当前位置:WooYun >> 漏洞信息

漏洞概要 关注数(24) 关注此漏洞

缺陷编号:wooyun-2016-0190398

漏洞标题:DU支付手环某漏洞看我如何知道所有MM详细信息(电话,照片,身高,体重,三围等)

相关厂商:dusmarter.com

漏洞作者: 带头大哥

提交时间:2016-04-07 14:29

修复时间:2016-05-22 14:50

公开时间:2016-05-22 14:50

漏洞类型:命令执行

危害等级:高

自评Rank:16

漏洞状态:厂商已经确认

漏洞来源: http://www.wooyun.org,如有疑问或需要帮助请联系 [email protected]

Tags标签:

4人收藏 收藏
分享漏洞:


漏洞详情

披露状态:

2016-04-07: 细节已通知厂商并且等待厂商处理中
2016-04-07: 厂商已经确认,细节仅向厂商公开
2016-04-17: 细节向核心白帽子及相关领域专家公开
2016-04-27: 细节向普通白帽子公开
2016-05-07: 细节向实习白帽子公开
2016-05-22: 细节向公众公开

简要描述:

带色情意味的小笑话,亦称“荤段子”。“黄段子”乃是民间化的色情与语言智慧的混合物。一度成为中国成年人饭局上必备的佐餐,反映了中国市井文化的空虚无聊的状况。
MM我来了...

详细说明:

DU手环是都飞科技旗下的一款智能穿戴产品,DU手环具有运动检测、睡眠监测等功能的同时还具有E通卡支付功能,所以也可称之为手环e通卡。
#开门见山-直入正题

http://115.159.56.188/admin/index.action


DU手环运营管理平台,存在Struts2命令执行漏洞,直接取shell.

111.png


拿到shell之后,简单分析了下,发现包含多处敏感信息:
数据库第一处:

com.mysql.jdbc.Driver
jdbc:mysql://localhost:3306/mysql?useUnicode=true&characterEncoding=GBK
dufreeband/dufreeband


数据库第二处:

com.mysql.jdbc.Driver
jdbc:mysql://localhost:3306/mysql?useUnicode=true&characterEncoding=GBK
alarm/alarm


数据库第三处:

com.mysql.jdbc.Driver
jdbc:mysql://localhost:3306/mysql?useUnicode=true&characterEncoding=GBK
cmc/cmc


一处mail:

<?xml version="1.0" encoding="UTF-8"?>
<jbpm-configuration>
<!-- <import resource="jbpm.default.cfg.xml" /> -->
<import resource="jbpm.customer.cfg.xml" />
<import resource="jbpm.tx.spring.cfg.xml" />
<import resource="jbpm.jpdl.cfg.xml" />
<import resource="jbpm.bpmn.cfg.xml" />
<!-- <import resource="jbpm.identity.cfg.xml" /> -->
<import resource="jbpm.businesscalendar.cfg.xml" />
<import resource="jbpm.console.cfg.xml" />
<import resource="jbpm.jobexecutor.cfg.xml" />

<process-engine-context>
<string name="spring.cfg" value="applicationContext.xml" />
</process-engine-context>
<transaction-context>
<hibernate-session current="true"/>
<object class="com.dofittech.idecloud.common.workFlow.enity.AppFlowIdentity"/>
<!-- <mail-session>
<mail-server>
<session-properties resource="jbpm.mail.properties"/>
<authenticator class="com.dofittech.idecloud.common.workFlow.service.MyAuthenticator">
<field name="userName"><string value="990409381@qq.com"/></field>
<field name="password"><string value="yffylqyffhtt"/></field>
</authenticator>
</mail-server>
</mail-session> -->
</transaction-context>
</jbpm-configuration>


简单列举下相关敏感信息,我们开始实操,连接库看看,当然服务器里面还有很多sql数据库存储的类型和相关信息文件,为了漏洞篇幅,最后附上sql文件,我们先继续往下看:
连接数据库一:

sms01.png


从第一个库我们可以看到查询sms可以获取到的信息:APP_SMS_ID CONTENT SEND_TO FROM_TO CREATED_DATE STATU 分别为用户的手机号码,验证码等各种码.

sms02.png


连接数据库二:

sjk02.png


用户设备信息:

sm03.png


连接数据库三:

sju003.png


用户相信详细地址,包括家庭地址等

xx01.png


然后在数据库中看到这个表:biz_user;连接之

biz-user.png


仔细看,图缩放的原因是因为为了让审核和厂商看的更全面,前面的信息包括电话,性别,身高,体重,三围什么的,后面包括设备信息加使用者拍的图,已上传到云端,但是我们有地址可以访问,比如:

http://bracelet-10003817.image.myqcloud.com/d90f65ce-5b0f-4cef-b426-96b3ace08925
http://bracelet-10003817.image.myqcloud.com/edfe890e-068e-44f7-9519-160c2511cd1c


121.png

122.png


结婚了,就变了,我不觉得图二的大嫂年轻的时候不漂亮,看到图一MM,我于是在此页面搜索下她的相关信息,当然包括她的设备,电话等

BIZ_USER_ID:8a035cb45383be4b0153a27177580363 
USER_NAME = phone注册的你的手机号:18906062385
昵称:A
性别:0
密码:b876e40f0fee3f4b4b006675506c9853
2016-03-23 15:47:38.0 http://bracelet-10003817.image.myqcloud.com/d90f65ce-5b0f-4cef-b426-96b3ace08925


看到注册的手机号,于是测试下,声明:纯属测试,无别的意思.

