Website Hijacking – Complete Tutorial Part-1

Okay now lets begin with the topic I have mentioned above.

Obviously “NO” would be the reply, the admin has a control panel as in case of your PC you have a control panel where you have designed and predefined things to manage your system. The same goes here the control panel is the mother of any website where the admin acts as a very good obedient kid. The control gives a database to the admin to store all the ID’s and passwords and when you try logging in you enter the ID and password which is then approved by the website database storing the ID’s and passwords.

Hence we all know that human are more intelligent than machine as we created machine so we can cheat the machine, that is we bypass the database procedure in some cases and in some cases we cheat the machine and upload our shells or deface the website or in some cases the worst is we poke and poke and poke the database using database management system technique and steal all the information from the database and gain access to the website. Have you guys not seen movies where one guy gets the other guy drunk and flatter him and acquire the required info ? That is the same in this case 3 too. We name this cases like the first case is called kidding where you bypass the asp governed sites, the second is XSS (cross site scripting method) and 3rd is the SQLi (my sequel commands injection).

Binary coding is in terms of 0’s and 1’s for every single thing we type as this is only what the system understands actually. even for ON ad OFF its o for OFF and 1 for ON.

in case of TRUE-FALSE o for FALSE and 1 represents TRUE.

so we’ll move direct to the first hijacking method that is KIDDING or call it KIDDO method:

usually the admins are a bit more intelligent as they have been gifted with few extra pounds of brain by their mother, so they use their login page as followed by domain name:







Now whats the password how do we find that out? In fact who cares and why should we waste our limited pounds brain finding the password for an asp governed website when we can simply bypass the database.

AND gate and OR gate, as the name suggest AND similar to ADD (so this gate multiplies any two input and returns the output)
where as the OR gate adds the inputs and returns the output value correspondingly.


Okay now understand these tables:                                                                                    `



Now we bypass the password using these tables making the database to read this conditions instead of typing the password and then the machine converts it to binary and then checks it out, we simply give it the binary codes directly and make the machine check the condition and give us access!

Remember this bypass is for asp governed site only so lets take an asp governed site and show it to you:

Go to Google and search for  asp login site and type the username/user ID as types I have mentioned above and in place of password try bypassing it using this method.

0 ‘or’ 0 ‘=’ 0 and hit enter you are either logged in or denied, if denied then try

1 ‘or’ 1 ‘=’ 1 and enter 🙂

Enjoy this, you have the entire tables above 😉

Then XSS and SQLi are too big to be posted in this post so it will be posted in my next post following thing… Hope you enjoy by then 🙂

Here are some dorks that will avail you this kinda vulnerable websites. Copy and paste them in Google search!





  1. or may be you are lazy enough not to try all the combination i have mentioned in the table above as i have already mentioned humans created machine so the machine is always weak, infact it works every time i attack and i recomend please do not demoralise others who are interested enough to practise and not give up and try the combinations mentioned above as this is the best way to hijack any asp governed site as the pattern will remain the same for every asp governed site.. thank you..


  2. Hey Ankit (NSM Techie), no trick is perfect bro…. You have to try all the methods if you want to hack anything which is targeted, but for random attack this one is good brother! And about the chances of getting them, well i can get you 100 sites vulnerable to this inject on the spot!


  3. It’s impressive that you are getting thoughts from this article as well as from our argument made here.


