主题 : 这样的报错 是攻击成功没
级别: 进士
UID: 63226
积分:2277 加为好友
威望: 22 精华: 0
主题:261 回复:571
注册时间:2014-06-13
在线时长:0
1#   发表于:2016-06-29 16:36:18  IP:58.226.*.*
java.lang.IllegalStateException: referer website uri not like 'http://.../...' pattern: 0' AND (SELECT 1417 FROM(SELECT COUNT(*),CONCAT(0x577151787550,(SELECT (CASE WHEN (1417=1417) THEN 1 ELSE 0 END)),0x564452427a76,FLOOR(RAND(0)*2))x FROM INFORMATION_SCHEMA.CHARACTER_SETS GROUP BY x)a) AND 'ezg'='ezg
at com.jeecms.cms.service.CmsSiteFlowCacheImpl.getRefererWebSite(CmsSiteFlowCacheImpl.java:388)
at com.jeecms.cms.service.CmsSiteFlowCacheImpl.getSource(CmsSiteFlowCacheImpl.java:403)
at com.jeecms.cms.service.CmsSiteFlowCacheImpl.visitAccess(CmsSiteFlowCacheImpl.java:192)
at com.jeecms.cms.service.CmsSiteFlowCacheImpl.flow(CmsSiteFlowCacheImpl.java:92)
at com.jeecms.cms.action.front.CmsSiteFlowAct.flowStatistic(CmsSiteFlowAct.java:23)
at sun.reflect.GeneratedMethodAccessor877.invoke(Unknown Source)
at sun.reflect.DelegatingMethodAccessorImpl.invoke(DelegatingMethodAccessorImpl.java:25)
at java.lang.reflect.Method.invoke(Method.java:597)
at org.springframework.web.bind.annotation.support.HandlerMethodInvoker.invokeHandlerMethod(HandlerMethodInvoker.java:176)
at org.springframework.web.servlet.mvc.annotation.AnnotationMethodHandlerAdapter.invokeHandlerMethod(AnnotationMethodHandlerAdapter.java:440)
at org.springframework.web.servlet.mvc.annotation.AnnotationMethodHandlerAdapter.handle(AnnotationMethodHandlerAdapter.java:428)
at org.springframework.web.servlet.DispatcherServlet.doDispatch(DispatcherServlet.java:925)
at org.springframework.web.servlet.DispatcherServlet.doService(DispatcherServlet.java:856)
at org.springframework.web.servlet.FrameworkServlet.processRequest(FrameworkServlet.java:936)
at org.springframework.web.servlet.FrameworkServlet.doGet(FrameworkServlet.java:827)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:617)
at org.springframework.web.servlet.FrameworkServlet.service(FrameworkServlet.java:812)
at javax.servlet.http.HttpServlet.service(HttpServlet.java:717)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:290)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at com.jeecms.common.web.XssFilter.doFilter(XssFilter.java:48)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at org.apache.shiro.web.servlet.AbstractShiroFilter.executeChain(AbstractShiroFilter.java:449)
at org.apache.shiro.web.servlet.AbstractShiroFilter$1.call(AbstractShiroFilter.java:365)
at org.apache.shiro.subject.support.SubjectCallable.doCall(SubjectCallable.java:90)
at org.apache.shiro.subject.support.SubjectCallable.call(SubjectCallable.java:83)
at org.apache.shiro.subject.support.DelegatingSubject.execute(DelegatingSubject.java:383)
at org.apache.shiro.web.servlet.AbstractShiroFilter.doFilterInternal(AbstractShiroFilter.java:362)
at org.apache.shiro.web.servlet.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:125)
