Jumat, 22 Februari 2013

"Custom Upload" Sql injection remote php shell upload vulnreblity

Google Dork : inurl:customupload.html

Poc : fileupload.html
Author : NoEntryPhc

SQL injection vulnreblity : 
Goto Google.com and Type this dork  : inurl:customupload.html now see results 
you'll get something like this http://www.site.com/customupload.html?category=5
now simple put ' sign to check SQL injection vulnreblity
if any error like Warning: Mysql then its vulnreable to Sql injection, now get admin password with Manuall sql injection or use any tool like Havij, SQLMap

Remote Shell Upload vulnreblity
Goto Google.com and Type dork inurl:customupload.html and check Search results 
Goto site, n fill details like first name last name email ( dont't fill real info here)
now in attachment upload your php shell 
To view your uploaded files Goto /fileuploads/ directory and check your file there
Live Demo :
http://www.choiceprintings.com/fileupload.html
http://www.copyplusus.com/fileupload.html
Result :
http://www.choiceprintings.com/fileuploads/hahashellphp%5e131.php

===============================================
Google Dork: inurl: costumupload.html
Poc: fileupload.html
Penulis: NoEntryPhc

SQL injection vulnreblity:
Pergi ke Google.com dan Ketik dork: inurl: customupload.html sekarang melihat hasil
Anda akan mendapatkan sesuatu seperti ini http://www.site.com/customupload.html?category=5
put sekarang sederhana 'tanda untuk memeriksa vulnreblity injeksi SQL
jika ada kesalahan seperti Peringatan: Mysql kemudian yang vulnreable untuk injeksi Sql, sekarang mendapatkan password admin dengan injeksi sql manuall atau menggunakan alat seperti Havij, SqlMap

Remote Shell Upload vulnreblity
Pergi ke Google.com dan Jenis inurl dork: customupload.html dan memeriksa hasil Pencarian
Pergi ke situs, n mengisi rincian seperti nama depan nama belakang email (tidak mengisi informasi nyata di sini)
sekarang dalam lampiran meng-upload Anda php shell
Untuk melihat file upload Ke / fileuploads / direktori dan memeriksa file Anda di sana
Live Demo:
http://www.choiceprintings.com/fileupload.html
http://www.copyplusus.com/fileupload.html
hasil:
http://www.choiceprintings.com/fileuploads/hahashellphp% 5e131.php

Tidak ada komentar:

Posting Komentar

"Custom Upload" Sql injection remote php shell upload vulnreblity

Google Dork : inurl:customupload.html Poc : fileupload.html Author : NoEntryPhc SQL injection vulnreblity :  Goto Google.com and ...