18906062385 --> 手机归属地
手机号码"18906062385"福建 漳州 中国电信


通过搜索知道妹子是福建漳州人,于是

12.jpg


还可以继续往下......

漏洞证明:

好了,回到正题:
然后我们继续看库里发现

admin 超级管理员 202cb962ac59075b964b07152d234b70
DU手环 DU手环 e10adc3949ba59abbe56e057f20f883e
懂小姐 懂小姐 e10adc3949ba59abbe56e057f20f883e


于是直接输入一开始的登陆地址:

1211.png


登录之后还可以推送广告/什么的....点到为止,
附上从库里看到sql文件此文就结束:
<code>/*
Navicat MySQL Data Transfer
Source Server : dufreeband
Source Server Version : 50532
Source Host : 192.168.1.137:3306
Source Database : dufreeband
Target Server Type : MYSQL
Target Server Version : 50532
File Encoding : 65001
Date: 2015-12-18 17:49:12
*/
SET FOREIGN_KEY_CHECKS=0;
-- ----------------------------
-- Table structure for `app_attach_file`
-- ----------------------------
DROP TABLE IF EXISTS `app_attach_file`;
CREATE TABLE `app_attach_file` (
`APP_ATTACH_FILE_ID` varchar(50) NOT NULL,
`BIZ_ENTITY_ID` varchar(50) NOT NULL,
`BIZ_MODULE_CD` varchar(20) DEFAULT NULL,
`FILE_NAME` text NOT NULL,
`REAL_FILE_NAME` text NOT NULL,
`FILE_PATH` text NOT NULL,
`FILE_TYPE_NAME` varchar(100) NOT NULL,
`FILE_SIZE` decimal(19,4) NOT NULL,
`MAIN_FLG` decimal(1,0) DEFAULT NULL,
`SMALL_PIC_NAME` text,
`STATUS_CD` varchar(20) DEFAULT NULL,
`REMARK` varchar(200) DEFAULT NULL,
`CREATOR` varchar(50) DEFAULT NULL,
`CREATED_DEPT_CD` varchar(50) DEFAULT NULL,
`CREATED_DATE` datetime DEFAULT NULL,
`UPDATOR` varchar(50) DEFAULT NULL,
`UPDATED_DEPT_CD` varchar(50) DEFAULT NULL,
`UPDATED_DATE` datetime DEFAULT NULL,
`RECORD_VERSION` decimal(10,0) NOT NULL,
`LOGO_FLAG` varchar(2) DEFAULT NULL,
PRIMARY KEY (`APP_ATTACH_FILE_ID`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- ----------------------------
-- Records of app_attach_file
-- ----------------------------
INSERT INTO `app_attach_file` VALUES ('4028b88151808209015180c2cf8b000e', '4028b881517af9c701517b066bd70004', 'advertisement', '20151208164300Gni0.jpg', 'Desert.jpg', 'upload/adv', 'image/pjpeg', '1.0000', '1', null, '1', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:43:49', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('4028b8815180c769015180c8d5fc0003', '4028b881517af9c701517b0668af0003', 'advertisement', '20151208165023iwJu.jpg', 'Tulips.jpg', 'http://bracelet-10003817.image.myqcloud.com/2861f956-9abb-4a98-acf1-385b494280f1', 'image/pjpeg', '1.0000', '1', null, '1', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:50:24', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('402881915189978f015189cd0c0f002b', '4028b881517af9c701517b0652260002', 'advertisement', '20151210105134TLtR.jpg', 'Hydrangeas.jpg', 'http://bracelet-10003817.image.myqcloud.com/dab1a8d0-28c0-4b65-8187-09be70d5443a', 'image/jpeg', '1.0000', '1', null, '1', null, null, null, '2015-12-10 10:51:35', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('4028b881518eba4c01518ed980590002', '4028b881518fd00f01518fe097bb0002', 'good', '20151211102316bkLR.jpg', 'Desert.jpg', 'http://bracelet-10003817.image.myqcloud.com/29fc3909-2b03-4e36-9161-2de4ff11c52e', 'image/pjpeg', '1.0000', null, null, '1', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-11 10:23:17', null, null, null, '1', null);
INSERT INTO `app_attach_file` VALUES ('402881915189eeca015189ef7adb0002', '4028b881517af9c701517b0652260002', 'advertisement', '20151210112906ShJS.jpg', 'Tulips.jpg', 'http://bracelet-10003817.image.myqcloud.com/16a2595c-f2fd-4ef7-91fe-219170229a29', 'image/jpeg', '1.0000', '1', null, '1', null, null, null, '2015-12-10 11:29:11', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('402881915189eeca015189ef7ae40003', '4028b881517af9c701517b0652260002', 'advertisement', '20151210112907IHq1.jpg', 'Penguins.jpg', 'http://bracelet-10003817.image.myqcloud.com/2698107c-e0e0-49c7-b6e1-224e06fa18fa', 'image/jpeg', '1.0000', '1', null, '1', null, null, null, '2015-12-10 11:29:11', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('402881915189eeca015189ef7ae40004', '4028b881517af9c701517b0652260002', 'advertisement', '20151210112908nmF4.jpg', 'Lighthouse.jpg', 'http://bracelet-10003817.image.myqcloud.com/25243eea-fa98-45ea-9ea8-72e4d7efa2c5', 'image/jpeg', '1.0000', '1', null, '1', null, null, null, '2015-12-10 11:29:11', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('402881915189eeca015189ef7ae50005', '4028b881517af9c701517b0652260002', 'advertisement', '20151210112908vK2Q.jpg', 'Tulips.jpg', 'http://bracelet-10003817.image.myqcloud.com/10b9009f-c198-41c4-90b6-95d397bf388c', 'image/jpeg', '1.0000', null, null, '1', null, null, null, '2015-12-10 11:29:11', null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('1', '4028b881518fd00f01518fe097bb0002', 'good', '20151210105134TLtR.jpg', 'Hydrangeas.jpg', 'http://bracelet-10003817.image.myqcloud.com/dab1a8d0-28c0-4b65-8187-09be70d5443a', 'image/jpeg', '0.0000', null, null, null, null, null, null, null, null, null, null, '0', null);
INSERT INTO `app_attach_file` VALUES ('4028b881519f8aab01519feb7f3a0003', '402881a7518b56f701518b5953460002', 'good', '20151214175629TLpy.jpg', 'Desert.jpg', 'http://bracelet-10003817.image.myqcloud.com/bfefad5b-d6f0-475f-ac16-75f2020737ec', 'image/pjpeg', '1.0000', '1', null, '1', null, null, null, '2015-12-14 17:56:29', null, null, null, '4', '1');
INSERT INTO `app_attach_file` VALUES ('4028819151b340e90151b34369670006', '9dPiVhEsiT', 'advertisement', '20151218120517HOnX.jpg', 'Penguins.jpg', 'http://bracelet-10003817.image.myqcloud.com/3a16c061-2e92-43e6-9669-2f1dc42a9be0', 'image/jpeg', '1.0000', null, null, '2', null, null, null, '2015-12-18 12:05:18', null, null, null, '0', null);
