Friday, August 20, 2010

Sql Injection

SQL injection
A code injection technique that exploits a security vulnerability occurring in the database layer of an application. The vulnerability is present when user input is either incorrectly filtered for string literal escape characters embedded in SQL statements or user input is not strongly typed and thereby unexpectedly executed. It is an instance of a more general class of vulnerabilities that can occur whenever one programming or scripting language is embedded inside another. SQL injection attacks are also known as SQL insertion attacks.


This kind of injection technique works on vulnerable sites. 


SQL Injectable Sites*
http://www.maynie.com/index.php?target=events&mode=access_key
http://www.shootingcentre.nsw.gov.au/article.php?id=21&chapter_id=31&cat_id=1
http://www.cost281.org/download.php?fid=487
http://www.jandlhomeaccents.com/store/index.php?target=events&mode=search
http://www.wisebuynow.com/cart/index.php?target=events&mode=access_key
http://www.onlymelbourne.com.au/melbourne_details.php?id=3495
http://www.haynesprintingonline.com/index.php?target=events&mode=access_key
http://www.thehistorychannel.co.uk/site/microsites/Abolition/index_microsite.php?microsite=Abolition&target=Events&section=608
http://www.tokiusa.com/index.php?target=events&mode=details&event_id=2
http://www.baltimorestyle.com/index.php/style/features_article/fe_pistol_jf06/
http://www.arguscycletour.co.za/events/index.php?page=20&Var_Search=yes&Var_Year_To=2009&Var_Month_To=05&Var_Event_Type=all&Var_Province=all&Var_SearchText=
http://www.marvel.com/boards/viewtopic.php?t=142968
https://www.tokiusa.com/index.php?target=events&mode=add
http://www.dancesavvy.com/index.php?target=events&mode=search
http://www.araquin.com/cscart/index.php?mode=search&target=events
https://www.ventureloop.com/ventureloop/jobdetail.php?jobid=9603
http://www.espnoutdoorsmedia.com/search/index.php?news=1&event_id=169&news_id=843&search_keywords=&search_images=&search_news=1&search_site_area=2&search_year_range=
http://www.dolphincommunicationproject.org/main/index.php?option=com_content&view=article&id=105&Itemid=140
http://www.pamelakristan.com/index.php?target=events&subtarget=top
http://www.teamsheeper.com/join/about_level1.php
http://www.shop4phim.com/index.php?target=events&mode=access_key
http://www.funnythings.se/shop/index.php?target=events&mode=access_key&sl=SE
http://www.deadseacosmetics.com/index.php?target=events&mode=access_key
http://www.jandlhomeaccents.com/store/index.php?target=events&mode=details&event_id=16
http://www.trucksaccessoriesonline.com/index.php?target=events&mode=search
http://www.eminweb.com/forum/index.php?showtopic=15
https://www.ventureloop.com/ventureloop/jobdetail.php?jobid=22236
http://www.iggsoftware.com/forums/viewtopic.php?f=11&t=6396
http://www.skyscrapercity.com/showthread.php?p=20421607
http://www.hidstores.com/store/index.php?target=events&mode=access_key
/custom?hl=en&client=pub-8993703457585266&channel=54741338



http://www.logaholic.com/support-center/index.php?x=&mod_id=2&id=3
http://www.scifiontherock.com/index.php?target=pages/workshops.php
http://www.mobilx.hu/index.php?page_id=letoltesek&target=pages
http://www.grotonsd.net/index.php?page_id=CU2&target=pages
http://www.jacobsdigital.co.uk/index.php?target=pages&page_id=stores
http://www.davidsfootwear.com/index.php?target=pages&page_id=about
https://www.final4ever.com/showthread.php?p=403139
http://www.pcwholesale.us/index.php?target=pages&page_id=recycling
http://www.zen-cart.com/forum/showthread.php?t=118146
http://www.bitrixsoft.com/products/cms/features/web_analytics.php
http://www.zen-cart.com/forum/showthread.php?t=66271
http://www.digitalinnovations.com/index.php?target=pages&page_id=pressrelease032309
http://www.openresource.com/MBD/mbd_sem_wiki.php
http://www.mothercare.com.hk/index.php?target=pages&page_id=store
http://www.westwind.ch/help.php
http://www.putlinks.com/index.php?page=en_Page+Rank
http://www.seopages.com/articles.php?articleId=12&page=&show=all
http://www.diplomacompany.com/index.php?target=pages&page_id=terms_conditions
http://www.westwind.ch/news.php
http://www.jamals.com/webbookyouraddnow.php
http://www.webdeveloper.com/forum/showthread.php?t=206515
http://www.leveltendesign.com/L10Apps/HC/help_advancedFeatures.php
http://www.screwturn.eu/forum/viewtopic.php?f=3&t=4452
http://www.webdeveloper.com/forum/showthread.php?t=148094
http://www.dynamicdrive.com/forums/showthread.php?t=3377
http://www.sitepoint.com/forums/showthread.php?t=614723
http://www.logaholic.com/support-center/index.php?x=&mod_id=2&id=6
http://www.atlantis-press.com/php/download_paper.php?id=1288
http://www.codingforums.com/archive/index.php/t-117755.html
http://www.springfield-chamber.org/advertising_info.php
http://www.katrinacostedio.com/index.php?page=tech
http://www.fruitpuff.com/pc/puffcash.com/terms.php
http://www.dynamicdrive.com/forums/archive/index.php/t-22271.html
http://www.webdesignfromscratch.com/web-doctor-reports/fair-say-feb-2009.php
http://www.xml-sitemaps.com/forum/index.php/topic,990.0/prev_next,prev.html
http://www.developertutorials.com/scripts/script-details/307148.php
http://www.ci.albany.or.us/dgssearch/search.php?q=hr&r=20






