From Evernote: |
[ESPC3] Web Secuity 0x09 |
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 237 to server version: 4.0.20-log
Type 'help;' or '\h' for help. Type '\c' to clear the buffer.
mysql> show databases;
+----------+
| Database |
+----------+
| mysql |
| temp |
| test |
| zboard |
| zboard2 |
+----------+
5 rows in set (0.06 sec)
Query OK, 0 rows affected (0.05 sec)
+----------+
| Database |
+----------+
| mysql |
| test |
| zboard |
| zboard2 |
+----------+
4 rows in set (0.00 sec)
Query OK, 1 row affected (0.00 sec)
mysql> show databases;
+----------+
| Database |
+----------+
| Jack2 |
| mysql |
| test |
| zboard |
| zboard2 |
+----------+
5 rows in set (0.00 sec)
Database changed
mysql> show tables;
Empty set (0.00 sec)
-> id INT,
-> title VARCHAR(20),
-> News VARCHAR(50));
Query OK, 0 rows affected (0.02 sec)
mysql> show tables;
+-----------------+
| Tables_in_Jack2 |
+-----------------+
| news |
+-----------------+
1 row in set (0.00 sec)
mysql> desc news;
+-------+-------------+------+-----+---------+-------+
| Field | Type | Null | Key | Default | Extra |
+-------+-------------+------+-----+---------+-------+
| id | int(11) | YES | | NULL | |
| title | varchar(20) | YES | | NULL | |
| News | varchar(50) | YES | | NULL | |
+-------+-------------+------+-----+---------+-------+
3 rows in set (0.00 sec)
Empty set (0.01 sec)
Query OK, 1 row affected (0.00 sec)
+------+-------+--------------+
| id | title | News |
+------+-------+--------------+
| 1 | Test1 | Yesterday is |
+------+-------+--------------+
1 row in set (0.00 sec)
+------+-------+--------------+
| id | title | News |
+------+-------+--------------+
| 1 | Test1 | Yesterday is |
| 2 | Test2 | Restart |
+------+-------+--------------+
2 rows in set (0.00 sec)
Query OK, 1 row affected (0.00 sec)
mysql> SELECT * FROM news;
+------+-------+--------------+
| id | title | News |
+------+-------+--------------+
| 1 | Test1 | Yesterday is |
+------+-------+--------------+
1 row in set (0.00 sec)
Query OK, 1 row affected (0.00 sec)
Rows matched: 1 Changed: 1 Warnings: 0
mysql> SELECT * FROM news;
+------+-------+---------+
| id | title | News |
+------+-------+---------+
| 1 | Test1 | Restart |
+------+-------+---------+
1 row in set (0.00 sec)
=> Yesterday 에서 Restart로 바뀐것을 확인할 수 있다.
Enter password:
[root@localhost root]# Starting mysqld daemon with databases from /usr/local/mysql/data
38 Query select division,headnum,arrangenum from zetyx_board_asd where division='1' order by headnum,arrangenum limit 0, 20
38 Query select * from zetyx_board_asd where (division='1' and headnum='-1' and arrangenum='0') order by headnum,arrangenum
38 Query select no,name from zetyx_admin_table where no!='1'
38 Query select count(*) from zetyx_now_connect
38 Query select count(*) from zetyx_now_connect where group_no='1'
38 Quit
/usr/local/mysql/libexec/mysqld, Version: 4.0.20-log, started with:
Tcp port: 3306 Unix socket: /tmp/mysql.sock
Time Id Command Argument
1 Init DB zboard2
1 Query delete from zetyx_now_connect where 1327147054 - logtime > 3600
1 Query select * from zetyx_admin_table where name='test'
1 Query select * from zetyx_group_table where no='1'
1 Query select count(*) from zetyx_now_connect where user_id='admin'
1 Query update zetyx_now_connect set logtime='1327147054' where user_id='admin'
1 Query select * from zetyx_member_table where user_id='admin' and password='067fdb130d7e610e'
1 Query update zetyx_board_test set download1=download1+1 where no='9'
1 Query select * from zetyx_board_test where no='9'
1 Quit
[root@localhost bbs]# vi download.php
44 mysql_query("update $t_board"."_$id set download".$filenum."= download".$filenum."+1 where no='$no'");
45
Enter password:
Welcome to the MySQL monitor. Commands end with ; or \g.
