this stuff is indeed common knowledge to developers... but wordpress is actually been used by a lot of people that just copy+paste stuff from the internet and throw a forum for their gameclan together and put it online.
and i actually know there are people that do not understand much about sql but if they would they would happily crash other peoples party by ruining a forum or website.
@MegaSHamed: Hello, I hope you realized that this video was split into two parts. Also, this video was meant to be educational; therefore, I started it by explaining the basics of SQL injection and why it works. After the viewer understands the concept of the attack, I gave an example of how it can be used to extract information from a website. When I made this video I had already fixed the flaw on my actual website, so hosted an un-patched version of my site on my local machine.
You have to be kidding me? An admin with a little bit of knowledge will make sure all the passwords are stored on an external localhost machine with md5 hashes. Your site is a joke
@RSaddon: An external localhost machine? I'm assuming you meant a remote host. Well I'm happy to inform you that members of my site have their passwords stored as salted MD5 Hashes on a remote MySql server. The website shown in this video was a clone of my real site with fake hashes. This way actual members don't have their hashes exposed.
then you have to find a different exploit because clearly that one doesnt work. Im not sure that a .html ending even uses php at all so you're screwed through that attack.
I honestly hate people like you. Why say "I already knew most of the stuff"...No you didn't. You're just a dickfuck that doesn't know shit. There is nothing wrong with LEARNING.
No prob, but usually after someone finds a site that is vulnerable and hacks it, it is quickly brought to the attention of the website staff and admin.
you could always google search Login Page. and try inputting these strings over and over and over into all the different login pages.
Stick to picking locks. One day, if you're lucky, you'll get caught by the cops and be accessorized with silver bracelets and contusions (bruises) as you're hauled away to the gray-bar hotel. While rotting there, you can take a course on computers and learn how to hack.
netoveride are you new? more like 9 times out of 10 when an exploit is found and published it's based upon an a weakness in code that could be attacked via sql injection. Someone needs to take a look at packetstorm sometime or milw0rm there isn't a day in the week when you can't find a newly published sql attack.
9 out of 10 websites with an sql database have been protected, try typing in admin/login.asp "all those have sql or asp" and see how many you can hack
but...wait before I say that...At the bottom (FerryWell) Why the heck would I need a 3 or 4 hundred dollar AirPcap Driver for webserver hacking. I don't (It is good for wireless hacking). What I was going to say is that even though this sql isn't as common, blind sql via manual input or sql brute force is still pretty common. If you use 1=1 and get a blank page it was succesful, error means not succesful. It is a yes/no game with the website. It is also the hardest type of attack
the SQL server aint the bit thats vunerable you noob! SQL servers get commands from SQL strings
if the SQL sting is SELECT * FROM USERS WHERE ID=1 and i add OR 1=1 to the end th full code would be SELECT * FROM USERS WHERE ID=1 OR 1=1 pointless example but thatsn the idea
its got nothing to do with the server. like he says in the video the stripslashes function. its all coded nothing to with the server. the server just responds to the commands u give it
try dsniff for sniffing passwords. It assumes you have access to the LAN (wireless is great!) and that you have suitable drivers and card on your attack device. I use a Sharp Zaurus running Debian pocketworkstation. It works a treat for FTP, email etc.
go to google and search for
inurl:asp inur;productid=
lots of sites are vulnerable to SQL injection, Ive hacked 3 this week but I'm a 'white hat' so I cant tell you the URLs
AWESOME SONG!! havent heard it in awhile, guess where i found this video... ON CBS!!! they were talking about the huge hack on JCX which is JCPennys headquaters i guess.. they were sayin, " it can even be found on youtube " like a 5 sec clip of you!! lol id be siked if i were u lol ahah awesome keep up the good work this S@#% rocks!!
This has been flagged as spam show
cs- bg. info/ nobody can hack this site!
If you want our protection,pm me
dasdasd280 1 day ago
you need to explain why blah? why not halb? or what ever?
adofri 4 weeks ago
@adofri It's just random stuff, that the server doesnt expect to have to return. It either is not there or its an invalid request. ex:
int(blah)
07PamPer07 3 weeks ago
download havij 1.4.0 version for password sql injection index.php and index.asp
makaveli190391 1 month ago
there are altot of these type tutorials on kobusvdwalt.blogspot.com
kobusvdwalt99 2 months ago
I have a tutorial on hacking here watch it itl blow you ur mind
kobusvdwalt99 2 months ago
Very interesting! I'll be sure to try a number of these out sometime.
