Thursday, March 4, 2010

--< Using mysql.user details from SQL Injection >--


--< Using mysql.user details from SQL Injection >--

02-18-2010, 06:16 PM (This post was last modified: 02-18-2010 07:27 PM by #BlackHat.)
Post: #1
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-
Tutorial written by: Like a Boss
Date: 18/02/2010
Description: Helping users understand what to do with and how to use mysql.user information obtained via SQL injection.
Release: Public
SPECIAL THANKS TO SERAVIN FOR PROVIDING KNOWLEDGE OF THIS APP
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-

Ok as most of us SQLinjectors have read in the beginner tutorials the list of databases usually presented for us when we find a site with SQL version 5> are commonly:
information_schema
mysql.user

Ok that's great. whatever other databases are listed note them down as you will need them later.

As we all know if you come across a site with mysql.user you are lucky, now in the mysql.user database there's a number of tables, we need to look in the User table for host:user:password

From here you will be presented with encrypted passwords, usually mysql sha1. We need to crack this. Once cracked you should now have the following:

host:user:password
and the database name you noted down earlier

my example:
127.0.0.1:root:mdweb123
limitart

Okay now the following application is the best to use for making a succesfull connection to a server without having trouble connecting as your ip address isnt listed as a trusted connection on their servers. The following application is clean and is public. I have the cracked version so here is a link to it:
Code:
http://rapidshare.com/files/352574477/MySQL-Front_v5.0_Build_1.0_DoTNXT_virus_virus.rar

Once downloaded install and open, it's pretty easy to use you should be fine, post here if you're having troubles using the application. Enjoy!
- Like A Boss

[Image: hfsig.png]


2 comments:

  1. Do you need to increase your credit score?
    Do you intend to upgrade your school grade?
    Do you want to hack your cheating spouse Email, whatsapp, Facebook, instagram or any social network?
    Do you need any information concerning any database.
    Do you need to retrieve deleted files?
    Do you need to clear your criminal records or DMV?
    Do you want to remove any site or link from any blog?
    you should contact this hacker, he is reliable and good at the hack jobs..
    contact : cybergoldenhacker at gmail dot com

    ReplyDelete
  2. CONTACT: onlineghosthacker247 @gmail. com
    -Find Out If Your Husband/Wife or Boyfriend/Girlfriend Is Cheating On You
    -Let them Help You Hack Any Website Or Database
    -Hack Into Any University Portal; To Change Your Grades Or Upgrade Any Personal Information/Examination Questions
    -Hack Email; Mobile Phones; Whatsapp; Text Messages; Call Logs; Facebook And Other Social Media Accounts
    -And All Related Services
    - let them help you in recovery any lost fund scam from you
    onlineghosthacker Will Get The Job Done For You
    onlineghosthacker247 @gmail. com
    TESTED AND TRUSTED!

    ReplyDelete