Close



Keep me logged in.

Forgot your password? | Register Now

Page 1 of 8 1 2 3 ... LastLast
Results 1 to 10 of 77
  1. Original Post
    It's not the same anymore ;(
    Curt's Avatar

    Default How to find vulnerable websites (For beginners)




    [font=Tahoma]I thought i'd post this because using a tool like this is much quicker than doing manual SQLI (unless you prefer doing it old school.:tongue This tool is a little like havij but in my opinion better. I will only be showing you howto find vulnerable websites with this tutorial as their's plenty of tutorials on how to deface an sql vulnerable site.

    First off you need to download the actual tool itself (No this is not my own tool)
    Download (Survey free);



    Once you've downloaded the program itself from the above download link, you need to extract it to a place you will know where to find it. You can find a picture of the programme itself, once opened, below.

    Spoiler:


    NOTE- Make sure you don't extract the tool away from the folder because that's where the dorks are.

    Ok so now for the tutorial, this is a little long but who ever said hacking was easy? just simply follow these steps bellow and then you will be successful in "hacking" your opponent.

    Step 1 -First you will need to click the "Scanner" tab and then the little "+" icon on the "All dorks". Once done you will see a list like below.
    Spoiler:

    this is called a "dork" you can pick any dork you want via clicking the little "+" icon, again.

    Step 2 - Next you will need to pick a specific "dork" I'm going to be using ASP with dork ; ".asp?bookI" you can (enter it into the search box the type of dork you're looking for. This tutorial doesn't require this specific dork, you can chose one to your own preference. So now our stage process should be as shown below.
    Spoiler:


    Step 3 - Now you will need to press the scan button, make sure to press "Remove duplicates". See the below picture.
    Spoiler:


    Step 4 - Once you've completed "Step 3" the next thing you will need to do is right click your list (the white part) and press "Send to SQLI Crawler" as so.
    Spoiler:


    Step 5 - Once in the SQLI Crawler you will need to press "Crawl" this will find you the vulnerable links from the ones you just just imported, this didn't work for me as good as I was hoping. It should look like the following.
    Spoiler:


    Step 6 - Once your list is populated you have now got yourself some vulnerable sites to SQL inject.

    I would of continued the tutorial into more depth of executing SQL injection with this tool but there's already tutorials around that you can use. If you need any help with SQL injecting/uploading a shell just PM me, I'll be more than happy to help. I know you might think this tutorial is well pointless but it's a simple way of finding vulnerable websites whilst using some of the best dorks. Oh and before you guys say isn't it better just using "Google" well in my opinion no, this method tells you if its vulnerable and gives you over +50 sites at a time which will keep you busy.

    I hope you liked this tutorial and remember whenever hacking/exploiting sites always use a proxy to hide yourself, here's a few proxy's that I use.



    (best in my opinion)



    Remember all my tutorials I do myself from my own personal knowledge. Here's some other tutorials I made ;




    Virus scan.
    Last edited by Curt; 09-06-2012 at 06:48 PM. Reason: New pictures + virus scan + new text.
    Register or log in to view signatures.

  2. The Following 68 Users Say Thank You to Curt For This Useful Post:

    <Jimbo> (04-16-2011), ----Nipples---- (06-02-2012), -Balance- (05-06-2011), -Ben- (04-17-2011), -Ginge (04-15-2011), -Hazz- (04-16-2011), -Syed- (04-12-2011), .JiampyPotter (04-17-2011), .Mitch (04-16-2011), 10ThousandFists (05-14-2011), AgentWkd-Botz (04-15-2011), Albani310 (09-14-2012), Axiom (04-13-2011), Bang Tidy (04-17-2011), Callum. (05-02-2011), Chief Keef Sosa (04-22-2011), Chronos (09-12-2011), consolaman (08-21-2012), Eggy551 (05-10-2011), ENZO's Turtle (04-17-2011), Epic? (04-12-2011), Febreze (04-13-2011), Founder Hawk (04-17-2011), frag06 (04-14-2011), Hurldoh (05-26-2011), I Got Cookies (04-14-2011), JamieMaCc (04-14-2011), Jannis96 (05-03-2011), gus248 (04-17-2011), JoeD232 (04-19-2011), johnw6619 (04-22-2011), Josh_ox3 (04-17-2011), jvideogamefreek (04-12-2011), legitmod (05-06-2011), Lydey (04-16-2011), MidgetGangBang (04-18-2011), Midnight.eGo (04-13-2011), Mr. Aimbot (04-17-2011), MrMOTO (04-15-2011), Mudkip (04-17-2011), Nickm0117 (04-17-2011), Night Wolf (04-14-2011), Ninja (05-07-2011), Pimp. (04-16-2011), Proboscis (04-12-2011), Purple Passion (04-15-2011), Farmer Rath (04-13-2011), Reay (05-02-2011), Refusing (04-14-2011), Relevant (05-13-2011), RGB (04-17-2011), Rip The Jacker (04-13-2011), Scouser94 (04-13-2011), Stx (04-13-2011), SwA_x_iBeaTs (10-07-2011), SweatyMidgets (05-03-2011), TehMike (04-12-2011), TryCatchMe (04-12-2011), Tupac (09-01-2012), tylerallmighty (04-13-2011), UNLIMITED G@M3R (04-15-2011), Valence2point0 (08-20-2011), xGunz (04-14-2011), xMurphyBoiix (04-14-2011), _Daz_ (04-16-2011)

  3. #2
    Ninja Turtle
    Pass Word's Avatar

    Default


    0 Not allowed! Not allowed!
    Good
    Register or log in to view signatures.

  4. #3
    Banned

    Default


    0 Not allowed! Not allowed!
    Another great thread Curt, cheers for this mate
    Register or log in to view signatures.

  5. #4
    Nobody is like me
    Cody_h4x's Avatar

    Default


    0 Not allowed! Not allowed!
    Sweet nice bro
    Its kinda hard finding a vulnerable website in google
    Good Work Curt
    Register or log in to view signatures.

  6. #5
    Like A Boss
    TryCatchMe's Avatar

    Default


    0 Not allowed! Not allowed!
    muahaha i got me some hacking to do
    thanks
    Register or log in to view signatures.

  7. #6
    It's not the same anymore ;(
    Curt's Avatar

    Default


    0 Not allowed! Not allowed!
    Looks like you kids are gonna have some fun within the next few hours
    Register or log in to view signatures.

  8. #7
    My controller's wireless?

    Default


    0 Not allowed! Not allowed!
    Nice work Curtis
    Register or log in to view signatures.

  9. #8
    Biz
    Dolla Bill
    Biz's Avatar

    Default


    0 Not allowed! Not allowed!
    This isn't your tutorial, same as the one on HF.
    Give credits, it's cool anyways.
    Last edited by longjohnsilver; 04-13-2011 at 09:22 AM.
    Register or log in to view signatures.

  10. #9
    ドリフト
    Alt's Avatar

    Default


    0 Not allowed! Not allowed!
    Nice thread, Thanks for sharing
    Couldn't thank you, So i Nominated it lmfao :ftw:
    Register or log in to view signatures.

  11. #10
    </Jimbo>
    <Jimbo>'s Avatar

    Default


    0 Not allowed! Not allowed!
    Nice tutorial curt! I've ****ed making deface pages and just put a redirect to *******! :carling: But never forget to grab the ****ers IP!
    Register or log in to view signatures.

Page 1 of 8 1 2 3 ... LastLast

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •