Join us at IRC!
Things are more like they are now than they have ever been before. - Dwight D. Eisenhower
Wednesday, May 23, 2012
Navigation
Members Online
Total Online: 37
Web Spiders: 20
Guests Online: 34
Members Online: 3

Registered Members: 70162
Newest Member: Windows-2012
Latest Articles
View Thread

HellBound Hackers | HellBound Hackers | Lessons

Author

Beginner & Intermediate Guide To Blind SQL Injection

nights_shadow
Member



Posts: 856
Location: /var/log/messages
Joined: 30.12.04
Rank:
God
Posted on 22-06-07 19:25
Visual Beginner's Guide To Blind SQL Injection

*In this video, i cover the basics of blind sql injection. We find a vulnerable page, test it for vulnerability, and exploit them. I attack two sites and gain admin priveleges in two different ways.

http://4filehosting.com/file/23692/blindsql-swf.html



Visual Intermediate Guide To Blind SQL Injection

*In this video, i attack retrieve root mysql information and use load_file() to retrieve more information on the site.

[edit]Full version available now ;)[/edit]

http://4filehosting.com/file/32539/blindsqlint-swf.html


-->I forgot to do INSERT INTO VALUES() in the intermediate one, so expect another intermediate guide somewhat in the future, hopefully ;).




Edited by nights_shadow on 03-07-07 19:43
nights_shadow@hackermail.com http://turboborland.blogspot.com
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

nights_shadow
Member



Posts: 856
Location: /var/log/messages
Joined: 30.12.04
Rank:
God
Posted on 03-07-07 19:42
I would like to express an apology to those who downloaded the intermediate video as it was cut off. The host only managed to up 6 megs, when the actual size is 18. So, here's the full version:

http://4filehosting.com/file/32539/blindsqlint-swf.html





Edited by nights_shadow on 03-07-07 19:42
nights_shadow@hackermail.com http://turboborland.blogspot.com
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

lesserlightsofheaven
Member

Posts: 723
Location: EAX
Joined: 02.11.06
Rank:
God
Warn Level: 30
Posted on 03-07-07 21:26
just finished watching, very clever work.
I enjoy your videos.


"'Following a telephone line north, I have come upon some wonderful places,' continued the repairman. 'Swamps where cedars grow and turtles wait on logs but not for anything in particular; fields bordered by crooked fences broken by years of standing still; orchards so old they have forgotten where the farmhouse is. In the north I have eaten my lunch in pastures rank with ferns and junipers, all under fair skies with a wind blowing. My business has taken me into spruce woods on winter nights where the snow lay deep and soft, a perfect place for a carnival of rabbits. I have sat at peace on the freight platforms of railroad junctions in the north, in the warm hours and with the warm smells. I know fresh lakes in the north, undisturbed except by fish and hawk and, of course, by the Telephone Company, which has to follow its nose. I know all these places well. They are a long way from here--don't forget that. And a person who is looking for something doesn't travel very fast.'"
If you know it, you know it. Public no longer.
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

DigitalFire
Member



Posts: 274
Location: Or perhaps just
Joined: 02.12.06
Rank:
HBH Guru
Posted on 06-07-07 04:55
i feel like an idiot but i couldn't find a download button... nor did http://4filehosting.com/file/23692/blindsql.swf get me anywhere. nights_shadow you should put those on rapidshare that worked a lot better.



I'll be in it all to watch it burn so carelessly
You cannot see a thing about me for in these blanks
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

lesserlightsofheaven
Member

Posts: 723
Location: EAX
Joined: 02.11.06
Rank:
God
Warn Level: 30
Posted on 06-07-07 04:59
DigitalFire wrote:
i feel like an idiot but i couldn't find a download button... nor did http://4filehosting.com/file/23692/blindsql.swf get me anywhere. nights_shadow you should put those on rapidshare that worked a lot better.


it's very light yellow text about halfway down the page.


"'Following a telephone line north, I have come upon some wonderful places,' continued the repairman. 'Swamps where cedars grow and turtles wait on logs but not for anything in particular; fields bordered by crooked fences broken by years of standing still; orchards so old they have forgotten where the farmhouse is. In the north I have eaten my lunch in pastures rank with ferns and junipers, all under fair skies with a wind blowing. My business has taken me into spruce woods on winter nights where the snow lay deep and soft, a perfect place for a carnival of rabbits. I have sat at peace on the freight platforms of railroad junctions in the north, in the warm hours and with the warm smells. I know fresh lakes in the north, undisturbed except by fish and hawk and, of course, by the Telephone Company, which has to follow its nose. I know all these places well. They are a long way from here--don't forget that. And a person who is looking for something doesn't travel very fast.'"
If you know it, you know it. Public no longer.
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

DigitalFire
Member



Posts: 274
Location: Or perhaps just
Joined: 02.12.06
Rank:
HBH Guru
Posted on 06-07-07 06:41
omg i cant find it...

what does the text say?



I'll be in it all to watch it burn so carelessly
You cannot see a thing about me for in these blanks
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

HackingForce
Member



Posts: 328
Location: -ⁿººƁ.land-
Joined: 24.11.06
Rank:
Mad User
Posted on 06-07-07 11:44
DigitalFire wrote:
omg i cant find it...

what does the text say?


it says "Please wait 30 seconds.."

and after 30 seconds, it gets replaced with a blue "Download" link...

Nice Videos Nights_shadow :)





Edited by HackingForce on 06-07-07 14:38
- ºººººººº - kr(i)s20045©hotmail.com - ºººººººº - ..Hacked..
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

mitz247
Member



Posts: 246
Location: far far away
Joined: 13.05.07
Rank:
God
Warn Level: 5
Posted on 06-07-07 11:53
hey man just watched the vids,, very very good!!

u should do some more

thanks alot!


/*\/*\ /*\/*\ its niiice
Author

RE: ...

summersgone
Member



Posts: 1
Location: Indonesia
Joined: 08.03.07
Rank:
Newbie
Posted on 18-07-07 20:25
how to do INSERT/UPDATE just after i 've figured all of the tables name and the fields name ? i tried it once using UNION UPDATE , but it failed. any suggestion ?:love:



every Me , every You
spider_hacks http://sleepwalker.ifastnet.com
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

ap101
Member



Posts: 19
Location: Unknown
Joined: 14.06.07
Rank:
Mad User
Posted on 05-09-07 19:05
The links are bad. Does anyone have the files and are willing to upload them again? Please?


One question makes and stops progress,
What if?
atheistpope101@hotmail.com Ask me
Author

RE: Beginner & Intermediate Guide To Blind SQL Injection

Neuromancer
Member



Posts: 16
Location: Croatia
Joined: 16.12.06
Rank:
Guest
Posted on 05-09-07 20:24
join the forum owned by mr. nights_shadow ;) there you can find all the videos + much more.

you'll find the URL in his profile.
Guest
Username

Password

Remember Me


Bookmark This Page
Affiliates
Adverts

 

 

Links
By using, viewing or obtaining any information contained on this site, you agree to the disclaimer.

© HellBound Hackers 2008- 2009. Since 3rd December 2004.