ثغره phpSitemapNG جاهز للاختراق

البحث كتالي
 phpSitemapNG create your personal google sitemap file
 create your personal google sitemap file
 This script is licensed under GPL
  
 تنزيل السكربت 
 شرح التثبيت
 Installation
 Installation phpSitemapNG 1.5.x
 Download the current release and store it on your harddisc
 Create a directory on your webserver (suggestion: /admin/phpsitemapng) and protect it with a .htaccess file
 Extract this archive and copy the files to this directory on your website, copy sitemap.xml and sitemap.xml.gz into the root directory of your website.
 Make the following files writable (chmod 0666):
 /sitemap.xml (- or /sitemap.xml.gz for compressed sitemap)
 /sitemap.txt (if you would like to write txt sitemaps files)
 settings/settings.inc.php (to store your settings)
 settings/files.inc.php – (store information about generated sitemap; only useful for small websites)
 That’s it, you can proceed with the usage of phpSitemapNG
 Installation of phpSitemapNG 1.6.x / kiting
 Just follow these steps to install phpSitemapNG
 Download the latest development release from the phpSitemapNG download section
 Extract this zip archive and copy the phpSitemapNG directory to your website
 Modify the attributes of the directory phpSitemapNG/tmp/ to 777 – all information of phpSitemapNG will be stored into this directory. Maybe this is not necessary – but this depends on your webhoster
 That’s it. Now read how to use phpSitemapNG “kiting” release
تم الاختراق dbcupload.net من اكتشافي الدخول بالصوره
من اكتشافي ^_^ بس ما عرفت اسم السكربت
شاك بهذا <<<<<<<<< by Musawir
او opensource design
بما ان السكربت مربوط معه هذا
phpFormGenerator v2.0 Admin Portal
الطريقه سهله
روابط البحث كتاليUploading Form
folder/use/upload/form1.html
use/upload/form1.html
upload/form1.html
او
الرفع يكون كذا شاهد الصوره
http://imghouse.us/images/0/300/oOOOohkrkoz_0.gif
الصوره الثانيه مهمه بعد ما ترفع : ترجع بمثال الرابط
http://dbcupload.net/folder/use/upload/
وتختار ملف
files/
لبحث عن رفعك اذا شه يسيطر على الوضع اذا صفحه : بعد تسيطر
شاهد الصوره
http://imghouse.us/images/0/301/oOOOohkrkoz_1.gif
شاهد الاختراق لتأكد
http://www.zone-h.org/component/option,com_mirrorwrp/Itemid,160/id,6700320/
بس الباقي عليكم
نواصل بالجديد
http://dbcupload.net/folder/use/upload/files/01_02_20_hKrKoz.php
phpFormGenerator is an easy-to-use tool to create reliable and efficient web forms. No programming of any sort is required. It has the ability to create up to 100 form fields, and to add a variety of field types including text boxes, drop down selection menus, check boxes, radio buttons, and freeform text areas. All field types are highly customizable. The form data can be sent to a provided email address, or stored in a database table (currently MySQL).
السكربت يحمل التالي من الملفات
Index of /formato/forms
Parent Directory admin/
bc_new.gif
button.jpg
files/
form1.html form2.html
global.inc.php
nav_m.gif
process.php
tile_back.gif
tile_sub.gif
الاختراق يتم بهذا <<<
forms\form1.html
والامر المضمون بالبحث عن مركبين السكربت جرب هذا
02_42_28_haar.html
و
phpFormGenerator installation verification
install phpFormGenerator
تنزيل البرمجه وهي بعده اصدارات : وهنا نقطه الانتبااااه
كمثال الملف ينزل بهذا الشكل
phpFormGen-php-2.0.tar
Index of /admin/phpsitemapng
/home4/itbjccom/public_html/
admin/phpsitemapng
var $log_path = 'D:\\web\\serveur\\xampp\\htdocs\\joomftcyclisme\\logs';
var $tmp_path = 'D:\\web\\serveur\\xampp\\htdocs\\joomftcyclisme\\tmp';
admin/phpSitemapNG/phpinfo.php
http://www.mageks-v.com/admin/phpSitemapNG/index.php?action=setup

إرسال تعليق

أحدث أقدم