Showing posts with label PHP. Show all posts
Showing posts with label PHP. Show all posts

Wednesday, January 16, 2013

PDFTribute.net PDF Link Scraper - Command Line PHP Tool

[sourcecode language="php"]
function unshorten_url($url) {
$ch = curl_init($url);
curl_setopt_array($ch, array(
CURLOPT_FOLLOWLOCATION => TRUE,
CURLOPT_RETURNTRANSFER => TRUE,
CURLOPT_SSL_VERIFYHOST => FALSE,
CURLOPT_SSL_VERIFYPEER => FALSE,
));
curl_exec($ch);
$url = curl_getinfo($ch, CURLINFO_EFFECTIVE_URL);
curl_close($ch);
return $url;
}

$target_url = "http://pdftribute.net/"; // Simply add page number for a specific page ie pdftribute.net/3
$userAgent = 'Googlebot/2.1 (http://www.googlebot.com/bot.html)';

$ch = curl_init();
curl_setopt($ch, CURLOPT_USERAGENT, $userAgent);
curl_setopt($ch, CURLOPT_URL,$target_url);
curl_setopt($ch, CURLOPT_FAILONERROR, true);
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, true);
curl_setopt($ch, CURLOPT_AUTOREFERER, true);
curl_setopt($ch, CURLOPT_RETURNTRANSFER,true);
curl_setopt($ch, CURLOPT_TIMEOUT, 10);
$html= curl_exec($ch);

$dom = new DOMDocument();
@$dom->loadHTML($html);
$xpath = new DOMXPath($dom);
$hrefs = $xpath->evaluate("/html/body//a");
$urls = array();
$pdfs = array();

for ($i = 0; $i < $hrefs->length; $i++) {
$href = $hrefs->item($i);
$url = $href->getAttribute('href');
$urls[] = $url;
}

foreach ($urls as $url)
if (substr(unshorten_url($url), -3, 3) == 'pdf') $pdfs[] = unshorten_url($url);

print_r($pdfs);
[/sourcecode]

Sunday, January 13, 2013

Stop Using MD5 - POC MD5 Hash Crack PHP Script

This is just a proof of concept of how a malicious hacker can get your password very quickly using a short script if your security is based on md5 hashing. Wake up people start using better encryption and pay attention to password strength, dictionary words for passwords are crackable in seconds. I'm not sharing the code on this one just in case some stupid kid wants to do something equally stupid with it.


http://youtu.be/ElS0ml74HqU

Wednesday, December 19, 2012

YouTube Mp3 Player Engine

If you have a YouTube channel and want to use your songs elsewhere still get views on your channel while making a custom landing page try this out. Can be tweaked to either be a simple mp3 player or a video player. Hint, pull the 'hidden' class off and style accordingly [:

Client side.


[sourcecode language="php"]
<?php require_once 'logic/controls.php'; ?>
<!DOCTYPE html>
<html lang="en">
<head><link href="styles.css"></head>
<body>
<div class="currentSong">
<p id="title"><?php echo $videos[$_SESSION['i']]['title']; ?></p>
<div id="video" class="hidden">
http://www.youtube.com/embed/
</div>
</div>
<div class="controls">
<button class="prev">Prev</button>
<button class="stop">Stop</button>
<button class="play">Play</button>
<button class="next">Next</button>
</div>
<div class="playlist">
<ul>
<?php foreach ($videos as $i => $video) : ?>
<li class="track <?php if ($_SESSION['i'] == $i){echo 'active';}?>" id="row<?php echo $i; ?>">
<span class="trackNumber"><?php echo $i + 1; ?></span>
<span class="trackTitle"><?php echo $video['title']; ?></span>
<span class="trackTime"><?php echo $video['time']; ?></span>
</li>
<?php endforeach; ?>
</ul>
</div>
<script src="//ajax.googleapis.com/ajax/libs/jquery/1.8.3/jquery.min.js"></script>
<script type="text/javascript">
function changeActive() {
$.get('logic/controls.php?getindex', function(data){
data = data.split(':');
$('li.active').removeClass('active');
$('li#row'+data[0]).addClass('active');
$('#title').html(data[1]);
});
}
function next() {
$('#video').html('');
$('#video').load('logic/controls.php?i=n' , function() {
changeActive();
});
}
function prev() {
$('#video').html('');
$('#video').load('logic/controls.php?i=p', function() {
changeActive();
});
}
function playtrack() {
$('#video').html('');
$('#video').load('logic/controls.php?i=c');
}
function stoptrack() {
$('#sontgtitle').html('');
$('#player').attr('src', '');
}
function trackByIndex(index) {
index = index.split('row')[1];
$('#video').html('');
$('#video').load('logic/controls.php?i='+index, function() {
changeActive();
});
}
$(function() {
$('.next').click(function(){next();});
$('.prev').click(function(){prev();});
$('.play').click(function(){playtrack();});
$('.stop').click(function(){stoptrack();});
$('.track').click(function(){trackByIndex($(this).attr('id'));});
});
</script>
</body>
</html>
[/sourcecode]

And on the server side for ajax calls


VIDEO should be a YouTube video id like 'cJkxyh8-KVU' TITLE is user defined, and TIME is the total seconds playtime.

