Using google DORK try to find the vulnerable website.
inurl:"/portals/0"
You can also modify this google dork according to your need & requirement
I have found these 2 website vulnerable to this attack:http://www.wittur.se/
http://www.b
n00bs can also try both of these websites for testing purpose.
Open the home page and check any image which is located in /portals/0/
Check the location of the image. It should be located in /portals/0/
For e.g. in case of http://www.wittur.se ..the image is located at location- http*://www.wittur.se/Portals/0/SHM.jpg*
Rename the new image as SHM.jpg which you want to upload as a proof of you owned the system.
Now here is the exploitProviders/HtmlEditorProviders/Fck
Simply copy paste it as shown below:www.site.com/Providers/HtmlEditorP
You will see the portal where it will ask you to upload. Select the third option File ( A File On Your Site
After selecting the third option, replace the URL bar with below script
For script click here http://tinypaste.com/af8b9
After running this JAVA script, you will see the option for Upload Selected File Now select you image file which you have renamed as SHM.jpg & upload here. Go to main page and refresh...BINGGOOOOOOOOOOOO you have hacked the website.
0 comments:
Post a Comment