website hack through sql injection

The technique of sql injection is pretty old but still u can hack some sites through this method.If you have some html and javascript knowledge then you can easily access some password protected websites. So you want to know how??

keep reading.....
1. Open the website you want to hack. Provide wrong username-password in its log in form.
(e.g : Username : me and Password: ' or 1=1 --)
An error will occur saying wrong username or password. Now be prepared
Your experiment starts from here...

2. Right click anywhere on that error page, go to view page source.

3. There you can see the html codings with javascripts.

4. There you find somewhat like this <_form action="..login....">
< =..login....>

5. Before this login information <=__LOGIN> copy the url of the site in which you are: (e.g :"<_form..........action=http://www.targetwebsite.com/login.......><..........=HTTP: com="">")<..........=HTTP: com="">
6. Then delete the javascript from the above that validates your information in the server.(Do this very carefully, ur success to hack the site depends upon this i.e how efficiently you delete the javascripts that validate ur account information)

7. Then take a close look for "<_input name="password" type="password">"[without quotes] -> replace "<_type=text> " there <=TEXT>instead of "<_"<=TEXT><=>. See there if maxlength of password is less than 11 then increase it to 11 (e.g : if
8. Just go to file then save as and save it any where in your hardisk with name ext.html.

9. Reopen your target web page by double clicking 'chan.html' file that you saved in your
harddisk earlier.

10. U see that some changes in current page as compared to original One. Don't get worried.

11. Provide any username[e.g:hacker] and password[e.g:' or 1=1 --]
Congrats!!!!!! You have successfully cracked the above website and entered into the account of Ist user saved in the server's database.

but hey guys dnt misuse!laws r meant to be broken but they also save us!(:->

1 comment:

Sunil Kosuru said...

Hey thnx for the info ur into my blogroll