LFI to RCE via access_log injection

PHP Pro Bid Blind SQL Injection Exploit


#!/usr/bin/perl

#
# [o] PHP Pro Bid Blind SQL Injection Exploit
#
# Software : Professional Auction Script Software by PHP Pro Bid
# Vendor : http://www.phpprobid.com/
# Author : NoGe
# Contact : noge[dot]code[at]gmail[dot]com
# Blog : http://evilc0de.blogspot.com
# Home : http://antisecurity.org
#
# [o] Usage
#
# root@noge:~# perl bid.txt
#
# [x]=======================================[x]
# | PHP Pro Bid Blind SQL Injection Exploit |
# | [F]ound by NoGe |
# [x]=======================================[x]
#
# [+] URL Path : www.target.com
# [+] Valid ID : 100015
#
# [!] Exploiting http://www.target.com/ ...
#
# [+] SELECT password FROM probid_admin LIMIT 0,1 ...
# [+] result> 3a5e10d2fcd005feefbbb38a24f2c51d
#
# [!] Exploit completed.
#
# root@noge:~#
#
# [o] Greetz
#
# Anti Security [ http://antisecurity.org ]
# Vrs-hCk OoN_BoY Paman bL4Ck_3n91n3 Angela Zhang aJe
# H312Y yooogy mousekill }^-^{ zxvf martfella noname
# skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke s4va
#
# [o] Note
#
# FUCK MALAYSIA!!!
# DON'T YOU HAVE YOUR OWN CULTURE?
# AHH I FORGOT.. YOU DON'T HAVE ANY CULTURE. HAHAHAHA...
#

read more follow link below brotha..

http://antisecurity.org/php-pro-bid-blind-sql-injection-exploit.antisecurity

blogspot not allowed open tags. -_-



./NoGe

Comments

labatterie said…
PHP Pro Bid Blind SQL Injection Exploit?