-- ----------------------------
-- Table structure for `app_button`
-- ----------------------------
DROP TABLE IF EXISTS `app_button`;
CREATE TABLE `app_button` (
`APP_BUTTON_ID` varchar(32) NOT NULL,
`APP_MENU_ID` varchar(32) DEFAULT NULL,
`APP_BUTTON_NAME` varchar(50) DEFAULT NULL,
`APP_BUTTON_CD` varchar(50) DEFAULT NULL,
`REMARK` varchar(200) DEFAULT NULL,
`CREATOR` varchar(32) DEFAULT NULL,
`CREATED_DEPT_CD` varchar(32) DEFAULT NULL,
`CREATED_DATE` datetime DEFAULT NULL,
`UPDATOR` varchar(32) DEFAULT NULL,
`UPDATED_DEPT_CD` varchar(32) DEFAULT NULL,
`UPDATED_DATE` datetime DEFAULT NULL,
`DETAIL` text,
PRIMARY KEY (`APP_BUTTON_ID`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- ----------------------------
-- Records of app_button
-- ----------------------------
-- ----------------------------
-- Table structure for `app_dict_data`
-- ----------------------------
DROP TABLE IF EXISTS `app_dict_data`;
CREATE TABLE `app_dict_data` (
`APP_DICT_DATA_ID` varchar(50) NOT NULL,
`APP_DICT_TYPE_ID` varchar(50) NOT NULL,
`DICT_CD` varchar(50) DEFAULT NULL,
`DICT_NAME` varchar(128) DEFAULT NULL,
`DISP_ORDER_NO` decimal(11,0) DEFAULT NULL,
`DEFAULT_FLG` decimal(1,0) DEFAULT NULL,
`REMARK` varchar(200) DEFAULT NULL,
`CREATOR` varchar(50) DEFAULT NULL,
`CREATED_DEPT_CD` varchar(50) DEFAULT NULL,
`CREATED_DATE` datetime DEFAULT NULL,
`UPDATOR` varchar(50) DEFAULT NULL,
`UPDATED_DEPT_CD` varchar(50) DEFAULT NULL,
`UPDATED_DATE` datetime DEFAULT NULL,
`RECORD_VERSION` decimal(10,0) NOT NULL,
PRIMARY KEY (`APP_DICT_DATA_ID`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- ----------------------------
-- Records of app_dict_data
-- ----------------------------
INSERT INTO `app_dict_data` VALUES ('40288191518a81ca01518a91c7ee0004', '40288191518a81ca01518a91407c0002', 'complete', '完善资料', '0', null, null, null, null, '2015-12-10 14:26:28', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('40288191518a81ca01518a9210bc0006', '40288191518a81ca01518a91407c0002', 'binding', '绑定设备', '1', null, null, null, null, '2015-12-10 14:26:47', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402880f751132f250151134acacb0005', '402880f751132f250151133476130002', 'LastedVersion', '1.0', '0', null, '发布时间:2015-12-1', null, null, null, null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('4028b88150e9bd670150e9c26ff50007', '4028b88150e9bd670150e9c03d470003', 'UpdatePassWordMsg', '尊敬的客户您好,您的修改密码验证码为:{0},如非本人操作请无视。', '1', null, '修改密码短信格式', null, null, null, null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('4028b88150e9bd670150e9c26ff60008', '4028b88150e9bd670150e9c03d470003', 'SendDXMessages', '尊敬的客户您好,您的验证码为:{0},如非本人操作请无视。', '2', null, ' 短信验证手机号码', null, null, null, null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189a455000007', '402881915189978f015189a071a00002', 'complete', '25', '0', null, '完善资料获取DU币', null, null, '2015-12-10 10:07:07', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189a48d5f0009', '402881915189978f015189a071a00002', 'binding', '25', '1', null, '绑定设备获取DU币', null, null, '2015-12-10 10:07:21', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189a5f03c000d', '402881915189978f015189a071a00002', 'registerShare', '100', '2', null, '注册分享DU币', null, null, '2015-12-10 10:08:52', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189a64682000f', '402881915189978f015189a071a00002', 'uploadHead', '100', '3', null, '上传头像', null, null, '2015-12-10 10:09:14', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189af239c0015', '402881915189978f015189a75cf40011', 'sign', '5', '0', null, '签到领取DU币', null, null, '2015-12-10 10:18:55', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189b01fa90018', '402881915189978f015189a75cf40011', 'shareSport', '6', '1', null, '分享运动数据领DU币', null, null, '2015-12-10 10:19:59', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189b1ce34001f', '402881915189978f015189a75cf40011', 'post', '6', '2', null, '发帖', null, null, '2015-12-10 10:21:50', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189b1ed7a0021', '402881915189978f015189a75cf40011', 'reply', '2', '3', null, '回帖', null, null, '2015-12-10 10:21:58', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189b287de0023', '402881915189978f015189a75cf40011', 'uploadRefresh', '13', '4', null, '上传刷新', null, null, '2015-12-10 10:22:37', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189978f015189b3277b0026', '402881915189978f015189a75cf40011', 'sportReward', '30', '5', null, '运动2000步奖励', null, null, '2015-12-10 10:23:18', null, null, null, '0');
INSERT INTO `app_dict_data` VALUES ('402881915189f3b7015189f79c160002', '402881915189978f015189a75cf40011', 'daylyComplete', '30', '6', null, '日常任务全完成', null, null, '2015-12-10 11:38:04', null, null, null, '0');
-- ----------------------------
-- Table structure for `app_dict_type`
-- ----------------------------
DROP TABLE IF EXISTS `app_dict_type`;
CREATE TABLE `app_dict_type` (
`APP_DICT_TYPE_ID` varchar(50) NOT NULL,
`DICT_TYPE_CD` varchar(50) DEFAULT NULL,
`DICT_TYPE_NAME` varchar(50) DEFAULT NULL,
`DISP_ORDER_NO` decimal(11,0) DEFAULT NULL,
`DEFAULT_FLG` decimal(1,0) DEFAULT NULL,
`REMARK` varchar(200) DEFAULT NULL,
`CREATOR` varchar(50) DEFAULT NULL,
`CREATED_DEPT_CD` varchar(50) DEFAULT NULL,
`CREATED_DATE` datetime DEFAULT NULL,
`UPDATOR` varchar(50) DEFAULT NULL,
`UPDATED_DEPT_CD` varchar(50) DEFAULT NULL,
`UPDATED_DATE` datetime DEFAULT NULL,
