Hacking PAK Website at Mass Just a another Hacking Story <b>So basically its a story from the Operation Sindoor Space Where I tried to help nation , what was happen actually check it out -> </b> Hey my reader , security researcher from India this side. Recently i open news channel I saw the PAK Starting attack on the India. So i decided to do some contribution to my country with my skills so that i can also be a part of the mission. Yeah i am being selfish here today cause if my country is working towards defence & war so i must do some of the contribution to my country where i am good.I can’t able to take the gun and fight on the border but i can exploit the servers access and extract the information from the website of the pakistan. I am going to tell to my Indian Community that this methodology & a simple way to exploit the application & I also want you to find the targets like the way i am finding and exploit. <b><i>Lets Come together Indian Hacker Community</i></b> For the target finding i am using here google dorking as well as the shodan to get the more about the websites and server those are hosting engines. Within the Google Dorking i found out many page with the cat?id= like. https://abc.abc.gov.pk?index.php?cat=1 As a Security Researcher , i know what to do next with this types of website , i am not going to tell you this small thing , I am just sharing methodology whatever i have done, so you do same too. TIP : If you find out any request that is parameterised there must be a chance to dig something big. <br>Then with help of many Google Dorking i found my targets.Those targets are seems like having the SQL Injection vulnerability i directly send them to the SQL Injection Automation Tools for further extraction of the data. Here after i started surfing on the internet and deep diving into the further Recon and enumeration so here i am using the shodan for checking out the IP where the website are hosted and more. <br>As per the Shodan result i found out many results in mass about the IP’s those are used to host Pak website as well as there trash servers. Here after taking many targets i started giving all my targets to the automation scripts those i have created and started hunting the core gov.pak website manually. You will not believe but rather then my manual exploitation the Automation tools with the proper queries that i have created give me the a kicky exploitation. <b>What I found out uptill now :<br>→ RCE ( Remote Code Execution)<br>→ SQL Injection and Database Extraction.<br>→ Private IPs<br>→ LFI , RFI<br>→ PII Leakage. (Sensitive Information)<br>→ Server Architecture completely.</b> <br>Now i am going to tell you proudly that i have found out Remote Code Execution of the server of the some websites IP. <br>As well as here i can able to dump the data of the Admin users from the particular target website. I have shared here enough that whatever i find out with this asap attack method to take out the mass hunting. Now I want every ethical hacker from India to take a moment to think about our knowledge and find out the exploitation.We are not doing anything wrong…. We are not doing the cyber attack here. we are here finding the weak points of there Cyber. So my all Security Researcher , Dont be a script kiddeee and do DDoS kinda thing. instead of that come with this any methodology and takeover the targets vulnerabilities and make them exploit. Always keep Hacking :) Jay Hind !!! Jay Bharat !!!!