Now follow the steps given below---
Step-1
- We need help of one google dork. So go to google and search this dork- inurl:\"/cart.php?m=\"
- Now look on the search result. The target URL will look like- www.domain.com/store/cart.php?m=view
- No time to think more. Just enter to that link. After That we will find the admin page to exploit that security.
- Here is the sample of admin page of this script. www.domain.com/store/admin
- Now you will get login area. So we need the username and password to enter this site.
- On these step we will use simple sql injection method. So our password and id will be---
username= 'or'1'='1
password= 'or'1'='1
Now You have entered to that site... Well done...
*** Remember its a shopping site and you can get lots of information including credit cards. So do it on your own risk. We are not telling you to do. this post is just for educational purpose only.***
If anything went wrong or for more help please drop us a line...
0 comments :
Post a Comment