Advertisement
Spider64

WHMCS 0day Auto Exploiter <= 5.2.8

Oct 19th, 2013
2,398
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.78 KB | None | 0 0
  1. So basically, you just need to crack hashes...
  2. In some cases just Google the hash and you'd get the password. Then log in to WHMCS and....
  3.  
  4. Scanned results are also saved in a text file: WMCS-Hashes.txt
  5.  
  6.  
  7. Here is the PHP code that you must save as WHMCS-Fucker.php:
  8. http://pastebin.com/cuikqkhA
  9. Here are some sample dorks that you can use:
  10. inurl:submitticket.php site:.com
  11. inurl:submitticket.php site:.net
  12. inurl:submitticket.php site:.us
  13. inurl:submitticket.php site:.eu
  14. inurl:submitticket.php site:.org
  15. inurl:submitticket.php site:.uk
  16. intext:"Powered by WHMCompleteSolution"
  17. intext:"Powered by WHMCompleteSolution" inurl:clientarea.php
  18. inurl:announcements.php intext:"WHMCompleteSolution"
  19. intext:"Powered by WHMCS"
  20. You can derive hundreds of more dorks, using the samples above.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement