Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How to upload a shell and deface filter_list
Author
Message
How to upload a shell and deface #1
What we need:

1-A Shell (Will be provided)

2-A website vulnerable to SQLi

3-Image or File upload area on that Vulnerable website

So firstly download the shell here.

Download

What is Shell ?

A shell script is a script written for the shell, or command line interpreter, of an operating system. It is often considered a simple domain-specific programming language. Typical operations performed by shell scripts include file manipulation, program execution, and printing text.
This is a plain c99 shell, BUT it is Undetected so you should not get a warning from a anti virus if you download it. (update: not Undetected anymore )

I am not going to explain SQLi just how to deface.

Sql Tut- http://hackingmania.com/Blog/sql-inj...nners-tutorial

So now go get yourself a vulnerable site, hack it and get the Admin Login details and get the Admin Page address.

Now login to the admin page with the admin details you got.



Go through the admin page until you find a place where you can upload a picture (Usually a picture).

Now you have to upload the shell. Right if you don’t get an error it is all good.

Now to find the shell

Go through the site until you find any image and if you are using firefox Right

- Click on it and “Copy Image Location”

Make a new tab and paste it there.

It will probably look something like this:

http://www.example.com/images/photonamehere.jpg

So now that we know that change “/photonamehere.jpg” to “/c99ud.php.jpg” (Without Qoutes)

Now a page will come up looking like this:

igz03k How To Upload Shell and Deface Tutorial

Does probably not look like that but will look similar.

Now you have access to all the files on the site
What you want to do is now,
Find index.php or whatever the main page is, and replace it with your HTML code for your Deface Page.

Then you can either delete all the other files OR (and I recommend this) Let it redirect to the main page.

Keep in mind:

• Change Admin Username and Password

•The people have FTP access so you need to change that Password too .

•Always use a Proxy or VPN...

ONLY FOR NOOBS...
Enjoy....
[Image: Animated-GIFS-the-joker-1971583-400-233.gif]

Reply

RE: How to upload a shell and deface #2
you say me noob .. I'm sad ;(

Reply

RE: How to upload a shell and deface #3
this looks copypasted as hell and link to sqli tut is broken

Reply

RE: How to upload a shell and deface #4
anyone have good shell php for share?

Reply

RE: How to upload a shell and deface #5
anyone have good shell php for share?

Reply

RE: How to upload a shell and deface #6
For shells you can check this: http://www.r57.gen.tr/


Quote:• Change Admin Username and Password

•The people have FTP access so you need to change that Password too .

I'd say these are one of the biggest mistakes what could do after uploading shell. Now, when you have a shell uploaded, what point on changing passwords? It's like ringing bells and shouting "HEY YOU NOOBY ADMIN, I HAVE HACKED YOUR WEBSITE! SHOW ME WHAT YOU CAN DO!".
Of course admin will get his ftp account back, because you haven't locked him out from root, and then he will check what changes you have been done, maybe even rollback the website. So you will lose that shell, admin will patch his applications and that's all, in best case senario. And if you are very unlucky and admin is very mean, he will try contact your proxy server's admin and ask for logs. And then he'll get you real ip...
Well, that's just my thinking. I may be wrong. But still, changing passwords seems stupid in any case. Smile

Reply

RE: How to upload a shell and deface #7
For shells you can check this: http://www.r57.gen.tr/


Quote:• Change Admin Username and Password

•The people have FTP access so you need to change that Password too .

I'd say these are one of the biggest mistakes what could do after uploading shell. Now, when you have a shell uploaded, what point on changing passwords? It's like ringing bells and shouting "HEY YOU NOOBY ADMIN, I HAVE HACKED YOUR WEBSITE! SHOW ME WHAT YOU CAN DO!".
Of course admin will get his ftp account back, because you haven't locked him out from root, and then he will check what changes you have been done, maybe even rollback the website. So you will lose that shell, admin will patch his applications and that's all, in best case senario. And if you are very unlucky and admin is very mean, he will try contact your proxy server's admin and ask for logs. And then he'll get you real ip...
Well, that's just my thinking. I may be wrong. But still, changing passwords seems stupid in any case. Smile

Reply