`RECORD_VERSION` decimal(10,0) NOT NULL,
PRIMARY KEY (`APP_DICT_TYPE_ID`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- ----------------------------
-- Records of app_dict_type
-- ----------------------------
INSERT INTO `app_dict_type` VALUES ('402880f751132f250151133476130002', 'appVersion', 'APP版本', '4', '0', 'DU手环APP版本', null, null, null, null, null, null, '3');
INSERT INTO `app_dict_type` VALUES ('402881e53450231d01345028aa6b0001', 'selectYesNo', '公用选择', '12', '1', '公用选择,是或否', 'admin', null, null, null, null, null, '2');
INSERT INTO `app_dict_type` VALUES ('40288191518a81ca01518a91407c0002', 'taskDetail', '任务内容', '6', '0', '任务完成内容', null, null, '2015-12-10 14:25:53', null, null, null, '2');
INSERT INTO `app_dict_type` VALUES ('4028b88150e9bd670150e9c03d470003', 'smsTemplate', '短信模板', '3', '0', 'DU手环', null, null, null, null, null, null, '3');
INSERT INTO `app_dict_type` VALUES ('402881915189978f015189a071a00002', 'taskCoin', '新手任务', '5', '0', '任务获取DU配置', null, null, '2015-12-10 10:02:52', null, null, null, '8');
INSERT INTO `app_dict_type` VALUES ('402881915189978f015189a75cf40011', 'daylyCoin', '日常任务', '6', '0', '日常任务获取DU币', null, null, '2015-12-10 10:10:25', null, null, null, '8');
-- ----------------------------
-- Table structure for `app_log`
-- ----------------------------
DROP TABLE IF EXISTS `app_log`;
CREATE TABLE `app_log` (
`APP_LOG_ID` varchar(32) NOT NULL,
`MODULE_BIZ_CD` varchar(32) DEFAULT NULL,
`MODULE_NAME` varchar(100) DEFAULT NULL,
`OBJ_ID` varchar(32) DEFAULT NULL,
`OBJ_NAME` varchar(100) DEFAULT NULL,
`LOG_DETAIL` text,
`IP_ADDR` varchar(40) DEFAULT NULL,
`LOG_TYPE_BIZ_CD` varchar(32) DEFAULT NULL,
`OPREATOR_ID` varchar(32) DEFAULT NULL,
`OPERATOR_NAME` varchar(50) DEFAULT NULL,
`OPERATE_DATE` datetime DEFAULT NULL,
`REMARK` varchar(200) DEFAULT NULL,
`CREATOR` varchar(32) DEFAULT NULL,
`CREATED_DEPT_CD` varchar(32) DEFAULT NULL,
`CREATED_DATE` datetime DEFAULT NULL,
`UPDATOR` varchar(32) DEFAULT NULL,
`UPDATED_DEPT_CD` varchar(32) DEFAULT NULL,
`UPDATED_DATE` datetime DEFAULT NULL,
`RECORD_VERSION` decimal(10,0) NOT NULL,
PRIMARY KEY (`APP_LOG_ID`)
) ENGINE=MyISAM DEFAULT CHARSET=utf8;
-- ----------------------------
-- Records of app_log
-- ----------------------------
INSERT INTO `app_log` VALUES ('4028808b5138584a0151385a4a66000d', '鹭游记', '菜单管理', null, null, '增加《消费明细》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-24 15:16:58', null, null, null, '2015-11-24 15:17:00', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028808b51385c1a0151385cf836000e', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-24 15:19:55', null, null, null, '2015-11-24 15:19:55', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028808b51387e0101513889bb700002', '鹭游记', '菜单管理', null, null, '增加《消费明细》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-24 16:08:48', null, null, null, '2015-11-24 16:08:49', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028808b513c27b801513c3db1920003', '鹭游记', '菜单管理', null, null, '增加《租赁管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-25 09:24:14', null, null, null, '2015-11-25 09:24:14', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028808b513c27b801513c3dd8660011', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-25 09:24:24', null, null, null, '2015-11-25 09:24:24', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880ba51617db90151618ea6a30003', '鹭游记', '菜单管理', null, null, '增加《商品管理》', '0:0:0:0:0:0:0:1', '业务日志正常', null, 'admin', '2015-12-02 15:18:37', null, null, null, '2015-12-02 15:18:37', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880ba51617db90151618f41580004', '鹭游记', '菜单管理', null, null, '增加《消费明细》', '0:0:0:0:0:0:0:1', '业务日志正常', null, 'admin', '2015-12-02 15:19:17', null, null, null, '2015-12-02 15:19:17', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880ba51618fd30151619227b50010', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '0:0:0:0:0:0:0:1', '业务日志正常', null, 'admin', '2015-12-02 15:22:27', null, null, null, '2015-12-02 15:22:27', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881b7513268660151326d80b30003', '鹭游记', '菜单管理', null, null, '增加《商户管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 11:40:15', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881b7513268660151327069f8000e', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 11:43:26', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881b75133575b0151335b8f090003', '鹭游记', '菜单管理', null, null, '增加《商户活动》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 16:00:15', null, null, null, '2015-11-23 16:00:15', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881b75133575b0151335fb3d2000f', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 16:04:48', null, null, null, '2015-11-23 16:04:48', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88150c5b6360150c5c0db02000b', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-02 09:12:41', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151130f110151133b65140003', '鹭游记', '用户管理', null, null, '增加《谢少军》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-17 10:17:18', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151130f110151133be1fe0005', '鹭游记', '角色管理', null, null, '增加《技术员》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-17 10:17:50', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151130f110151133c02260008', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-17 