BdMdrFckr 3 months ago
Use havij. its easier
NewJerseyModding 3 months ago
mysql_real_escape_string();
problem solved.
cyrix1986 4 months ago
This has been flagged as spam show
I am hacker from China want to sell YOU fresh stuff :)
sellfresh@yahoo.cn
i am seller for cc, dumps, bank accounts, paypal will be in shop soon!
sellfresh@yahoo.cn
Qannabiz 5 months ago
big fat guy dont know anything he is just secretly hearing what they talking about and learn from them
sbukhari7 5 months ago
can i hang out with you guys
charmanderstail 6 months ago
dun trust this video. try my site: vnphoto.net
rockoperaca 6 months ago in playlist Hacking
Most of this stuff doesn't work anymore.... :-(
madjimms 6 months ago
@Spicniggereater Dude SHUT THE FUCK UP ALREADY Fucking Cock Sucker! don't run your mouth about something in which you have no understanding
pspheaven 7 months ago
This has been flagged as spam show
havij works better :) mediafire . com/?d4d9ackbidf77go
sneakylight 7 months ago
hi sir i want to know more about sql injection ....................I try it but not success more in it.
47mukesh 9 months ago
Program to search for vulnerabilities in php scripts
You can download the program go to:
rapidshare. com/files/454622728/security.rar
depositfiles. com/files/946egeo54
Note:
In reference to remove blank!
The file can swear antivirus!
kevin54683 10 months ago
fooling
AnonymousShare 10 months ago
this stuff is indeed common knowledge to developers... but wordpress is actually been used by a lot of people that just copy+paste stuff from the internet and throw a forum for their gameclan together and put it online.
and i actually know there are people that do not understand much about sql but if they would they would happily crash other peoples party by ruining a forum or website.
karibeuzum 1 year ago
This has been flagged as spam show
We have thousands of profiles for Naughty women mworld5.info
AILEENROBERTAify 1 year ago
This has been flagged as spam show
My name is Mike from LA Although there busizz4me.info
pdisanyaka 1 year ago
This has been flagged as spam show
Sexy Be Naughty women benaughtyman.info
ranidymalshika 1 year ago
Comment removed
MegaSHamed 1 year ago
Comment removed
MegaSHamed 1 year ago
Comment removed
MegaSHamed 1 year ago
Comment removed
MegaSHamed 1 year ago
@MegaSHamed: Hello, I hope you realized that this video was split into two parts. Also, this video was meant to be educational; therefore, I started it by explaining the basics of SQL injection and why it works. After the viewer understands the concept of the attack, I gave an example of how it can be used to extract information from a website. When I made this video I had already fixed the flaw on my actual website, so hosted an un-patched version of my site on my local machine.
Gregorpm 1 year ago
@Gregorpm i took my words back, great job guys.
MegaSHamed 1 year ago
@MegaSHamed make a better one...
obiwanfisher537 1 year ago
Comment removed
MegaSHamed 1 year ago
You have to be kidding me? An admin with a little bit of knowledge will make sure all the passwords are stored on an external localhost machine with md5 hashes. Your site is a joke
RSaddon 1 year ago
@RSaddon: An external localhost machine? I'm assuming you meant a remote host. Well I'm happy to inform you that members of my site have their passwords stored as salted MD5 Hashes on a remote MySql server. The website shown in this video was a clone of my real site with fake hashes. This way actual members don't have their hashes exposed.
Gregorpm 1 year ago 14
@RSaddon 1) you know nothing 2) unsalted md5 hashes are fairly weak pieces of shit if your users do not choose strong passwords.
mlqty 6 months ago
Finally a good tutorial on SQL injections thanks nice video
m8ko 1 year ago
@vertizontal0071
of course all famous sites protect their scripts for example with
mysql_real_escape_string.
600g13 1 year ago
Go Linux!
Microfrost is crap!
