ColdFusion和Oracle SQL注入示例

gfr*_*ius 0 sql oracle coldfusion sql-injection

假设ColdFusion 10,0,13,287689和Oracle Database 11g企业版11.2.0.2.0 - 64位生产.

有了这个例子......

<cfquery name="q" datasource="ds">
    update someTable set
    #form.col#label = <cfqueryparam cfsqltype="cf_sql_varchar" value="#x#">
    where id = <cfqueryparam cfsqltype="cf_sql_decimal" value="#id#">
</cfquery>
Run Code Online (Sandbox Code Playgroud)

还假设没有数据验证检查#form.col#,如何利用它?显然,它们可能会导致查询失败并显示无效列,但由于多个语句无法在单个语句中运行,因此我没有看到任何更恶意的行为<cfquery>.所以像这样的东西不起作用......

#form.col#:

id = 1; delete from users; --comment everything else out...
Run Code Online (Sandbox Code Playgroud)

我知道使用SELECT会更容易利用联合来获取您无权查看的数据,但我对这个特定的更新语句很好奇.

Pet*_*ton 5

虽然SQL注入的传统示例涉及顺序SQL语句,但这只是用于突出显示问题的简单示例 - 如果在任何查询中的任何位置都允许使用不受保护的用户派生文本,则攻击者有可能能够使用它.

在此特定示例中,您的查询是:

update someTable
set #form.col#label = ?
where id = ?`
Run Code Online (Sandbox Code Playgroud)

滥用这很简单 - 在真实col价值前加上类似的东西:

public_column = (SELECT badly_encrypted_password 
FROM users WHERE username='admin' ), <orig_value>
Run Code Online (Sandbox Code Playgroud)

结果SQL然后是:

update someTable
set public_column = ( SELECT badly_encrypted_password FROM users WHERE username='admin' )
  , <orig_value>label = ?
where id = ?`
Run Code Online (Sandbox Code Playgroud)

当然,将该列的值设置为子查询的结果,然后在另一个区域中单独选择将无意中返回敏感数据.

或者,攻击者可能决定使用此方法简单地删除/删除数据,并且根据Oracle的SQL语法允许的内容,其他事情可能是可能的.