Sinisterly
[Local Injection][TUT] How to exploit a vulnerable site - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Tutorials (https://sinister.li/Forum-Tutorials)
+--- Thread: [Local Injection][TUT] How to exploit a vulnerable site (/Thread-Local-Injection-TUT-How-to-exploit-a-vulnerable-site)

Pages: 1 2


[Local Injection][TUT] How to exploit a vulnerable site - Quentin™ - 05-19-2012

How to exploit a vulnerable site

What is this?

This is a tutorial showing you how to exploit vulnerable sites. If you continue to read on, I suggest using this tutorial for educational purposes only.


Lets get started

First you need to find a vulnerable site. You may say how do I find these vulnerable sites, well first off go to google.com and type in

Spoiler:
Quote:admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html




Once you find a site that looks like this

[Image: 2jb4px2.jpg]


Where it says Connector change ASP to PHP


Download

Now next, download Horny Monkeys Deface Builder

Spoiler:


Virus Total - https://www.virustotal.com/file/580f4198bbb4cca8a5979f108a46392338c8f246e31bffae595d6c9e02550367/analysis/1337460492/

Once you have downloaded that Open it up, and Enter what you would like it to do.

[Image: 2q83g2w.png]

Once you have done that, click "Build" then the HTML code to the right Highlight it and press ctrl + c to copy it. Once you have copied it paste it in notepad and save it as "anything.html" to your desktop.

Time To Test Everything Out Now

Go here - www.example.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html

Once you get there change ASP to PHP. Click choose file and open the html file that you saved to your desktop. Now click upload. Once it's done, go to the site name then put the name of your file at the end of it

Spoiler:



Now your done Smile


RE: [TuT] How to exploit a vulnerable site - #Swag_mybb_import6403 - 05-19-2012

Thanks for the tutorial bruh!


RE: [TuT] How to exploit a vulnerable site - Quentin™ - 05-19-2012

No Problem man I try, Wink


RE: [TuT] How to exploit a vulnerable site - killerOfCode - 05-19-2012

This is a great share, however, I don't believe there is an easy way to find websites that have this URL. ;/


RE: [TuT] How to exploit a vulnerable site - Quentin™ - 05-19-2012

In my method it shows how, when you type in
Quote:admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html
look at all of the websites url's that look similar to the code.


RE: [TuT] How to exploit a vulnerable site - Quentin™ - 05-20-2012

I just edited this posted


RE: [TuT] How to exploit a vulnerable site - Dawnc0re - 05-20-2012

Awesome Tutorial Smile


RE: [TuT] How to exploit a vulnerable site - 1llusion - 05-20-2012

Nice tutorial, however I had to remove the links. Keep up the nice work =)


RE: [TuT] How to exploit a vulnerable site - HrDe - 05-20-2012

This tutorial really nice, g8t job bro!


RE: [TuT] How to exploit a vulnerable site - Quentin™ - 05-20-2012

(05-20-2012, 09:28 AM)HrDe Wrote: This tutorial really nice, g8t job bro!

Thanks,