PS3Apps 1 year ago
ok, the best thing about windows is when you uninstall it
mlortime 1 year ago
windows XP lol
K2ACP 1 year ago
@K2ACP Best windows so?
plokooni 1 year ago
@plokooni but it's windows -_- and i thought ME & 98 were the best
K2ACP 1 year ago
@K2ACP 98 isnt stable enough
linux ftw :p
plokooni 1 year ago
@plokooni agreed. i use openSUSE (mac's are prettty good too!)
K2ACP 1 year ago
Yea i prefer gentoo :)
plokooni 1 year ago
guys are you great ,but i have questen for you what if web sites no have user ,alredy memeber e.g 436.html.
What now?
mickopi 2 years ago
then you have to find a different exploit because clearly that one doesnt work. Im not sure that a .html ending even uses php at all so you're screwed through that attack.
JustJealouse514 1 year ago
This has been flagged as spam show
View my Channel, there you will find Programs which can hack Websites (e.g WebsiteHackerPro).
TheHack33r1 2 years ago
It's rare to find any vunerable websites with this, stripslashes is basic knowlege with php.
linkinpark9sc 2 years ago
by the way what's the title of the song?
norlan02 2 years ago
Jambi - Tool
stewiesrage 2 years ago
you guys are great!! can i be a part of your team? just hoping.,
norlan02 2 years ago
I honestly hate people like you. Why say "I already knew most of the stuff"...No you didn't. You're just a dickfuck that doesn't know shit. There is nothing wrong with LEARNING.
DangerD205 2 years ago 23
@DangerD205 I think your being a bit harsh, alot of this stuff is common knowldge for alot of web developers.
Although I do agree, theres nothing wrong with admiting that you learnt something.
dalawdog 1 year ago
Just i hace a dream that as a programmer will be a good hacker. just curious. Can i help some one
rakibulalam 2 years ago
no use hex. it will except it with out /'s. look it up: hex converter.
nickrohn93 2 years ago
how did you guys all meet, and when did you guys start hacking? just curious, seems like you guys know your stuff.
ImC00LyourNOT 3 years ago 2
anyone know any websites that are vulnurable?
elobire 3 years ago
part of hacking and cracking is finding the things out for yourself.
coilgunner2 3 years ago 3
just aksing for sum friendly help
elobire 3 years ago
No prob, but usually after someone finds a site that is vulnerable and hacks it, it is quickly brought to the attention of the website staff and admin.
you could always google search Login Page. and try inputting these strings over and over and over into all the different login pages.
coilgunner2 3 years ago
yes i have but like you said ther either allredy hacked and messed up or most have been made sql proof
elobire 3 years ago
@elobire Book: "Exploiting Software - How to Break Code". Get a good book on SQL, learn by doing--read, research, practice.
keithbadeau 9 months ago
i never gona understand that.too complicated
laurentiudll 3 years ago 5
louder/better audio please
CFALC0N 3 years ago 3
Comment removed
SearchBillHicks 3 years ago
great video!great opening music![tool]!give us more...and maybe some php?;)
ph03nix0 3 years ago
hmm on what websites does it work? couldn't get this or XSS to work...any help? :)
2JZGTTTE 3 years ago
what computers are those? What others are able to run bt3 without any problem. Thinking of buying a laptop for bt3 and ubuntu?
ghabhg 3 years ago
Why is the big dude always staring at his computer screen with his head down in some of the episodes of infinity exits?
Just, like to... Ocupate the free space in the camera?
Anyways, Nice vid
TiLeNpWneD 3 years ago
Not many sites work with SQL now they all stopped it.
Pokemon4949 3 years ago
Pokemon4949: Are you dumb? MANY MANY sites are vulnerable. Most sites, actually. Don't say anything when you've no idéa..
leljala 3 years ago 4
Ermm It Dowent work For All The Websites!
