SQL INJECTION

SQL injection is a code injection technique, used to attack data-driven applications, in which malicious SQL statements are inserted into an entry field for execution (e.g. to dump the database contents to the attacker).




 
dear friends,
Today I am going to show manual SQL injection steps before that lets talk what are the other ways to perform a sql injection

1.HAVIJ (simple tool working with windows  xp)


2.SQL map
3.SQL ninja
(free and open sos tools)

OK 
LET's Start manul sql injection 


1.first we need find sql vulnerable web site 
to do this use google.
type :  inurl:.php?id=

there are more sql injection vulnerable web pages
don't damage them this is only for education

2 .To do this easy install Hackerbar add-on in firefox install it from here

  
 

restart web browser and and press f9 hackerbar will display   if  not you can jest type in browser url bar

every steps in the video  watch it 











Previous
Next Post »