\
Powered by Blogger.

Blog Archive

Cara Deface Dengan Shell upload vulnerability

By admin → Wednesday, February 20, 2013
Langsung saja ;) 
 
Dork    :
inurl:"/?ptype=post_listing"
inurl:"/?ptype=post_event"
inurl:"/?page=property_submit"
intext:"Geo Places Theme by"
intext:"(You can upload more than one images to create image gallery on detail page)"
 

Site::
- http://site.com/?ptype=post_listing
- http://
site.com/?ptype=post_event
- http://
site.com/path/?ptype=post_listing
- http://
site.com/path/?ptype=post_event
 
Sebelumnya Rename dulu Shellmu jadi ext. jpg
cth: shell.php.jpg / shell.php;.jpg
Upload shellmu,, gunakan tamper data.  Silahkan Lihat Cara Tamper Data (Upload PHP File) 
 
 
Hasilnya bisa dilihat
- http://
site.com/wp-content/themes/GeoPlaces/images/tmp/[shellmu]
- http://
site.com/path/wp-content/themes/GeoPlaces/images/tmp/[shellmu]
 
Video Tutorial 
  
  

Post Tags:

Ichsan Bahri

I'm Ichsan. A full time web designer. I enjoy to make modern template. I love create blogger template and write about web design, blogger. Now I'm working with Themeforest. You can buy our templates from Themeforest.

No Comment to " Cara Deface Dengan Shell upload vulnerability "