First we start by opening SQLi dumper v.7
Now please delete all current dorks you have on dork box.
and open 2014 google dorks. Copy all and paste to dork box
Spoiler
no you can't start yet.
Now you want to go tools&setting tab and then proxy tab.
Now unstick "enable proxy".
Spoiler
Yes you're ready to start now.Go back to online scanner tab. But don't forgot "don't never change thread amount, always keep it like it is".
Go ahead and hit Start scanner. Now you see if dumper will start adding links.
Spoiler
Think that's it? No it's not even close to end. Now if all urls are scanned or if you stop after you have good amount of urls [etc lets say 100k urls or so]
Now click on Exploitables tab. What do you need to do here? NOTHING. click start exploiter and wait until urls have been scanned against exploit. Don't worrie there is more steps.
Spoiler
Now lets start with finding injectable sites. There is one note! Stick all unions!
and start analizer.
Spoiler
Got some injectable urls? COOOL .
Lets start looking for database to dump.
What you need to do is : right click on ulr and click "go dumper".
Spoiler
Found database? Cool.
What you need to do? Click on database and then click "get tables"
Spoiler
Got a lot of tables? Have no idea what to do now? Ehh i will explain obv.
Oki , now most common shit you want to find is "Users/User", "Memebers/Member" or "Customers/Cusomer" , something what have something to do with users. Found it? Wolaa cool, now go ahead and click on table and click "get columns" . Now you obv want to see users, pass or email, pass, or w.e is close to username/email and password.
Spoiler
Oh i found username and password, what i do now? Ehh nothing much , you will stick both you wanna dump. Etc i have username and password. Feel free to stick it and click "dump data".
Spoiler
Cool, now i got a lot of accounts and passwords, how i can export them? Ofcourse export button heuheu
Spoiler
good job u got ur first db
now enjoy cracking an using sqli
not responsible for wat u do
and i dont take credit for this