Base64 Encode/Decode SQL Injection By RAi Jee
Today Our Topic is Base64 encoded/decoded SQLi Queries.
Here is A Example of Base64 Parameter.
http://www.FakeSite.com/detail.php?id=MTU=
If we add Single Quote (') where detail.php?id=MTU='
We can see there is no error or any kind of Changes in the Webpage.
We cant inject These Type of Parameters Directly .
SO HOW CAN WE INJECT THESE TYPE OF WEBSITES ???
Lets Start Injecting.
Hmmm So Here Is our TARGET .
First you Have HACKBAR Addon installed in your Browser.
You Can Installed it From Here .
https://addons.mozilla.org/en-us/firefox/addon/hackbar/
See Our TARGET detail.php?id=MTU= Parameter is Encoded in Base64
http://www.bio1usa.com/detail.php?id=MTU=
Now Select Base64 Encoded Parameter. Open Hackbar Encoding Option and Select Base64 Decode.
And we get detail.php?id=MTU= Parameter as detail.php?id=15
Now Lets Start Our Manually SQL Injection From Here. add Single Quote (') at The end Of Parameter And Again Encode it Using Hackbar Encoding Option Base64 Encode and execute URL.
And We Get MYSQL Error !!
Now Next Process is to Count Columns using order/group by . and After this Prepare UNION SELECT Statement for getting Tables and Columns.
Our Injection is Simple . Just what we have to do is.
- Base64 decode our parameter
- add our SQLi commands to it
- then Base64 encode it
- and execute the command
Read From My PREVIOUS SQL Injection Tutorials.
• Nice and good article. It is very useful for me to learn and understand easily. Thanks for sharing your valuable information and time. Please keep updatingAzure Online course Bangalore
ReplyDelete">x
ReplyDeleteNice Blog ! It was really a nice article and i was really impressed by reading this. Thanks for sharing such detailed information.
ReplyDeleteMicrosoft Windows Azure Training | Online Course | Certification in chennai | Microsoft Windows Azure Training | Online Course | Certification in bangalore | Microsoft Windows Azure Training | Online Course | Certification in hyderabad | Microsoft Windows Azure Training | Online Course | Certification in pune