Re: [Full-disclosure] SANS PHP Port Scanner Remote Code Execution

2013-03-05 Thread Fayyaz Ali
$host = $_POST['ip']; system(ping $host); On Wed, Mar 6, 2013 at 5:46 AM, laurent gaffie laurent.gaf...@gmail.comwrote: http://resources.infosecinstitute.com/php-build-your-own-mini-port-scanner/ Finding the vulnerability in this code is left as an exercise to the reader. PS: *Your

[Full-disclosure] sql query displaying on error

2013-01-23 Thread Fayyaz Ali
http://demo.demolink.biz/index.php?option=com_contentview=articleid=94Itemid=236 Table './demolink_ccdemo/are1s_session' is marked as crashed and should be repaired SQL=INSERT INTO `are1s_session` (`session_id`, `client_id`, `time`) VALUES ('526944509a863ca28cd0dd7763eb1e3e', 0, '1358966730')