Actually I've planned to write a bunch of new articles. But before that i wanted to complete my SQL injection series. So today i will be writing about hacking asp/aspx websites using SQL injection.
If you are new to SQL Injection , i would recommend you to go through my previous articles on Sql Injection.
You can read them from here.
- SQL Injections Part 1
- SQL Injections Part 2
- SQL Injections Part 3
- SQL Injections Part 4
- SQL Injections Part 5
Hacking ASP/ASPX sites
ASPX injection is also similar to PHP based sql injection. But here, we don't use queries that contain order by, union select etc. Instead, we will cheat the server to respond with the information we needed. It is an error based injection technique. We will get the information in the form of errors.
Step 1: Find Out A Vulnerable Link
First, we need find out a vulnerable asp/aspx link which looks like
Step 2: Checking For Vulnerability
As in the PHP based injection, we will test for the vulnerability by adding a single quote at the end of the URL.
In asp/aspx based injections, we need not find out the number of columns or the most vulnerable column. We will directly find out the table names,column names and then we will extract the data.
Step 3: Finding Out The Table Names.
But this may not be the desired table for us. So we need to find out the next table name in the database.
For that, we will use the following query.
Now we will get the second table name as shown in the figure. Still if we don't get our desired table, we will continue the procedure until we get the desired table name. Now the query looks like
Step 4: Finding Out The Columns
Now we got the admin table. So we need to find out the columns now.
Replace admin_table with the table name we got. In our case, it is "vw_system_admin"
If the first column is not related to our desired column names, then follow the steps as we have done in step 3.
Replace first_column_name with the column name we got.
Step 5:Extracting The Data
After finding out all the columns, we need to extract the data such as user names and passwords.
For that, we use the following query
For user name,