Google Dork : inurl:customupload.html
Poc : fileupload.html
Author : NoEntryPhc
SQL injection vulnreblity :
Goto Google.com and Type this dork : inurl:customupload.html now see results
Goto Google.com and Type this dork : inurl:customupload.html now see results
you'll get something like this http://www.site.com/customupload.html?category=5
now simple put ' sign to check SQL injection vulnreblity
if any error like Warning: Mysql then its vulnreable to Sql injection, now get admin password with Manuall sql injection or use any tool like Havij, SQLMap
Remote Shell Upload vulnreblity
Goto Google.com and Type dork inurl:customupload.html and check Search results
Goto site, n fill details like first name last name email ( dont't fill real info here)
To view your uploaded files Goto /fileuploads/ directory and check your file there
Live Demo :
http://www.choiceprintings.com/fileupload.html
http://www.copyplusus.com/fileupload.html
Result :
http://www.choiceprintings.com/fileuploads/hahashellphp%5e131.php
===============================================
Google Dork: inurl: costumupload.html
Poc: fileupload.html
Penulis: NoEntryPhc
SQL injection vulnreblity:
Pergi ke Google.com dan Ketik dork: inurl: customupload.html sekarang melihat hasil
Anda akan mendapatkan sesuatu seperti ini http://www.site.com/customupload.html?category=5
put sekarang sederhana 'tanda untuk memeriksa vulnreblity injeksi SQL
jika ada kesalahan seperti Peringatan: Mysql kemudian yang vulnreable untuk injeksi Sql, sekarang mendapatkan password admin dengan injeksi sql manuall atau menggunakan alat seperti Havij, SqlMap
Remote Shell Upload vulnreblity
Pergi ke Google.com dan Jenis inurl dork: customupload.html dan memeriksa hasil Pencarian
Pergi ke situs, n mengisi rincian seperti nama depan nama belakang email (tidak mengisi informasi nyata di sini)
sekarang dalam lampiran meng-upload Anda php shell
Untuk melihat file upload Ke / fileuploads / direktori dan memeriksa file Anda di sana
Live Demo:
http://www.choiceprintings.com/fileupload.html
http://www.copyplusus.com/fileupload.html
hasil:
http://www.choiceprintings.com/fileuploads/hahashellphp% 5e131.php
http://www.choiceprintings.com/fileuploads/hahashellphp%5e131.php
===============================================
Google Dork: inurl: costumupload.html
Poc: fileupload.html
Penulis: NoEntryPhc
SQL injection vulnreblity:
Pergi ke Google.com dan Ketik dork: inurl: customupload.html sekarang melihat hasil
Anda akan mendapatkan sesuatu seperti ini http://www.site.com/customupload.html?category=5
put sekarang sederhana 'tanda untuk memeriksa vulnreblity injeksi SQL
jika ada kesalahan seperti Peringatan: Mysql kemudian yang vulnreable untuk injeksi Sql, sekarang mendapatkan password admin dengan injeksi sql manuall atau menggunakan alat seperti Havij, SqlMap
Remote Shell Upload vulnreblity
Pergi ke Google.com dan Jenis inurl dork: customupload.html dan memeriksa hasil Pencarian
Pergi ke situs, n mengisi rincian seperti nama depan nama belakang email (tidak mengisi informasi nyata di sini)
sekarang dalam lampiran meng-upload Anda php shell
Untuk melihat file upload Ke / fileuploads / direktori dan memeriksa file Anda di sana
Live Demo:
http://www.choiceprintings.com/fileupload.html
http://www.copyplusus.com/fileupload.html
hasil:
http://www.choiceprintings.com/fileuploads/hahashellphp% 5e131.php
Tidak ada komentar:
Posting Komentar