A mobile phone application developed by the universal Century (or only responsible for O & M ..) The URL used to pull user credits has SQL injection. Attackers can execute system commands. The URL used for pulling user points in an android mobile phone game developed by the wanpu Century (or only responsible for O & M) (for the 30-life-of-the-Soul IOS version) does not detect one of the parameters, SQL Injection exists. Sysadmin permission. You can obtain the database version, operating system version, and intranet information. You can obtain/modify user information and execute system commands until you control the entire intranet. After setting up the mobile phone android packet capture environment, it is known that the key URL used to pull user points information is: http://app.wapx.cn/action/account/getinfo? Udid = ********** & app_id = ********* this test, found that the app_id is not filtered. Step 1: normal access Step 2: The parameter is enclosed in single quotes Step 3: omnipotent and 1 = 1 to determine whether the other side has SQL injection. Next, judge the database version. Step 4: @ version: Check the database version. Step 5: Check the current permission.
Extension: app_id indicates the Application ID. If this parameter is incorrect, it indicates that this problem exists in all applications developed or maintained by the company.Solution:1. Strictly check the parameters. 2. Do not run SQL databases with sysadmin permissions. 3. encrypt the points acquisition page.