Your MySQL connection id is 3 to server version: 4.0.20-log
Type 'help;' or '\h' for help. Type '\c' to clear the buffer.
mysql> show databases;
+----------+
| Database |
+----------+
| Jack2 |
| mysql |
| test |
| zboard |
| zboard2 |
+----------+
5 rows in set (0.00 sec)
mysql> use zboard2;
Database changed
mysql> show tables;
+---------------------------+
| Tables_in_zboard2 |
+---------------------------+
| zetyx_admin_table |
| zetyx_board_category_test |
| zetyx_board_comment_test |
| zetyx_board_test |
| zetyx_division_test |
| zetyx_get_memo |
| zetyx_group_table |
| zetyx_member_table |
| zetyx_now_connect |
| zetyx_send_memo |
+---------------------------+
10 rows in set (0.00 sec)
+---------------+------------------+------+-----+---------+----------------+
| Field | Type | Null | Key | Default | Extra |
+---------------+------------------+------+-----+---------+----------------+
| no | int(20) unsigned | | PRI | NULL | auto_increment |
| division | int(10) | | MUL | 1 | |
| headnum | int(20) | | | 0 | |
| arrangenum | int(20) | | | 0 | |
| depth | int(10) unsigned | | MUL | 0 | |
| prev_no | int(20) | | MUL | 0 | |
| next_no | int(20) | | MUL | 0 | |
| father | int(20) | | MUL | 0 | |
| child | int(20) | | | 0 | |
| ismember | int(20) | | | 0 | |
| islevel | int(2) | | | 10 | |
| memo | text | YES | | NULL | |
| ip | varchar(15) | YES | | NULL | |
| password | varchar(20) | YES | | NULL | |
| name | varchar(20) | | MUL | | |
| homepage | varchar(255) | YES | | NULL | |
| email | varchar(255) | YES | | NULL | |
| subject | varchar(250) | | | | |
| use_html | char(1) | YES | | 0 | |
| reply_mail | char(1) | YES | | 0 | |
| category | int(11) | | MUL | 1 | |
| is_secret | char(1) | | | 0 | |
| sitelink1 | varchar(255) | YES | | NULL | |
| sitelink2 | varchar(255) | YES | | NULL | |
| file_name1 | varchar(255) | YES | | NULL | |
| file_name2 | varchar(255) | YES | | NULL | |
| s_file_name1 | varchar(255) | YES | | NULL | |
| s_file_name2 | varchar(255) | YES | | NULL | |
| download1 | int(11) | | MUL | 0 | |
| download2 | int(11) | | MUL | 0 | |
| reg_date | int(13) | | MUL | 0 | |
| hit | int(11) | | MUL | 0 | |
| vote | int(11) | | MUL | 0 | |
| total_comment | int(11) | | | 0 | |
| x | varchar(255) | YES | | NULL | |
| y | varchar(255) | YES | | NULL | |
+---------------+------------------+------+-----+---------+----------------+
36 rows in set (0.00 sec)
+----+----------+-----------+
| no | memo | download1 |
+----+----------+-----------+
| 9 | 다운로드 | 1 |
+----+----------+-----------+
1 row in set (0.01 sec)
Rows matched: 1 Changed: 1 Warnings: 0
mysql> SELECT no, memo, download1 FROM zetyx_board_test WHERE no='9';
+----+----------+-----------+
| no | memo | download1 |
+----+----------+-----------+
| 9 | 다운로드 | 100 |
+----+----------+-----------+
1 row in set (0.00 sec)
+----+----------+-----------+
| no | memo | download1 |
+----+----------+-----------+
| 9 | 다운로드 | 1000 |
+----+----------+-----------+
1 row in set (0.00 sec)
+-----------+
| download1 |
+-----------+
| 1000 |
| 1000 |
| 1000 |
| 1000 |
| 1000 |
| 1000 |
| 1000 |
| 1000 |
| 1000 |
+-----------+
9 rows in set (0.00 sec)
magic_quotes_gpc = Off
+-----------+
| memo |
+-----------+
| Changed!! |
+-----------+
1 row in set (0.00 sec)
'Computer Engineering > Security' 카테고리의 다른 글
[ESPC3] Web Secuity 0x0A (0) | 2012.02.01 |
---|---|
[WebScrab]WebScarab Getting Started - OWASP (0) | 2012.01.14 |
[퍼옴]2011년 주요 보안 이슈 정리 및 2012년 보안 이슈 전망 (0) | 2011.12.12 |
[ESPC]0x01 (0) | 2011.11.14 |
[ESPC]0x00 (0) | 2011.11.14 |