10:17:58', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151130f110151133c34d0000a', '鹭游记', '角色用户', null, null, '增加', '127.0.0.1', '业务日志异常', null, 'admin', '2015-11-17 10:18:11', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151187ede0151187f7e6c0002', '鹭游记', '菜单管理', null, null, '增加《数据维护》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 10:49:47', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151187ede0151189706930003', '鹭游记', '菜单管理', null, null, '增加《设备管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:15:29', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151187ede015118972f58000c', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:15:39', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881511898360151189bffc00002', '鹭游记', '机构管理', null, null, '增加机构《旅游集散中心》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:20:55', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881511898360151189c3d230003', '鹭游记', '机构管理', null, null, '增加机构《渠道代理商》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:21:11', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881511898360151189c8beb0004', '鹭游记', '机构管理', null, null, '增加机构《渠道合作商A》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:21:31', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881511898360151189caf660005', '鹭游记', '机构管理', null, null, '增加机构《渠道合作商B》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:21:40', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881511898360151189cc80a0006', '鹭游记', '机构管理', null, null, '增加机构《渠道合作商C》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 11:21:46', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151192410015119404a3c000c', '鹭游记', '数据字典', null, null, '增加设备属性', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-18 14:20:22', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b8815131e6fd0151320022ed0003', '鹭游记', '菜单管理', null, null, '增加《规则管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 09:40:48', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b8815131e6fd015132004a29000d', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 09:40:58', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b8815131e6fd0151321df4dc000f', '鹭游记', '数据字典', null, null, '增加设备属性', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 10:13:22', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151325dde01513260c0be0003', '鹭游记', '用户管理', null, null, '删除《谢少军》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-11-23 11:26:20', null, null, null, null, null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881516bb15401516bc51cc10004', '鹭游记', '菜单管理', null, null, '增加《附件管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-04 14:54:18', null, null, null, '2015-12-04 14:54:18', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881516bb15401516bc54b660014', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-04 14:54:30', null, null, null, '2015-12-04 14:54:30', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881516bb15401516bc588b10015', '鹭游记', '菜单管理', null, null, '增加《附件管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-04 14:54:46', null, null, null, '2015-12-04 14:54:46', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a12ca860002', '鹭游记', '菜单管理', null, null, '删除《消费明细》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:33:50', null, null, null, '2015-12-07 09:33:50', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a12f0a20003', '鹭游记', '菜单管理', null, null, '删除《规则管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:34:00', null, null, null, '2015-12-07 09:34:00', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a1301790004', '鹭游记', '菜单管理', null, null, '删除《设备管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:34:04', null, null, null, '2015-12-07 09:34:04', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a130e770005', '鹭游记', '菜单管理', null, null, '删除《商户活动》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:34:07', null, null, null, '2015-12-07 09:34:07', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a131e090006', '鹭游记', '菜单管理', null, null, '删除《商户管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:34:11', null, null, null, '2015-12-07 09:34:11', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a1330b40007', '鹭游记', '菜单管理', null, null, '删除《租赁管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:34:16', null, null, null, '2015-12-07 09:34:16', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a141cda0009', '鹭游记', '菜单管理', null, null, '增加《广告管理》', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:35:17', null, null, null, '2015-12-07 09:35:17', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517a10c701517a1448040014', '鹭游记', '角色菜单', null, null, '增加角色菜单关联', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 09:35:28', null, null, null, '2015-12-07 09:35:28', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b2cac01517b30391c0002', '鹭游记', '数据字典', null, null, '增加短信模板', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 14:45:36', null, null, null, '2015-12-07 14:45:36', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b2cac01517b3116d70003', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-07 14:46:33', null, null, null, '2015-12-07 14:46:33', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b2cac01517b3209570004', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 14:47:35', null, null, null, '2015-12-07 14:47:35', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b2cac01517b3262a60005', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 