .... lololo NOOB !
LudakLudi 9 months ago
@LudakLudi Noob? You watched my video to learn how to get those accounts. There may be confusion but H4ckingHQ is my new channel.
H4ckingHQ 9 months ago
@LudakLudi lolololol
jaradgrant1 9 months ago
wish you could do that for windows live
tom2197 10 months ago
w00t
AMAZING!, how old are you?
xD
Trunksinflames 10 months ago
@Trunksinflames At the time of recording this I was 14/15.
H4ckingHQ 9 months ago
Microsoft VBScript runtime error '800a000d'
Type mismatch: 'menu'
/gui/default/header.asp, line 106
TH3L44R123 10 months ago
@TH3L44R123 So think about it, there using ASP which is generally locked down to MS-SQL as its database, the above video is aimed toward MySQL injection attacks, go research MS-SQL and ASP injection methods.
H4ckingHQ 9 months ago
i got error at 9 ?
TH3L44R123 10 months ago
Can you please tell me witch song was that? :D
farhad746 10 months ago
unknown column name in information_schema i can't get past the ascii code on any website it always says the same thing i have tried and tried can someone please tell me what has happened?
oliverxboxable 11 months ago
song on the start?
ProRiverside 1 year ago
brilliant, my site is now protected :)
BeanzVideos 1 year ago
dude what are you? Like dude accicents are beast mode :P so how many collums do u think runescape has?
rstipsandhelp4u 1 year ago
@rstipsandhelp4u lol runescape isnt hackable through sql injections.... only unsecure sites are not big company game sites
bKfASSASSIN 1 year ago
When I'm entering "union all select 1,2,3,4,5,6--" it's giving me a SQL error...
Why?
doras100p 1 year ago
That site is full of web shell.
jacksawild 1 year ago
Kids Stuff :) >:) I only want to know the song when the video beggins :)
x3nonnofficial 1 year ago
Go to a website where the end of the URL looks like admin/login.asp , adminlogin.asp or anywhere along those lines, and put the username as admin and the password as 'or''='
Syn2Die4 1 year ago
Aha, I just visited the site after so long, what's with all the defacements? My suggestion grow up :) I was doing that shit when I was 13/14????
dragonlover61 1 year ago
@dragonlover61 I wonder, does the owner of the site even know this? Serveral defacements here and there. Nice tutorial I learned something.
kiNGLYtUbe 1 year ago
Isn't it easier to first use "group_concat(table_name") or (column_name) so you get it in a group, and use "from information_schema.tables/columns where table_schema=database()--" ? :P
Randomwhiner 1 year ago
I like ur accent :D !!!!
darkwizzard70 1 year ago
i forgot to add that the website is hosted by drupal,com
CyphenPhsyX 1 year ago
the site i am trying to hack dosnt give me any errors when i use ' or 1 or 2 or 3... or eve 999999999
so i did the union all select 1,2,3,4,5]
but no box appeared and nothing. Whats wrong?
Btw very nice tutorial, clear and all :)
CyphenPhsyX 1 year ago
@CyphenPhsyX
This mostly means that the website which you are trying to hack isn´t vulnerable.
mago1094 1 year ago
@mago1094
Ah ok, nvm then =P thanks for reply tho :)
CyphenPhsyX 1 year ago
@CyphenPhsyX remove the bracket
ikkyblob 1 year ago
Great tutorial! Could you explain why you put the hex value after the column name? (5:45).
klaboem0 1 year ago
@klaboem0 I'm not 100% sure on this one but when I looked it up I think the hex is a ':' (colon) which suggests its just how SQL wants you to split up your selections.
What do you think?
Yes:No
dragonlover61 1 year ago
@klaboem0
The keyword concat that he used is short for concatenate which means that it will chain everything together in one big lump, there is nothing there to separate the entities. So in this case, without the hex, it would look like this:
NatalieSachNatalie,KathrynJonesgla....
pkbeast 7 months ago
You sound just like the guy that works for CCP
dracomasta13 1 year ago
nicely done! ... I like the way you use the application against itself...
htimsl 1 year ago
cool
AltCtrlRemix 1 year ago
rofl, someone edited one of the pages and inserted a file upload, shell tiem!!!!
DjRareware 1 year ago
HOW DO YOU EDIT THE INFO IN THE TABLES? E.G. THE BLOG`?
blacksiddis 1 year ago
HAYY! I understood your accent just fine! so you other people shut up, you're just retarded ! thumbs up on the vid.
nsahler 1 year ago
im getting error at the part where you write from information_schema-tables -.-
blacksiddis 1 year ago
when issuing the union all select command I get an error.
blacksiddis 1 year ago
I don't see the wrong with your accent, for me it's very easy to understand. And I'm swedish lol
OlloX3 1 year ago
@dragonlover61 When i type union all select 1,2,3,4...-- I can't see any numbers , Why is that ? I tried on many sites and I never see any numbers .
HELP PLS
TheBokiPFC 1 year ago
gr8 dude gr8....
mrperfect1314 1 year ago
Thanks for the tutorial. I have been reading up on it all day but seeing you do it and hearing you explain why helped it click when all those hours of reading didn't. Thanks again, I hope you continue to upload these tutorials
sn0wy11 1 year ago
sql is hard i hate this
vis4r 1 year ago
@vis4r LOL sql is easy. Sits right beside VB XD
nsahler 1 year ago
@nsahler Pretty much :D And i'm not being a douche but all the people asking questions I have gave you the basics now go away and read read read..... Its better to learn yourself in my opinion.
dragonlover61 1 year ago
I understand you just fine, but yer music prior and post video is TERRIBLY loud. I think you made a great video though, props.
DRUNKINSKATER 1 year ago 26
This has been flagged as spam show
Hey dragonlover61...everything went fine until findin the desired columns...but the problem i face comes from displaying the column... i type exactly as u said
union all select 1,user,3,4,5 from user--
when i type enter i get a error....why is that...can you help me ??
raghul2hacker 1 year ago
Hey dragonlover61...everything went fine until findin the desired columns...but the problem i face comes from displaying the column... i type exactly as u said
union all select 1,user,3,4,5 from user--
when i type enter i get a error....why is that...can you help me ??
raghul2hacker 1 year ago