Terkadang masuk ke Dashboard Wordpress, terkendala dengan Upload Shell..
Cara umum spt
Install Themes/Plugins harus melewati FTP Password
![[Image: wp2.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0JAk9D7KPr2N-DGJ7f7zVNv4SpMEi5hzc-hx1yz70TO2484NMkhUXP9K-MViojNoiTCEuKsBO6KhLFsH9KS8e9MADuq0pGK56R8CM5AMjhJLNUVGxQlX-VNr4F0E21v3J0k5pT9uMP0Y/s400/wp2.png)
Editor Themes/Plugins juga nggak dijinkan
![[Image: wp1.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLzCGFq5avC-WXODYLchcUvAPjiEXTg4GhiFur1td1ZUmnkJpomSu6kW46JUHHNhcCmIuVwCGvMw1bB87kB_7NGC4IG66QdGAJXJOiPjyrmW_DXdZZS1Vaj0bhWQVbt4vXclUQXhOILr0/s400/wp1.png)
Kita akan coba melewati proteksi tersebut, dan sepanjang kasus yg saya lewati nyaris 100% berhasil.
![[Image: wp3.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizVe240gke2auikbCUr62sIFQ1w2u-lAOWaid9ZOz30VnAX8ptWbUP8UWzlIZ_qElRUQBvBnbhq54bIU-HcutcLjcZPUT90ImvA4-Vb416L0qP0OfE2EBrpMUnipX1r19TdI08e3rCyAs/s400/wp3.png)
Saat muncul identify FTP Password, berarti shell anda sudah terupload :)
Tempat Shell biasanya di
- /wp-content/uploads/shell.php
- /wp-content/uploads/YYYY/MM/shell.php
- /wp-content/upgrade/shell.php
![[Image: wp4.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6SHubu9VPbRKOo6O2ktxEFWAR577xRtdGaUnGvsw4aCQR6LBbX0WkgMx4NvCtiX6JFQV_QruuEzn1UBtIXG1Zdt1FxFnbC53reRVMF7i0Ra6L8r89xiemYpQwRnlh825ftCxGe-Fy6SU/s400/wp4.png)
#wink
![[Image: wp5.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsKcY_7bAh87dECnP6ivsV4tBvJikPJh-ExvIqfS-4njVpgqaR347uoZJtfXprNZU1O9YIMsuUwtTtKaA4IqF9pXK7U_KtYqslbFu8xwA2qO0FYH7CpONEwMXV1pjO-boyr9vrGmsfPPY/s400/wp5.png)
Lanjutannya :
http://cemengin.tv/deb.html
http://hack-db.com/374628.html
=======================================
Langsung praktek =
http://cemengin.tv/wp-login.php
username = gececi_16
password = 1122qqww
Jangan rubah password yah..., dan jangan merusak content website.
Cara umum spt
Install Themes/Plugins harus melewati FTP Password
![[Image: wp2.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh0JAk9D7KPr2N-DGJ7f7zVNv4SpMEi5hzc-hx1yz70TO2484NMkhUXP9K-MViojNoiTCEuKsBO6KhLFsH9KS8e9MADuq0pGK56R8CM5AMjhJLNUVGxQlX-VNr4F0E21v3J0k5pT9uMP0Y/s400/wp2.png)
Editor Themes/Plugins juga nggak dijinkan
![[Image: wp1.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjLzCGFq5avC-WXODYLchcUvAPjiEXTg4GhiFur1td1ZUmnkJpomSu6kW46JUHHNhcCmIuVwCGvMw1bB87kB_7NGC4IG66QdGAJXJOiPjyrmW_DXdZZS1Vaj0bhWQVbt4vXclUQXhOILr0/s400/wp1.png)
Kita akan coba melewati proteksi tersebut, dan sepanjang kasus yg saya lewati nyaris 100% berhasil.
Code:
Kembali ke upload untuk themes ex : "http://target/wp-admin/theme-install.php?tab=upload"
dan langsung aja upload shell kamu, dalam format "php"
![[Image: wp3.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizVe240gke2auikbCUr62sIFQ1w2u-lAOWaid9ZOz30VnAX8ptWbUP8UWzlIZ_qElRUQBvBnbhq54bIU-HcutcLjcZPUT90ImvA4-Vb416L0qP0OfE2EBrpMUnipX1r19TdI08e3rCyAs/s400/wp3.png)
Saat muncul identify FTP Password, berarti shell anda sudah terupload :)
Tempat Shell biasanya di
- /wp-content/uploads/shell.php
- /wp-content/uploads/YYYY/MM/shell.php
- /wp-content/upgrade/shell.php
![[Image: wp4.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh6SHubu9VPbRKOo6O2ktxEFWAR577xRtdGaUnGvsw4aCQR6LBbX0WkgMx4NvCtiX6JFQV_QruuEzn1UBtIXG1Zdt1FxFnbC53reRVMF7i0Ra6L8r89xiemYpQwRnlh825ftCxGe-Fy6SU/s400/wp4.png)
#wink
![[Image: wp5.png]](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsKcY_7bAh87dECnP6ivsV4tBvJikPJh-ExvIqfS-4njVpgqaR347uoZJtfXprNZU1O9YIMsuUwtTtKaA4IqF9pXK7U_KtYqslbFu8xwA2qO0FYH7CpONEwMXV1pjO-boyr9vrGmsfPPY/s400/wp5.png)
Lanjutannya :
http://cemengin.tv/deb.html
http://hack-db.com/374628.html
=======================================
Langsung praktek =
http://cemengin.tv/wp-login.php
username = gececi_16
password = 1122qqww
Jangan rubah password yah..., dan jangan merusak content website.
Posting Komentar