Pages

Showing posts with label shell. Show all posts
Showing posts with label shell. Show all posts

Thursday, March 22, 2012

PHP : LFI server Scanner by Lagripe-Dz

 LFI ServerScanner

cyber_security1.jpg (400×300) 
Scan Server Site Trying 2 Find LFI bug

Tool w0rk with 2 marks

first : [ daemon ] it's in /etc/passwd file
second : [ failed to open stream ] when there's opening error in the page

this's result pic :

it's easy 2 use

Download Video

"Testing Image collection" shell and files upload vulnrablity

Dorks : inurl:"modules/filemanagermodule/actions/?picker.php??id=0"
           intitle:"Testing Image Collections"

Goto Google or Bing and Type Dork  inurl:"modules/filemanagermodule/actions/?picker.php??id=0" or intitle:"Testing Image Collections" 
 
now see search results in google or bing search ..
select any site from search results and look for upload option 
here is demo of upload button : 
image_2326254.original.jpg (374×39)
Now select your shell or deface page and upload it
To view your upload shell or deface go to:
http://website.com/files/yourfilehere  or
http://websites.com/path/yourfilehere
Live Demo :
http://www.bantamorloff.co.uk/modules/filemanagermodule/actions/picker.php?id=&highlight_file=472
result :  http://www.bantamorloff.co.uk/files/backlinks.html
other live examples : 


http://www.admiralfc.co.uk/modules/filemanagermodule/actions/picker.php?id=0 
http://www.dogandduckfc.com/newsite/modules/filemanagermodule/actions/picker.php?id=0

"Tmedit Popuop" Deface and Shell upload vulnerability


"Tmedit Popuop" Deface and Shell upload vulnerability

zac+efron+2012.jpg (642×374)

Dork: inurl:/editor/tmedit/popups
Exploit Path : /editor/tmedit/popups/InsertFile/insert_file.php
#start :)
open Google.com or Bing.com and type this dork inurl:/editor/tmedit/popups
i got 9740 vulnrable results, now select any site from seacrh result and look for upload option on that Page now upload you shell, deface page, or anyfile there,
After uploading your  file  you'll see your uploaded file's url there, if you are not getting any perview url then goto /images directory to view your uploaded file 
for example : http://vulnrablesite.com/images/yourfilehere
Live Demo : 
http://www.arabicthailand.com/editor/tmedit/popups/insert_image_en.php
http://www.masjidklangchachengsao.com/editor/tmedit/popups/InsertFile/insert_file.php