How To Hack & Exploit MySQL Port 3306 Metasploitable 2 Full Walkthrough - Home Hacking Lab Video 13

Поділитися
Вставка
  • Опубліковано 6 січ 2025

КОМЕНТАРІ • 26

  • @manuelgiraldocarro1956
    @manuelgiraldocarro1956 Рік тому +7

    But how did you get the password then? you didnt show it

  • @navr1111111111111111
    @navr1111111111111111 6 місяців тому +2

    There was no exploiting done.. You just used default creds to access the database. Where is the exploit? How do you gain access to the target system from this point? Being able to dump the databases does not mean you have any level of control on the system..

  • @iliealexandru2181
    @iliealexandru2181 Рік тому +2

    I got the usernames and all of them are empty as in this example but for me does not work, after I am pressing enter is giving me the same error, do you have any idea ?

    • @InfoSecPat
      @InfoSecPat  Рік тому +1

      Just make sure you have the file that contains the information like the user names and passwords. Go on my Discord and show me the error please so I can see what you’re getting.

    • @iliealexandru2181
      @iliealexandru2181 Рік тому

      @@InfoSecPat Hello! The discord invite is invalid.

  • @albertolinarescorrales7654
    @albertolinarescorrales7654 Рік тому +2

    good evening, I have a problem when launching the module I get the following error:
    LOGIN FAILED: root: (Unable to Connect: invalid packet: scramble_length(0) != length of scramble(21)). how can I solve??

    • @a_k1214
      @a_k1214 Рік тому +1

      I have same problem did you solve it?????

  • @georgepauleldose3897
    @georgepauleldose3897 11 місяців тому +1

    Sir,I got the same error as well saying tls/ssl error:wrong version number.I tried joining your discord channel but it says invite invalid

    • @ayotolu-f4f
      @ayotolu-f4f 11 місяців тому

      He was not clear on the password in the demonstration…Did u later get it right?

  • @ceecalanjaro4099
    @ceecalanjaro4099 9 місяців тому

    your actually missed that you got a green on guest as you were scrolling as well. but thanks for the video simple to the point

  • @NijatZadeh
    @NijatZadeh Рік тому +1

    How can I move files from the target machine to my own machine?

    • @InfoSecPat
      @InfoSecPat  Рік тому +1

      Yeah if you wanted to get the files and download to your local computer

  • @OneIdeaTooMany
    @OneIdeaTooMany Рік тому

    Could you then use that MySQL connection to get access to a shell?

  • @caocau8859
    @caocau8859 Рік тому +2

    Great video, got the same error as the other comments... Everything works fine until I try to connect to the SQL database at the end, even as root user. Error I get is: ERROR 2026 (HY000): TLS/SSL error: wrong version number. My guess is the newer version has some change that causes this.

    • @alexng99
      @alexng99 Рік тому +1

      Don't use the newest version of Kali. Old version don't show this error.

    • @muhammadsatria2202
      @muhammadsatria2202 Рік тому

      @@alexng99so what version should i use and how to install the old version?

    • @alexissavila1
      @alexissavila1 5 місяців тому

      --ssl=FALSE try with it

  • @philandreitan704
    @philandreitan704 Рік тому

    I get this error saying "ERROR 2026 (HY000): TLS/SSL error: wrong version number" everytime i try to run the mysql -u root -h command are there any fixes to this?

    • @InfoSecPat
      @InfoSecPat  Рік тому

      Just make sure you running it with an upgraded shell once you get on the machine. That’s a critical point. And if you join my discord, we can try to help you out. You can find the link and one of the newer videos.

    • @philandreitan704
      @philandreitan704 Рік тому

      @@InfoSecPat what command should i input to upgrade the shell?

  • @ayotolu-f4f
    @ayotolu-f4f 11 місяців тому

    Sir what password did you use, because we cannot figure out the password to complete this.

  • @lovedaysmart9183
    @lovedaysmart9183 Рік тому +1

    I think it also found ‘guest’ this is really cool. Do you do bug bounties sir?

    • @InfoSecPat
      @InfoSecPat  Рік тому +1

      Nice I’m glad it’s helpful. I don’t really do too many bug bounty

  • @Emi_Trading
    @Emi_Trading Рік тому +1

    y like your videos