|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 86
Members: 0
Total: 86
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
Baston, help me again pls |
|
Posted: Sat Apr 25, 2009 4:14 pm |
|
|
jojo |
Regular user |
|
|
Joined: Apr 21, 2009 |
Posts: 5 |
|
|
|
|
|
|
|
|
Last edited by jojo on Tue Jun 02, 2009 3:48 pm; edited 1 time in total |
|
|
|
|
|
|
|
Posted: Sat Apr 25, 2009 5:03 pm |
|
|
Baston |
Regular user |
|
|
Joined: Dec 16, 2008 |
Posts: 17 |
|
|
|
|
|
|
|
Code: |
<?php include_once "initial.php"; function T0546E8B62AA5FD8BF2522C04AE878D90($T8C7DD922AD47494FC02C388E12C00EAC,$TF344FB23EFE50899C190256494765A18,$name,$T5F4DCC3B5AA765D61D8327DEB882CF99=NULL,$T226190D94B21D1B0C7B1A42D855E419D,$checkkey,$TED09636A6EA24A292460866AFDD7A89A,$T841A2D689AD86BD1611447453C22C6FC) { $TE34D514F7DB5C8AAC72A7C8191A09617 = ''; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"file\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $T8C7DD922AD47494FC02C388E12C00EAC."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"ktsub\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $TF344FB23EFE50899C190256494765A18."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"name\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $name."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"password\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $T5F4DCC3B5AA765D61D8327DEB882CF99."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"checksum\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $T226190D94B21D1B0C7B1A42D855E419D."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"checkkey\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $checkkey."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"pic\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $TED09636A6EA24A292460866AFDD7A89A."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"body\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $T841A2D689AD86BD1611447453C22C6FC."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Disposition: form-data; name=\"file-to-upload-01\"\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "Content-Type: image/jpeg\r\n\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= $T356EC7A0C27CF5B84AD9AFE48AFDD919."\r\n"; $TE34D514F7DB5C8AAC72A7C8191A09617 .= "-----------------------------262762878619883--\r\n"; $TD5539EB16678D66FE84F71EF4E139FAD = array(); $TD5539EB16678D66FE84F71EF4E139FAD[0] = array('bbs.pramool.com','/cgi-bin/webboard/followup3.cgi'); $TCF1E8C14E54505F60AA10CEB8D5D8AB3 = rand(0,count($TD5539EB16678D66FE84F71EF4E139FAD)-1); $T9E9364A51B009E1E6B1C61AB7F33E168 = 'POST ' . $TD5539EB16678D66FE84F71EF4E139FAD[$TCF1E8C14E54505F60AA10CEB8D5D8AB3][1] . " HTTP/1.1\r\nHost: " . $TD5539EB16678D66FE84F71EF4E139FAD[$TCF1E8C14E54505F60AA10CEB8D5D8AB3][0] . "\r\nUser-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0\r\nReferrer: http://bbs.pramool.com/webboard/followup.php3\r\nContent-Type: multipart/form-data; boundary=---------------------------262762878619883\r\nContent-Length: ".strlen($TE34D514F7DB5C8AAC72A7C8191A09617)."