http://pvgrind.com/parks.php?id=1 (Blind Injection)
http://cwis.fcla.edu/edl/SPT--BrowseResources.php?ParentId=769 (MYSQL Injection)
http://www.inderscience.com/browse/index.php?journalID=233 (MYSQL Injection)
http://imagebase.lib.vt.edu/browse.php?folio_ID=/camp (MYSQL Injection)
http://www.austinparks.org/apfweb/park.php?parkId=282 (MYSQL Injection)
http://pvgrind.com/parks.php?id=1 (Blind Injection)
http://cwis.fcla.edu/edl/SPT--BrowseResources.php?ParentId=769 (MYSQL Injection)
http://www.inderscience.com/browse/index.php?journalID=233 (MYSQL Injection)
http://imagebase.lib.vt.edu/browse.php?folio_ID=/camp (MYSQL Injection)
http://www.austinparks.org/apfweb/park.php?parkId=282 (MYSQL Injection)
http://pvgrind.com/parks.php?id=1 (Blind Injection)
http://cwis.fcla.edu/edl/SPT--BrowseResources.php?ParentId=769 (MYSQL Injection)
http://www.inderscience.com/browse/index.php?journalID=233 (MYSQL Injection)
http://imagebase.lib.vt.edu/browse.php?folio_ID=/camp (MYSQL Injection)
http://www.austinparks.org/apfweb/park.php?parkId=282 (MYSQL Injection)
http://pvgrind.com/parks.php?id=1 (Blind Injection)
http://cwis.fcla.edu/edl/SPT--BrowseResources.php?ParentId=769 (MYSQL Injection)
http://www.inderscience.com/browse/index.php?journalID=233 (MYSQL Injection)
http://imagebase.lib.vt.edu/browse.php?folio_ID=/camp (MYSQL Injection)
http://www.austinparks.org/apfweb/park.php?parkId=282 (MYSQL Injection)
http://pvgrind.com/parks.php?id=1 (Blind Injection)
http://cwis.fcla.edu/edl/SPT--BrowseResources.php?ParentId=769 (MYSQL Injection)
http://www.inderscience.com/browse/index.php?journalID=233 (MYSQL Injection)
http://imagebase.lib.vt.edu/browse.php?folio_ID=/camp (MYSQL Injection)
http://www.austinparks.org/apfweb/park.php?parkId=282 (MYSQL Injection)
http://pvgrind.com/parks.php?id=1 (Blind Injection)
http://cwis.fcla.edu/edl/SPT--BrowseResources.php?ParentId=769 (MYSQL Injection)
http://www.inderscience.com/browse/index.php?journalID=233 (MYSQL Injection)
http://imagebase.lib.vt.edu/browse.php?folio_ID=/camp (MYSQL Injection)



http://www.standardsuk.com/shop/products_view.php?prod=2063
http://www.standardsuk.com/shop/products_view.php?prod=6536
http://www.standardsuk.com/shop/products_view.php?prod=41063
http://www.fastengineparts.com/products_view.php?id=55
http://www.tradeprintsupplies.com/shop/products_view.php?prod=347
http://www.worldwidestandards.com/shop/products_view.php?prod=36528
https://www.solidagency.com/products_view.php?id=1649
http://www.worldwidestandards.com/shop/products_view.php?prod=34189
https://www.fastengineparts.com/products_view.php?id=1687
http://www.worldwidestandards.com/shop/products_view.php?prod=36532



http://www.cosforums.com/showthread.php?t=117938
http://www.movie-list.com/trailers.php?id=beautyshop
http://www.the-wine-list.com/catalog/index.php
http://www.peskimo.com/web/shop.php
http://www.chevroncars.com/store/index.php?target=pages&page_id=help_using_your_wish_list
https://www.balticmill.com/shop/ProductDetails.php?firstLevelCatID=7&productID=359&secondLevelCatID=27
http://www.tamatalk.com/IB/index.php?showtopic=90316
http://www.naturacos.com/shop/mall.php?cat=010006000
http://www.runningroom.com/hm/inside.php?id=3033
http://www.mothering.com/shop/index.php?target=events&mode=details&event_id=9
http://www.pinkflag.com/read/mailing-list.php
http://www.fasttraxskishop.com/news.php
http://www.hipundies.com/shop/product.php/1959
http://www.openpinoy.com/shop/step1.php?number=1502



*source from www.techkranti.com

No comments:

Post a Comment