Pages

Subscribe:
Showing posts with label deface and shell upload vulnerability. Show all posts
Showing posts with label deface and shell upload vulnerability. Show all posts

Wednesday, March 21, 2012

Tmedit Popup Deface and Shell Upload Vulnerability

Hello today I will give you an idea of new exploits.

Google dork: inurl:/editor/tmedit/popups
Exploits: /editor/tmedit/popups/InsertFile/insert_file.php

Lets start.

1st go to google.com and search the dork  inurl:/editor/tmedit/popups . You can get some results.



Pick anyone of this. Now select your deface page and upload. After uploading click on uploaded file and you get the link.
By this way you can also upload shell.

Demo: http://www.bihap.org/uploadfiles/xd.html
             http://www.masjidklangchachengsao.com/uploadfiles/xd.html
read more "Tmedit Popup Deface and Shell Upload Vulnerability"

Wednesday, February 29, 2012

Web Hacking: Deface and Shell Upload Vulnerability

Some of sites have file upload option. You can use this vulnerability and upload your deface and shell. Let's see about this vulnerability.



Google Dork : "intext:File Upload by Encodable"

First open google.com and put intext:File Upload by Encodable in search box. You have got so many result. But all are not our vulnerable sites. You must select sites which have a title Upload a File. Open a site and you can see a upload form in the site. Give any description. You may give email address like admin@microsoft.com or leader@nasa.gov


Now choose your file and upload it.. Lolz our work already finish. After upload you need to find the link. For find the link you may try this url

/upload/files/
or /upload/userfiles/
Happy Hacking... xd 
read more "Web Hacking: Deface and Shell Upload Vulnerability"
Related Posts Plugin for WordPress, Blogger...
 

Alexa Rank

Review www.allitemz.blogspot.com on alexa.com

Total Pageviews

Your IP

what is my ip address?
back to top