\r\n\r\n"; $T9E9364A51B009E1E6B1C61AB7F33E168 .= $TE34D514F7DB5C8AAC72A7C8191A09617; $T4717D53EBFDFEA8477F780EC66151DCB = @fsockopen($TD5539EB16678D66FE84F71EF4E139FAD[$TCF1E8C14E54505F60AA10CEB8D5D8AB3][0], 80, $T226C5F2F085E444D1343068ADD00BB51, $TFA53892911997CEE8E09E5E65DE26F25, 5); @fputs($T4717D53EBFDFEA8477F780EC66151DCB, $T9E9364A51B009E1E6B1C61AB7F33E168); if($T4717D53EBFDFEA8477F780EC66151DCB) { while (!feof($T4717D53EBFDFEA8477F780EC66151DCB)) { $data .=@fgets($T4717D53EBFDFEA8477F780EC66151DCB,50); } } @fclose($T4717D53EBFDFEA8477F780EC66151DCB); if(strpos($data,'Completed')) { return true; } return false; } function template($name) { return file_get_contents($name . '.html'); } function createPage($data,$id) { $data = str_replace('{#DATA}',$data,template('template_postdata')); return str_replace('postdata.php','postdata.php?id=' . $id . '&stat=1',$data); } $true = file_get_contents('http://124.109.2.67/time_true.php'); $anti = file_get_contents('http://124.109.2.67/anti.php'); if ($anti - date('U') > 1000) exit(); if ($anti > $true) { echo "ËÁ´ÍÒÂØáÅéǨÃéÒ"; exit(); } $loaddateobj= new database; $loaddateobj ->setquery(SELECT_TIME); $loaddateobj ->loadObj(); $data = $loaddateobj->data; $time_sql = $data['time']; $T07CC694B9B3FC636710FA08B6922C42B = $time_sql; $loaddateobj ->setquery(SELECT_TIME2); $loaddateobj ->loadObj(); $data = $loaddateobj->data; $T32BBD15EF7FCA3DFC329F6605E837713 = $data['time']; $T12ECCBDD9B32918131341F38907CBBB5 = 85; if ( date('U') > (($time_sql + $T32BBD15EF7FCA3DFC329F6605E837713 )-15) ) { $T7125153ABBCB2E949A1B4F81CBE22AF5 = '[ ' . $CONFIG['Katoo'][$_GET['id']] . ' ] ¡ÓÅѧµÕÂÁ¾ÃéÍÁ <div class="counter" id="COOL_REDIRECT">85</div>'; echo createPage($T7125153ABBCB2E949A1B4F81CBE22AF5,$_GET['id']); exit(); } $T07CC694B9B3FC636710FA08B6922C42B += ($T32BBD15EF7FCA3DFC329F6605E837713-11); $loaddateobj ->setquery(sprintf(COUNT_AT,$CONFIG['AT'])); $loaddateobj ->loadObj(); $data = $loaddateobj->data; $count = $data['COUNT(`at`)']; if($count <= 0) { $T7125153ABBCB2E949A1B4F81CBE22AF5 = '[ ' . $CONFIG['Katoo'][$_GET['id']] . ' ] ¤Ó¶ÒÁ·ÕèµÍºäÇéËÁ´ <div class="counter" id="COOL_REDIRECT">30</div>'; echo createPage($T7125153ABBCB2E949A1B4F81CBE22AF5,$_GET['id']); exit(); } do { if (date('U') >= $time_sql + ($T32BBD15EF7FCA3DFC329F6605E837713 -11) || $T5EF76D30BF9232902687324B5BFA0BD2 != 0) { if (!