[sourcecode language="php"]
<?php
session_start();

$videos = array(
array('title' => '<TITLE>', 'video' => '<VIDEO>', 'time' => '<TIME>'),
array('title' => '<TITLE>', 'video' => '<VIDEO>', 'time' => '<TIME>'),
array('title' => '<TITLE>', 'video' => '<VIDEO>', 'time' => '<TIME>'),
array('title' => '<TITLE>', 'video' => '<VIDEO>', 'time' => '<TIME>'),
array('title' => '<TITLE>', 'video' => '<VIDEO>', 'time' => '<TIME>')
);

if (!isset($_SESSION['i'])) $_SESSION['i'] = 0;
$count = count($videos) - 1;
$head = '



';

if (isset($_GET['getindex'])) {echo $_SESSION['i'].':'.$videos[$_SESSION['i']]['title'];}
if (isset($_GET['i']) && ($_GET['i'] == 'p' || $_GET['i'] == 'n' || $_GET['i'] == 'c' || is_numeric($_GET['i']))) {
if ($_GET['i'] == 'p') {
if ($_SESSION['i'] == 0) {
$_SESSION['i'] = $count;
echo $head.$videos[$_SESSION['i']]['video'].$tail;
} else {
$_SESSION['i']--;
echo $head.$videos[$_SESSION['i']]['video'].$tail;
}
} elseif ($_GET['i'] == 'n') {
if ($_SESSION['i'] == $count) {
$_SESSION['i'] = 0;
echo $head.$videos[$_SESSION['i']]['video'].$tail;
} else {
$_SESSION['i']++;
echo $head.$videos[$_SESSION['i']]['video'].$tail;
}
} elseif ($_GET['i'] == 'c') {
echo $head.$videos[$_SESSION['i']]['video'].$tail;
}

if (is_numeric($_GET['i']) && $_GET['i'] <= $count) {
$_SESSION['i'] = $_GET['i'];
echo $head.$videos[$_SESSION['i']]['video'].$tail;
}
}
[/sourcecode]
And the end result with some styling care of briguy
YouTube MP3

Wednesday, December 5, 2012

Too Many Dirs!

sick

Work I'm doing right now while sick as shit from home. Using this to make a landing page archive viewer, just save this as index.php and drop your landing page or newsletter folders in the same directory for a quick archive page [:


[sourcecode language="php"]
<?php
define('BD', '<INSERT PATH HERE>');

$_dirs = scandir(BD);
$x = 0;
foreach ($_dirs as $_dir) {
if (is_dir($_dir) && $_dir !== '.' && $_dir !== '..') {
$dirs[] = $_dir;
$inner_dir_contents = scandir(BD.$_dir);}
$x++;} $c = count($dirs);
?>

<!DOCTYPE HTML><html lang="en-US"><head>
<style type="text/css">
#nav ul{list-style: none;}
.left {background: #e0e0e0;}
body {height: 100%;background:#333;}
#nav ul li a{color: #555;font-size: 18px;padding: 3px;}
#nav ul li:hover, .active{color: #fff;background: #600;}
#nav ul li{border-bottom: 1px solid #777;line-height: 25px;}
.left p{text-align: center;color: #333;font-weight: bold;font-size: 22px;}
#nav {width:15%;float:left;height: 400px;overflow: scroll;background: white;}
#frame-container {width:82%;height:600px;float:left;border:solid 20px #fff;min-height: 100%;}
</style>
</head>
<body>
<div class="left">
<p>Past Promotions</p>
<div id="nav">
<ul>
<?php
for ($x = ($c - 1); $x >= 0; $x--)
echo '<li><a class="frame_nav" href="'.$dirs[$x].'/index.php">'.
ucwords(str_replace('-', ' ', str_replace('_', ' ', $dirs[$x])))
.'</a>';
?>
</ul>
</div>
</div>
<div id="frame-container">

</div>
<script type="text/javascript" src="https://ajax.googleapis.com/ajax/libs/jquery/1.7.2/jquery.min.js"></script>
<script type="text/javascript">
$(function() {
$('.frame_nav').click(function(e) {
$('.frame_nav').each(function(){$(this).parent().removeClass('active');});
$(this).parent().addClass('active');
e.preventDefault();
$('#frame').attr('src', $(this).attr('href'));
})
})
</script>
</body></html>
[/sourcecode]

