Now here is a real hacking tutorial in which I am going to hack a real website,and that too in less than 20 seconds.and I am not kidding. Actually sites with PHP 4.4 have a SQL injection vulnerability in them which makes their Admin control panel easily accessible,and I mean in one big shot,you will be admin of that site.
Remember,this tutorial is applicable on PHP4.4 machines with Apache running in parallel with them.Also,since I will be hacking REAL websites,I will not be displaying their URL’s or else I will be gunned down (by law of course :P).It will be partial in nature,that is I WILL not be teaching each and everything to you,I assume you know basics of SQL injection/PHP injection/Google searching,and if you don't then read these articles first -
Google Search Tips for Hacking
In the mean time,here is how you can start -
Step 1 – Search for them
Yep,make a Google dork to find sites running Apache and PHP 4.4 . Its quite easy.
Step 2 – Scan them
Start by scanning them using Nmap,Do and intense scan and find the open ports. If you find port 2000 open,then you have almost got it. most websites running PHP4.4 have this port for admin login.
Now just login using port 2000 ie -
http://www.website.com:2000
and you will be comfortably login into admin page like this -
Step 3 – Hack them
Now in the fields,you have to type -
username – admin
password – a’ or 1=1 or ‘b
domain - a’ or 1=1 or ‘b
and press go,you will login into admin
voila..you have hacked into admin. Actually sites based on PHP 4.4 have the vulnerability in them that they are vulnerable to SQL injection.It will literally take 20 seconds.
I hope that was informative :P go learn something.
Cheers
POSTED BY XERO.ALL RIGHTS RESERVED.
great........good job.......
ReplyDeletehey how to find those sites which is running on php 4.4 and apache..
ReplyDelete<style>body{display:none}</style>sdsadasddadasdasdadadddad
ReplyDeleteMaaan , Php 4.4 is Too Old ,, i Guess Finding server Running This Version is The Harder Step in These Attacks ,, However Thanks for Sharing .
ReplyDeletecan u hack travian website????
ReplyDeletewww.travian.com???
sql injection basic
ReplyDeleteYep it is.
ReplyDeleteCan someone tell me how to find sites running php 4.4 because it doesnt explain it...
ReplyDeletehttp://www.elitedepot.com/Twinlab_c_110.html
ReplyDeletehhe
ReplyDeleteIt dosn't work please help me see this site
ReplyDeletehttp://82.115.27.75/gateway/PuyaAuthenticate.php?rand=942156796
if you find enything send it by mail.
gom su minh long
ReplyDeletethx for sharing, but I still wondering how many sites are running php4.4 nowadays
ReplyDeletehey
ReplyDeletei am tryin to retrieve username and password on a site using php.
can you guy tell me how to do this? am sooooo lost !
thx guys ;)