BOOK THIS SPACE FOR AD
ARTICLE ADHow to find P1 SQL injection in indian website.
Just going through Google dorks
Like: site:*.*.gov.in
Got some few pages from Google
Tip: never hunt on first page from Google.
I was told not to share the site name
Lets take 🎯.com
In burp first crawl the website first or you could also use zaproxy for spidering
Ones you get enough endpoints start scanning the each endpoints with active scan make sure you control you request or you could be blocked.
As I was scanning the endpoints suddenly an SQL injection error occurred. I just trusted the burp and found SQL injection in website.
Most of people don’t trust burp or zaproxy scanner. Just trust them & do verify the information given by them. Most of them are 80% right.
That’s all for today.
Thankyou for reading my blog
🔜