at org.springframework.web.filter.DelegatingFilterProxy.invokeDelegate(DelegatingFilterProxy.java:343)
at org.springframework.web.filter.DelegatingFilterProxy.doFilter(DelegatingFilterProxy.java:260)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at org.springframework.orm.hibernate3.support.OpenSessionInViewFilter.doFilterInternal(OpenSessionInViewFilter.java:230)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at org.springframework.web.filter.CharacterEncodingFilter.doFilterInternal(CharacterEncodingFilter.java:88)
at org.springframework.web.filter.OncePerRequestFilter.doFilter(OncePerRequestFilter.java:107)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at com.jeecms.common.web.ProcessTimeFilter.doFilter(ProcessTimeFilter.java:35)
at org.apache.catalina.core.ApplicationFilterChain.internalDoFilter(ApplicationFilterChain.java:235)
at org.apache.catalina.core.ApplicationFilterChain.doFilter(ApplicationFilterChain.java:206)
at org.apache.catalina.core.StandardWrapperValve.invoke(StandardWrapperValve.java:233)
at org.apache.catalina.core.StandardContextValve.invoke(StandardContextValve.java:191)
at org.apache.catalina.core.StandardHostValve.invoke(StandardHostValve.java:127)
at org.apache.catalina.valves.ErrorReportValve.invoke(ErrorReportValve.java:102)
at org.apache.catalina.core.StandardEngineValve.invoke(StandardEngineValve.java:109)
at org.apache.catalina.connector.CoyoteAdapter.service(CoyoteAdapter.java:298)
at org.apache.coyote.http11.Http11Processor.process(Http11Processor.java:857)
at org.apache.coyote.http11.Http11Protocol$Http11ConnectionHandler.process(Http11Protocol.java:588)
at org.apache.tomcat.util.net.JIoEndpoint$Worker.run(JIoEndpoint.java:489)
at java.lang.Thread.run(Thread.java:619)
级别: 版主
UID: 70293
积分:78391 加为好友
威望: 1 精华: 0
主题:7 回复:68397
注册时间:2014-12-03
在线时长:0
2#   发表于:2016-06-29 16:38:17  IP:220.64.*.*
这我判断不了,我们服务器上应该有这种日志,但我看不到
1
级别: 进士
UID: 63226
积分:2277 加为好友
威望: 22 精华: 0
主题:261 回复:571
注册时间:2014-06-13
在线时长:0
3#   发表于:2016-06-29 16:42:06  IP:58.226.*.*
回复第2楼 按正常 逻辑 报错了  代码就运行不了  是不是 就没成功?  理性分析一下
级别: 版主
UID: 70293
积分:78391 加为好友
威望: 1 精华: 0
主题:7 回复:68397
注册时间:2014-12-03
在线时长:0
4#   发表于:2016-06-29 16:43:04  IP:220.64.*.*
应该是算拦截成功了,你那有什么功能用不了吗
1
级别: 进士
UID: 63226
积分:2277 加为好友
威望: 22 精华: 0
主题:261 回复:571
注册时间:2014-06-13
在线时长:0
5#   发表于:2016-06-29 16:49:43  IP:58.226.*.*
回复第4楼   那么多功能  谁知道阿  目前来说 服务器 没挂  这家伙 攻击了 几个小时 
级别: 版主
UID: 70293
积分:78391 加为好友
威望: 1 精华: 0
主题:7 回复:68397
注册时间:2014-12-03
在线时长:0
6#   发表于:2016-06-29 16:50:51  IP:220.64.*.*
你看下站点访问量功能,报错里的类涉及到了这个
1
级别: 进士
UID: 63226
积分:2277 加为好友
威望: 22 精华: 0
主题:261 回复:571
注册时间:2014-06-13
在线时长:0
7#   发表于:2016-06-29 16:56:53  IP:58.226.*.*
回复第6楼   哥们 我也没法测试阿
级别: 版主
UID: 70293
积分:78391 加为好友
威望: 1 精华: 0
主题:7 回复:68397
注册时间:2014-12-03
在线时长:0
8#   发表于:2016-06-29 16:57:48  IP:220.64.*.*
那我也不好说啊,应该是拦截成功了
1
1 共1页