Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: UPload shell in mybb and wordpress and Hack via simlink


Senior Member

Status: Offline
Posts: 317
Date:
UPload shell in mybb and wordpress and Hack via simlink
Permalink Closed


Hie Hf it is my first tut here i hope it will help some noobs :

Lets Start:
Here I will use my site just to show you how u can upload shell in mybb sites:

Go to the admin panel :site.com/admin:

[Image: 70609712.jpg]

username:ImNotGoing To show here
pass:yourpass

Now we are inside the mybb control panel:
[Image: 90927372.jpg]

Now go to >>Themes and Style

and import this xml file:

Code:
http://hackerstown.com/hackerstownxml.zip


[Image: 84269503.jpg]

and click on Import Theme:

[Image: 53553497.jpg]

you will see this page:

[Image: 89605231.jpg]

One your xml file imported successfully go to the main page and click on usercp and click on edit option:

[Image: 36470787.jpg]

and now select your uploaded xml:

[Image: 69434754.jpg]

now you will see this up loader:

[Image: 20628871.jpg]

upload your shell and browse :


[Image: 58809002.jpg]

__

Lets do some Hacking With symlink:

Click on symlink :
[Image: 128ss.jpg]

you will see the list of all the website hosted on the same server :

[Image: 45665620.jpg]

select your target website :
I'm selection a wordpress site :
click on symlink at the right side to the domain name:
you will see something like this:
[Image: 62702259.jpg]

now click on wp-config.php /*it is for wordpress */

you will see the database name , username ,host and pass in wp-config.php note the details and click on tools over the upper side of your shell you will see a page something like this:

[Image: 51674594.jpg]

Fill it with the details u got from wp-config.php
it will change the password of the admin panel:
Once your password has been changed login into the admin panel here:
target_site_.com/wp-admin

and now go to the Appearance and edit theme:
[Image: 41726899.jpg]

select theme Im selecting twentytwelve now edit 404 Template
(404.php ) and paste your shell here:

[Image: 60586358.jpg]

and now browse your shell here:

Quote:target_site_.com/wp-content/themes/twentytwelve/404.php


I hope you understand have any question regarding security pm me.
In next tut i will show u how you can prevent your site from simlink:

Thankyou



__________________
Page 1 of 1  sorted by
 
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard