You are on page 1of 10

JetSQL version 1.

0
Do ny thy phong tro hack Jet SQL Injection ca anh em rm r qu nn tui cng my m th. C iu thy vic on tn table v column
ca admin account m nn qu. V vy, hm nay wn wn, ly ci VB6 ra m vit ci tool gip cho vic on table v column tr nn d dng
hn, nhanh chng hn; gip anh em ko mt qu nhiu thi gian cho vic ny. Vy thi, bt u no ^_^!
* Giao din ca chng trnh:

Nhp tn file cha cc table name vo y, hoc c


th click nt Tm tm file
Ni nhp link li Jet SQL Injection

Bt u qu trnh on
tn table

Ton b thng tin v qu


trnh on tn table s hin
y

* Qu trnh on table name:

I. Nhp link b li Jet SQL Injection:


C th nhn bit li SQL no l Jet SQL Injection qua thng bo li nh sau (cc thng bo li c th khc nhau i cht):
Microsoft JET Database Engine error '80040e14'
Syntax error in string in query expression 'catID=''';'.
/category.asp, line 8

V ci link b li Jet SQL Injection c th ging nh vy:


1/ Tham s b dnh li l s:
http://www.xxx.com.vn/ProductDetail.asp?CateID=33&SubID=0&ProductID=97

Tham s b dnh li l s (97), v d nh trong ci link trn th ta b du phy cui cng i ch paste vo Link b li SQL Injection nh vy
thi:
http://www.xxx.com.vn/ProductDetail.asp?CateID=33&SubID=0&ProductID=97

2. i vi tham s li l chui k t ging nh v d sau:


http://www.blueocean.com.vn/category.asp?catcode=abc'

th ta c nguyn du phy nh vy ri paste vo.


Paste link b Jet SQL Injection vo y

Cn c 1 vn na i vi link cn nhp, l khi tham s b li ko phi nm cui cng trong link, v d nh trng hp sau:
http://www.xxx.com.vn/ProductDetail.asp?ProductID=97&CateID=33&SubID=0

hay:
http://www.xxx.com.vn/ProductDetail.asp?CateID=33&ProductID=97&SubID=0

th ta u chuyn ci tham s ra sau cng trong link ht nh sau ri mi paste vo chng trnh:
http://www.xxx.com.vn/ProductDetail.asp?CateID=33&SubID=0&ProductID=97

Lu l gia cc tham s c du &, khi chuyn cc bn chuyn cho tht chnh xc th chng trnh mi chy ng c.

II. Ch nh file cha cc table name dng on table:

Hoc click nt ny tm
Nhp trc tip vo y

C th nhp trc tip tn file cha cc table name vo File chua table name hoc nu bn ko nh ng dn th c th click nt Ti`m tm
n. File cha cc table name ch l 1 file text bnh thng trong cha tn cc table, mi tn table l 1 dng. V d:

Mnh c to sn file tablename.txt cha nhiu tn table thng dng, cc bn c th dng n. cng lc cng hiu qu hn, mi khi bn hack
c 1 site no th nh cp nht tn table cha admin account vo file ny nh :D.

III. Bt u on table:
Click nt Doan table bt u. Khi on ra tn table, 1 thng bo s hin ra cho bit bn thnh cng =P~.

y mi l phin bn th nghim u tin ca chng trnh, n cn rt nhiu li v mnh cn c thi gian hon thin n. Mong cc bn dng
th v gip mnh lm cho n tt hn, c nhiu tnh nng hn.
Phin bn k tip ca chng trnh ny s gm nhiu tnh nng mi nh on s lng column ca table, tn ca cc column.
Mi gp , bo li xin lin h 1ucky10v3 [at] hcegroup.net

You might also like