当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2015-0162600

漏洞标题:拉手网主站SQL注入(绕过过滤机制)

相关厂商:拉手网

漏洞作者: 沦沦

提交时间:2015-12-19 09:26

修复时间:2016-02-01 19:48

公开时间:2016-02-01 19:48

漏洞类型:SQL注射漏洞

危害等级:高

自评Rank:20

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2015-12-19: 细节已通知厂商并且等待厂商处理中
2015-12-19: 厂商已经确认,细节仅向厂商公开
2015-12-29: 细节向核心白帽子及相关领域专家公开
2016-01-08: 细节向普通白帽子公开
2016-01-18: 细节向实习白帽子公开
2016-02-01: 细节向公众公开

简要描述:

拉手网主站SQL注入(绕过过滤机制)

详细说明:

POST /ajax/address.php?modify=m HTTP/1.1
Host: www.lashou.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Referer: http://www.lashou.com/account/address/
Cookie: client_key=2f06c4d7dfb3f8281ddff967ca8d600e; visit_city_string=beijing; __utma=1.1169558814.1450413021.1450441806.1450449931.3; __utmz=1.1450413021.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); uuid=9abe7913c3df1c973089208e4923e0f968eejxu15676286184; downBanner=1; history=9028797%2C10895388; lastpay=alipay; __utmv=1.|2=%E8%B4%AD%E4%B9%B0%E7%8A%B6%E6%80%81=%E9%A6%96%E6%AC%A1%E8%B4%AD%E4%B9%B0=1; ThinkID=7v2nkos6s8l9v63npm1k8c7ie3; __utmc=1; login_name2=per1sh; pwd2=f4a95c006e7939b1b7c68cd30c1c79cf; city_b=2419; show_index_qr=1; view_goods=%5B%2211981290%22%2C%2211939804%22%5D; weatherinfo=%u5317%u4EAC%2C1%2C11%2C%u591A%u4E91%2C32%u2103%7E19%u2103
X-Forwarded-For: 8.8.8.8
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 281
id=27198894&id=27198894&username=1111&province=130000&city=130300&town=110228&address=111111111111111111&code=100001&phone1=&phone2=&phone3=&mobliephone=130****0764&real_mobliephone=130****0764


id参数没进行过滤,可进行延进注入
延时3秒

1.png


延时2秒

2.png


判断长度当前数据库长度为4

4.png


由于过滤了一部份关健字包括ascii被过滤了,但还是能绕过的

5.png


database:logs

漏洞证明:

POST /ajax/address.php?modify=m HTTP/1.1
Host: www.lashou.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: zh-CN,zh;q=0.8,en-US;q=0.5,en;q=0.3
Accept-Encoding: gzip, deflate
Referer: http://www.lashou.com/account/address/
Cookie: client_key=2f06c4d7dfb3f8281ddff967ca8d600e; visit_city_string=beijing; __utma=1.1169558814.1450413021.1450441806.1450449931.3; __utmz=1.1450413021.1.1.utmcsr=(direct)|utmccn=(direct)|utmcmd=(none); uuid=9abe7913c3df1c973089208e4923e0f968eejxu15676286184; downBanner=1; history=9028797%2C10895388; lastpay=alipay; __utmv=1.|2=%E8%B4%AD%E4%B9%B0%E7%8A%B6%E6%80%81=%E9%A6%96%E6%AC%A1%E8%B4%AD%E4%B9%B0=1; ThinkID=7v2nkos6s8l9v63npm1k8c7ie3; __utmc=1; login_name2=per1sh; pwd2=f4a95c006e7939b1b7c68cd30c1c79cf; city_b=2419; show_index_qr=1; view_goods=%5B%2211981290%22%2C%2211939804%22%5D; weatherinfo=%u5317%u4EAC%2C1%2C11%2C%u591A%u4E91%2C32%u2103%7E19%u2103
X-Forwarded-For: 8.8.8.8
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 281
id=27198894&id=27198894&username=1111&province=130000&city=130300&town=110228&address=111111111111111111&code=100001&phone1=&phone2=&phone3=&mobliephone=130****0764&real_mobliephone=130****0764


id参数没进行过滤,可进行延进注入
延时3秒

1.png


延时2秒

2.png


判断长度当前数据库长度为4

4.png


由于过滤了一部份关健字包括ascii被过滤了,但还是能绕过的

5.png


database:logs

修复方案:

过滤

版权声明:转载请注明来源 沦沦@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:9

确认时间:2015-12-19 11:01

厂商回复:

谢谢您的反馈,我们正在处理.

最新状态:

暂无


漏洞评价:

评价

  1. 2015-12-19 09:46 | ago ( 普通白帽子 | Rank:544 漏洞数:93 )

    掐指一算,有第三发

  2. 2015-12-19 12:46 | Bear baby ( 普通白帽子 | Rank:187 漏洞数:22 | 进步的唯一方式是坚持学习)

    沦总,求装备。。