14:47:58', null, null, null, '2015-12-07 14:47:58', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b356d01517b3600780002', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-07 14:51:55', null, null, null, '2015-12-07 14:51:55', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b356d01517b376ddd0003', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-07 14:53:28', null, null, null, '2015-12-07 14:53:28', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b356d01517b3902dd0004', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 14:55:12', null, null, null, '2015-12-07 14:55:12', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b3e68800003', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:01:06', null, null, null, '2015-12-07 15:01:06', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b3fad950004', 'DU手环', '附件管理', null, null, '删除附件《20151207150100DgiI.jpg》', '127.0.0.1', '业务日志正常正常', null, 'admin', '2015-12-07 15:02:29', null, null, null, '2015-12-07 15:02:29', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b40dc900006', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:03:47', null, null, null, '2015-12-07 15:03:47', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b415adf0007', 'DU手环', '附件管理', null, null, '删除附件《201512071503100Mbc.jpg》', '127.0.0.1', '业务日志正常正常', null, 'admin', '2015-12-07 15:04:19', null, null, null, '2015-12-07 15:04:19', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b356d01517b47ed0c0005', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-07 15:11:30', null, null, null, '2015-12-07 15:11:30', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b356d01517b4a79c60006', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 15:14:17', null, null, null, '2015-12-07 15:14:17', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f8517b356d01517b4ae6990007', '鹭游记', '数据字典', null, null, '增加APP版本', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-07 15:14:44', null, null, null, '2015-12-07 15:14:45', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b51f44f0009', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:22:27', null, null, null, '2015-12-07 15:22:27', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b57ff31000a', 'DU手环', '附件管理', null, null, '删除附件《20151207152222B7Ye.jpg》', '127.0.0.1', '业务日志正常正常', null, 'admin', '2015-12-07 15:29:03', null, null, null, '2015-12-07 15:29:03', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b58535a000c', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:29:24', null, null, null, '2015-12-07 15:29:24', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b5c8d19000e', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:34:01', null, null, null, '2015-12-07 15:34:01', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b6215f80010', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:40:04', null, null, null, '2015-12-07 15:40:04', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b62bfc70012', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:40:47', null, null, null, '2015-12-07 15:40:47', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b6bad690014', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:50:32', null, null, null, '2015-12-07 15:50:33', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b6bd1b60016', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:50:41', null, null, null, '2015-12-07 15:50:42', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517b3d7b01517b6c074f0018', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 15:50:56', null, null, null, '2015-12-07 15:50:56', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c48157c0003', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:51:17', null, null, null, '2015-12-07 19:51:17', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c48649c0004', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:51:37', null, null, null, '2015-12-07 19:51:37', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c48b9830007', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:51:59', null, null, null, '2015-12-07 19:51:59', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c48d2fe0008', 'DU手环', '附件管理', null, null, '删除附件《20151207195158qiBT.png》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-07 19:52:06', null, null, null, '2015-12-07 19:52:06', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c4918190009', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:52:23', null, null, null, '2015-12-07 19:52:23', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c49348d000a', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:52:31', null, null, null, '2015-12-07 19:52:31', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c49e022000b', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:53:14', null, null, null, '2015-12-07 19:53:15', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c49fec2000c', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:53:22', null, null, null, '2015-12-07 19:53:22', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c4c29b2000e', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:55:44', null, null, null, '2015-12-07 19:55:44', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c4daad7000f', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:57:23', null, null, null, '2015-12-07 19:57:23', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c4df4550012', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:57:42', null, null, null, '2015-12-07 