Compromising plasma botnets 03-28-2014, 02:52 PM
#1
Special thanks to @Hellborn for providing some of this information.
Okay so this is more of admin stupidity then a vulnerability, like the merge dir for mybb or the install for vbulletin.
First, you're gonna need to find some plasma URLs, if you dont have one, try using a google dork like
"inurl:plasma/login.php"
or you can go to http://cybercrime-tracker.net/index.php?search=plasma where people report the login pages.
After you have a target website, simply replace login.php with install.php and create a new account, then go back to login.php and login.
This rarely works, but its pretty cool when it does.
So again thanks hellborn.
Okay so this is more of admin stupidity then a vulnerability, like the merge dir for mybb or the install for vbulletin.
First, you're gonna need to find some plasma URLs, if you dont have one, try using a google dork like
"inurl:plasma/login.php"
or you can go to http://cybercrime-tracker.net/index.php?search=plasma where people report the login pages.
After you have a target website, simply replace login.php with install.php and create a new account, then go back to login.php and login.
This rarely works, but its pretty cool when it does.
So again thanks hellborn.
Wavy baby





![[+]](https://sinister.li/images/modern/collapse_collapsed.png)



![[Image: xlbdwZT.png]](http://i.imgur.com/xlbdwZT.png)

I tried some of the sites on cybercrime tracker, but none of those worked. Seems like a cool method though if you could get it to work correctly. ![[Image: e41e887e66a5f51303a56eafd27ba344.png]](https://i.gyazo.com/e41e887e66a5f51303a56eafd27ba344.png)

























![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)