The Cache: Technology Expert's Forum
 
*
Welcome, Guest. Please login or register. September 16, 2019, 05:16:40 PM

Login with username, password and session length


Pages: [1]
  Print  
Author Topic: View PHP file's REAL source code !  (Read 3133 times)
NYDAz
Expert
****
Offline Offline

Posts: 212

The Night Stalker


View Profile
« on: April 24, 2009, 02:47:56 PM »

Guys can you point me in the right direction ? 

I want to view the REAL source code of an php file from a website !

I know that php is a server-side script so when I've tried with View Source in Mozilla i've seen only bullshits !

Now I've tried with file_get_contents like below :

Code:
<?php
// http://www.example.com/test.php
$file file_get_contents ("http://www.example.com/test.php");
echo 
$file;
?>


loaded in my localhost and got nothing!

 Need Help
Logged

what's up?
perkiset
Olde World Hacker
Administrator
Lifer
*****
Offline Offline

Posts: 10096



View Profile
« Reply #1 on: April 24, 2009, 03:07:44 PM »

You will not be able to view the source code unless the apache module has phps defined... try doing a pull for (thesite)/theFile.phps - if they've opened that portal then you'll be able to see the source, rather than having the php interpreter get the code and execute it.

But even then, if they have some tricky stuff going on you will not be able to view the source code. It is actually unlikely that they would have that portal open.
Logged

It is now believed, that after having lived in one compound with 3 wives and never leaving the house for 5 years, Bin Laden called the U.S. Navy Seals himself.
NYDAz
Expert
****
Offline Offline

Posts: 212

The Night Stalker


View Profile
« Reply #2 on: April 24, 2009, 03:11:54 PM »

Triyed with

http://www.example.com/test.phps

Got this

Quote
Additionally, a 404 Not Found error was encountered while trying to use an ErrorDocument to handle the request.

So I think it's not vulnerable ! Right ?  Angry
Logged

what's up?
perkiset
Olde World Hacker
Administrator
Lifer
*****
Offline Offline

Posts: 10096



View Profile
« Reply #3 on: April 24, 2009, 05:50:18 PM »

Correct. Apache needs to have the .phps extension configured for it to work right. Default php install is this way, most Apache managers disable that straight away, yours truly included.

Logged

It is now believed, that after having lived in one compound with 3 wives and never leaving the house for 5 years, Bin Laden called the U.S. Navy Seals himself.
Pages: [1]
  Print  
 
Jump to:  

Perkiset's Place Home   Best of The Cache   phpMyIDE: MySQL Stored Procedures, Functions & Triggers
Politics @ Perkiset's   Pinkhat's Perspective   
cache
mart
coder
programmers
ajax
php
javascript
Powered by MySQL Powered by PHP Powered by SMF 1.1.2 | SMF © 2006-2007, Simple Machines LLC
Seo4Smf v0.2 © Webmaster's Talks


Valid XHTML 1.0! Valid CSS!