[*]Introduction
Welcome to my step by step tutorial on how to hack a website using WebCruiser Scanner.
As always I will try to explain it in the easiest way so it will be n00b friendly.
I suggest you to practice "hacking" manually as using tools wont make your skills go higher.
Whatsoever there are lazy-ass guys :P who find it better to perform these attacks by tools.
Ok , first of all we need to download WebCruiser Scanner.
Download me here !
Note: If you need a serial code for the program , leave a comment here and I will generate one for you with your nickname, DO NOT PM ME.
_____________________________
________________________
[*]Let's start:
You will need a target , you can use google dorks to find vuln websites.
I won't bother on that part as there are billions of google dorks out there.
Ok , I found my vulnerable website:
Let's open WebCruiser Scanner and check the target for vulnerabilities like on the picture below:
![[Image: 6yqz.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sE4Uwv7Qz1CKqH0XveW2YFPDf4kvFAQWeA-8kwhSKjxYVX5kcIrPcdZfva5cNuGIoSoKHihrI-qbymhFLsSgDDGwDi74v98wWANzT9sV-JTP00=s0-d)
Then click Scan Site.
![[Image: uiba.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uPFvRHQqaanvtHF4W_oo5PhxUIG5UTLGgOqsNAVRxlkYExzmLywldG9I9v-QGcA1sonTatA9k6W7ajBPAGtba7J_Nsx89W0c7wBxpgdgKsNXQ=s0-d)
Now we will wait a minute or two , depends on you internet connection speed for the scan to finish , then we will see the results like the image below.
![[Image: 6f7u.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tuml4Dn7xbDMyA93Rs6JGLKW8M6ukWocpBga95sN5NW4NuwdK8HzBRLGX3MxAMALV3kRZBukNMAKciOkf3YKx4l7W8hfBVq5GUfHVLXzJzQrE=s0-d)
As we can see the website is vulnerable to Sql injection & XSS.
We will perform a SQL injection this time.
[*]Attack
Right click on the vulnerable url and then SQL INJECTION POC , now you
just need to follow the steps below.
I have explained step by step with pictures so it will be easier for you to understand.
![[Image: tIYUXPt.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_snQzzA-hz6dbxB0YpgqRhd-v5rIQdW_wQIqQkLWugKnvx9qp4imRPdRKGOvHQXx47ky10pAns8Gp6APB56VBlx=s0-d)
![[Image: Zz3KsjE.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_t1UdpZv8z8sOXWYv6VghAUW8YbnywtxLTEDF4Y094AYgoGHgTB2SjT_6IOzL2PJKjJjc94Zs6UgUe9LlR-fU7f=s0-d)
![[Image: phfVa9g.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_srXvK1Hv_YnG2FzcZHuniY6ZyyPY1GxWBhUpFk-ewnZypIq7K7pty4CRvScPQOsIGfXLyLtU_8oMEUGXzCjCHMGQ=s0-d)
So that's all guys , we got the admin info in just 5 minutes :>
Welcome to my step by step tutorial on how to hack a website using WebCruiser Scanner.
As always I will try to explain it in the easiest way so it will be n00b friendly.
I suggest you to practice "hacking" manually as using tools wont make your skills go higher.
Whatsoever there are lazy-ass guys :P who find it better to perform these attacks by tools.
Ok , first of all we need to download WebCruiser Scanner.
Download me here !
Note: If you need a serial code for the program , leave a comment here and I will generate one for you with your nickname, DO NOT PM ME.
_____________________________
________________________
[*]Let's start:
You will need a target , you can use google dorks to find vuln websites.
I won't bother on that part as there are billions of google dorks out there.
Ok , I found my vulnerable website:
Code:
http://www.target.com/vmarket.php?id=17
Let's open WebCruiser Scanner and check the target for vulnerabilities like on the picture below:
Then click Scan Site.
Now we will wait a minute or two , depends on you internet connection speed for the scan to finish , then we will see the results like the image below.
As we can see the website is vulnerable to Sql injection & XSS.
We will perform a SQL injection this time.
[*]Attack
Right click on the vulnerable url and then SQL INJECTION POC , now you
just need to follow the steps below.
I have explained step by step with pictures so it will be easier for you to understand.
Image has been scaled down 15% (814x505). Click this bar to view original image (954x591). Click image to open in new window.
Image has been scaled down 16% (814x504). Click this bar to view original image (961x594). Click image to open in new window.
Image has been scaled down 17% (814x469). Click this bar to view original image (975x561). Click image to open in new window.
So that's all guys , we got the admin info in just 5 minutes :>
0 Comments:
Post a Comment