ALERT!
Click here to register with a few steps and explore all our cool stuff we have to offer!

Jump to content



Photo

how to use sqli


  • Please log in to reply
how to use sqli

#1

pruned_44204423
pruned_44204423
    Offline
    38
    Rep
    264
    Likes

    da combo plug

  • PipPipPipPipPipPipPip
Posts: 784
Threads: 304
Joined: Jun 27, 2016
Credits: 0

Seven years registered
#1

First we start by opening SQLi dumper v.7
Now please delete all current dorks you have on dork box.
and open 2014 google dorks. Copy all and paste to dork box

Spoiler


no you can't start yet. 
Now you want to go tools&setting tab and then proxy tab.
Now unstick "enable proxy".
Spoiler


Yes you're ready to start now.Go back to online scanner tab. But don't forgot "don't never change thread amount, always keep it like it is".
Go ahead and hit Start scanner. Now you see if dumper will start adding links.
Spoiler


Think that's it? No it's not even close to end. Now if all urls are scanned or if you stop after you have good amount of urls [etc lets say 100k urls or so]
Now click on Exploitables tab. What do you need to do here? NOTHING. click start exploiter and wait until urls have been scanned against exploit. Don't worrie there is more steps.

Spoiler



Now lets start with finding injectable sites. There is one note! Stick all unions!
and start analizer.
Spoiler



Got some injectable urls? COOOL .
Lets start looking for database to dump.
What you need to do is : right click on ulr and click "go dumper".

Spoiler


Found database? Cool.
What you need to do? Click on database and then click "get tables"
 
Spoiler



Got a lot of tables? Have no idea what to do now? Ehh i will explain obv.
Oki , now most common shit you want to find is "Users/User", "Memebers/Member" or "Customers/Cusomer" , something what have something to do with users. Found it? Wolaa cool, now go ahead and click on table and click "get columns" . Now you obv want to see users, pass or email, pass, or w.e is close to username/email and password.
Spoiler


Oh i found username and password, what i do now? :( Ehh nothing much , you will stick both you wanna dump. Etc i have username and password. Feel free to stick it and click "dump data". 
 
Spoiler


Cool, now i got a lot of accounts and passwords, how i can export them? Ofcourse export button heuheu
Spoiler


good job u got ur first db

now enjoy cracking an using sqli

not responsible for wat u do 

and i dont take credit for this
 


  • 2
Posted Image

#2

iGotBars
iGotBars
    Offline
    2
    Rep
    2
    Likes

    Same

Posts: 251
Threads: 7
Joined: Mar 24, 2016
Credits: 0

Eight years registered
#2

is it normal that i have like 700 000 accounts? lol


  • 0

#3

Tzuyu12
Tzuyu12
    Offline
    0
    Rep
    0
    Likes

    New Member

Posts: 13
Threads: 0
Joined: May 07, 2017
Credits: 0
Seven years registered
#3

Well Lets See if This Guide Tips Works


  • 0


 Users browsing this thread: and 1 guests