Friday, November 18, 2011

How to use Havij Software Advanced SQL Injection

DISCLAIMER: "THIS POST IS FOR EDUCATIONAL PURPOSE ONLY, BY VIEWING THIS POST , YOU AGREE THAT I AM NOT LIABLE ON WHATEVER DAMAGE IT MIGHT CAUSE YOU"

There are many vulnerable site all around the web. and because of that, hackers are now eager to get those sites. how?, Others hack a website by SQL injection.  first let s know what SQL Injection is.


SQL injection is an attack in which malicious code is inserted into strings that are later passed to an instance of SQL Server for parsing and execution. Any procedure that constructs SQL statements should be reviewed for injection vulnerabilities because SQL Server will execute all syntactically valid queries that it receives. Even parameterized data can be manipulated by a skilled and determined attacker.


Now that you got an idea about what SQL Injection is, let's now start to tackle about, how to use the havij software to hack a vulnerable website.


What is Havij Software?
Havij software is an automated SQL injection tool that helps testers to find and exploit SQL injection vulnerabilities on a webpage. Other's use this tool to minimize their effort to hack a website. 
you can also hack website even without this tool. but that is a lot of task and effort.


1. Download the Havij software. there is a free trial to download it. but you can only get limited function. but there are also cracked and working version of havij. you can download the free version here HAVIJ main website
I also have the free version. you can leave your comment here in my post. leave your email address and I'll send it to you.


2. After downloading the Havij software, Unzip it and install the software.
3. Open the Havij Application.8
4. Open your google search
Search for vulnerable sites on  google.you just need to post one of this on the google search bar:

inurl:index.php?id=
inurl:trainers.php?id=
inurl:buy.php?category=
inurl:article.php?ID=
inurl:lay_old.php?id=
inurl:declaration_more.php?decl_id=
inurl:ageid=
inurl:games.php?id=
inurl:age.php?file=
inurl:newsDetail.php?id=
inurl:gallery.php?id=
inurl:article.php?id=
inurl:show.php?id=
inurl:staff_id=
inurl:newsitem.php?num=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:historialeer.php?num=
inurl:rtray-Questions-View.php?num=
inurl:forum_bds.php?num=
inurl:game.php?id=
inurl:view_product.php?id=
inurl:newsone.php?id=
inurl:sw_comment.php?id=
inurl:news.php?id=
inurl:avd_start.php?avd=
inurl:event.php?id=
inurlroduct-item.php?id=
inurl:sql.php?id=
inurl:news_view.php?id=
inurl:select_biblio.php?id=
inurl:humor.php?id=
inurl:aboutbook.php?id=
inurl:fiche_spectacle.php?id=
inurl:communique_detail.php?id=
inurl:sem.php3?id=
inurl:kategorie.php4?id=
inurl:news.php?id=
inurl:index.php?id=
inurl:faq2.php?id=
inurl:show_an.php?id=
inurl:review.php?id=
inurl:loadpsb.php?id=
inurlinions.php?id=
inurl:spr.php?id=
inurl:ages.php?id=
inurl:announce.php?id=
inurl:clanek.php4?id=
inurl:articipant.php?id=
inurl:download.php?id=
inurl:main.php?id=
inurl:review.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:rod_detail.php?id=
inurl:viewphoto.php?id=
inurl:article.php?id=
inurl:erson.php?id=
inurlroductinfo.php?id=
inurl:showimg.php?id=
inurl:view.php?id=
inurl:website.php?id=
inurl:hosting_info.php?id=
inurl:gallery.php?id=
inurl:rub.php?idr=
inurl:view_faq.php?id=
inurl:artikelinfo.php?id=
inurl:detail.php?ID=
inurl:index.php?=
inurl:rofile_view.php?id=
inurl:category.php?id=
inurl:ublications.php?id=
inurl:fellows.php?id=
inurl:downloads_info.php?id=
inurl:rod_info.php?id=
inurl:shop.php?do=part&id=
inurl:roductinfo.php?id=
inurl:collectionitem.php?id=
inurl:band_info.php?id=
inurlroduct.php?id=
inurl:releases.php?id=
inurl:ray.php?id=
inurl:roduit.php?id=
inurlp.php?id=
inurl:shopping.php?id=
inurl:roductdetail.php?id=
inurlst.php?id=
inurl:viewshowdetail.php?id=
inurl:clubpage.php?id=
inurl:memberInfo.php?id=
inurl:section.php?id=
inurl:theme.php?id=
inurl:age.php?id=
inurl:shredder-categories.php?id=
inurl:tradeCategory.php?id=
inurl:roduct_ranges_view.php?ID=
inurl:shop_category.php?id=
inurl:transcript.php?id=
inurl:channel_id=
inurl:item_id=
inurl:newsid=
inurl:trainers.php?id=
inurl:news-full.php?id=
inurl:news_display.php?getid=
inurl:index2.php?option=
inurl:readnews.php?id=
inurl:top10.php?cat=
inurl:newsone.php?id=
inurl:event.php?id=
inurlroduct-item.php?id=
inurl:sql.php?id=
inurl:aboutbook.php?id=
inurl:review.php?id=
inurl:loadpsb.php?id=
inurl:ages.php?id=
inurl:material.php?id=
inurl:clanek.php4?id=
inurl:announce.php?id=
inurl:chappies.php?id=
inurl:read.php?id=
inurl:viewapp.php?id=
inurl:viewphoto.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:review.php?id=
inurl:iniziativa.php?in=
inurl:curriculum.php?id=
inurl:labels.php?id=
inurl:story.php?id=
inurl:look.php?ID=
inurl:newsone.php?id=
inurl:aboutbook.php?id=
inurl:material.php?id=
inurlinions.php?id=
inurl:announce.php?id=
inurl:rub.php?idr=
inurl:galeri_info.php?l=
inurl:tekst.php?idt=
inurl:newscat.php?id=
inurl:newsticker_info.php?idn=
inurl:rubrika.php?idr=
inurl:rubp.php?idr=
inurl:ffer.php?idf=
inurl:art.php?idm=
inurl:title.php?id=
you just need to pick one.


5. after posting that, you will get many results. just pick one. then copy the link.
6. (IN YOUR HAVIJ SOFTWARE)
put your target url and click Analyze. (after clicking analyze wait for a few seconds until the status is already "IDLE" it means the tool is is done on analyzing.


7. CLICK THE GET TABLES and wait again for a few seconds until the STATUS is changed to IDLE again.



GET the COLUMNS of the "user" or "users" or something like that. then "GET COLUMNS"



 
 then you will see a bunch of words. but what's important here is the ID and PASSWORD , tick the boxes of ID and PASSWORD then click GET DATA




then you will get the username and the password of the website owner. you can get the admin log in page using this tool by clicking the FIND ADMIN button.
sometimes passwords are hidden in MD5 hash. once you get a long password like this below, it means you need to use the MD5 hash to reeveal the real password of the admin log in. that's what good about Havij software. MD5 hash are also included in the software.






hope you like and learn in my tutorial on how to use havij software to hack or to SQL inject vulnerable site.
leave comment for those of you who wants to get the free cracked version of havij.