19:57:42', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402880f0517c2d2b01517c5003820014', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 19:59:57', null, null, null, '2015-12-07 19:59:57', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517c41ab01517c51dc1a0003', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 20:01:58', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-07 20:01:58', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517c41ab01517c56f5c30005', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 20:07:32', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-07 20:07:32', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517c41ab01517c5890ad0007', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 20:09:17', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-07 20:09:17', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517c41ab01517c58c6d00008', 'DU手环', '附件管理', null, null, '删除附件《20151207200917TRTL.jpg》', '127.0.0.1', '业务日志正常正常', null, 'admin', '2015-12-07 20:09:31', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-07 20:09:31', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b881517c41ab01517c58d984000a', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-07 20:09:36', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-07 20:09:36', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c64ff01517c65b1520002', 'DU手环', '附件管理', null, null, '增加《bizGood》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 20:23:37', null, null, null, '2015-12-07 20:23:38', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c64ff01517c66d1c60004', 'DU手环', '附件管理', null, null, '增加《bizGood》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 20:24:51', null, null, null, '2015-12-07 20:24:51', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c64ff01517c673e420006', 'DU手环', '附件管理', null, null, '删除附件《201512072025013USS.png》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-07 20:25:19', null, null, null, '2015-12-07 20:25:19', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c64ff01517c6741400007', 'DU手环', '附件管理', null, null, '删除附件《20151207202345efcd.png》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-07 20:25:20', null, null, null, '2015-12-07 20:25:20', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c64ff01517c6896b80009', 'DU手环', '附件管理', null, null, '删除附件《20151207202531R9Ha.png》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-07 20:26:47', null, null, null, '2015-12-07 20:26:47', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c64ff01517c69872f000b', 'DU手环', '附件管理', null, null, '增加《bizGood》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 20:27:49', null, null, null, '2015-12-07 20:27:49', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c6c7501517c6d2af00002', 'DU手环', '附件管理', null, null, '增加《bizGood》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 20:31:47', null, null, null, '2015-12-07 20:31:47', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c6c7501517c6db9e10004', 'DU手环', '附件管理', null, null, '删除附件《20151207203153HOds.png》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-07 20:32:24', null, null, null, '2015-12-07 20:32:24', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c726101517c73c22c0003', 'DU手环', '附件管理', null, null, '增加《bizGood》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 20:38:59', null, null, null, '2015-12-07 20:38:59', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517c726101517c7b66da000a', 'DU手环', '附件管理', null, null, '增加《BizGood》', '0:0:0:0:0:0:0:1', '业务日志异常正常', null, 'admin', '2015-12-07 20:47:20', null, null, null, '2015-12-07 20:47:20', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517f144301517f2665e50002', 'DU手环', '附件管理', null, null, '删除附件《20151207204144CRAg.jpg》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-08 09:13:21', null, null, null, '2015-12-08 09:13:21', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881aa517f144301517f27c5d20003', 'DU手环', '附件管理', null, null, '删除附件《201512072040179CVb.jpg》', '0:0:0:0:0:0:0:1', '业务日志正常正常', null, 'admin', '2015-12-08 09:14:51', null, null, null, '2015-12-08 09:14:51', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b8815180820901518095b68b0003', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 15:54:33', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 15:54:33', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180a1e7760004', 'DU手环', '附件管理', null, null, '删除附件《20151208155037Yt7Q.jpg》', '127.0.0.1', '业务日志正常正常', null, 'admin', '2015-12-08 16:07:52', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:07:52', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180a269560006', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 16:08:26', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:08:26', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180bca89a0007', 'DU手环', '附件管理', null, null, '删除附件《20151208160811lEvZ.jpg》', '127.0.0.1', '业务日志正常正常', null, 'admin', '2015-12-08 16:37:06', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:37:06', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180bcde1a0009', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 16:37:20', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:37:20', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180bea408000b', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 16:39:16', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:39:16', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180c03a2d000d', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 16:41:00', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:41:00', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b88151808209015180c2d00f000f', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 16:43:49', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:43:49', null, null, null, '0');