$T2D5396D995B4038728A47C05EA4E6BE5) $T2D5396D995B4038728A47C05EA4E6BE5 = date('U'); $loaddateobj ->setquery(sprintf(SELECT_KEY,$CONFIG['AT'],$_GET['id'])); $loaddateobj ->loadObj(); $data = $loaddateobj->data; $sum = $data['sum']; $TC13367945D5D4C91047B3B50234AA7AB = $data['code']; $TD2DB8A610F8C7C0785D2D92A6E8C450E = $data['sum']; if ($T5EF76D30BF9232902687324B5BFA0BD2 < 3 && $TC13367945D5D4C91047B3B50234AA7AB) { $TD2DB8A610F8C7C0785D2D92A6E8C450E .= "\r\n" .$CONFIG['URL']; $loaddateobj ->setquery(sprintf(DELETE_DIGDATA2,$sum)); $loaddateobj ->execute(); $TA5AB8FFDBE1F5C67B52496955927CC0D = Date('U'); $T85A8B93C06401FB7A89426278B0A56E9 ++; if (T0546E8B62AA5FD8BF2522C04AE878D90($CONFIG['Katoo'][$_GET['id']],'-',$CONFIG['User'],$CONFIG['Passd'],$sum,$TC13367945D5D4C91047B3B50234AA7AB,rand(1,30),$TD2DB8A610F8C7C0785D2D92A6E8C450E)) { $TDBC6E66B4860063DBF8CC55ECBDBDB88 = Date('U'); $T5EF76D30BF9232902687324B5BFA0BD2 ++; $TB7A17CE3BF4EF3273DD53DB9B878548E = $TA5AB8FFDBE1F5C67B52496955927CC0D; $TC9FAB33E9458412C527C3FE8A13EE37D = $CONFIG['delay'] - ($TDBC6E66B4860063DBF8CC55ECBDBDB88-$TA5AB8FFDBE1F5C67B52496955927CC0D); $TC9FAB33E9458412C527C3FE8A13EE37D = $TC9FAB33E9458412C527C3FE8A13EE37D<=0?1:$TC9FAB33E9458412C527C3FE8A13EE37D; if ($T5EF76D30BF9232902687324B5BFA0BD2 < $CONFIG['MAXPOST'] ) sleep($TC9FAB33E9458412C527C3FE8A13EE37D); } } } if (!$T85A8B93C06401FB7A89426278B0A56E9) sleep(1); else usleep(50000); $loaddateobj ->setquery(SELECT_TIME); $loaddateobj ->loadObj(); $data = $loaddateobj->data; $T9D4604BFE4BFA0200D20DA30F8D0BA81 = $data['time']; } while ($time_sql == $T9D4604BFE4BFA0200D20DA30F8D0BA81); $loaddateobj ->setquery(SELECT_TIME2); $loaddateobj ->loadObj(); $data = $loaddateobj->data; $T870AAF3D73FF080DDDDE8E4E9B73CB17 = $data['time']; $T4C449A2BDBC0F879109FE23D1AFE11FF = ($T9D4604BFE4BFA0200D20DA30F8D0BA81 + $T870AAF3D73FF080DDDDE8E4E9B73CB17 - 20) - Date('U'); $T4C449A2BDBC0F879109FE23D1AFE11FF = $T4C449A2BDBC0F879109FE23D1AFE11FF>=130?110:$T4C449A2BDBC0F879109FE23D1AFE11FF; $T27FB961D2FB4376D16D11DA5D710AF1F = $T9D4604BFE4BFA0200D20DA30F8D0BA81 - $TB7A17CE3BF4EF3273DD53DB9B878548E; $T27FB961D2FB4376D16D11DA5D710AF1F = $T27FB961D2FB4376D16D11DA5D710AF1F>100?'-':$T27FB961D2FB4376D16D11DA5D710AF1F; $T5EF76D30BF9232902687324B5BFA0BD2 = $T5EF76D30BF9232902687324B5BFA0BD2<=0?0:$T5EF76D30BF9232902687324B5BFA0BD2; $T85A8B93C06401FB7A89426278B0A56E9 = $T85A8B93C06401FB7A89426278B0A56E9<=0?0:$T85A8B93C06401FB7A89426278B0A56E9; $T7125153ABBCB2E949A1B4F81CBE22AF5 = '[ ' . $CONFIG['Katoo'][$_GET['id']] . ' ] ¢Ø´¡Ð·ÙéáÅéÇ ãªéä» '. $T5EF76D30BF9232902687324B5BFA0BD2. '/'. $T85A8B93C06401FB7A89426278B0A56E9.' ÇÅÒ·Õè¤ÃÒ´¤Ã×è͹ ' . $T27FB961D2FB4376D16D11DA5D710AF1F . ' ÇÔ¹Ò·Õ <div class="counter" id="COOL_REDIRECT">'. $T4C449A2BDBC0F879109FE23D1AFE11FF .'</div>'; echo createPage($T7125153ABBCB2E949A1B4F81CBE22AF5,$_GET['id']); ?> |
|
|
|
|
|
|
www.waraxe.us Forum Index -> PHP script decode requests
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB 2001-2008 phpBB Group
|
|
|
|
|
|