Latency injection exists on important sites of the pull Network
Punch card
GET /wangpiao/checkCinema.php?robId=46&filmid=59674 HTTP/1.1Host: m.lashou.comUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: td_cookie=924922937; ThinkID=ske83b5kkskrq1t3c0gro9m001; client_key=2f06c4d7dfb3f8281ddff967ca8d600e; visit_city_string=beijing; cookie_check=1; __utma=1.1169558814.1450413021.1450413021.1450413021.1; __utmc=1; __utmz=1.1450413021.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); uuid=9abe7913c3df1c973089208e4923e0f968eejxu15676286184; downBanner=1; history=9028797%2C10895388; lastpay=alipay; __utmv=1.|2=%E8%B4%AD%E4%B9%B0%E7%8A%B6%E6%80%81=%E9%A6%96%E6%AC%A1%E8%B4%AD%E4%B9%B0=1X-Forwarded-For: 8.8.8.8Connection: keep-alive
The robId parameter has delayed injection.
Latency: 5 seconds
Delay: 3 seconds
Construct statement for Injection
GET /wangpiao/checkCinema.php?robId=46&filmid=59674 HTTP/1.1Host: m.lashou.comUser-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3Accept-Encoding: gzip, deflateCookie: td_cookie=924922937; ThinkID=ske83b5kkskrq1t3c0gro9m001; client_key=2f06c4d7dfb3f8281ddff967ca8d600e; visit_city_string=beijing; cookie_check=1; __utma=1.1169558814.1450413021.1450413021.1450413021.1; __utmc=1; __utmz=1.1450413021.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); uuid=9abe7913c3df1c973089208e4923e0f968eejxu15676286184; downBanner=1; history=9028797%2C10895388; lastpay=alipay; __utmv=1.|2=%E8%B4%AD%E4%B9%B0%E7%8A%B6%E6%80%81=%E9%A6%96%E6%AC%A1%E8%B4%AD%E4%B9%B0=1X-Forwarded-For: 8.8.8.8Connection: keep-alive
The robId parameter has delayed injection.
Latency: 5 seconds
Delay: 3 seconds
Construct statement for Injection
Solution:
Filter.