INSERT INTO `app_log` VALUES ('4028b8815180c769015180c8d65c0004', 'DU手环', '附件管理', null, null, '增加《BizAdvertisement》', '127.0.0.1', '业务日志异常正常', null, 'admin', '2015-12-08 16:50:24', null, 'admin', '4028811535a946930135a9527ee60013', '2015-12-08 16:50:24', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a071e20003', '鹭游记', '数据字典', null, null, '增加DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:02:52', null, null, null, '2015-12-10 10:02:52', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a3c51c0004', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:06:30', null, null, null, '2015-12-10 10:06:30', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a40bd60006', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:06:48', null, null, null, '2015-12-10 10:06:48', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a4550d0008', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:07:07', null, null, null, '2015-12-10 10:07:07', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a48d6c000a', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:07:21', null, null, null, '2015-12-10 10:07:21', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a550d1000b', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:08:11', null, null, null, '2015-12-10 10:08:11', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a5a5f2000c', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:08:33', null, null, null, '2015-12-10 10:08:33', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a5f04a000e', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:08:52', null, null, null, '2015-12-10 10:08:52', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a6468f0010', '鹭游记', '数据字典', null, null, '增加新手任务获取DU币', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:09:14', null, null, null, '2015-12-10 10:09:14', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a75cfe0012', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:10:25', null, null, null, '2015-12-10 10:10:25', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a78bfe0013', '鹭游记', '数据字典', null, null, '增加新手任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:10:37', null, null, null, '2015-12-10 10:10:37', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189a807cd0014', '鹭游记', '数据字典', null, null, '增加新手任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:11:09', null, null, null, '2015-12-10 10:11:09', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189af23aa0016', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:18:55', null, null, null, '2015-12-10 10:18:55', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189af829a0017', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-10 10:19:19', null, null, null, '2015-12-10 10:19:19', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b01fb70019', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:19:59', null, null, null, '2015-12-10 10:19:59', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b0485c001a', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-10 10:20:10', null, null, null, '2015-12-10 10:20:10', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b125d7001c', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:21:06', null, null, null, '2015-12-10 10:21:06', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b1701e001d', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-10 10:21:25', null, null, null, '2015-12-10 10:21:25', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b18d41001e', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-10 10:21:33', null, null, null, '2015-12-10 10:21:33', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b1ce410020', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:21:50', null, null, null, '2015-12-10 10:21:50', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b1ed870022', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:21:58', null, null, null, '2015-12-10 10:21:58', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b287f60024', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:22:37', null, null, null, '2015-12-10 10:22:37', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b2a8c80025', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志异常', null, 'admin', '2015-12-10 10:22:45', null, null, null, '2015-12-10 10:22:45', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189b327880027', '鹭游记', '数据字典', null, null, '增加日常任务', '127.0.0.1', '业务日志正常', null, 'admin', '2015-12-10 10:23:18', null, null, null, '2015-12-10 10:23:18', null, null, null, '0');
INSERT INTO `app_log` VALUES ('402881915189978f015189cc9c9c0029', 'DU

修复方案:

整理的好累,亲,我是来找礼物的.

版权声明:转载请注明来源 带头大哥@乌云


漏洞回应

厂商回应:

危害等级:中

漏洞Rank:8

确认时间:2016-04-07 14:46

厂商回复:

感谢提醒, 已转交信息安全部处理

最新状态:

暂无


漏洞评价:

评价

  1. 2016-03-29 16:27 | 疯狗 认证白帽子 ( 实习白帽子 | Rank:44 漏洞数:2 | 阅尽天下漏洞,心中自然无码。)

    支付手环~

  2. 2016-04-07 14:49 | zmx ( 普通白帽子 | Rank:164 漏洞数:42 | wooyun)

    我猜是遍历

  3. 2016-04-07 14:51 | 带头大哥 ( 普通白帽子 | Rank:786 漏洞数:231 | |任意邮件伪造| |目录遍历| |任意文件读取|...)

    8rank?笑死。 。 。厂商会评分不?至少15rank➕礼物一份!