Eg gang bliss,bebo,gangster pardise
QMalik786 3 years ago
Tool :)
Uentil 3 years ago
This comment has received too many negative votes show
this is so fuckin hard to do i don't understand it at all
tropico5 3 years ago
Stick to picking locks. One day, if you're lucky, you'll get caught by the cops and be accessorized with silver bracelets and contusions (bruises) as you're hauled away to the gray-bar hotel. While rotting there, you can take a course on computers and learn how to hack.
cerebraljourney 3 years ago
Jambi! haha love that song
aldex123 3 years ago 2
This comment has received too many negative votes show
Hi guys,my computor crashed lately and I lost all my data. Can someone show me how to retrieve it without paying big shitty companies?
hotpixie3 3 years ago
Make your SQL Query in (int), this will protect you from this ;)
mmcmill7 3 years ago
Tool!!! xD
1337pr0 3 years ago
Excellent guys v.good job!!
SONOFRAMBOW 3 years ago
netoveride are you new? more like 9 times out of 10 when an exploit is found and published it's based upon an a weakness in code that could be attacked via sql injection. Someone needs to take a look at packetstorm sometime or milw0rm there isn't a day in the week when you can't find a newly published sql attack.
zeromod 3 years ago
Don't even answer the past comment dumb question
rockystone123 3 years ago
Could you post a .asp website hack?
rockystone123 3 years ago
9 out of 10 websites with an sql database have been protected, try typing in admin/login.asp "all those have sql or asp" and see how many you can hack
netoveride 3 years ago
but...wait before I say that...At the bottom (FerryWell) Why the heck would I need a 3 or 4 hundred dollar AirPcap Driver for webserver hacking. I don't (It is good for wireless hacking). What I was going to say is that even though this sql isn't as common, blind sql via manual input or sql brute force is still pretty common. If you use 1=1 and get a blank page it was succesful, error means not succesful. It is a yes/no game with the website. It is also the hardest type of attack
ajatkinson2004 3 years ago
wow, Nice vid guys, learned alot =P
u seem to be pro hackers as well =)
PersianSexBomb 3 years ago
nice vid guys.
s3xybeast333 4 years ago
There are allmost no SQL based servers who are still voulnurable for this sort of scripting...
Even not IE's forum ;)
ferrywell 4 years ago
the SQL server aint the bit thats vunerable you noob! SQL servers get commands from SQL strings
if the SQL sting is SELECT * FROM USERS WHERE ID=1 and i add OR 1=1 to the end th full code would be SELECT * FROM USERS WHERE ID=1 OR 1=1 pointless example but thatsn the idea
9966869 4 years ago
DUH! but people made it impossible to put in strings like that through an external adress sinds this got public...
When you try the 1 equals 1 trick it wil just say user not found OR giving an empty user page...
And by server i ment device hosting SQL language based scripts such as forums...
ferrywell 4 years ago
its got nothing to do with the server. like he says in the video the stripslashes function. its all coded nothing to with the server. the server just responds to the commands u give it
9966869 4 years ago
can anyone tell me a good password sniffer for a remote FTP server login?
do you any of you know of any SQL vulnurable sites???
wolfenheil 4 years ago
Anything that as SQL on it ;)
ferrywell 4 years ago
try dsniff for sniffing passwords. It assumes you have access to the LAN (wireless is great!) and that you have suitable drivers and card on your attack device. I use a Sharp Zaurus running Debian pocketworkstation. It works a treat for FTP, email etc.
go to google and search for
inurl:asp inur;productid=
lots of sites are vulnerable to SQL injection, Ive hacked 3 this week but I'm a 'white hat' so I cant tell you the URLs
Earthspan 4 years ago
Yeah thats like a cain & abel idea... like the AirPcap :P i love the device... :) still need to order one but seen what it can do :D ^^
If you are realy going to try this stuf just buy some good gear like a AirPcap Card ;) ( or USB ).
ferrywell 4 years ago
sweet that was good clip
Demonboy121 4 years ago
AWESOME SONG!! havent heard it in awhile, guess where i found this video... ON CBS!!! they were talking about the huge hack on JCX which is JCPennys headquaters i guess.. they were sayin, " it can even be found on youtube " like a 5 sec clip of you!! lol id be siked if i were u lol ahah awesome keep up the good work this S@#% rocks!!
ryandoe11 4 years ago
Thanks
the song is Tool - Jambi
Gregorpm 4 years ago
Nice Vid guys
keep up the good work.
ps: wats the name of the song?
petze08 4 years ago