Monday, December 3, 2012

PHP Code To Binary And Back, Eval'd

Have no clue why the fuck you'd want to do this except for some rudimentary obfuscation, but I sure as hell had fun playing around with it.
[sourcecode language="php"]
<?php
function binary_chunk($str)
{
$func = str_split($str);
$binary_chunk = '';
$l = count($func);
$x = 0;
foreach ($func as $k => $chr) {
$binary_chunk .= decbin(ord($chr));
($x == $l - 1) ?: $binary_chunk .= ' ';
$x++;
}

return $binary_chunk;
}

function decode_binary_chunk($bin)
{
$decoded_binary = '';
$binary_chunk = explode(' ',$bin);
foreach ($binary_chunk as $chunk) {
$decoded_binary .= chr(bindec($chunk));
}
return $decoded_binary;
}

$binary_chunk = binary_chunk('function add($a,$b){return $a+$b;}');
echo "\nFunction chunked to binary:\n";
echo $binary_chunk;
echo "\n\n";

$decoded_binary = decode_binary_chunk($binary_chunk);
echo "Binary chunks glued together:\n";
echo $decoded_binary;
echo "\n\n";

eval($decoded_binary);
echo "Result of decoded function add(1,1):\n";
$x = add(1,1);
echo "$x\n\n";
[/sourcecode]


Sample Output


binary-obfuscation

Wednesday, November 21, 2012

Exponents^

6 lines of PHP, over 40gb of data without hitting an infinite loop... exponents are slow in PHP.


[sourcecode language="php"]
<?php $l=33;$h=126;$n="\n";
for ($a=$l;$a<=$h;$a++) echo chr($a).$n;
for ($a=$l;$a<=$h;$a++) for ($b=$l;$b<=$h;$b++) echo chr($a).chr($b).$n;
for ($a=$l;$a<=$h;$a++) for ($b=$l;$b<=$h;$b++) for ($c=$l;$c<=$h;$c++) echo chr($a).chr($b).chr($c).$n;
for ($a=$l;$a<=$h;$a++) for ($b=$l;$b<=$h;$b++) for ($c=$l;$c<=$h;$c++) for ($d=$l;$d<=$h;$d++) echo chr($a).chr($b).chr($c).chr($d).$n;
for ($a=$l;$a<=$h;$a++) for ($b=$l;$b<=$h;$b++) for ($c=$l;$c<=$h;$c++) for ($d=$l;$d<=$h;$d++) for ($e=$l;$e<=$h;$e++) echo chr($a).chr($b).chr($c).chr($d).chr($e).$n;
[/sourcecode]

Tuesday, November 20, 2012

Data is Code and Code is Data

So I was reading a really good article on The Nature of Lisp and came across a really interesting concept. In the article Slava Akhmechet gives an example of some pretty simple xml data like so.



[sourcecode language="xml"]
<todo name="housework">
<item priority="high">Clean the house.</item>
<item priority="medium">Wash the dishes.</item>
<item priority="medium">Buy more soap.</item>
</todo>
[/sourcecode]

Nothing crazy just a todo list that could very easily be parsed and displayed in an app. Now let's step back for a second and consider a big hypothetical. Let's pretend us humans in our physical existence were controlled by computers. Now that we've brought this data into a different context we can see that this "data" could just as easily be code. When we look at a todo list we are basically looking at a set of instructions or code. Take Slava's more apparent second xml example.



[sourcecode language="xml"]
<define-function return-type="int" name="add">
<parameters>
<param type="int">arg1</param>
<param type="int">arg2</param>
</parameters>
<body>
<return>
<add value1="arg1" value2="arg2" />
</return>
</body>
</define-function>
[/sourcecode]

Now this is starting to look a bit more like a set of instructions and thats because it is. This could have just as easily been written in php as



[sourcecode language="php"]
function add($arg1, $arg2) {return $arg1 + $arg2;}
[/sourcecode]

My first thoughts seeing this was that xml could very well be an amazing platform for portable code, I'm speaking language portability here. A short scenario of the usefulness of this would go like this. I write an app in C and want to port the logic over to a web app. Instead of completely reverse engineering the C into php, I take my C source code pass it though a parser and spits out a highly formalized xml file that can then have the reverse process done on the php side. Mind you it would be a bit of an undertaking to create the xml specifications well enough to take into account the nuances of the many languages it may be de-parsed into, but the benefits would be enormous. Reusability of code is always an issue, no one likes spending 6 months on a project only to have their boss change they're mind last minute and drop the project (true story). Just some food for thought, all you programmers out there get crackin' .I expect to see the specs by next year...